Tools to download or provide CSAF (Common Security Advisory Framework) documents.
-
Updated
Sep 23, 2026 - Go
Tools to download or provide CSAF (Common Security Advisory Framework) documents.
Vulnerability correlation engine that works at scale turning your evidence (SBOMs, advisories) into assertions. Links vulnerability ↔ component ↔ product ↔ VEX across CSAF/VEX, OSV and CVE, and answers affectedness questions via REST API.
vexctl is a tool to attest VEX impact statements
Secvisogram is a web tool for creating and editing security advisories in the CSAF 2.0 format
Secvisogram is a web tool for creating and editing security advisories in the CSAF 2.0 format
A parser and validator for CSAF documents written in Rust
A library and CLI to work with CSAF and SBOM data
CSAF CMS Backend is a REST-based backend to support the creation and management of CSAF 2.0 documents
A web based CSAF Management System as Free Software
A CVRF CSAF Converter, taking care about OASIS specification.
Vulnogram is a tool for creating Security Advisories and CVE ID information.
csaf-validator-lib is a library that can be used to check whether a given CSAF 2.0 document is valid.
Github Action: Publish CSAF Documents from repository to GitHub Pages.
Web app (module) to display a CSAF 2 document and to browse CSAF 2 ROLIE feeds.
csaf-validator-service is a REST-based service that can be used to check whether a given CSAF 2.0 document is valid.
To associate your repository with the csaf topic, visit your repo's landing page and select "manage topics."