Ross ROSS = Recommend OSS · open-source software intelligence for agents

ossf/criticality_score

Gives criticality score for an open source project observed · 2026-08-28

github.com/ossf/criticality_score · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

67/100

  • Activity 99
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2115
  • days_rel: n/a
  • days_push: 7
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1452 stars · 142 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Go CLI tool from the OpenSSF that computes a criticality score (0 to 1) for open source projects based on parameters like contributor count, commit frequency, and dependents. It helps identify the critical open source projects the community depends on so their security posture can be proactively improved.

Use cases

  • score how critical an open source project is
  • find the open source projects my dependencies rely on most
  • prioritize security audits for widely-used open source projects
  • generate a ranked list of critical open source projects
  • assess supply chain risk of open source dependencies
  • measure influence and importance of a GitHub repository

When to choose

  • you need a standardized, data-driven measure of an open source project's importance
  • you're doing dependency risk analysis or supply chain security prioritization
  • you want to identify which OSS projects deserve security investment

When to avoid

  • you need a full security audit or vulnerability scan rather than an importance score
  • you want code quality or license compliance analysis
  • the project isn't hosted on a supported platform like GitHub

Facets

cli-tool · maturity active

security analytics developer-tools security developer-tools windows go cli open-source-security criticality-score ossf supply-chain-security project-analysis open-source linux macos

1 source

Member repositories

RepositoryRoleHealth v2
ossf/criticality_scoremain67

For agents

markdown · JSON · MCP: product_card(name="ossf/criticality_score")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem