Tool

OpenSSF Scorecard

OpenSSF Scorecard is an open-source security assessment tool developed as part of the Open Source Security Foundation. It evaluates open-source projects and dependencies for software supply-chain risks through automated checks covering source code, build processes, dependencies, testing, and project maintenance. Each check produces a score and risk level, which are combined into an aggregate security-posture score with remediation guidance. Scorecard can run automatically through a GitHub Action on repositories a user controls or manually through its command-line interface, which can assess other repositories and allows users to select checks and control result detail.

Visit site Mentioned in 1 video ↓

What OpenSSF Scorecard is used for

1 use taken from transcripts — each links to the moment in the video.

  • Provides automated checks used in a software delivery pipeline to evaluate open-source security practices.

Videos mentioning OpenSSF Scorecard

1 in the library.