🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
-
Updated
Jun 7, 2026 - Ruby
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
GitGoat is an open source tool that was built to enable DevOps and Engineering teams to design and implement a sustainable misconfiguration prevention strategy. It can be used to test products with access to GitHub repositories without a risk to your production environment.
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
Format agnostic SBOM tooling
From the Linux Foundation office in New York City, welcome to "The Untold Stories of Open Source". Each week we explore the people who are supporting Open Source projects, how they became involved with it, and the problems they faced along the way.
Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
Supply chain risk scorer for npm and PyPI — single-maintainer CRITICAL flags before attacks happen
OpenSSF Dashboard allows you to check the OpenSSF scorecards for entire organisations and users on GitHub or Gitlab.
Agent Skill for enterprise readiness assessment - security, quality, and automation | Claude Code compatible
Track NodeSecure organization issues
Azure Pipelines Task for OpenSSF Scorecard
OpenSSF `criticality_score` tool in a container.
Predict the next supply chain attack.
Local-first TUI for auditing AI agent state, MCP config, and dotfiles backup safety
Add a description, image, and links to the openssf topic page so that developers can more easily learn about it.
To associate your repository with the openssf topic, visit your repo's landing page and select "manage topics."