OpenSSF Project Community
HomePersonasProblemsProjectsPublicationsAbout

Quick Links

Browse by Persona
Software Developer / MaintainerOpen Source Professional (OSPO)Security Engineer / ArchitectCI/CD DevOps & Tooling IntegratorPackage & Repository ManagerExecutive / End-User Consumer
Browse by Problem
Build & Provenance IntegrityArtefact Signing & VerificationDependency & SBOM VisibilityVulnerability ManagementSecure Repository ConfigurationMeasuring Security PosturePolicy & Compliance EnforcementSecrets Management
Browse by Project
Best Practices BadgeBomctlCriticality ScoreFuzz IntrospectorFuzzingBrainGemaragittufGUACin-totoMinderOpenSSF Model Signing (OMS)OpenBaoOpenSSF ScorecardOSS-CRSPackage AnalysisProtobom / SBOM ToolsRepository Service for TUF (RSTUF)SBOMitSecure Agentic FrameworkSigstoreslsa-github-generatorslsa-verifierZarf
Browse by Publication
Gemara Whitepaperin-toto AttestationOSPS BaselineOSV Schema & OpenVEXOSV Record (vulnerability record format)SARIFSoftware Bill of MaterialsSecurity InsightsSLSASLSA ProvenanceVulnerability Exploitability eXchange
About
Problem view

Build & Provenance Integrity

Ensuring artefacts are built from the expected source, on a trusted platform, without tampering — and that the resulting provenance is verifiable by anyone downstream.

Build Integrity Signing Visibility Vulnerabilities Configuration Posture Compliance Secrets

5 OpenSSF projects and publications help with Build Integrity, each with a one-sentence note on how. Prefer another way in? Browse by role →

OpenSSF Model Signing (OMS)

Attaches verifiable signatures to model artifacts, letting downstream users trace a model back to its origin.

Full breakdown

Repository Service for TUF (RSTUF)

Protects the distribution chain against rollback and man-in-the-middle attacks between repository and client.

Full breakdown

SBOMit

Binds in-toto and Witness attestations to SBOM entries so each component carries verifiable proof of how it was built.

Full breakdown

Sigstore

Records signatures in a transparency log, making artefact provenance independently auditable downstream.

Full breakdown

SLSA

Defines progressive levels for source, build, and provenance integrity so artefacts can be traced back to their origin.

Full breakdown

Personas who care about this

Developer Security DevOps Package Manager OSPO Executive
Pick a different problem Browse all projects
  • OpenSSF contributors
  • operations@openssf.org

Browse OpenSSF projects by the role you play. Every project is mapped to the personas it serves and the problems it solves, with a one-sentence, role-specific usage guide for each.

Copyright © OpenSSF contributors, a Series of LF Projects, LLC. For website terms of use, trademark policy, and other project policies please see https://lfprojects.org. This site is open source. View or contribute at GitHub.