ocsf-lib
Tools for working with the OCSF schema
Decision gist · record as of 2026-08-14
Yes, if you work with OCSF schemas and need validation, comparison, or compilation tooling. The low install friction and permissive license make it accessible. However, the aging maintenance status warrants caution for production deployments—verify that the package still meets your schema version requirements and that the public API integration tests remain reliable.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later.
- Integration tests depend on network access to https://schema.ocsf.io.
- Low install friction with three lightweight runtime dependencies.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; you must include a copy of the license and note any modifications.
last release 2025-07-07 (403 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 554,097 downloads/mo, #6,038 on PyPI
Alternatives
Verify before relying
pip install ocsf-lib
from ocsf.util import get_schema
schema = get_schema("1.1.0")
# Or use CLI:
# python -m ocsf.compile path/to/ocsf-schema
# python -m ocsf.compare 1.0.0 1.1.0- Whether the aging maintenance status reflects active stability or abandonment risk for production use.
- Whether the public OCSF server integration tests still pass reliably against https://schema.ocsf.io.
- Current reliability of the package against OCSF schema versions in active use.
What it is and what it does
ocsf-lib is a Python toolkit for working with the Open Cybersecurity Schema Framework. It provides both CLI commands and programmatic APIs to compile OCSF schemas from repository sources, validate them for backwards compatibility, compare different schema versions to detect breaking changes, and fetch schemas from the official OCSF API. The library is built around several discrete packages: ocsf.schema for data model representation, ocsf.repository for working with schema repositories on disk, ocsf.compile for schema compilation, ocsf.compare for detecting schema differences, and ocsf.validate.compatibility for breaking-change detection.
The package targets Python 3.11 and depends on dacite for dataclass deserialization, semver for version handling, and termcolor for CLI output formatting. It is designed as a namespace package so other OCSF-related tools can coexist in the same namespace. The library grew out of internal tooling and aims to make OCSF more hackable by providing reference implementations and composable utilities for the OCSF community.
Use it for
- Validate OCSF schema pull requests for breaking changes before merging.
- Programmatically detect and report schema differences between two OCSF versions.
- Compile an OCSF schema repository into a single JSON file for deployment.
- Build adapters between different OCSF schema versions or flavors.
- Fetch and cache OCSF schemas from the official API for local use.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you work with OCSF schemas and need validation, comparison, or compilation tooling.
The low install friction and permissive license make it accessible. However, the aging maintenance status warrants caution for production deployments—verify that the package still meets your schema version requirements and that the public API integration tests remain reliable.
Install
ocsf-lib on PyPI
Before you install
Low install friction with three lightweight runtime dependencies. Maintenance status is aging, so expect slower response to issues, though no recent vulnerabilities are recorded.
Requires Python 3.11 or later. Integration tests depend on network access to https://schema.ocsf.io.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; you must include a copy of the license and note any modifications.
Quickstart
pip install ocsf-lib
from ocsf.util import get_schema
schema = get_schema("1.1.0")
# Or use CLI:
# python -m ocsf.compile path/to/ocsf-schema
# python -m ocsf.compare 1.0.0 1.1.0
Verify before relying
- Whether the aging maintenance status reflects active stability or abandonment risk for production use.
- Whether the public OCSF server integration tests still pass reliably against https://schema.ocsf.io.
- Current reliability of the package against OCSF schema versions in active use.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <4.0,>=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesdacitesemvertermcolor |
| Maintenance | Aging 403 days since the last release |
| First released | |
| Downloads | 554,097 / month, #6,038 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.11 |
Evidence: ocsf_lib-0.10.4-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “OCSF schema compiler”
- ocsf-libProvides Python tools to compile, validate, compare, and work with…
- py-ocsf-modelsProvides Python models for the Open Cybersecurity Schema Framework…
- DeepFriedMarshmallowAccelerates Marshmallow schema serialization and deserialization by…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also py-ocsf-models · fastjsonschema · warchant_dc_schema · sqlalchemy-diff · kubernetes-validate · check-jsonschema · jsonschema-pydantic · flex · yamale · py-solc-x