Project overview
oss-due-diligence guides a four-phase assessment of open-source repositories and third-party dependencies: identity and license checks, adversarial review, operating posture, and incident response. It adjusts emphasis for project archetypes and includes shell scripts for dependency hygiene, risky patterns, secrets, and release signals. The methodology is explicit about what was checked and avoids treating a limited review as proof that a dependency is safe.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- May 3, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Capabilities
Verification and evals