Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

OpenSSF Scorecard assesses observable security practices in open-source projects, including practices that matter even when no known CVE is available. Its scores are useful risk signals—not a prediction of undiscovered flaws, a pass/fail certificate, or proof that a package is safe.

What OpenSSF Scorecard checks

Scorecard is an automated assessment tool for open-source project security practices. It examines more than published vulnerability records: its checks cover source code, build and release processes, dependency handling, testing, and project maintenance. The official overview describes 18 checks across three themes; the set of checks can change, so consult the live documentation for the current inventory.

Holistic security practices

Examples include unfixed vulnerabilities, using OSV; dependency update tooling; project maintenance; a security policy; licensing; an OpenSSF Best Practices badge; CI tests; fuzzing; and static analysis (SAST).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Source risk assessment

Checks include binary artifacts committed to the repository, branch protection, dangerous GitHub Actions workflows, code review, and contributions from multiple organizations.

#1 Best Overall

Build risk assessment

Checks include pinned dependencies, workflow token permissions, publishing packages through CI/CD, and signed releases. These checks examine practices around how code is developed and distributed, not only whether a vulnerability has already been recorded.

What a Scorecard score means

Each automated check returns a score out of 10 and a risk level. The risk level affects how the result contributes to the aggregate score, which the overview presents as a sense of the project’s overall security posture. Scorecard also offers remediation prompts. Neither the aggregate nor an individual score is a probability of compromise or a guarantee of safety.

Risk labels provide context, but they do not tell you by themselves whether a finding is important to your situation. The overview labels dangerous workflows as critical, several source-control and build controls as high risk, and other checks as medium or low. Use the individual result and its evidence to understand what was observed, then assess how it affects the package and the way you intend to use it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How it can help when a package has no known CVE

Scorecard’s Vulnerabilities check looks for unfixed vulnerabilities and uses OSV. But a package can still merit scrutiny when there is no known CVE to cite. For example, code review, workflow token permissions, dependency pinning, and signed releases provide signals about development and release practices that vulnerability databases alone do not capture.

These checks help identify practices worth investigating; they do not promise to predict undiscovered vulnerabilities or detect every threat. A favorable result is evidence about the checks performed, not proof that the code has no hidden flaw. The overview reports no independently validated accuracy rate or performance benchmark for Scorecard.

How to run Scorecard

If you maintain the repository

Use the Scorecard GitHub Action on a repository you own or administer. The project describes integrating the action into CI/CD, including running it on pull requests. Findings can help identify improvements before a release or become part of ongoing maintenance.

If you are evaluating someone else’s package

Use the Scorecard CLI to assess another project’s repository. The CLI lets you choose checks and control how much result detail to display. The overview’s quick start specifies a GitHub personal access token with the public_repo scope; follow the current official installation instructions for setup, version, and authentication details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to use a result in a dependency decision

  1. Inspect the check-level findings. Read what each result says and review its evidence rather than relying on the aggregate alone.
  2. Consider the risk label in context. A label helps prioritize attention, but the finding’s relevance depends on the project’s practices and your intended use.
  3. Assess recency and coverage. Check how current the result is and which checks were run before treating it as a useful signal for a decision.
  4. Look for a practical remediation path. Where a finding matters, use Scorecard’s remediation prompt and the project’s own context to decide what action is appropriate.

The Scorecard overview says public data can evaluate the security posture of over 1 million of the most-used open-source projects. It does not attach a publication year to that figure, so treat it as a statement from the overview rather than a dated current count.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the cited vulnerability statistic does—and does not—show

The Scorecard overview attributes an estimate to Synopsys’s 2021 Open Source Security and Risk Analysis Report: 84% of codebases had at least one vulnerability, with an average of 158 vulnerabilities per codebase. The overview also says the majority had been in code for more than two years and had documented solutions available. These are figures attributed to that 2021 report, not measurements made by Scorecard, and they should not be read as current prevalence estimates.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.