VOOZH about

URL: https://apify.com/maximedupre/openssf-scorecard-projects-scraper

โ‡ฑ OpenSSF Scorecard GitHub Project Scraper ยท Apify


๐Ÿ‘ OpenSSF Scorecard Projects Scraper avatar

OpenSSF Scorecard Projects Scraper

Pricing

from $17.10 / 1,000 scored projects

Go to Apify Store

OpenSSF Scorecard Projects Scraper

OpenSSF Scorecard Projects Scraper checks GitHub repositories. Export scores, commits, Scorecard versions, check results, reasons, details, and documentation links.

Pricing

from $17.10 / 1,000 scored projects

Rating

0.0

(0)

Developer

๐Ÿ‘ Maxime Duprรฉ

Maxime Duprรฉ

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Share

๐Ÿ›ก๏ธ OpenSSF Scorecard projects scraper

Check GitHub repositories with OpenSSF Scorecard and export one clean row per reachable project. The Actor returns the repository score, scored commit, Scorecard date, Scorecard version, and check-level results with source-backed reasons, details, and documentation links when OpenSSF provides them. It is useful for security teams, maintainers, DevSecOps workflows, and research pipelines that need repeatable Scorecard data without manually querying each repo.

๐Ÿ“ฆ Returned data

Each successful dataset row represents one GitHub repository with an available OpenSSF Scorecard result.

The output includes:

  • repository: normalized GitHub repository, such as github.com/ossf/scorecard.
  • score: overall OpenSSF Scorecard score.
  • commit: Git commit SHA used for the result when the source provides it.
  • scorecardDate: source-native Scorecard date or timestamp.
  • scorecardVersion: OpenSSF Scorecard version that produced the result.
  • checks: check-level results with name, numeric score, reason, detail lines, and documentation URL when present.

Failed, invalid, private, or unavailable repositories are handled in run logs and are not emitted as result rows.

๐Ÿš€ How to run

Add GitHub repositories in the input form and start the Actor. Use either github.com/owner/repo or owner/repo format.

Good first-run examples:

{
"repositories":[
"github.com/ossf/scorecard",
"github.com/kubernetes/kubernetes",
"github.com/golang/go"
]
}

The Actor queries public OpenSSF Scorecard data. You do not need GitHub credentials, cookies, or an OpenSSF API key.

๐ŸŽฏ Input

The public input has one required field:

  • repositories: a list of GitHub repositories to check.

The form accepts up to 500 repository targets. Enter fewer repositories when you want a smaller run. Source access settings, retries, concurrency, and cleanup are handled by the Actor.

๐Ÿงพ Output example

{
"repository":"github.com/ossf/scorecard",
"score":9,
"commit":"916bfc57fa7431467a33a5a013cba3f8a0c1ec50",
"scorecardDate":"2026-06-27T02:23:36Z",
"scorecardVersion":"v5.3.0",
"checks":[
{
"name":"Security-Policy",
"score":10,
"reason":"security policy file detected",
"details":[
"Found security policy: SECURITY.md"
],
"documentationUrl":"https://github.com/ossf/scorecard/blob/main/docs/checks.md#security-policy"
}
]
}

The checks array preserves source-native scores, including sentinel values such as -1 when OpenSSF returns them.

๐Ÿ’ณ Pricing

This Actor uses pay-per-event pricing. You are charged for each GitHub repository that returns a successful OpenSSF Scorecard result. Repositories that do not produce a result are not charged as scored projects.

๐Ÿ”Œ Integrations

  • Run the Actor from the Apify API to add Scorecard checks to CI, reporting, or asset-inventory workflows.
  • Schedule recurring runs to monitor a fixed list of repositories.
  • Export results as JSON, CSV, Excel, or through Apify dataset API endpoints.
  • Send finished runs to webhooks, Google Sheets, Make, Zapier, or your own data pipeline.

โ“ FAQ

Can I scan any GitHub repository?
You can submit public GitHub repositories. A dataset row is emitted when OpenSSF Scorecard has a successful result for that repository.

Does this require GitHub credentials or an OpenSSF API key?
No. The Actor uses public OpenSSF Scorecard data and does not ask for cookies, GitHub tokens, or source API keys.

What does the fan-out query "OpenSSF Scorecard projects scraper OpenSSF Scorecard GitHub projects list Scorecard API projects OpenSSF Scorecard repo scan" mean for this Actor?
It points to the same core job: checking a list of GitHub repositories and exporting OpenSSF Scorecard project data for each reachable repo.

Why not use the OpenSSF Scorecard API?
You can use the API directly. This Actor is useful when you want an Apify-ready workflow with bulk input, dataset exports, scheduling, API access, webhooks, and pay-per-successful-result charging.

What are OpenSSF Scorecard alternatives?
Security teams often combine Scorecard data with CVE feeds, dependency scanners, repository metadata, and policy checks. This Actor stays focused on source-backed OpenSSF Scorecard project results.

Do failed repositories appear in the dataset?
No. The dataset contains successful Scorecard project rows only. Missing, invalid, private, or unresolved targets are surfaced in logs/status instead.

Can I use this for monitoring open-source project health?
Yes. Schedule the Actor with the same repository list and export the latest source-backed Scorecard results to your reporting workflow.

๐Ÿ“ Changelog

  • 1.0: Initial release.

๐Ÿ†˜ Support

For issues, questions, or feature requests, file a ticket and I'll fix or implement it in less than 24h ๐Ÿซก

๐Ÿ”— Other actors

Made with โค๏ธ by Maxime Duprรฉ

You might also like

OpenSSF Scorecard Projects Scraper

automation-lab/openssf-scorecard-projects-scraper

Export OpenSSF Scorecard checks for public GitHub repositories: scores, reasons, docs, commits, and pass/warn/fail security findings.

๐Ÿ‘ User avatar

Stas Persiianenko

2

OpenSSF Scorecard Projects Scraper

parseforge/openssf-scorecard-projects-scraper

Surface records from multiple Openssf sources in a single run and get a unified, normalized result set. Pull names, identifiers, dates, descriptions, status flags and source links per record. Perfect for research, lead generation and intelligence pipelines.

College Scorecard Scraper

crawlerbros/college-scorecard-scraper

Search US colleges and universities using the Department of Education's College Scorecard API. Get admissions rates, SAT/ACT scores, tuition costs, earnings data, completion rates, and more for 6,000+ institutions.

College Scorecard Scraper

crawlergang/college-scorecard-scraper

Search US colleges and universities using the Department of Education's College Scorecard API. Get admissions rates, SAT/ACT scores, tuition costs, earnings data, completion rates, and more for 6,000+ institutions.

1

5.0

College Scorecard Schools Scraper

crawlerbros/college-scorecard-schools-scraper

Searches US colleges and universities using the US Department of Education College Scorecard API - 6,000+ institutions with admission rates, costs, outcomes. Free, uses public DEMO_KEY.

Website SEO Scorecard & Grader - Instant Audit

santhej/seo-scorecard

Instant SEO scorecard for any URL: a graded 0-100 score, prioritized issues, wins, and Core Web Vitals (LCP, CLS, FID). A shareable website grader for agencies and audits. Bulk URLs, no API key.

๐Ÿ‘ User avatar

Santhej Kallada

3

5.0

College Scorecard Scraper

parseforge/college-scorecard-scraper

Scrape 6,000+ US colleges and universities from College Scorecard. Get tuition costs, admission rates, graduation rates, post-graduation earnings, demographics, financial aid data, and 65+ fields per school. Filter by state and degree type.

Vulnerability & Security Intel Aggregator

parseforge/vulnerability-security-intel-scraper

Pull live security intel from GitHub Advisories, MITRE ATT&CK, Exploit DB, OpenSSF Scorecard and URLhaus in one feed. Get CVE IDs, severity, affected packages, threat techniques and active malware URLs. Built for SecOps, threat intel and DevSecOps.