benchmarkingfosstarssecurity-ratingsastcommunity-health

SAP — Fosstars Security Rating

Provides a formal, open-source framework for multi-dimensional security ratings and comparative benchmarking of open-source projects.

Summary

SAP's Fosstars rating core (OssSecurityRating) provides a formal security assessment framework that assigns labels (GOOD, MODERATE, BAD, UNCLEAR) using a normal distribution relative to industry benchmarks like curl, Netty, and OpenSSL. The rating evaluates over 35 factors, including static analysis (CodeQL, LGTM grade), dependency security (Dependabot, OWASP Dependency Check), and community activity (commits and contributors in the last 3 months). It also weights projects by their foundation membership (Apache, Eclipse) and corporate support, providing a multi-dimensional view of how well a project and its community care about security and maintenance hygiene.

Related Checks

SOURCE_REPO_STALE

The rating evaluates activity by checking the number of commits and contributors specifically in the last three months.

Adverse Outcome

gradual security decay due to a loss of community momentum and developer attention

Because

short-term (90-day) activity windows are more responsive indicators of project health than long-term (1-year) staleness metrics.

Gaps Analysis

Evidence

The rating assesses... whether the project runs CodeQL checks... LGTM grade... OSS-Fuzz... signed artifacts... signed commits... number of watchers.

Blind Spot

Risk Guard tracks stars but doesn't explicitly factor in 'Watchers', 'LGTM grade', or 'OSS-Fuzz' status into its scores.

Actionable Capability

Risk Guard would be better if it integrated a wider array of 'Security Maturity' signals such as Fuzzing status and static analysis grades (LGTM/CodeQL).

← Previous Next →