ResearchTrend.AI
  • Communities
  • Connect sessions
  • AI calendar
  • Organizations
  • Join Slack
  • Contact Sales
Papers
Communities
Social Events
Terms and Conditions
Pricing
Contact Sales
Parameter LabParameter LabTwitterGitHubLinkedInBlueskyYoutube

© 2026 ResearchTrend.AI, All rights reserved.

  1. Home
  2. Papers
  3. 2208.03412
255
28
v1v2v3v4 (latest)

PREPRINT: Can the OpenSSF Scorecard be used to measure the security posture of npm and PyPI?

IEEE Security and Privacy (IEEE S&P), 2022
6 August 2022
Nusrat Zahan
Parth Kanakiya
Brian Hambleton
S. Shohan
Laurie A. Williams
ArXiv (abs)PDFHTML
Abstract

The OpenSSF Scorecard project is an automated tool to monitor the security health of open source software. We used the tool to understand the security practices and gaps in npm and PyPI ecosystems and to confirm the applicability of the Scorecard tool.

View on arXiv
Comments on this paper