OpenSSF Scorecard, data/ML stack posture (agent-curated)
Weekly security-health snapshot of a curated ~138-repository data/ML open-source universe (ML frameworks, LLM tooling, data processing, viz, orchestration, MLOps, serving, vector DBs, ...), from the official keyless OpenSSF Scorecard REST API (CDLA-Permissive-2.0, attribution required). Each repo is deduplicated on its canonical owner/name identity and carries its curated category + criticality tier (1 foundational .. 3 niche), the upstream 0-10 overall score, the scan date, and a 12-check security panel (Code-Review, Maintained, Branch-Protection, Token-Permissions, Signed-Releases, Binary-Artifacts, Dependency-Update-Tool, Vulnerabilities, Dangerous-Workflow, Pinned-Dependencies, Packaging, Fuzzing) where upstream -1 (inconclusive) becomes an honest null. A documented 0-100 security_score = 100 * mean(conclusive checks) / 10 is ranked as security_rank (ties: upstream overall desc, missing last, then repo asc) and bucketed into security_grade A (>= 80), B (>= 65), C (>= 50), D (>= 35), F (< 35). weakest_check names the lowest conclusive check (the highest-leverage fix); repos that 404, are unscanned, or have fewer than 4 conclusive checks are excluded. Week-granular as-of stamping makes same-week re-runs hash-identical. Columns: snapshot week, fetch timestamp, repo, source URL, category, criticality, overall score, scan date, 12 check scores, conclusive-check count, security score/grade/rank, weakest check + score. Primary key: (snapshot_week, repo). Cadence: weekly. Nullability: individual check columns null when Scorecard reports inconclusive (-1); weakest_check_score null only when no conclusive check exists (row excluded). Caveats: only projects scanned by Scorecard appear — the universe is curated, not an exhaustive registry; a Scorecard rescan later in the week can change snapshot content; the composite is an unweighted mean of conclusive checks, a comparison heuristic, not a risk model. Security scores, grades and the ranking are derived signals computed by this connector. Sample use: filter criticality = 1 for the foundational stack, order by security_rank, read weakest_check for the first fix to make.
- technology
- cybersecurity
- open-source
- signals