Security Engineer / Architect
You design and defend the systems around the software. You need tools that give you architectural visibility, threat-model traceability, and automated enforcement of security guarantees.
Here are the 18 OpenSSF projects and publications that address the Security persona, each with a one-sentence action written for the role. Prefer another way in? Browse by problem →
Best Practices Badge
Uses the Best Practices Badge as a signaling mechanism to verify that a project adheres to good practices.
Full breakdown
Bomctl
Pulls together SBOMs from disparate sources so a component can be traced wherever it appears in the portfolio.
Full breakdown
Criticality Score
Queries the Criticality Score to prioritize dependencies and automate the assessment of project impact, ensuring the highest-risk single points of failure receive immediate architectural review.
Full breakdown
Gemara
Maps threats, controls, and evidence onto Gemara's layered schema to drive automated, repeatable risk assessment.
Full breakdown
gittuf
Enforces access and authorization policy on Git itself, backed by a tamper-evident log that survives a forge compromise.
Full breakdown
GUAC
Utilizes GUAC to establish architectural traceability of published components across the software supply chain.
Full breakdown
Minder
Maps repository configurations to enterprise threat models, using Minder to continuously enforce secure development lifecycles and prevent configuration drift.
Full breakdown
OpenSSF Model Signing (OMS)
Verifies model signatures before deployment to keep tampered or untrusted model weights out of production systems.
Full breakdown
OpenBao
Designs centralized secrets management architectures using OpenBao to enforce strict access controls and credential rotation.
Full breakdown
OpenSSF Scorecard
Leverages the OpenSSF Scorecard to assess open source projects for security risks through automated checks.
Full breakdown
Protobom / SBOM Tools
Analyzes ingested SBOMs to rapidly identify and triage vulnerable components across the organization's application portfolio.
Full breakdown
Repository Service for TUF (RSTUF)
Implements The Update Framework (TUF) via RSTUF to secure software delivery architectures and protect cryptographic root keys.
Full breakdown
SBOMit
Validates the in-toto attestations carried inside an SBOM to confirm the supply-chain steps behind every listed component.
Full breakdown
Sigstore
Validates the transparency log to audit the provenance and authenticity of software components used in production.
Full breakdown
OSPS Baseline
Integrates the OSPS Baseline to enforce structured security requirements and reduce defects early in the software creation phase.
Full breakdown
OSV Schema & OpenVEX
Adopts the OSV Schema and OpenVEX to standardize vulnerability reporting and coordinate incident response and analysis.
Full breakdown
Security Insights
Consumes Security Insights metadata to automatically assess the vulnerability management practices of third-party libraries.
Full breakdown
SLSA
Uses the SLSA framework to identify architectural gaps in the build process and design tamper-evident build systems.
Full breakdown