OpenSSF publication

Security Insights

A machine-processable YAML specification that lets a project declare its security posture, vulnerability-handling process, and supporting resources.

How each persona uses Security Insights

Software Developer / Maintainer Developer

Creates a Security Insights file to report their project's security information in a machine-processable way.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Aggregates Security Insights files across projects to programmatically monitor the security health and maintenance status of open source dependencies.

See everything for OSPO →

Security Engineer / Architect Security

Consumes Security Insights metadata to automatically assess the vulnerability management practices of third-party libraries.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Uses the machine-readable Security Insights YAML file to automatically approve or block dependencies during pipeline execution.

See everything for DevOps →

Package & Repository Manager Package Manager

Incorporates Security Insights data into the repository index to allow users to search and filter packages based on their security policies.

See everything for Package Manager →

Executive / End-User Consumer Executive

Analyzes machine-processable metadata and prioritization to evaluate operational risk and establish trust in vendors.

See everything for Executive →

Problems Security Insights helps with

Measuring Security Posture Posture

Lets a project self-declare its security posture in a machine-readable file that consumers can aggregate and compare.

See everything for Posture →

Dependency & SBOM Visibility Visibility

Surfaces a project's vulnerability-handling process and resources so downstream consumers can reason about it programmatically.

See everything for Visibility →