OpenSSF project

OpenSSF Scorecard

An automated tool that assesses open source projects against a curated set of security-health checks and produces a comparable score.

How each persona uses OpenSSF Scorecard

Software Developer / Maintainer Developer

Leverages the OpenSSF Scorecard to identify and implement the security practices required for commercial downstream adoption.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Utilizes the OpenSSF Scorecard to systematically measure project security health and establish baseline enterprise policies for safe open source consumption.

See everything for OSPO →

Security Engineer / Architect Security

Leverages the OpenSSF Scorecard to assess open source projects for security risks through automated checks.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Embeds the OpenSSF Scorecard to execute automated security health checks directly within CI/CD pipelines.

See everything for DevOps →

Package & Repository Manager Package Manager

Displays OpenSSF Scorecard metrics on the registry interface to help users evaluate the security hygiene of available packages.

See everything for Package Manager →

Executive / End-User Consumer Executive

Evaluates trust and mitigates supply chain risk by reviewing the health metrics of dependencies.

See everything for Executive →

Problems OpenSSF Scorecard helps with

Measuring Security Posture Posture

Runs automated health checks against a project and produces a single comparable score consumers can act on.

See everything for Posture →

Secure Repository Configuration Configuration

Flags risky repository configuration through automated checks so it can be hardened before adoption.

See everything for Configuration →

Relationships

Outgoing

  • consumesOSV Record (vulnerability record format)publicationneeds-review

    Scorecard reads vulnerability data via the OSV API; whether that counts as consuming OSV records or only querying the database is a curator judgement call.

  • producesSARIFpublication