Find the right OpenSSF projects that fit your situation
The OpenSSF ships 23 projects that secure open source software — but not all of them speak to every role or every problem. Start from whichever angle fits how you think.
Browse by role
Pick the persona that matches your day job to see the projects written for you.
Software Developer / Maintainer
Developer
You write and maintain the software. You need tools that shift security left — into local builds, pull-request checks, and everyday release hygiene — without slowing you down.
See their project guide
Open Source Professional (OSPO)
OSPO
You steward your organization's open source strategy. You need tools that let you set, enforce, and measure consistent security expectations across every project you touch.
See their project guide
Security Engineer / Architect
Security
You design and defend the systems around the software. You need tools that give you architectural visibility, threat-model traceability, and automated enforcement of security guarantees.
See their project guide
CI/CD DevOps & Tooling Integrator
DevOps
You own the pipelines that build, test, and ship code. You need tools that bolt cleanly into CI/CD, block unsafe dependencies, and produce verifiable artefacts at every stage.
See their project guide
Package & Repository Manager
Package Manager
You run the registries and repositories that serve software to the world. You need tools that surface trust signals to consumers and protect artefacts in flight.
See their project guide
Executive / End-User Consumer
Executive
You make procurement, compliance, and risk decisions on behalf of a larger organization. You need tools that translate supply-chain evidence into signals you can act on.
See their project guide
Browse by problem
Know the problem you're trying to solve? Start there and see which projects help.
Build & Provenance Integrity
Build Integrity
Ensuring artefacts are built from the expected source, on a trusted platform, without tampering — and that the resulting provenance is verifiable by anyone downstream.
See the projects that help
Artefact Signing & Verification
Signing
Proving who produced an artefact and confirming it has not been altered in transit, ideally without the burden of managing long-lived signing keys.
See the projects that help
Dependency & SBOM Visibility
Visibility
Knowing exactly what components ship inside your software — direct and transitive — and being able to query that inventory when something changes.
See the projects that help
Vulnerability Management
Vulnerabilities
Tracking which known vulnerabilities affect your software, sharing machine-readable exploitability status, and cutting through false positives.
See the projects that help
Secure Repository Configuration
Configuration
Keeping source repositories configured to a safe baseline — branch protection, required reviews, hardened settings — and stopping drift before it becomes an entry point.
See the projects that help
Measuring Security Posture
Posture
Quantifying how healthy and well-maintained a project is, so maintainers, consumers, and registries can compare projects and prioritise attention.
See the projects that help
Policy & Compliance Enforcement
Compliance
Defining a consistent set of security expectations and automatically enforcing them across many projects — and producing evidence for auditors and regulators.
See the projects that help
Secrets Management
Secrets
Storing, rotating, and brokering access to credentials and signing keys so they never end up hardcoded in source or leaked through a pipeline.
See the projects that help
Or browse every project
Already know the project? The project index lists all 23 and opens into the personas it serves, the problems it solves, and the projects it pairs well with.