OpenSSF Project Community
HomePersonasProblemsProjectsPublicationsAbout

Quick Links

Browse by Persona
Software Developer / MaintainerOpen Source Professional (OSPO)Security Engineer / ArchitectCI/CD DevOps & Tooling IntegratorPackage & Repository ManagerExecutive / End-User Consumer
Browse by Problem
Build & Provenance IntegrityArtefact Signing & VerificationDependency & SBOM VisibilityVulnerability ManagementSecure Repository ConfigurationMeasuring Security PosturePolicy & Compliance EnforcementSecrets Management
Browse by Project
Best Practices BadgeBomctlCriticality ScoreFuzz IntrospectorFuzzingBrainGemaragittufGUACin-totoMinderOpenSSF Model Signing (OMS)OpenBaoOpenSSF ScorecardOSS-CRSPackage AnalysisProtobom / SBOM ToolsRepository Service for TUF (RSTUF)SBOMitSecure Agentic FrameworkSigstoreslsa-github-generatorslsa-verifierZarf
Browse by Publication
Gemara Whitepaperin-toto AttestationOSPS BaselineOSV Schema & OpenVEXOSV Record (vulnerability record format)SARIFSoftware Bill of MaterialsSecurity InsightsSLSASLSA ProvenanceVulnerability Exploitability eXchange
About
Problem view

Measuring Security Posture

Quantifying how healthy and well-maintained a project is, so maintainers, consumers, and registries can compare projects and prioritise attention.

Build Integrity Signing Visibility Vulnerabilities Configuration Posture Compliance Secrets

6 OpenSSF projects and publications help with Posture, each with a one-sentence note on how. Prefer another way in? Browse by role →

Best Practices Badge

Turns adherence to recognised practices into a single, comparable trust signal that consumers can read at a glance.

Full breakdown

Criticality Score

Scores how critical a project is to the wider ecosystem so attention and investment can be prioritised where it matters most.

Full breakdown

Gemara

Standardizes how risk and control evidence are expressed so posture can be assessed automatically and compared across projects.

Full breakdown

OpenSSF Scorecard

Runs automated health checks against a project and produces a single comparable score consumers can act on.

Full breakdown

OSPS Baseline

Defines the floor of expected security practices so projects can be measured against a shared bar.

Full breakdown

Security Insights

Lets a project self-declare its security posture in a machine-readable file that consumers can aggregate and compare.

Full breakdown

Personas who care about this

Developer OSPO Security DevOps Package Manager Executive
Pick a different problem Browse all projects
  • OpenSSF contributors
  • operations@openssf.org

Browse OpenSSF projects by the role you play. Every project is mapped to the personas it serves and the problems it solves, with a one-sentence, role-specific usage guide for each.

Copyright © OpenSSF contributors, a Series of LF Projects, LLC. For website terms of use, trademark policy, and other project policies please see https://lfprojects.org. This site is open source. View or contribute at GitHub.