Understand OSPS Baseline Coverage in Scorecard
mainScorecard provides coverage analysis against the OSPS Baseline v2026.02.19. This analysis maps Scorecard's probes and checks to specific OpenSSF security controls across three levels of maturity.
Coverage Status Legend
When reviewing coverage, use the following status indicators:
- COVERED: Scorecard has probes that fully satisfy the control.
- PARTIAL: Scorecard has probes that provide evidence but do not fully satisfy the control.
- GAP: No existing probe provides meaningful evidence for this control.
- NOT_OBSERVABLE: The control requires data Scorecard cannot access (e.g., organization-level admin permissions).