Persona view

Package & Repository Manager

You run the registries and repositories that serve software to the world. You need tools that surface trust signals to consumers and protect artefacts in flight.

Here are the 16 OpenSSF projects and publications that address the Package Manager persona, each with a one-sentence action written for the role. Prefer another way in? Browse by problem →

Best Practices Badge

Uses the badge as a metadata indicator to highlight secure and well-maintained packages to end users in the repository.

Bomctl

Translates and consolidates incoming SBOMs so the registry can serve a clean, format-consistent component inventory.

Criticality Score

Surfaces criticality scores in package registries to help developers make informed decisions about which packages to adopt.

GUAC

Leverages GUAC to expose actionable metadata about components and their relationships for supply chain integrity.

Minder

Ensures that published packages originate from repositories that continuously pass strict security posture checks.

OpenSSF Model Signing (OMS)

Surfaces and verifies model signatures so a model registry can prove the provenance of the weights it serves.

OpenBao

Utilizes OpenBao to manage secrets and signing keys, ensuring the untampered and trusted distribution of packages.

OpenSSF Scorecard

Displays OpenSSF Scorecard metrics on the registry interface to help users evaluate the security hygiene of available packages.

Protobom / SBOM Tools

Distributes generated Software Bill of Materials (SBOMs) alongside packages to provide consumers with a transparent component inventory.

Repository Service for TUF (RSTUF)

Implements RSTUF to secure content downloads against tampering between the remote repository and the client.

SBOMit

Distributes SBOMs whose contents are cryptographically tied to verifiable build steps, raising the trust of served packages.

Sigstore

Integrates Sigstore natively into the package registry to automatically verify incoming artifact signatures and display provenance to users.

OSPS Baseline

Requires adherence to the baseline as a prerequisite for verifying or promoting packages within the repository ecosystem.

OSV Schema & OpenVEX

Serves OSV-formatted advisories directly from the registry to ensure package consumers receive actionable, machine-readable vulnerability updates.

Security Insights

Incorporates Security Insights data into the repository index to allow users to search and filter packages based on their security policies.

SLSA

Requires specific SLSA compliance levels before allowing high-profile packages to be published or verified in the repository.

Problems these projects help you with