← Back to Discover
ossf

ossf/malicious-packages

GoApache-2.0active
76Health

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

Stars622
Forks160
Open Issues62
Contributors160
Last Push2d ago

Health Breakdown

Activity
25
Community
13
Maintenance
13
Popularity
25
View on GitHub ↗Issues (62) ↗Pull Requests ↗

Should you contribute to ossf/malicious-packages?

ossf/malicious-packages has a FoundDev health score of 76/100, which puts it in the active-and-maintained tier. The maintainer team is shipping recently, issues are being closed, and a PR you open this week has a realistic chance of being reviewed.

Last push was 2 days ago — that signals an actively maintained project. New issues are likely to get a maintainer response within days. The project is written primarily in Go, so prior Go experience will shorten ramp-up.

Licensed under Apache-2.0, a standard OSI-approved license — safe to contribute to under normal employer IP policies.

Community

ossf76

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

active
★ 622160 contributors62 issues
2d ago

More Go repos

jumpserver
jumpserver/koko
KoKo is a connector of JumpServer for secure connections using character protocols, supporting SSH, Telnet, Kubernetes, SFTP and database protocols
★ 53793
jiwoochris
jiwoochris/artex-ko
ARTEX 한국어판 · AI 자율 침투 테스트 프레임워크 현지화 (upstream: Autumn-27/ARTEX, AGPL-3.0)
★ 30193
axone-protocol
axone-protocol/axoned
⛓️ Axone blockchain 💫
★ 17693