Provides a formal, open-source framework for multi-dimensional security ratings and comparative benchmarking of open-source projects.
SAP's Fosstars rating core (OssSecurityRating) provides a formal security assessment framework that assigns labels (GOOD, MODERATE, BAD, UNCLEAR) using a normal distribution relative to industry benchmarks like curl, Netty, and OpenSSL. The rating evaluates over 35 factors, including static analysis (CodeQL, LGTM grade), dependency security (Dependabot, OWASP Dependency Check), and community activity (commits and contributors in the last 3 months). It also weights projects by their foundation membership (Apache, Eclipse) and corporate support, providing a multi-dimensional view of how well a project and its community care about security and maintenance hygiene.
The rating evaluates activity by checking the number of commits and contributors specifically in the last three months.
gradual security decay due to a loss of community momentum and developer attention
short-term (90-day) activity windows are more responsive indicators of project health than long-term (1-year) staleness metrics.
The rating assesses... whether the project runs CodeQL checks... LGTM grade... OSS-Fuzz... signed artifacts... signed commits... number of watchers.
Risk Guard tracks stars but doesn't explicitly factor in 'Watchers', 'LGTM grade', or 'OSS-Fuzz' status into its scores.
Risk Guard would be better if it integrated a wider array of 'Security Maturity' signals such as Fuzzing status and static analysis grades (LGTM/CodeQL).