OpenSSF publication
Security Insights
A machine-processable YAML specification that lets a project declare its security posture, vulnerability-handling process, and supporting resources.
How each persona uses Security Insights
Software Developer / Maintainer Developer
Creates a Security Insights file to report their project's security information in a machine-processable way.
Open Source Professional (OSPO) OSPO
Aggregates Security Insights files across projects to programmatically monitor the security health and maintenance status of open source dependencies.
Security Engineer / Architect Security
Consumes Security Insights metadata to automatically assess the vulnerability management practices of third-party libraries.
CI/CD DevOps & Tooling Integrator DevOps
Uses the machine-readable Security Insights YAML file to automatically approve or block dependencies during pipeline execution.
Package & Repository Manager Package Manager
Incorporates Security Insights data into the repository index to allow users to search and filter packages based on their security policies.
Executive / End-User Consumer Executive
Analyzes machine-processable metadata and prioritization to evaluate operational risk and establish trust in vendors.
Problems Security Insights helps with
Measuring Security Posture Posture
Lets a project self-declare its security posture in a machine-readable file that consumers can aggregate and compare.
Dependency & SBOM Visibility Visibility
Surfaces a project's vulnerability-handling process and resources so downstream consumers can reason about it programmatically.