OpenSSF Project Community
HomePersonasProblemsProjectsPublicationsAbout

Quick Links

Browse by Persona
Software Developer / MaintainerOpen Source Professional (OSPO)Security Engineer / ArchitectCI/CD DevOps & Tooling IntegratorPackage & Repository ManagerExecutive / End-User Consumer
Browse by Problem
Build & Provenance IntegrityArtefact Signing & VerificationDependency & SBOM VisibilityVulnerability ManagementSecure Repository ConfigurationMeasuring Security PosturePolicy & Compliance EnforcementSecrets Management
Browse by Project
Best Practices BadgeBomctlCriticality ScoreFuzz IntrospectorFuzzingBrainGemaragittufGUACin-totoMinderOpenSSF Model Signing (OMS)OpenBaoOpenSSF ScorecardOSS-CRSPackage AnalysisProtobom / SBOM ToolsRepository Service for TUF (RSTUF)SBOMitSecure Agentic FrameworkSigstoreslsa-github-generatorslsa-verifierZarf
Browse by Publication
Gemara Whitepaperin-toto AttestationOSPS BaselineOSV Schema & OpenVEXOSV Record (vulnerability record format)SARIFSoftware Bill of MaterialsSecurity InsightsSLSASLSA ProvenanceVulnerability Exploitability eXchange
About
Problem view

Dependency & SBOM Visibility

Knowing exactly what components ship inside your software — direct and transitive — and being able to query that inventory when something changes.

Build Integrity Signing Visibility Vulnerabilities Configuration Posture Compliance Secrets

5 OpenSSF projects and publications help with Visibility, each with a one-sentence note on how. Prefer another way in? Browse by role →

Bomctl

Bridges SBOM generation and analysis by fetching, merging, and translating bills of materials into one queryable inventory.

Full breakdown

GUAC

Aggregates SBOMs and attestations into one queryable graph so you can trace any component and its relationships.

Full breakdown

Protobom / SBOM Tools

Generates and translates SBOMs in standard formats so the component inventory travels with the artefact.

Full breakdown

SBOMit

Produces a standard SBOM as the carrier for that provenance, keeping the component inventory and its evidence together.

Full breakdown

Security Insights

Surfaces a project's vulnerability-handling process and resources so downstream consumers can reason about it programmatically.

Full breakdown

Personas who care about this

Developer OSPO Security DevOps Package Manager Executive
Pick a different problem Browse all projects
  • OpenSSF contributors
  • operations@openssf.org

Browse OpenSSF projects by the role you play. Every project is mapped to the personas it serves and the problems it solves, with a one-sentence, role-specific usage guide for each.

Copyright © OpenSSF contributors, a Series of LF Projects, LLC. For website terms of use, trademark policy, and other project policies please see https://lfprojects.org. This site is open source. View or contribute at GitHub.