← Back to Discover
ossf

ossf/malicious-packages

GoApache-2.0active
77Health

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

Stars600
Forks131
Open Issues41
Contributors131
Last Push3d ago

Health Breakdown

Activity
25
Community
13
Maintenance
14
Popularity
25
View on GitHub ↗Issues (41) ↗Pull Requests ↗

Should you contribute to ossf/malicious-packages?

ossf/malicious-packages has a FoundDev health score of 77/100, which puts it in the active-and-maintained tier. The maintainer team is shipping recently, issues are being closed, and a PR you open this week has a realistic chance of being reviewed.

Last push was 3 days ago — that signals an actively maintained project. New issues are likely to get a maintainer response within days. The project is written primarily in Go, so prior Go experience will shorten ramp-up.

Licensed under Apache-2.0, a standard OSI-approved license — safe to contribute to under normal employer IP policies.

Community

ossf77

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

active
600131 contributors41 issues
3d ago

More Go repos

canopy-network
canopy-network/canopy
The official go implementation of the Canopy Network protocol
15.5k100
kubernetes-sigs
kubernetes-sigs/azuredisk-csi-driver
Azure Disk CSI Driver
16998
kubevirt
kubevirt/hyperconverged-cluster-operator
Operator pattern for managing multi-operator products
18798