🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
-
Updated
Apr 17, 2026 - Ruby
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
GitGoat is an open source tool that was built to enable DevOps and Engineering teams to design and implement a sustainable misconfiguration prevention strategy. It can be used to test products with access to GitHub repositories without a risk to your production environment.
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
Format agnostic SBOM tooling
From the Linux Foundation office in New York City, welcome to "The Untold Stories of Open Source". Each week we explore the people who are supporting Open Source projects, how they became involved with it, and the problems they faced along the way.
Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
OpenSSF Dashboard allows you to check the OpenSSF scorecards for entire organisations and users on GitHub or Gitlab.
Track NodeSecure organization issues
Agent Skill for enterprise readiness assessment - security, quality, and automation | Claude Code compatible
Azure Pipelines Task for OpenSSF Scorecard
Predict the next supply chain attack.
A minimal, security-first starter kit that adds pre-commit and CI/CD guardrails to any codebase — catch secrets, scan dependencies, and generate SBOMs before bad code ships.
OpenSSF `criticality_score` tool in a container.
Stage273: Structured Review Context — binding review records to SBOM and vulnerability scan artifacts as verifiable evidence.
Advanced Repository Security Posture Engine (DevSecOps CLI)
Project to generate statistics about OpenSSF Compliance in the BEAM ecosystem.
Stage271: External Review Linked Proof — signed, hash-linked, CI-verifiable review records on top of Stage270.
Add a description, image, and links to the openssf topic page so that developers can more easily learn about it.
To associate your repository with the openssf topic, visit your repo's landing page and select "manage topics."