Projects

All 23 OpenSSF projects in the mapping. Each one opens into the personas it serves and the problems it helps with — plus links to similar and complementary projects.

Looking for a different angle? Browse by role → or by problem →

Best Practices Badge

A voluntary self-certification program that lets open source projects demonstrate they follow recognized development best practices.

See personas & problems

Bomctl

Format-agnostic Software Bill of Materials tooling that bridges the gap between SBOM generation and SBOM analysis — fetching, merging, and manipulating SBOMs across SPDX and CycloneDX.

See personas & problems

Criticality Score

A metric that quantifies how critical an open source project is to the broader ecosystem so maintainers and consumers can prioritize attention and investment.

See personas & problems

Fuzz Introspector

Improves the fuzzing experience for projects by providing visibility into fuzzer coverage and reachability.

See personas & problems

FuzzingBrain

An OSSF project approved by the TAC and currently in LF legal formation; public documentation is not yet available, so scope and classification are provisional.

See personas & problems

Gemara

Schemas, SDKs, and tooling implementing the Gemara GRC engineering model — machine-readable formats that bridge high-level compliance requirements and low-level technical evidence to enable automated risk assessment across security tooling.

See personas & problems

gittuf

A platform-agnostic security layer for Git that applies The Update Framework concepts to source control — enforcing who may change what through signed policy and a tamper-evident reference state log.

See personas & problems

GUAC

Graph for Understanding Artifact Composition — a queryable supply-chain knowledge graph that aggregates SBOMs, attestations, and vulnerability data.

See personas & problems

in-toto

A framework for cryptographically attesting supply-chain steps. Defines the in-toto attestation envelope that SLSA Provenance and other signed-statement formats ship in.

See personas & problems

Minder

A software-supply-chain security platform that continuously verifies secure practices and enforces standardized policies across repositories and artefacts.

See personas & problems

OpenSSF Model Signing (OMS)

A library and CLI for cryptographically signing and verifying machine learning models of any format or size, supporting multiple PKI backends including Sigstore, self-signed certificates, and bare key pairs.

See personas & problems

OpenBao

A community-governed, open source secrets management platform for storing, rotating, and brokering access to secrets, credentials, tokens, and cryptographic keys.

See personas & problems

OpenSSF Scorecard

An automated tool that assesses open source projects against a curated set of security-health checks and produces a comparable score.

See personas & problems

OSS-CRS

A framework for LLM-based bug-finding and bug-fixing systems applied to open source software, exploring autonomous vulnerability discovery and remediation.

See personas & problems

Package Analysis

Dynamically and statically analyzes packages from open source package registries to detect malicious behavior such as credential exfiltration and backdoors.

See personas & problems

Protobom / SBOM Tools

A shared library and toolset for generating, translating, and consuming Software Bills of Materials in standard formats such as SPDX and CycloneDX.

See personas & problems

Repository Service for TUF (RSTUF)

A drop-in implementation of The Update Framework (TUF) that protects software repositories from compromise, rollback, and man-in-the-middle attacks.

See personas & problems

SBOMit

An SBOM-format-independent method that embeds in-toto and Witness attestations into Software Bills of Materials, cryptographically validating the steps performed across the software supply chain.

See personas & problems

Secure Agentic Framework

An OSSF project approved by the TAC and currently in LF legal formation; public documentation is not yet available, so scope and classification are provisional.

See personas & problems

Sigstore

A free, identity-based artefact-signing service backed by a public transparency log so anyone can verify who built what.

See personas & problems

slsa-github-generator

Reference implementations of SLSA Level 3 build provenance generators for GitHub Actions. Produces signed in-toto attestations bound to the builder identity per the SLSA build track.

See personas & problems

slsa-verifier

Reference implementation of the SLSA Provenance verifier. Consumes signed in-toto attestations, validates the builder identity, and enforces SLSA build-level expectations on incoming artefacts.

See personas & problems

Zarf

Enables continuous software delivery onto air-gapped, disconnected, or otherwise constrained systems by bundling applications and their dependencies into portable packages.

See personas & problems