vunnel
A tool for fetching, transforming, and storing vulnerability data from a variety of sources.
Supported data sources:
- Alpine (https://secdb.alpinelinux.org)
- Amazon (https://alas.aws.amazon.com/AL2/alas.rss & https://alas.aws.amazon.com/AL2022/alas.rss)
- Azure (https://github.com/microsoft/AzureLinuxVulnerabilityData)
- Debian (https://security-tracker.debian.org/tracker/data/json & https://salsa.debian.org/security-tracker-team/security-tracker/raw/master/data/DSA/list)
- Echo (https://advisory.echohq.com/data.json)
- GitHub Security Advisories (https://api.github.com/graphql)
- NVD (https://services.nvd.nist.gov/rest/json/cves/2.0)
- Oracle (https://linux.oracle.com/security/oval)
- RedHat (https://www.redhat.com/security/data/oval)
- SLES (https://ftp.suse.com/pub/projects/security/oval)
- Ubuntu (https://launchpad.net/ubuntu-cve-tracker)
- Wolfi (https://packages.wolfi.dev)
Prerequisites
The following system tools must be available on your PATH:
- git - Required by some providers that fetch data from git repositories
Installation
With pip:
pip install vunnel
With docker:
docker run \
--rm -it \
-v $(pwd)/data:/data \
-v $(pwd)/.vunnel.yaml:/.vunnel.yaml \
ghcr.io/anchore/vunnel:latest \
run nvd
Where:
- the
datavolume keeps the processed data on the host - the
.vunnel.yamluses the host application config (if present) - you can swap
latestfor a specific version (same as the git tags)
See the vunnel package for a full listing of available tags.
Getting Started
List the available vulnerability data providers:
$ vunnel list
alpine
amazon
chainguard
debian
echo
github
mariner
minimos
nvd
oracle
rhel
sles
ubuntu
wolfi
Download and process a provider:
$ vunnel run wolfi
2023-01-04 13:42:58 root [INFO] running wolfi provider
2023-01-04 13:42:58 wolfi [INFO] downloading Wolfi secdb https://packages.wolfi.dev/os/security.json
2023-01-04 13:42:59 wolfi [INFO] wrote 56 entries
2023-01-04 13:42:59 wolfi [INFO] recording workspace state
You will see the processed vulnerability data in the local ./data directory
$ tree data
data
└── wolfi
├── checksums
├── metadata.json
├── input
│ └── secdb
│ └── os
│ └── security.json
└── results
└── wolfi:rolling
├── CVE-2016-2781.json
├── CVE-2017-8806.json
├── CVE-2018-1000156.json
└── ...
Note: to get more verbose output, use -v, -vv, or -vvv (e.g. vunnel -vv run wolfi)
Delete existing input and result data for one or more providers:
$ vunnel clear wolfi
2023-01-04 13:48:31 root [INFO] clearing wolfi provider state
Example config file for changing application behavior:
# .vunnel.yaml
root: ./processed-data
log:
level: trace
providers:
wolfi:
request_timeout: 125
runtime:
existing_input: keep
existing_results: delete-before-write
on_error:
action: fail
input: keep
results: keep
retry_count: 3
retry_delay: 10
Use vunnel config to get a better idea of all of the possible configuration options.
FAQ
Can I implement a new provider?
Yes you can! See the provider docs for more information.
Why is it called "vunnel"?
This tool "funnels" vulnerability data into a single spot for easy processing... say "vulnerability data funnel" 100x fast enough and eventually it'll slur to "vunnel" :).
Release files for vunnel 0.63.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vunnel-0.63.1.tar.gz | 764.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vunnel-0.63.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.0 MB
Release files / vunnel-0.63.1.tar.gz
| Download URL | vunnel-0.63.1.tar.gz |
|---|---|
| Size | 764.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
facdd100473a606e88ae227d3589a81924641def9aacee962b9c874bc2af88f0
|
|
BLAKE2b-256 checksum How to use checksums |
2318838d892c5617bd84482dcadeb45e19bc0eb6b1ed922b2a8cfce611b00506
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.0 {"installer":{"name":"uv","version":"0.12.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / vunnel-0.63.1-py3-none-any.whl
| Download URL | vunnel-0.63.1-py3-none-any.whl |
|---|---|
| Size | 269.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b89b413a7d466492fecc9061a14986d01722701e166aa2a51953bfabf295261a
|
|
BLAKE2b-256 checksum How to use checksums |
41423aff81bfdd539405e68396661395cfcb35b6c8a8ef874647ef427b511bf2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.0 {"installer":{"name":"uv","version":"0.12.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|