Open Source Professional (OSPO)
You steward your organization's open source strategy. You need tools that let you set, enforce, and measure consistent security expectations across every project you touch.
Here are the 16 OpenSSF projects and publications that address the OSPO persona, each with a one-sentence action written for the role. Prefer another way in? Browse by problem →
Best Practices Badge
Mandates the achievement of the badge across internal open source projects to demonstrate a commitment to security and quality.
Full breakdown
Bomctl
Normalizes SBOMs arriving in mixed formats into a consistent inventory the organization can track across every project.
Full breakdown
Criticality Score
Utilizes the criticality score to prioritize resource allocation and security audits for the most crucial dependencies used within the enterprise.
Full breakdown
Gemara
Expresses the organization's controls and compliance requirements in Gemara's shared model so they can be assessed consistently across projects.
Full breakdown
gittuf
Applies consistent, forge-independent repository security policy across projects regardless of which Git host each one uses.
Full breakdown
GUAC
Leverages GUAC to maintain a comprehensive, queryable graph of software supply chain metadata across all enterprise projects.
Full breakdown
Minder
Deploys Minder to establish and continuously verify standardized security policies across all internal and open source project portfolios.
Full breakdown
OpenBao
Promotes OpenBao as the standard, open-source-governed solution for managing secrets across the organization's projects.
Full breakdown
OpenSSF Scorecard
Utilizes the OpenSSF Scorecard to systematically measure project security health and establish baseline enterprise policies for safe open source consumption.
Full breakdown
Protobom / SBOM Tools
Mandates the use of standard SBOM formats and tools like Protobom to maintain a comprehensive inventory of third-party software assets.
Full breakdown
Repository Service for TUF (RSTUF)
Recommends RSTUF to ensure the organization's internally hosted artifact repositories are resilient against compromise.
Full breakdown
Sigstore
Standardizes on keyless signing (Sigstore) across the enterprise to eliminate the overhead of managing long-lived cryptographic keys.
Full breakdown
OSPS Baseline
Uses the OSPS Baseline to define and enforce security expectations for projects across the enterprise.
Full breakdown
OSV Schema & OpenVEX
Adopts the OSV schema to standardize how vulnerability information is ingested and tracked across all enterprise open source usage.
Full breakdown
Security Insights
Aggregates Security Insights files across projects to programmatically monitor the security health and maintenance status of open source dependencies.
Full breakdown
SLSA
Adopts the SLSA framework as an organizational standard to systematically measure and improve the supply chain security of all projects.
Full breakdown