Open source security foundation
export GITHUB_AUTH_TOKEN=<your access token> scorecard --repo={owner}/{repo}
branch protection github api works pooly
scorecard --repo=google/jax --show-details \ --show-annotations --checks \ Signed-Releases,Contributors,License,Maintained,CI-Tests,Token-Permissions,Binary-Artifacts,Code-Review,Dangerous-Workflow,Fuzzing,Packaging,Vulnerabilities,CII-Best-Practices,Pinned-Dependencies,SAST,Security-Policy,Dependency-Update-Tool
api
OpenSSF Scorecard
https://api.securityscorecards.dev/
part of
Home
Quickly assess open source projects for risky practices
https://scorecard.dev/

OSS foundataion
Open Source Security Foundation – Linux Foundation Projects
Collaborate on capabilities and best practices that secure open source software.
https://openssf.org/
Open Source Security Foundation (OpenSSF)
OpenSSF is a community of software developers and security engineers who are working together to secure open source software for the greater public good. - Open Source Security Foundation (OpenSSF)
https://github.com/ossf

Seonglae Cho