$npx skillfedfor your agent

csaf-tool

CSAF generator and analyser

With conditionsPyPI SecurityReleased Jun 202477.6K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — csaf_tool-0.3.2-py2.py3-none-any.whl
v0.3.2 · released 2024-06-12 · Python >=3.7 · 2 runtime deps: packageurl-python, rich

Yes, if you need to generate or analyze CSAF 2.0 documents and accept dormant maintenance. The low install friction, permissive license, and zero known vulnerabilities make it safe to use. However, do not expect bug fixes or new features—evaluate whether the current feature set and stability meet your long-term needs before adopting it in a critical workflow.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.7 or later.
  • CSV input files must follow the documented schema (product,vendor,release and product,release,id,description,status,comment headers).
  • Low install friction with only two runtime dependencies.

License · maintenance · safety

MIT (permissive) — MIT license is permissive, allowing commercial and private use with minimal restrictions.

last release 2024-06-12 (793 days) · last repo commit 2024-10-16 · 9 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,614 downloads/mo, #14,511 on PyPI

Verify before relying

pip install csaf-tool

csaf-tool --generate --product products.csv --vulnerabilities vulns.csv --output-file advisory.json --config csaf.ini
  • Whether the tool validates CSAF documents against the official CSAF 2.0 schema
  • Support for CSAF formats beyond 2.0 or backward compatibility with earlier versions
  • Whether programmatic library usage is documented or tested
Same gist for agents: .md · .json

What it is and what it does

CSAF-Tool is a command-line utility and Python library for working with CSAF 2.0 documents—the Common Security Advisory Framework standard for publishing structured vulnerability information. It reads product and vulnerability data from CSV files and generates a compliant CSAF JSON document that includes a product tree, vulnerability details, and remediation status. It can also parse and display an existing CSAF document in human-readable table format using the rich library.

The tool is designed for security teams and vendors who need to publish standardized vulnerability advisories. It depends on packageurl-python for package identification and rich for formatted terminal output. Development is dormant as of mid-2024, so it is suitable for stable, straightforward CSAF generation workflows but not for projects requiring active maintenance or new features.

Use it for

  • Generate a CSAF advisory document from a CSV list of products and their known vulnerabilities
  • Parse and display an existing CSAF JSON file in a formatted table for review
  • Integrate CSAF generation into a security advisory pipeline using the package as a library
  • Publish vendor security advisories in the standardized CSAF format for compliance or distribution

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need to generate or analyze CSAF 2.0 documents and accept dormant maintenance.

The low install friction, permissive license, and zero known vulnerabilities make it safe to use. However, do not expect bug fixes or new features—evaluate whether the current feature set and stability meet your long-term needs before adopting it in a critical workflow.

Install

csaf-tool on PyPI

Before you install

Low install friction with only two runtime dependencies. Maintenance is dormant—last commit was 2024-10-16, over 793 days ago—so expect no active bug fixes or feature updates.

Requires Python 3.7 or later. CSV input files must follow the documented schema (product,vendor,release and product,release,id,description,status,comment headers).

License in practice

MIT license is permissive, allowing commercial and private use with minimal restrictions.

Quickstart

pip install csaf-tool

csaf-tool --generate --product products.csv --vulnerabilities vulns.csv --output-file advisory.json --config csaf.ini

Verify before relying

  • Whether the tool validates CSAF documents against the official CSAF 2.0 schema
  • Support for CSAF formats beyond 2.0 or backward compatibility with earlier versions
  • Whether programmatic library usage is documented or tested

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.7
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
packageurl-pythonrich
MaintenanceDormant 793 days since the last release
Last repo commit
First released
Downloads77,614 / month, #14,511 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: csaf_tool-0.3.2-py2.py3-none-any.whl

Tags

Capabilities
CSAF document generationvulnerability advisory formatproduct security advisoriesCSAF 2.0 parserVEX vulnerability exchangesecurity advisory tool
Topics
security-advisorycsaf-vex
PyPI keywords
securitytoolsCSAFCSAF 2.0VexDevSecOpsvulnerabilities

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “CSAF document generation”

  • csaf-toolGenerates and analyzes CSAF 2.0 documents, which describe product…
  • lib4vexLib4VEX parses and generates VEX (Vulnerability Exploitability…
  • atlassian-doc-builderProgrammatically generate and validate Atlassian Document Format…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also lib4vex · reqif · spdx-tools · distro2sbom · zizmor · semgrep · pip-audit · cwe2 · njsscan · defusedcsv