ossf/allstar
GitHub App to set and enforce security policies observed · 2026-08-28
Health v2 · maintenance only
74/100
- Activity 99
- Release rhythm 26
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 133
- age_days: 1926
- days_rel: 337
- days_push: 9
- n_releases_24m: 2
Adoption not part of the score
1444 stars · 150 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Allstar is a GitHub App from OpenSSF that continuously monitors GitHub organizations and repositories for adherence to security best practices. When it detects a policy violation, it opens an issue to alert owners and can automatically revert offending project settings to their expected state.
Use cases
- enforce security policies across a GitHub organization
- detect when branch protection or security settings are changed
- automatically revert unauthorized repository setting changes
- monitor open source repos for security best practice compliance
- alert maintainers when a repo falls out of compliance
- self-host a security policy enforcement bot for GitHub
When to choose
- you manage a GitHub org with many repositories needing consistent security settings
- you want OpenSSF Scorecard-style policies continuously enforced rather than scanned once
- you need org-level defaults with per-repo opt-in/opt-out control
- you want violations surfaced as GitHub issues or auto-remediated
When to avoid
- your code is not hosted on GitHub
- you need general-purpose CI/CD rather than security policy enforcement
- you want a one-time audit instead of continuous monitoring
- you cannot install GitHub Apps or self-host a service
Facets
application · maturity active
security monitoring alerting ci-cd configuration-management security developer-tools cloud self-hosted go github-app openssf security-policy repository-governance policy-enforcement scorecard devops automation docker
1 source
- readme: https://github.com/ossf/allstar · fetched 2026-08-28 · ceba994ca1c7
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ossf/allstar | main | 74 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem