OpenSSF Scorecard - Security health metrics for Open Source
-
Updated
Oct 2, 2026 - Go
OpenSSF Scorecard - Security health metrics for Open Source
Official GitHub Action for OpenSSF Scorecard.
Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
Dead code doesn't get patched. Detect abandoned & end-of-life dependencies that SCA tools miss — before they become the next xz-utils.
Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
Cross-ecosystem dependency maintenance auditor: flags unmaintained, archived, stale, and below-the-fix deps across the full transitive graph. Ruby gems natively; npm/pypi/cargo/go/maven/nuget via CycloneDX SBOM. Signals: activity, OpenSSF Scorecard, OSV advisories, libyear, poison-pill, runtime-ceiling. Outputs SARIF/JSON/CycloneDX with CI gates.
scir-oss is a tool that integrates public data and information regarding open source software projects and their products into a Project, Product, Protection, and Policy report (OSS-P4/R).
OpenSSF Dashboard allows you to check the OpenSSF scorecards for entire organisations and users on GitHub or Gitlab.
Scorecard action for checking when new dependencies are added to the repository.
Neurosymbolic CI/CD governance scanner for a ~400-repo estate: rule-based detection with Bayesian confidence gating, safety-triangle remediation (eliminate > substitute > control), SARIF output and machine-checked proofs.
Azure Pipelines Task for OpenSSF Scorecard
Scan Git history for repository-contained OpenSSF Scorecard security signals.
中/英自然语言找+装+改 agent skill (Claude Code / Codex) | Cross-agent skill discovery in CN/EN. 三维评分 R/U/T + OpenSSF Scorecard + OSV 漏洞库安全审 + agent-as-LLM 架构 + 三槽位版本快照.
Auditable repository-health scorecard with evidence for every point — a Claude Code agent + deterministic CLI, aligned with OpenSSF & GitHub standards. CI-ready.
A Git-native secret detection CLI with pre-commit enforcement, CI scanning, and policy-as-code validation for DevSecOps pipelines.
Secure ML release control plane with deterministic policy gates, artifact signing, Kubernetes deployment, observability, rollback, and advisory AI release intelligence.
A scaffolder that makes a new repository OSS-ready from the first commit.
🔐 Repositories security and analysis.
Reusable GitHub Actions workflow that scans your repo (or any external repo) with Semgrep, Gitleaks, OSV, Checkov, Trivy and SBOM, then emails a graded security report enriched with CISA KEV, FIRST EPSS and OpenSSF Scorecard.
To associate your repository with the openssf-scorecard topic, visit your repo's landing page and select "manage topics."