Ross ROSS = Recommend OSS · open-source software intelligence for agents

ossf/allstar

GitHub App to set and enforce security policies observed · 2026-08-28

github.com/ossf/allstar · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

74/100

  • Activity 99
  • Release rhythm 26
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 133
  • age_days: 1926
  • days_rel: 337
  • days_push: 9
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1444 stars · 150 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Allstar is a GitHub App from OpenSSF that continuously monitors GitHub organizations and repositories for adherence to security best practices. When it detects a policy violation, it opens an issue to alert owners and can automatically revert offending project settings to their expected state.

Use cases

  • enforce security policies across a GitHub organization
  • detect when branch protection or security settings are changed
  • automatically revert unauthorized repository setting changes
  • monitor open source repos for security best practice compliance
  • alert maintainers when a repo falls out of compliance
  • self-host a security policy enforcement bot for GitHub

When to choose

  • you manage a GitHub org with many repositories needing consistent security settings
  • you want OpenSSF Scorecard-style policies continuously enforced rather than scanned once
  • you need org-level defaults with per-repo opt-in/opt-out control
  • you want violations surfaced as GitHub issues or auto-remediated

When to avoid

  • your code is not hosted on GitHub
  • you need general-purpose CI/CD rather than security policy enforcement
  • you want a one-time audit instead of continuous monitoring
  • you cannot install GitHub Apps or self-host a service

Facets

application · maturity active

security monitoring alerting ci-cd configuration-management security developer-tools cloud self-hosted go github-app openssf security-policy repository-governance policy-enforcement scorecard devops automation docker

1 source

Member repositories

RepositoryRoleHealth v2
ossf/allstarmain74

For agents

markdown · JSON · MCP: product_card(name="ossf/allstar")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem