Skip to main content

TsunamiSight

A client that extracts vulnerability-related observations from the Tsunami Security Scanner plugins repository and publishes them as sightings on a Vulnerability-Lookup instance.

Each committed Tsunami detector is a compiled, executable proof-of-concept for a specific vulnerability. Google's newer templated plugins (.textproto files under templated/templateddetector/plugins/) are also parsed for CVE sightings. TsunamiSight emits one sighting per (plugin, CVE) pair with the default type published-proof-of-concept.

Installation

$ pipx install TsunamiSight
$ export TSUNAMISIGHT_CONFIG=~/.TsunamiSight/conf.py
$ git clone https://github.com/google/tsunami-security-scanner-plugins.git tsunami-security-scanner-plugins

Copy tsunamisight/conf_sample.py to your chosen config path and fill in the token + URL.

With Docker

git clone <this repo>
cd TsunamiSight
cp tsunamisight/conf_sample.py tsunamisight/conf.py   # then fill in token
docker compose up --build

Usage

TsunamiSight --help
usage: TsunamiSight [-h] [--init] [--dry-run]

Extract CVE references from the Tsunami plugins repo and publish sightings.

options:
  -h, --help   show this help message and exit
  --init       Full sweep: emit sightings for every CVE-bearing plugin.
  --dry-run    Parse and print (plugin, CVE, timestamp) triples without POSTing.

License

TsunamiSight is licensed under GNU General Public License version 3

Copyright (c) 2026 Computer Incident Response Center Luxembourg (CIRCL)
Copyright (C) 2026 Philippe Parage - https://github.com/pparage

Release files for TsunamiSight 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for TsunamiSight 0.1.1
File Size Uploaded
tsunamisight-0.1.1.tar.gz 18.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for TsunamiSight 0.1.1
File Interpreter ABI Platform
tsunamisight-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 39.7 kB

Release files / tsunamisight-0.1.1.tar.gz

Download URL tsunamisight-0.1.1.tar.gz
Size 18.4 kB
Tags Source
SHA-256 checksum
How to use checksums
0999a9aaaf89a55c6900b8d7bad5306689b464abd84c413d7e626058097f7c5a
BLAKE2b-256 checksum
How to use checksums
218ee6b4b8b1aaa7b5cde49146cdc8687e40d5044541fc2688cb61ff8cafb055
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 29, 2026.

Transparency log

Release files / tsunamisight-0.1.1-py3-none-any.whl

Download URL tsunamisight-0.1.1-py3-none-any.whl
Size 21.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9a549154aeb553c2867fbb76e1f345bce7964d3853e98b201e194b416b1e6bad
BLAKE2b-256 checksum
How to use checksums
0dd0809e09a28c7ae2df38fc05f352d45abda40546b476400a8014643e340d96
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page