The S2C2F SIG is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
active 2023-08-19 → 2026-03-31 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 956 days from 2023-08-19 to 2026-03-31. Pushes: 37 total, peak 5 in a day. Pull requests: 46 total, peak 5 in a day. Issues: 18 total, peak 3 in a day. Comments: 52 total, peak 8 in a day. Stars: 120 total, peak 3 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| adriandiglio | 57 | 8 | 13 | 16 |
| joshuagl | 34 | 0 | 2 | 21 |
| tombedfordgit | 27 | 6 | 7 | 5 |
| camaleon2016 | 25 | 8 | 9 | 2 |
| jasminewang0 | 14 | 9 | 4 | 0 |
| hythloda | 9 | 4 | 4 | 0 |
| xee5ch | 8 | 0 | 0 | 3 |
| redenmartinez | 4 | 2 | 2 | 0 |
| ralphbean | 2 | 0 | 1 | 1 |
| lehors | 1 | 0 | 1 | 0 |
| gkunz | 1 | 0 | 1 | 0 |
| arewm | 1 | 0 | 1 | 0 |
| scovetta | 1 | 0 | 0 | 1 |
| kborchers | 1 | 0 | 1 | 0 |
| SantiagoTorres | 1 | 0 | 0 | 1 |
| victorjunlu | 1 | 0 | 0 | 0 |
| david-a-wheeler | 1 | 0 | 0 | 1 |
| laenan8466 | 1 | 0 | 0 | 0 |
| ABirHAsan123-beep | 1 | 0 | 0 | 1 |
Recent activity
Latest issues, pull requests and releases
- Issue comment#63ralphbean2025-06-26 20:39Mention that ING-4 supports GPL compliance
- Pull request#63ralphbean2025-06-22 22:02
- Pull request#62tombedfordgit2025-05-26 18:06
- Pull request#62kborchers2025-05-26 18:01
- Issue#61laenan84662025-02-17 14:32Reference: Dead Link to CNCF_SSCP_v1.pdf
- Pull request#59tombedfordgit2025-01-31 10:44
- Issue comment#15SantiagoTorres2024-12-03 21:59Crosswalk with "Taxonomy of Attacks on OSS Supply Chains" by Ladisa et al
- Issue comment#58adriandiglio2024-09-24 19:35Can s2c2f be extended and cover AI Use cases ?
- Issue#58adriandiglio2024-09-24 19:35Can s2c2f be extended and cover AI Use cases ?
- Issue#60adriandiglio2024-09-24 19:34Create AI Use Case workstream to extend S2C2F guidance for Data Scientist persona
- Issue comment#58adriandiglio2024-08-28 20:32Can s2c2f be extended and cover AI Use cases ?
- Issue#58victorjunlu2024-08-27 19:44Can s2c2f be extended and cover AI Use cases ?
- Issue comment#52adriandiglio2024-08-27 19:41Suggestion: be less prescriptive on where UPD-3 happens
- Issue#52adriandiglio2024-08-27 19:41Suggestion: be less prescriptive on where UPD-3 happens
- Pull request#57adriandiglio2024-08-27 19:40
- Issue comment#57adriandiglio2024-08-27 19:31Update UPD-3
- Pull request#57adriandiglio2024-08-27 19:29
- Issue comment#43adriandiglio2024-08-27 19:20Discuss with OpenSSF TAC about our plans to submit an Exploratory Report to the PAS process for International Standardization
- Issue#43adriandiglio2024-08-27 19:20Discuss with OpenSSF TAC about our plans to submit an Exploratory Report to the PAS process for International Standardization
- Issue comment#46adriandiglio2024-07-16 19:16Annotate maturity graphic with requirement ID's
- Issue#46adriandiglio2024-07-16 19:16Annotate maturity graphic with requirement ID's
- Pull request#56tombedfordgit2024-07-16 16:22
- Pull request#56adriandiglio2024-07-15 14:51
- Issue comment#1ABirHAsan123-beep2024-06-20 19:32Suggestion: Move "Deny List" from maturity level 2 to level 3
- Issue#48tombedfordgit2024-06-05 14:40Clarify that SCA-5 is about tool-based analysis
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 120 stars here means stars gained during the window, not the repo's star count.