Persona view

Open Source Professional (OSPO)

You steward your organization's open source strategy. You need tools that let you set, enforce, and measure consistent security expectations across every project you touch.

Here are the 16 OpenSSF projects and publications that address the OSPO persona, each with a one-sentence action written for the role. Prefer another way in? Browse by problem →

Best Practices Badge

Mandates the achievement of the badge across internal open source projects to demonstrate a commitment to security and quality.

Bomctl

Normalizes SBOMs arriving in mixed formats into a consistent inventory the organization can track across every project.

Criticality Score

Utilizes the criticality score to prioritize resource allocation and security audits for the most crucial dependencies used within the enterprise.

Gemara

Expresses the organization's controls and compliance requirements in Gemara's shared model so they can be assessed consistently across projects.

gittuf

Applies consistent, forge-independent repository security policy across projects regardless of which Git host each one uses.

GUAC

Leverages GUAC to maintain a comprehensive, queryable graph of software supply chain metadata across all enterprise projects.

Minder

Deploys Minder to establish and continuously verify standardized security policies across all internal and open source project portfolios.

OpenBao

Promotes OpenBao as the standard, open-source-governed solution for managing secrets across the organization's projects.

OpenSSF Scorecard

Utilizes the OpenSSF Scorecard to systematically measure project security health and establish baseline enterprise policies for safe open source consumption.

Protobom / SBOM Tools

Mandates the use of standard SBOM formats and tools like Protobom to maintain a comprehensive inventory of third-party software assets.

Repository Service for TUF (RSTUF)

Recommends RSTUF to ensure the organization's internally hosted artifact repositories are resilient against compromise.

Sigstore

Standardizes on keyless signing (Sigstore) across the enterprise to eliminate the overhead of managing long-lived cryptographic keys.

OSPS Baseline

Uses the OSPS Baseline to define and enforce security expectations for projects across the enterprise.

OSV Schema & OpenVEX

Adopts the OSV schema to standardize how vulnerability information is ingested and tracked across all enterprise open source usage.

Security Insights

Aggregates Security Insights files across projects to programmatically monitor the security health and maintenance status of open source dependencies.

SLSA

Adopts the SLSA framework as an organizational standard to systematically measure and improve the supply chain security of all projects.

Problems these projects help you with