Open Source Security Foundation (OpenSSF)
Open Source Security Foundation (OpenSSF)
package-manager-best-practices
Collection of security best practices for package managers.
Project-Security-Metrics
Collect, curate, and communicate relevant security metrics for open source projects.
alpha-omega
Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
great-mfa-project
The Great Multi-Factor Authentication (MFA) Distribution Project of the Open Source Security Foundation (OpenSSF). We work to distribute hardware MFA tokens to critical open source software (OSS) proj...
oss-vulnerability-guide
A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
s2c2f
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to secu...
sbom-everywhere
Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
secure-sw-dev-fundamentals
Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)