Projects
All 23 OpenSSF projects in the mapping. Each one opens into the personas it serves and the problems it helps with — plus links to similar and complementary projects.
Looking for a different angle? Browse by role → or by problem →
Best Practices Badge
A voluntary self-certification program that lets open source projects demonstrate they follow recognized development best practices.
See personas & problems
Bomctl
Format-agnostic Software Bill of Materials tooling that bridges the gap between SBOM generation and SBOM analysis — fetching, merging, and manipulating SBOMs across SPDX and CycloneDX.
See personas & problems
Criticality Score
A metric that quantifies how critical an open source project is to the broader ecosystem so maintainers and consumers can prioritize attention and investment.
See personas & problems
Fuzz Introspector
Improves the fuzzing experience for projects by providing visibility into fuzzer coverage and reachability.
See personas & problems
FuzzingBrain
An OSSF project approved by the TAC and currently in LF legal formation; public documentation is not yet available, so scope and classification are provisional.
See personas & problems
Gemara
Schemas, SDKs, and tooling implementing the Gemara GRC engineering model — machine-readable formats that bridge high-level compliance requirements and low-level technical evidence to enable automated risk assessment across security tooling.
See personas & problems
gittuf
A platform-agnostic security layer for Git that applies The Update Framework concepts to source control — enforcing who may change what through signed policy and a tamper-evident reference state log.
See personas & problems
GUAC
Graph for Understanding Artifact Composition — a queryable supply-chain knowledge graph that aggregates SBOMs, attestations, and vulnerability data.
See personas & problems
in-toto
A framework for cryptographically attesting supply-chain steps. Defines the in-toto attestation envelope that SLSA Provenance and other signed-statement formats ship in.
See personas & problems
Minder
A software-supply-chain security platform that continuously verifies secure practices and enforces standardized policies across repositories and artefacts.
See personas & problems
OpenSSF Model Signing (OMS)
A library and CLI for cryptographically signing and verifying machine learning models of any format or size, supporting multiple PKI backends including Sigstore, self-signed certificates, and bare key pairs.
See personas & problems
OpenBao
A community-governed, open source secrets management platform for storing, rotating, and brokering access to secrets, credentials, tokens, and cryptographic keys.
See personas & problems
OpenSSF Scorecard
An automated tool that assesses open source projects against a curated set of security-health checks and produces a comparable score.
See personas & problems
OSS-CRS
A framework for LLM-based bug-finding and bug-fixing systems applied to open source software, exploring autonomous vulnerability discovery and remediation.
See personas & problems
Package Analysis
Dynamically and statically analyzes packages from open source package registries to detect malicious behavior such as credential exfiltration and backdoors.
See personas & problems
Protobom / SBOM Tools
A shared library and toolset for generating, translating, and consuming Software Bills of Materials in standard formats such as SPDX and CycloneDX.
See personas & problems
Repository Service for TUF (RSTUF)
A drop-in implementation of The Update Framework (TUF) that protects software repositories from compromise, rollback, and man-in-the-middle attacks.
See personas & problems
SBOMit
An SBOM-format-independent method that embeds in-toto and Witness attestations into Software Bills of Materials, cryptographically validating the steps performed across the software supply chain.
See personas & problems
Secure Agentic Framework
An OSSF project approved by the TAC and currently in LF legal formation; public documentation is not yet available, so scope and classification are provisional.
See personas & problems
Sigstore
A free, identity-based artefact-signing service backed by a public transparency log so anyone can verify who built what.
See personas & problems
slsa-github-generator
Reference implementations of SLSA Level 3 build provenance generators for GitHub Actions. Produces signed in-toto attestations bound to the builder identity per the SLSA build track.
See personas & problems
slsa-verifier
Reference implementation of the SLSA Provenance verifier. Consumes signed in-toto attestations, validates the builder identity, and enforces SLSA build-level expectations on incoming artefacts.
See personas & problems
Zarf
Enables continuous software delivery onto air-gapped, disconnected, or otherwise constrained systems by bundling applications and their dependencies into portable packages.
See personas & problems