OpenSSF project
OpenSSF Scorecard
An automated tool that assesses open source projects against a curated set of security-health checks and produces a comparable score.
How each persona uses OpenSSF Scorecard
Software Developer / Maintainer Developer
Leverages the OpenSSF Scorecard to identify and implement the security practices required for commercial downstream adoption.
Open Source Professional (OSPO) OSPO
Utilizes the OpenSSF Scorecard to systematically measure project security health and establish baseline enterprise policies for safe open source consumption.
Security Engineer / Architect Security
Leverages the OpenSSF Scorecard to assess open source projects for security risks through automated checks.
CI/CD DevOps & Tooling Integrator DevOps
Embeds the OpenSSF Scorecard to execute automated security health checks directly within CI/CD pipelines.
Package & Repository Manager Package Manager
Displays OpenSSF Scorecard metrics on the registry interface to help users evaluate the security hygiene of available packages.
Executive / End-User Consumer Executive
Evaluates trust and mitigates supply chain risk by reviewing the health metrics of dependencies.
Problems OpenSSF Scorecard helps with
Measuring Security Posture Posture
Runs automated health checks against a project and produces a single comparable score consumers can act on.
Secure Repository Configuration Configuration
Flags risky repository configuration through automated checks so it can be hardened before adoption.
Relationships
Outgoing
-
consumesOSV Record (vulnerability record format)publicationneeds-review
Scorecard reads vulnerability data via the OSV API; whether that counts as consuming OSV records or only querying the database is a curator judgement call.
- producesSARIFpublication