The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed confidence in the security of open source projects. We do this by collecting, curating, and communicating relevant metrics and metadata from open source projects and the ecosystems of which they are a part.
☆222Apr 23, 2024Updated 2 years ago
Alternatives and similar repositories for wg-metrics-and-metadata
Users that are interested in wg-metrics-and-metadata are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OpenSSF Security Tooling Working Group☆326Jul 6, 2025Updated last year
- The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by h…☆228Feb 4, 2026Updated 7 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆208Updated this week
- Helping allocate resources to secure the critical open source projects we all depend on.☆411Sep 2, 2026Updated last week
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Mar 13, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for ope…☆1,067Sep 1, 2026Updated last week
- Technical Advisory Council☆152Updated this week
- A community collection of security reviews of open source software components.☆101Feb 29, 2024Updated 2 years ago
- OpenSSF Endusers Working Group☆28Mar 21, 2024Updated 2 years ago
- OpenSSF Working Group on Securing Software Repositories☆134Apr 6, 2026Updated 5 months ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆142Aug 19, 2026Updated 3 weeks ago
- ☆41Jul 9, 2020Updated 6 years ago
- ☆27Mar 17, 2026Updated 5 months ago
- OpenSSF Scorecard - Security health metrics for Open Source☆5,686Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)☆205Aug 21, 2026Updated 3 weeks ago
- AIBOM Workshop RSA 2024☆15May 20, 2024Updated 2 years ago
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- Supply-chain Levels for Software Artifacts☆1,929Updated this week
- Software Component Verification Standard (SCVS)☆168Apr 1, 2025Updated last year
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆544Updated this week
- Collection of security best practices for package managers.☆164Sep 26, 2022Updated 3 years ago
- Kilt is a project that defines how to inject foreign apps into containers☆13Dec 15, 2023Updated 2 years ago
- Build, edit, validate, and export CycloneDX BOMs through an intuitive browser-based interface☆26Jul 24, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Scan GitHub Actions Workflow logs for IOCs☆19Updated this week
- PPT of my talks.☆13Jun 23, 2025Updated last year
- Data about all known supply-chain attacks through history☆79Aug 12, 2026Updated last month
- Quantitate binary risk assessment☆16May 9, 2022Updated 4 years ago
- GitHub App to set and enforce security policies☆1,451Updated this week
- Go client and SDK for Falco☆55Mar 18, 2026Updated 5 months ago
- A documentation and tracking project with the goal of making package management systems more secure.☆52Mar 5, 2021Updated 5 years ago
- Monitors Github for leaked secrets☆208Oct 25, 2024Updated last year
- Open Source Package Analysis☆911Sep 4, 2026Updated last week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆143Oct 5, 2023Updated 2 years ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆121Feb 28, 2026Updated 6 months ago
- Software Supply Chain Transparency Log☆1,205Updated this week
- Sigstore OIDC PKI☆880Updated this week
- THOR APT Scanner User Manual☆23Updated this week
- Very simple and primitive Python script that sends ModSecurity JSON Audit Logs to Elasticsearch☆17Oct 9, 2018Updated 7 years ago
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Dec 21, 2022Updated 3 years ago