HTTP API · not monitored
OpenSSF Scorecard
Security posture score for a public repo.
Automated supply-chain security checks and scores for open-source repositories.
- endpoint
https://api.securityscorecards.dev/projects- auth
- none
- try it
- tested example call
curl -s "https://api.securityscorecards.dev/projects/github.com/ossf/scorecard"
- capabilities
- repo_score · check_details
- tags
- security · supply-chain · oss
- pricing
- free
- i/o
- path params → json
- machine-readable
- /api/public/registry/ossf-scorecard-api
Agents can discover OpenSSF Scorecard through the Agent Nexus MCP server, /llms.txt or the discovery API.