Skip to main content

Greenbone Logo

greenbone-scap - Python library for downloading CVE and CPE from NIST NVD

GitHub releases PyPI release codecov Build and test

The greenbone-scap Python package is a collection of utilities and tools to download the CPE and CVE information from the NIST NVD REST API into a PostgreSQL database.

Table of Contents

Installation

Requirements

Python 3.11 and later is supported.

Install using pipx

You can install the latest stable release of greenbone-scap from the Python Package Index (pypi) using pipx

python3 -m pipx install greenbone-scap

Install using pip

You can install the latest stable release of greenbone-scap from the Python Package Index (pypi) using pip

python3 -m pip install --user greenbone-scap

Usage

The greenbone-scap Python package provides three tools,

  • greenbone-cve-download to download all CVE information from NIST NVD into a PostgreSQL database,
  • greenbone-cpe-download to download all CPE information from NIST NVD into a PostgreSQL database and
  • greenbone-cpe-find to search for specific CPEs in the PostgreSQL database.

All three tools require to setup a PostgreSQL database to work correctly. The parameters for the PostgreSQL database like host, port, username and password can be set via environment variables or passed as CLI arguments.

Docker Compose

The tools are easiest to use via the provided docker compose file. For a quick setup the following commands can be used:

cd docker
echo "DATABASE_PASSWORD=my-super-safe-password" > .env
docker compose up

Additionally a NIST API key can be used to extend the rate limits for the download.

echo "NVD_API_KEY=my-nist-api-key" >> .env

On the first startup all CPE and CVE information will be downloaded. This will take some hours depending on your network connection and the server reliability at NIST. On the next startup only the changed and new CPEs and CVEs since the previous startup are updated or created.

To only download CPEs run docker compose up cpe and to only download CVEs docker compose up cve.

To re-download and re-update all CPE and CVE information the data volume can be deleted by running docker volume rm greenbone-scap_data.

To restart from scratch all containers have to be shutdown and the volumes have to be removed. This can be done by running docker compose down -v.

The PostgreSQL database can be accessed from the docker host via psql -U scap -h localhost -p 5432 scap and using the defined database password from the .env file.

Command Completion

greenbone-scap comes with support for command line completion in bash and zsh. All greenbone-scap CLI commands support shell completion. As examples the following sections explain how to set up the completion for greenbone-cve-download with bash and zsh.

Setup for bash

echo "source ~/.greenbone-cve-download-complete.bash" >> ~/.bashrc
greenbone-cve-download --print-completion bash > ~/.greenbone-cve-download-complete.bash

Alternatively, you can use the result of the completion command directly with the eval function of your bash shell:

eval "$(greenbone-cve-download --print-completion bash)"

Setup for zsh

echo 'fpath=("$HOME/.zsh.d" $fpath)' >> ~/.zsh
mkdir -p ~/.zsh.d/
greenbone-cve-download --print-completion zsh > ~/.zsh.d/_greenbone_cve_download

Alternatively, you can use the result of the completion command directly with the eval function of your zsh shell:

eval "$(greenbone-cve-download --print-completion zsh)"

Development

greenbone-scap uses poetry for its own dependency management and build process.

First install poetry via pipx

python3 -m pipx install poetry

Afterwards run

poetry install

in the checkout directory of greenbone-scap (the directory containing the pyproject.toml file) to install all dependencies including the packages only required for development.

Afterwards activate the git hooks for auto-formatting and linting via autohooks.

poetry run autohooks activate

Validate the activated git hooks by running

poetry run autohooks check

Maintainer

This project is maintained by Greenbone AG

Contributing

Your contributions are highly appreciated. Please create a pull request on GitHub. Bigger changes need to be discussed with the development team via the issues section at GitHub first.

License

Copyright (C) 2024 Greenbone AG

Licensed under the GNU General Public License v3.0 or later.

Metadata

Release files for greenbone-scap 0.3.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for greenbone-scap 0.3.6
File Size Uploaded
greenbone_scap-0.3.6.tar.gz 60.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for greenbone-scap 0.3.6
File Interpreter ABI Platform
greenbone_scap-0.3.6-py3-none-any.whl Python 3 none any Details

Total release size: 137.4 kB

Release files / greenbone_scap-0.3.6.tar.gz

Download URL greenbone_scap-0.3.6.tar.gz
Size 60.2 kB
Tags Source
SHA-256 checksum
How to use checksums
e342a6838ab4d846f0e23f6d0b15239e5287c6694b4c37e54d7186517ac5d2c7
BLAKE2b-256 checksum
How to use checksums
6903d96a0517967bf62b6c1374362d44fbc1e7831fc002ca5da4a947623008de
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.1 CPython/3.12.11

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 25, 2025.

Transparency log

Release files / greenbone_scap-0.3.6-py3-none-any.whl

Download URL greenbone_scap-0.3.6-py3-none-any.whl
Size 77.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
71154504eb8ce63e15223493b1c50ac7dc2b2fb211177d4af9d450494857e785
BLAKE2b-256 checksum
How to use checksums
3611c8c32dbb0863c8e25579add42b5c53b935d1241e707204357dc31b8ead5f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.1 CPython/3.12.11

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 25, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.6 This release

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

0.0.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page