pycadf
CADF Library
Decision gist · record as of 2026-08-14
Yes, if you are building or extending OpenStack or need to emit CADF-compliant audit events. The low install friction, active maintenance, permissive license, and zero known vulnerabilities make it a safe choice. If you are not working within an OpenStack context or do not need CADF compliance, this library is unlikely to be relevant.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later.
- Low install friction with only two runtime dependencies (oslo.config and oslo.serialization).
- Active maintenance with a release 36 days ago.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most deployment contexts.
last release 2026-07-09 (36 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 329,177 downloads/mo, #7,547 on PyPI
Alternatives
Verify before relying
pip install pycadf
from pycadf import cadf_base
from oslo.serialization import jsonutils
event = cadf_base.CADFBase()
event_json = jsonutils.dumps(event.as_dict())- Whether the package is actively maintained by OpenStack or has transitioned to community maintenance.
- Real-world adoption rate beyond OpenStack projects.
- Performance characteristics when serializing large audit event volumes.
What it is and what it does
PyCADF is a Python library that implements the Cloud Auditing Data Federation (CADF) specification published by the DMTF. It provides a data model and serialization layer for audit events, allowing systems to emit structured, standardized audit notifications that comply with the CADF schema. The library is primarily used within OpenStack but can be adopted by any system that needs to produce audit trails meeting the CADF standard.
The package depends on oslo.config and oslo.serialization for configuration and JSON serialization. It establishes strict expectations about audit event structure, making it easier for auditors and compliance tools to parse and validate audit logs from diverse sources. The library has been actively maintained since its initial release and supports modern Python versions.
Use it for
- Emit standardized CADF-compliant audit events from OpenStack services.
- Build audit logging into cloud applications that need to meet compliance or security standards.
- Serialize audit events to JSON for ingestion into centralized audit log aggregation systems.
- Validate audit event structure against the CADF specification before transmission.
- Integrate audit trail generation into systems that must interoperate with CADF-aware tools.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building or extending OpenStack or need to emit CADF-compliant audit events.
The low install friction, active maintenance, permissive license, and zero known vulnerabilities make it a safe choice. If you are not working within an OpenStack context or do not need CADF compliance, this library is unlikely to be relevant.
Install
pycadf on PyPI
Before you install
Low install friction with only two runtime dependencies (oslo.config and oslo.serialization). Active maintenance with a release 36 days ago. Supports current Python versions (3.11–3.14).
Requires Python 3.11 or later.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most deployment contexts.
Quickstart
pip install pycadf
from pycadf import cadf_base
from oslo.serialization import jsonutils
event = cadf_base.CADFBase()
event_json = jsonutils.dumps(event.as_dict())
Verify before relying
- Whether the package is actively maintained by OpenStack or has transitioned to community maintenance.
- Real-world adoption rate beyond OpenStack projects.
- Performance characteristics when serializing large audit event volumes.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesoslo.configoslo.serialization |
| Maintenance | Actively maintained 36 days since the last release |
| First released | |
| Downloads | 329,177 / month, #7,547 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: OpenStackIntended Audience :: Information TechnologyIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: pycadf-4.1.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “CADF audit events”
- pycadfPyCADF implements the Cloud Auditing Data Federation specification to…
- google-cloud-audit-logProvides Python bindings to Google Cloud Audit Log protocol buffers,…
- alibabacloud-actiontrail20200706Provides Python bindings to Alibaba Cloud's ActionTrail service for…
Give your agent the search over MCP, or paste the wish link into any chat.
More Monitoring packages
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
Provides generated Python code for OpenTelemetry semantic conventions, enabling standardized attribute naming and constant definitions for instrumentation and telemetry collection.
Install it if you are using OpenTelemetry and want to follow semantic conventions correctly.
Provides the reference implementation of the OpenTelemetry API for collecting and exporting traces, metrics, and logs from Python applications.
Provides the abstract API and interfaces for OpenTelemetry instrumentation in Python, defining how to emit traces, metrics, and logs without tying code to a specific SDK implementation.
Exports OpenTelemetry observability data to an OpenTelemetry Collector using Protobuf-encoded messages over HTTP.
Install it if you are using OpenTelemetry in Python and need to send data to a Collector over HTTP.
Provides automatic instrumentation commands and programmatic APIs to inject distributed tracing into Python applications without code changes, detecting and instrumenting packages used by your program.
Install it if you need distributed tracing without code changes and have compatible instrumented packages in your environment.
See also os-vif · cloudsec-audit · keystoneauth1 · aa-memberaudit · SQLAlchemy-Continuum · graphene-federation · django-easy-audit · google-cloud-audit-log · asdf-standard · ciris-persist