greenbone-scap - Python library for downloading CVE and CPE from NIST NVD
The greenbone-scap Python package is a collection of utilities and tools to download the CPE and CVE information from the NIST NVD REST API into a PostgreSQL database.
Table of Contents
Installation
Requirements
Python 3.11 and later is supported.
Install using pipx
You can install the latest stable release of greenbone-scap from the Python Package Index (pypi) using pipx
python3 -m pipx install greenbone-scap
Install using pip
You can install the latest stable release of greenbone-scap from the Python Package Index (pypi) using pip
python3 -m pip install --user greenbone-scap
Usage
The greenbone-scap Python package provides three tools,
greenbone-cve-downloadto download all CVE information from NIST NVD into a PostgreSQL database,greenbone-cpe-downloadto download all CPE information from NIST NVD into a PostgreSQL database andgreenbone-cpe-findto search for specific CPEs in the PostgreSQL database.
All three tools require to setup a PostgreSQL database to work correctly. The parameters for the PostgreSQL database like host, port, username and password can be set via environment variables or passed as CLI arguments.
Docker Compose
The tools are easiest to use via the provided docker compose file. For a quick setup the following commands can be used:
cd docker
echo "DATABASE_PASSWORD=my-super-safe-password" > .env
docker compose up
Additionally a NIST API key can be used to extend the rate limits for the download.
echo "NVD_API_KEY=my-nist-api-key" >> .env
On the first startup all CPE and CVE information will be downloaded. This will take some hours depending on your network connection and the server reliability at NIST. On the next startup only the changed and new CPEs and CVEs since the previous startup are updated or created.
To only download CPEs run docker compose up cpe and to only download CVEs
docker compose up cve.
To re-download and re-update all CPE and CVE information the data volume can be
deleted by running docker volume rm greenbone-scap_data.
To restart from scratch all containers have to be shutdown and the volumes have
to be removed. This can be done by running docker compose down -v.
The PostgreSQL database can be accessed from the docker host via
psql -U scap -h localhost -p 5432 scap and using the defined database password
from the .env file.
Command Completion
greenbone-scap comes with support for command line completion in bash and zsh.
All greenbone-scap CLI commands support shell completion. As examples the
following sections explain how to set up the completion for greenbone-cve-download
with bash and zsh.
Setup for bash
echo "source ~/.greenbone-cve-download-complete.bash" >> ~/.bashrc
greenbone-cve-download --print-completion bash > ~/.greenbone-cve-download-complete.bash
Alternatively, you can use the result of the completion command directly with the eval function of your bash shell:
eval "$(greenbone-cve-download --print-completion bash)"
Setup for zsh
echo 'fpath=("$HOME/.zsh.d" $fpath)' >> ~/.zsh
mkdir -p ~/.zsh.d/
greenbone-cve-download --print-completion zsh > ~/.zsh.d/_greenbone_cve_download
Alternatively, you can use the result of the completion command directly with the eval function of your zsh shell:
eval "$(greenbone-cve-download --print-completion zsh)"
Development
greenbone-scap uses poetry for its own dependency management and build process.
First install poetry via pipx
python3 -m pipx install poetry
Afterwards run
poetry install
in the checkout directory of greenbone-scap (the directory containing the
pyproject.toml file) to install all dependencies including the packages only
required for development.
Afterwards activate the git hooks for auto-formatting and linting via autohooks.
poetry run autohooks activate
Validate the activated git hooks by running
poetry run autohooks check
Maintainer
This project is maintained by Greenbone AG
Contributing
Your contributions are highly appreciated. Please create a pull request on GitHub. Bigger changes need to be discussed with the development team via the issues section at GitHub first.
License
Copyright (C) 2024 Greenbone AG
Licensed under the GNU General Public License v3.0 or later.
Metadata
Release files for greenbone-scap 0.3.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| greenbone_scap-0.3.6.tar.gz | 60.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| greenbone_scap-0.3.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 137.4 kB
Release files / greenbone_scap-0.3.6.tar.gz
| Download URL | greenbone_scap-0.3.6.tar.gz |
|---|---|
| Size | 60.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e342a6838ab4d846f0e23f6d0b15239e5287c6694b4c37e54d7186517ac5d2c7
|
|
BLAKE2b-256 checksum How to use checksums |
6903d96a0517967bf62b6c1374362d44fbc1e7831fc002ca5da4a947623008de
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/5.1.1 CPython/3.12.11
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 25, 2025.
Transparency logRelease files / greenbone_scap-0.3.6-py3-none-any.whl
| Download URL | greenbone_scap-0.3.6-py3-none-any.whl |
|---|---|
| Size | 77.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
71154504eb8ce63e15223493b1c50ac7dc2b2fb211177d4af9d450494857e785
|
|
BLAKE2b-256 checksum How to use checksums |
3611c8c32dbb0863c8e25579add42b5c53b935d1241e707204357dc31b8ead5f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/5.1.1 CPython/3.12.11
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 25, 2025.
Transparency log