Lightweight vulnerability query tool for multi-source security data aggregation
Project description
vulnq - Vulnerability Query Tool
vulnq is a lightweight, multi-source vulnerability query tool that consolidates security data from multiple vulnerability databases. It accepts various software identifiers (PURLs, CPEs, hashes) and returns comprehensive vulnerability information including CVEs, severity scores, and available fixes.
Key Features
- Multiple ID Formats - Accepts PURLs, CPE strings, and file hashes
- Multi-Source Aggregation - Queries OSV.dev, GitHub Advisory, NIST NVD, and more
- Smart Format Detection - Auto-detects input format or accepts explicit flags
- Upgrade Path Suggestions - Identifies fixed versions when available
- Lightweight - API-only design, no local vulnerability databases
- Flexible Output - JSON, table, and markdown formats
Installation
pip install vulnq
For development:
git clone https://github.com/SemClone/vulnq.git
cd vulnq
pip install -e .
Quick Start
Command Line
# Query using Package URL (auto-detected)
vulnq pkg:npm/express@4.17.1
# Query using CPE string (example: Apache Log4j)
vulnq --cpe "cpe:2.3:a:apache:log4j:2.14.0:*:*:*:*:*:*:*"
# Note: Hash-based queries are not currently supported by vulnerability databases
# Query multiple identifiers from file
vulnq --input packages.txt
# Filter by severity
vulnq pkg:pypi/django@3.2.1 --min-severity high
# Output as JSON
vulnq pkg:gem/rails@6.0.0 --format json
# Include fixed versions only
vulnq pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1 --show-fixes
Python API
from vulnq import VulnerabilityQuery
# Initialize the query engine
vq = VulnerabilityQuery()
# Query by PURL
results = vq.query("pkg:npm/express@4.17.1")
# Query by CPE
results = vq.query_cpe("cpe:2.3:a:apache:log4j:2.14.0:*:*:*:*:*:*:*")
# Note: Hash queries are not currently supported by vulnerability databases
# Future versions may support this through file-to-package mapping services
# Process results
for vuln in results.vulnerabilities:
print(f"{vuln.id}: {vuln.severity} - {vuln.summary}")
if vuln.fixed_versions:
print(f" Fixed in: {', '.join(vuln.fixed_versions)}")
Supported Vulnerability Sources
- OSV.dev - Google's Open Source Vulnerability database
- GitHub Advisory Database - GitHub Security Advisories
- NIST NVD - National Vulnerability Database
- FIRST.org - Forum of Incident Response and Security Teams (planned)
- Sonatype OSS Index - Component vulnerability data (planned)
Supported Identifier Formats
Package URLs (PURLs)
pkg:npm/package@versionpkg:pypi/package@versionpkg:maven/group/artifact@versionpkg:gem/package@versionpkg:cargo/package@versionpkg:nuget/package@versionpkg:golang/module@version
CPE (Common Platform Enumeration)
cpe:2.3:a:vendor:product:version:*:*:*:*:*:*:*cpe:/a:vendor:product:version(legacy format)
File Hashes
- SHA256
- SHA1
- MD5
Configuration
vulnq can be configured via environment variables or config file:
# API Keys (optional, for higher rate limits)
export GITHUB_TOKEN="your_github_token"
export NVD_API_KEY="your_nvd_api_key"
# Cache settings
export VULNQ_CACHE_DIR="~/.vulnq/cache"
export VULNQ_CACHE_TTL="3600" # seconds
# Rate limiting
export VULNQ_MAX_CONCURRENT="5"
Integration with SEMCL.ONE
vulnq is designed to work seamlessly with other SEMCL.ONE tools:
# Pipe PURLs from src2purl to vulnq
src2purl /path/to/project | vulnq --format json
# Check vulnerabilities for detected packages
upmex /path/to/package.json | vulnq --min-severity critical
# Generate vulnerability report from SBOM
cat sbom.json | vulnq --input - --format markdown > vulns.md
Output Formats
Table (default)
┌──────────────┬──────────┬──────────┬─────────────────┬──────────────┐
│ CVE │ Severity │ CVSS │ Package │ Fixed In │
├──────────────┼──────────┼──────────┼─────────────────┼──────────────┤
│ CVE-2021-1234│ HIGH │ 7.5 │ express@4.17.1 │ 4.17.2 │
│ CVE-2021-5678│ CRITICAL │ 9.8 │ express@4.17.1 │ 4.18.0 │
└──────────────┴──────────┴──────────┴─────────────────┴──────────────┘
JSON
{
"query": "pkg:npm/express@4.17.1",
"vulnerabilities": [
{
"id": "CVE-2021-1234",
"severity": "HIGH",
"cvss_score": 7.5,
"summary": "Remote Code Execution...",
"fixed_versions": ["4.17.2", "4.18.0"],
"references": [...]
}
],
"metadata": {
"sources": ["osv", "github", "nvd"],
"query_time": "2024-11-04T10:30:00Z"
}
}
Development
Running Tests
# Run all tests
pytest
# Run with coverage
pytest --cov=vulnq tests/
# Run specific test
pytest tests/test_osv_client.py -v
Building
# Build package
python -m build
# Install locally for testing
pip install -e .
Contributing
We welcome contributions! Please see CONTRIBUTING.md for details.
License
vulnq is released under the Apache License 2.0. See LICENSE for details.
Support
- Issues: GitHub Issues
- Discussions: GitHub Discussions
- Security: Report vulnerabilities to security@semcl.one
Part of the SEMCL.ONE Software Composition Analysis toolchain
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vulnq-1.0.2.tar.gz.
File metadata
- Download URL: vulnq-1.0.2.tar.gz
- Upload date:
- Size: 34.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9151318b6ce4772d081fd528f301fd8bebc437307f7464d4dcc57212cae639b1
|
|
| MD5 |
0279f35f6feb3245c5ee96494274b8e6
|
|
| BLAKE2b-256 |
5ad1a0f63a182d9d4627a9a237d0e4754b48906df1fa15ead740feea8a826c2d
|
Provenance
The following attestation bundles were made for vulnq-1.0.2.tar.gz:
Publisher:
python-publish.yml on SemClone/vulnq
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vulnq-1.0.2.tar.gz -
Subject digest:
9151318b6ce4772d081fd528f301fd8bebc437307f7464d4dcc57212cae639b1 - Sigstore transparency entry: 673875405
- Sigstore integration time:
-
Permalink:
SemClone/vulnq@5b0af115dce1d34af0c2ff4f424fb427f57a459c -
Branch / Tag:
refs/tags/v1.0.2 - Owner: https://github.com/SemClone
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
python-publish.yml@5b0af115dce1d34af0c2ff4f424fb427f57a459c -
Trigger Event:
release
-
Statement type:
File details
Details for the file vulnq-1.0.2-py3-none-any.whl.
File metadata
- Download URL: vulnq-1.0.2-py3-none-any.whl
- Upload date:
- Size: 30.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0ebae76bdc3ff6e5f0c79b9c4f66c06bc3246fc6d79c9e2d9f48586e9e7051d4
|
|
| MD5 |
1a9194ba9cb9d72bb1208f46a50bb267
|
|
| BLAKE2b-256 |
d2638b9595978998a746ba66dfdca624c395f8e0f9efd397d6d73551c8a234a0
|
Provenance
The following attestation bundles were made for vulnq-1.0.2-py3-none-any.whl:
Publisher:
python-publish.yml on SemClone/vulnq
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vulnq-1.0.2-py3-none-any.whl -
Subject digest:
0ebae76bdc3ff6e5f0c79b9c4f66c06bc3246fc6d79c9e2d9f48586e9e7051d4 - Sigstore transparency entry: 673875451
- Sigstore integration time:
-
Permalink:
SemClone/vulnq@5b0af115dce1d34af0c2ff4f424fb427f57a459c -
Branch / Tag:
refs/tags/v1.0.2 - Owner: https://github.com/SemClone
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
python-publish.yml@5b0af115dce1d34af0c2ff4f424fb427f57a459c -
Trigger Event:
release
-
Statement type: