Skip to main content

TsunamiSight

A client that extracts vulnerability-related observations from the Tsunami Security Scanner plugins repository and publishes them as sightings on a Vulnerability-Lookup instance.

Each committed Tsunami detector is a compiled, executable proof-of-concept for a specific vulnerability. Google's newer templated plugins (.textproto files under templated/templateddetector/plugins/) are also parsed for CVE sightings. TsunamiSight emits one sighting per (plugin, CVE) pair with the default type published-proof-of-concept.

Installation

$ pipx install TsunamiSight
$ export TSUNAMISIGHT_CONFIG=~/.TsunamiSight/conf.py
$ git clone https://github.com/google/tsunami-security-scanner-plugins.git tsunami-security-scanner-plugins

Copy tsunamisight/conf_sample.py to your chosen config path and fill in the token + URL.

With Docker

git clone <this repo>
cd TsunamiSight
cp tsunamisight/conf_sample.py tsunamisight/conf.py   # then fill in token
docker compose up --build

Usage

TsunamiSight --help
usage: TsunamiSight [-h] [--init] [--dry-run]

Extract CVE references from the Tsunami plugins repo and publish sightings.

options:
  -h, --help   show this help message and exit
  --init       Full sweep: emit sightings for every CVE-bearing plugin.
  --dry-run    Parse and print (plugin, CVE, timestamp) triples without POSTing.

License

TsunamiSight is licensed under GNU General Public License version 3

Copyright (c) 2026 Computer Incident Response Center Luxembourg (CIRCL)
Copyright (C) 2026 Philippe Parage - https://github.com/pparage

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

tsunamisight-0.1.1.tar.gz (18.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

tsunamisight-0.1.1-py3-none-any.whl (21.2 kB view details)

Uploaded Python 3

File details

Details for the file tsunamisight-0.1.1.tar.gz.

File metadata

  • Download URL: tsunamisight-0.1.1.tar.gz
  • Upload date:
  • Size: 18.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for tsunamisight-0.1.1.tar.gz
Algorithm Hash digest
SHA256 0999a9aaaf89a55c6900b8d7bad5306689b464abd84c413d7e626058097f7c5a
MD5 472d63647fd09331a8882fd6b2706010
BLAKE2b-256 218ee6b4b8b1aaa7b5cde49146cdc8687e40d5044541fc2688cb61ff8cafb055

See more details on using hashes here.

Provenance

The following attestation bundles were made for tsunamisight-0.1.1.tar.gz:

Publisher: release.yml on vulnerability-lookup/TsunamiSight

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file tsunamisight-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: tsunamisight-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 21.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for tsunamisight-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 9a549154aeb553c2867fbb76e1f345bce7964d3853e98b201e194b416b1e6bad
MD5 64f5e041207eed5e12fe75eb6e74e147
BLAKE2b-256 0dd0809e09a28c7ae2df38fc05f352d45abda40546b476400a8014643e340d96

See more details on using hashes here.

Provenance

The following attestation bundles were made for tsunamisight-0.1.1-py3-none-any.whl:

Publisher: release.yml on vulnerability-lookup/TsunamiSight

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page