python-gvm
Library to communicate with remote servers over GMP or OSP
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained (release 11 days old), has no known vulnerabilities, supports current Python versions (3.10–3.14), and carries low install friction. The copyleft GPL-3.0-or-later license is a consideration only if you plan to distribute derivative works. Install if you need to programmatically control Greenbone vulnerability management systems; skip if you have no Greenbone infrastructure to manage.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Requires a running Greenbone Management daemon accessible via Unix socket or network connection.
- Low friction installation with three straightforward runtime dependencies (httpx, lxml, paramiko).
License · maintenance · safety
GPL-3.0-or-later (copyleft) — Licensed under GPL-3.0-or-later (copyleft). Any derivative work or modification must be distributed under the same license terms, and source code must be made available to users.
last release 2026-08-03 (11 days) · last repo commit 2026-08-10 · 125 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 85,212 downloads/mo, #13,942 on PyPI
Alternatives
Verify before relying
pip install python-gvm
from gvm.connections import UnixSocketConnection
from gvm.protocols.gmp import GMP
from gvm.transforms import EtreeTransform
connection = UnixSocketConnection()
transform = EtreeTransform()
with GMP(connection, transform=transform) as gmp:
gmp.authenticate('user', 'pass')
tasks = gmp.get_tasks()- Whether the package works with all Greenbone Community Edition and Enterprise Appliance versions currently in use, given the documented version compatibility constraints.
- Performance characteristics and typical response times for large-scale vulnerability queries.
- Whether paramiko is used for SSH transport or only for specific connection types.
What it is and what it does
python-gvm is a Python library that wraps the Greenbone Management Protocol (GMP) and Open Scanner Protocol (OSP) to enable remote control of Greenbone vulnerability management systems. It abstracts the underlying XML-based communication protocols, allowing developers to authenticate, retrieve vulnerability data, manage tasks, and interact with Greenbone Community Edition installations and Enterprise Appliances through straightforward Python method calls. The library uses lxml for XML parsing and httpx for HTTP communication, with paramiko available for SSH-based connections.
The package is actively maintained by Greenbone AG, supports Python 3.10 through 3.14, and is classified as Production/Stable. It handles the complexity of GMP/OSP protocol details so users can focus on vulnerability management workflows rather than protocol mechanics. The library is typically used by security teams and automation platforms that need programmatic access to Greenbone scanning and reporting capabilities.
Use it for
- Automate vulnerability scanning workflows by remotely creating, scheduling, and retrieving results from Greenbone tasks.
- Build custom dashboards or reporting tools that aggregate vulnerability data from Greenbone installations.
- Integrate Greenbone scanning into CI/CD pipelines to perform automated security assessments on deployments.
- Develop security orchestration scripts that coordinate vulnerability management across multiple Greenbone instances.
- Query and export vulnerability data in custom formats for compliance reporting or third-party analysis.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained (release 11 days old), has no known vulnerabilities, supports current Python versions (3.10–3.14), and carries low install friction. The copyleft GPL-3.0-or-later license is a consideration only if you plan to distribute derivative works. Install if you need to programmatically control Greenbone vulnerability management systems; skip if you have no Greenbone infrastructure to manage.
Install
python-gvm on PyPI
Before you install
Low friction installation with three straightforward runtime dependencies (httpx, lxml, paramiko). Actively maintained with a release 11 days old and last commit on 2026-08-10, indicating steady development.
Requires Python 3.10 or later. Requires a running Greenbone Management daemon accessible via Unix socket or network connection.
License in practice
Licensed under GPL-3.0-or-later (copyleft). Any derivative work or modification must be distributed under the same license terms, and source code must be made available to users.
Quickstart
pip install python-gvm
from gvm.connections import UnixSocketConnection
from gvm.protocols.gmp import GMP
from gvm.transforms import EtreeTransform
connection = UnixSocketConnection()
transform = EtreeTransform()
with GMP(connection, transform=transform) as gmp:
gmp.authenticate('user', 'pass')
tasks = gmp.get_tasks()
Verify before relying
- Whether the package works with all Greenbone Community Edition and Enterprise Appliance versions currently in use, given the documented version compatibility constraints.
- Performance characteristics and typical response times for large-scale vulnerability queries.
- Whether paramiko is used for SSH transport or only for specific connection types.
Package facts
| License | GPL-3.0-or-later copyleft |
| Python support | Supports the current Python release <4,>=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packageshttpxlxmlparamiko |
| Maintenance | Actively maintained 11 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 85,212 / month, #13,942 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: Libraries :: Python Modules |
Evidence: python_gvm-27.6.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “greenbone vulnerability management api”
- python-gvmPython library that abstracts the Greenbone Management Protocol (GMP)…
- pontosPontos is a collection of Python utilities and tools for common…
- pyTenablepyTenable provides a unified Python interface to Tenable's…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also pontos · pyghmi · safety · uv-secure · zaproxy · cisco-ai-mcp-scanner · clamav-client · pigpio · ibm-platform-services