ca9
Open source Python package security and evidence-backed SCA triage
Decision gist · record as of 2026-08-14
Yes, if you use Python and want to reduce CVE alert noise with evidence-backed triage. ca9 is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem—most flagged CVEs are unreachable. The MPL-2.0 license is permissive for local use. Start with `ca9 scan` on an existing SCA report to see the impact. Early-stage (Alpha), so expect API evolution, but the core reachability logic is sound.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- For full functionality, your project should have a recognized lockfile or SCA report to analyze.
- Low friction: pure Python wheel with only two runtime dependencies (packaging, tomli).
License · maintenance · safety
MPL-2.0 (copyleft) — MPL-2.0 is copyleft: you may use ca9 freely and modify it, but if you distribute modified versions, you must disclose source and license derivative works under MPL-2.0. For most local security tooling use, this poses no practical barrier.
last release 2026-06-27 (48 days) · last repo commit 2026-08-14 · 8 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,301 downloads/mo, #14,537 on PyPI
Alternatives
Verify before relying
pip install ca9[cli]
ca9 scan --repo . --coverage coverage.json
ca9 inventory --repo . -f json- Whether static import tracing and coverage analysis work reliably on complex dependency graphs with dynamic imports.
- Performance characteristics on large monorepos or projects with hundreds of transitive dependencies.
- Completeness of vulnerable API detection rules and how often they require manual tuning.
- Reliability of reachability verdicts across different Python packaging patterns and import styles.
What it is and what it does
ca9 is a local-first supply-chain defense tool that reads your Python project's manifests, lockfiles, and SCA reports, then answers a single critical question for each CVE alert: is this vulnerable code actually reachable from your application? It combines three evidence sources—static AST import tracing, dependency graph analysis, and optional runtime coverage data—to classify each vulnerability as reachable, unreachable (static or dynamic), or inconclusive, with an evidence trail and confidence score for each verdict.
Instead of patching every flagged CVE, you get a filtered list of only the vulnerabilities that matter: code your app actually imports and executes. ca9 also provides broader supply-chain vetting (malware advisories, registry trust, artifact hashes, license policy, dependency confusion risk) and runtime preflight enforcement via `ca9 run`, so you can block unsafe packages before they install. It reads native Python manifests, npm lockfiles, and SBOM inputs, and outputs JSON, SARIF, OpenVEX, or Markdown for integration into CI gates and audit workflows.
Use it for
- Filter CVE alerts from SCA tools to identify which vulnerabilities actually affect your code, reducing alert fatigue.
- Build a normalized package inventory from mixed lockfile formats to audit direct and transitive dependencies.
- Enforce supply-chain policy in CI by blocking untrusted registries, dependency-confusion risks, or missing hashes.
- Combine static import analysis with coverage data to confirm whether a vulnerable function is ever called.
- Generate OpenVEX or SARIF reports for downstream security tools, enriching SCA output with reachability evidence.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you use Python and want to reduce CVE alert noise with evidence-backed triage.
ca9 is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem—most flagged CVEs are unreachable. The MPL-2.0 license is permissive for local use. Start with `ca9 scan` on an existing SCA report to see the impact. Early-stage (Alpha), so expect API evolution, but the core reachability logic is sound.
Install
ca9 on PyPI
Before you install
Low friction: pure Python wheel with only two runtime dependencies (packaging, tomli). Active maintenance—last commit 2026-08-14, released 2026-06-27, only 48 days old. Supports Python 3.10 through 3.13. No known vulnerabilities.
Requires Python 3.10 or later. For full functionality, your project should have a recognized lockfile or SCA report to analyze.
License in practice
MPL-2.0 is copyleft: you may use ca9 freely and modify it, but if you distribute modified versions, you must disclose source and license derivative works under MPL-2.0. For most local security tooling use, this poses no practical barrier.
Quickstart
pip install ca9[cli]
ca9 scan --repo . --coverage coverage.json
ca9 inventory --repo . -f json
Verify before relying
- Whether static import tracing and coverage analysis work reliably on complex dependency graphs with dynamic imports.
- Performance characteristics on large monorepos or projects with hundreds of transitive dependencies.
- Completeness of vulnerable API detection rules and how often they require manual tuning.
- Reliability of reachability verdicts across different Python packaging patterns and import styles.
Package facts
| License | MPL-2.0 copyleft |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagespackagingtomli |
| Maintenance | Actively maintained 48 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 77,301 / month, #14,537 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0)Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: SecurityTopic :: Software Development :: Quality Assurance |
Evidence: ca9-0.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cve reachability analysis”
- ca9ca9 analyzes Python package supply chains to determine whether…
- debsecan-mcpAn MCP server that scans Debian systems for known security…
- cwe2cwe2 provides programmatic access to the Common Weakness Enumeration…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also socketsecurity · safety · pip-audit · pysentry-rs · guarddog · pdfid · debsecan-mcp · flawfinder · cvss · hello-world