Aller au contenu

Open-source security posture of the data/ML stack (weekly)

Usage commercial OKÀ jourLicence: CDLA-Permissive-2.0
Interroger dans l’atelier

Suivre ce jeu de données

Recevez un avis dans votre fil à chaque nouvel instantané publié. En option, nous l’envoyons aussi par POST à votre webhook.

Doit être une adresse https publique. Nous ne suivons jamais les redirections.

Le jeu complet n’est pas encore publié — revenez après la prochaine actualisation.Télécharger l'exemple CSVTélécharger l'exemple JSONLignes d’exemple seulement (jusqu’à 20) — pas le jeu de données complet.

Weekly security-health snapshot of a curated ~138-repository data/ML open-source universe (ML frameworks, LLM tooling, data processing, viz, orchestration, MLOps, serving, vector DBs, ...), from the official keyless OpenSSF Scorecard REST API (CDLA-Permissive-2.0, attribution required). Each repo is deduplicated on its canonical owner/name identity and carries its curated category + criticality tier (1 foundational .. 3 niche), the upstream 0-10 overall score, the scan date, and a 12-check security panel (Code-Review, Maintained, Branch-Protection, Token-Permissions, Signed-Releases, Binary-Artifacts, Dependency-Update-Tool, Vulnerabilities, Dangerous-Workflow, Pinned-Dependencies, Packaging, Fuzzing) where upstream -1 (inconclusive) becomes an honest null. A documented 0-100 security_score = 100 * mean(conclusive checks) / 10 is ranked as security_rank (ties: upstream overall desc, missing last, then repo asc) and bucketed into security_grade A (>= 80), B (>= 65), C (>= 50), D (>= 35), F (< 35). weakest_check names the lowest conclusive check (the highest-leverage fix); repos that 404, are unscanned, or have fewer than 4 conclusive checks are excluded. Week-granular as-of stamping makes same-week re-runs hash-identical. Columns: snapshot week, fetch timestamp, repo, source URL, category, criticality, overall score, scan date, 12 check scores, conclusive-check count, security score/grade/rank, weakest check + score. Primary key: (snapshot_week, repo). Cadence: weekly. Nullability: individual check columns null when Scorecard reports inconclusive (-1); weakest_check_score null only when no conclusive check exists (row excluded). Caveats: only projects scanned by Scorecard appear — the universe is curated, not an exhaustive registry; a Scorecard rescan later in the week can change snapshot content; the composite is an unweighted mean of conclusive checks, a comparison heuristic, not a risk model. Security scores, grades and the ranking are derived signals computed by this connector. Sample use: filter criticality = 1 for the foundational stack, order by security_rank, read weakest_check for the first fix to make.

Les titres et les descriptions proviennent des sources de données, en anglais.

Lignes
108
Colonnes
26
Cadence de la source
Hebdomadaire
Dernière actualisation
25 sept. 2026
Thème
technology

Utiliser votre propre clé d’IA

Une fois l’allocation gratuite du jour épuisée, les fonctions d’IA peuvent passer par votre propre compte fournisseur.

Conservée uniquement dans cet onglet (effacée à sa fermeture) et envoyée avec chaque requête d’IA. Nos serveurs l’utilisent pour cette requête et ne la stockent ni ne la journalisent jamais.