Package & Repository Manager
You run the registries and repositories that serve software to the world. You need tools that surface trust signals to consumers and protect artefacts in flight.
Here are the 16 OpenSSF projects and publications that address the Package Manager persona, each with a one-sentence action written for the role. Prefer another way in? Browse by problem →
Best Practices Badge
Uses the badge as a metadata indicator to highlight secure and well-maintained packages to end users in the repository.
Full breakdown
Bomctl
Translates and consolidates incoming SBOMs so the registry can serve a clean, format-consistent component inventory.
Full breakdown
Criticality Score
Surfaces criticality scores in package registries to help developers make informed decisions about which packages to adopt.
Full breakdown
GUAC
Leverages GUAC to expose actionable metadata about components and their relationships for supply chain integrity.
Full breakdown
Minder
Ensures that published packages originate from repositories that continuously pass strict security posture checks.
Full breakdown
OpenSSF Model Signing (OMS)
Surfaces and verifies model signatures so a model registry can prove the provenance of the weights it serves.
Full breakdown
OpenBao
Utilizes OpenBao to manage secrets and signing keys, ensuring the untampered and trusted distribution of packages.
Full breakdown
OpenSSF Scorecard
Displays OpenSSF Scorecard metrics on the registry interface to help users evaluate the security hygiene of available packages.
Full breakdown
Protobom / SBOM Tools
Distributes generated Software Bill of Materials (SBOMs) alongside packages to provide consumers with a transparent component inventory.
Full breakdown
Repository Service for TUF (RSTUF)
Implements RSTUF to secure content downloads against tampering between the remote repository and the client.
Full breakdown
SBOMit
Distributes SBOMs whose contents are cryptographically tied to verifiable build steps, raising the trust of served packages.
Full breakdown
Sigstore
Integrates Sigstore natively into the package registry to automatically verify incoming artifact signatures and display provenance to users.
Full breakdown
OSPS Baseline
Requires adherence to the baseline as a prerequisite for verifying or promoting packages within the repository ecosystem.
Full breakdown
OSV Schema & OpenVEX
Serves OSV-formatted advisories directly from the registry to ensure package consumers receive actionable, machine-readable vulnerability updates.
Full breakdown
Security Insights
Incorporates Security Insights data into the repository index to allow users to search and filter packages based on their security policies.
Full breakdown
SLSA
Requires specific SLSA compliance levels before allowing high-profile packages to be published or verified in the repository.
Full breakdown