{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"}],"enrichment":{"capability":"Parses, compares, and evaluates Common Platform Enumeration (CPE) identifiers in WFN, URI, and FS formats according to MITRE/NIST standards.","skillfed_tags":["asset-identification","vulnerability-management","standards-compliance"],"use_cases":["Parse and normalize CPE identifiers in vulnerability databases or asset management systems.","Compare CPE strings to match software and hardware across different naming conventions.","Evaluate CPE matching logic in security scanning tools that need to identify affected assets.","Convert between CPE format versions (1.1, 2.2, 2.3) when integrating legacy and modern systems.","Build asset classification and inventory tools that rely on standardized platform enumeration."],"what_it_does":"CPE is a Python implementation of the Common Platform Enumeration standard developed by MITRE and maintained by NIST. It provides tools to parse, compare, and evaluate CPE identifiers\u2014standardized names for applications, operating systems, and hardware devices used in enterprise asset management and vulnerability tracking. The package handles three CPE formats (WFN, URI, and FS) and supports rich comparison operations and cross-version conversion between CPE versions 1.1, 2.2, and 2.3.\n\nThe package has no runtime dependencies, making it lightweight for integration into security tools, asset inventory systems, and vulnerability scanners. However, it requires installation from source (high friction), and its maintenance status is aging. The LGPLv3 license is copyleft, meaning any derivative work must also be open-source and GPL-compatible.","worth_installing":"Yes, with conditions. Install if you need CPE parsing and matching for security or asset management workflows and can accept the LGPLv3 copyleft constraint. The package is stable and dependency-free, but verify Python version compatibility before use\u2014classifiers suggest Python 2.7 only, which is unmaintained. The high install friction and aging maintenance status mean you should confirm the package still works with your target Python version and CPE specification version before committing to it."},"id":"cpe","links":{"html":"https://skillfed.io/packages/cpe","md":"https://skillfed.io/packages/cpe.md","pypi":"https://pypi.org/project/cpe/"},"maintenance":{"status":"aging"},"meta":{"latest_release":"2024-10-02","license_spdx":null,"license_treatment":"copyleft","name":"cpe","python_support":"unspecified","summary":"CPE: Common Platform Enumeration for Python"},"popularity":{"monthly_downloads":232645,"position":9060,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"1.3.1"}
