csaf-tool
CSAF generator and analyser
Decision gist · record as of 2026-08-14
Yes, if you need to generate or analyze CSAF 2.0 documents and accept dormant maintenance. The low install friction, permissive license, and zero known vulnerabilities make it safe to use. However, do not expect bug fixes or new features—evaluate whether the current feature set and stability meet your long-term needs before adopting it in a critical workflow.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.7 or later.
- CSV input files must follow the documented schema (product,vendor,release and product,release,id,description,status,comment headers).
- Low install friction with only two runtime dependencies.
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing commercial and private use with minimal restrictions.
last release 2024-06-12 (793 days) · last repo commit 2024-10-16 · 9 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,614 downloads/mo, #14,511 on PyPI
Alternatives
Verify before relying
pip install csaf-tool
csaf-tool --generate --product products.csv --vulnerabilities vulns.csv --output-file advisory.json --config csaf.ini- Whether the tool validates CSAF documents against the official CSAF 2.0 schema
- Support for CSAF formats beyond 2.0 or backward compatibility with earlier versions
- Whether programmatic library usage is documented or tested
What it is and what it does
CSAF-Tool is a command-line utility and Python library for working with CSAF 2.0 documents—the Common Security Advisory Framework standard for publishing structured vulnerability information. It reads product and vulnerability data from CSV files and generates a compliant CSAF JSON document that includes a product tree, vulnerability details, and remediation status. It can also parse and display an existing CSAF document in human-readable table format using the rich library.
The tool is designed for security teams and vendors who need to publish standardized vulnerability advisories. It depends on packageurl-python for package identification and rich for formatted terminal output. Development is dormant as of mid-2024, so it is suitable for stable, straightforward CSAF generation workflows but not for projects requiring active maintenance or new features.
Use it for
- Generate a CSAF advisory document from a CSV list of products and their known vulnerabilities
- Parse and display an existing CSAF JSON file in a formatted table for review
- Integrate CSAF generation into a security advisory pipeline using the package as a library
- Publish vendor security advisories in the standardized CSAF format for compliance or distribution
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to generate or analyze CSAF 2.0 documents and accept dormant maintenance.
The low install friction, permissive license, and zero known vulnerabilities make it safe to use. However, do not expect bug fixes or new features—evaluate whether the current feature set and stability meet your long-term needs before adopting it in a critical workflow.
Install
csaf-tool on PyPI
Before you install
Low install friction with only two runtime dependencies. Maintenance is dormant—last commit was 2024-10-16, over 793 days ago—so expect no active bug fixes or feature updates.
Requires Python 3.7 or later. CSV input files must follow the documented schema (product,vendor,release and product,release,id,description,status,comment headers).
License in practice
MIT license is permissive, allowing commercial and private use with minimal restrictions.
Quickstart
pip install csaf-tool
csaf-tool --generate --product products.csv --vulnerabilities vulns.csv --output-file advisory.json --config csaf.ini
Verify before relying
- Whether the tool validates CSAF documents against the official CSAF 2.0 schema
- Support for CSAF formats beyond 2.0 or backward compatibility with earlier versions
- Whether programmatic library usage is documented or tested
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagespackageurl-pythonrich |
| Maintenance | Dormant 793 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 77,614 / month, #14,511 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy |
Evidence: csaf_tool-0.3.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “CSAF document generation”
- csaf-toolGenerates and analyzes CSAF 2.0 documents, which describe product…
- lib4vexLib4VEX parses and generates VEX (Vulnerability Exploitability…
- atlassian-doc-builderProgrammatically generate and validate Atlassian Document Format…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also lib4vex · reqif · spdx-tools · distro2sbom · zizmor · semgrep · pip-audit · cwe2 · njsscan · defusedcsv