Persona view

Security Engineer / Architect

You design and defend the systems around the software. You need tools that give you architectural visibility, threat-model traceability, and automated enforcement of security guarantees.

Here are the 18 OpenSSF projects and publications that address the Security persona, each with a one-sentence action written for the role. Prefer another way in? Browse by problem →

Best Practices Badge

Uses the Best Practices Badge as a signaling mechanism to verify that a project adheres to good practices.

Bomctl

Pulls together SBOMs from disparate sources so a component can be traced wherever it appears in the portfolio.

Criticality Score

Queries the Criticality Score to prioritize dependencies and automate the assessment of project impact, ensuring the highest-risk single points of failure receive immediate architectural review.

Gemara

Maps threats, controls, and evidence onto Gemara's layered schema to drive automated, repeatable risk assessment.

gittuf

Enforces access and authorization policy on Git itself, backed by a tamper-evident log that survives a forge compromise.

GUAC

Utilizes GUAC to establish architectural traceability of published components across the software supply chain.

Minder

Maps repository configurations to enterprise threat models, using Minder to continuously enforce secure development lifecycles and prevent configuration drift.

OpenSSF Model Signing (OMS)

Verifies model signatures before deployment to keep tampered or untrusted model weights out of production systems.

OpenBao

Designs centralized secrets management architectures using OpenBao to enforce strict access controls and credential rotation.

OpenSSF Scorecard

Leverages the OpenSSF Scorecard to assess open source projects for security risks through automated checks.

Protobom / SBOM Tools

Analyzes ingested SBOMs to rapidly identify and triage vulnerable components across the organization's application portfolio.

Repository Service for TUF (RSTUF)

Implements The Update Framework (TUF) via RSTUF to secure software delivery architectures and protect cryptographic root keys.

SBOMit

Validates the in-toto attestations carried inside an SBOM to confirm the supply-chain steps behind every listed component.

Sigstore

Validates the transparency log to audit the provenance and authenticity of software components used in production.

OSPS Baseline

Integrates the OSPS Baseline to enforce structured security requirements and reduce defects early in the software creation phase.

OSV Schema & OpenVEX

Adopts the OSV Schema and OpenVEX to standardize vulnerability reporting and coordinate incident response and analysis.

Security Insights

Consumes Security Insights metadata to automatically assess the vulnerability management practices of third-party libraries.

SLSA

Uses the SLSA framework to identify architectural gaps in the build process and design tamper-evident build systems.

Problems these projects help you with