OpenSSF project
Minder
A software-supply-chain security platform that continuously verifies secure practices and enforces standardized policies across repositories and artefacts.
How each persona uses Minder
Software Developer / Maintainer Developer
Uses Minder to proactively manage their security posture and attest secure practices to downstream consumers.
Open Source Professional (OSPO) OSPO
Deploys Minder to establish and continuously verify standardized security policies across all internal and open source project portfolios.
Security Engineer / Architect Security
Maps repository configurations to enterprise threat models, using Minder to continuously enforce secure development lifecycles and prevent configuration drift.
CI/CD DevOps & Tooling Integrator DevOps
Configures Minder to execute security posture management checks and minimize risk along the supply chain.
Package & Repository Manager Package Manager
Ensures that published packages originate from repositories that continuously pass strict security posture checks.
Executive / End-User Consumer Executive
Leverages verifiable proof of secure development practices to satisfy auditors and enterprise customers through continuous attestation.
Problems Minder helps with
Secure Repository Configuration Configuration
Continuously verifies repository configuration against secure-by-default rules and prevents drift over time.
Policy & Compliance Enforcement Compliance
Enforces standardized security policy across whole portfolios of repositories and artefacts from one control plane.