CSAF Community Days 2026: Nov 16-18, Germany – Call for Presentations and Call for Sponsors open

Open Source Services & Tools

Services

Secvisogram

Secvisogram is a tool for creating and editing advisories in CSAF format.

MIT

CSAF 2.0 Schema Visualizer

A tool to visualize the CSAF JSON Schema.

MIT

CSAF Provider Online Check

A website which provides easy access to the CSAF Provider Checker.

Apache-2.0

CSAF Provider Index

A website listing known CSAF Providers and Publishers. Users can submit new entries to the index.

Apache-2.0

Sec-O-Simple

A website guiding you through the creation of CSAF documents. Allows editing of existing documents as well.

Apache-2.0

Tools

CSAF Provider

An implementation of the role CSAF Trusted Provider, also offering a simple HTTPS based management service.

Apache-2.0

CSAF Uploader

A command line tool that uploads CSAF documents to the CSAF Provider.

Apache-2.0

CSAF Aggregator

An implementation of the role CSAF Aggregator.

Apache-2.0

CSAF Checker

A tool for testing a CSAF Trusted Provider according to Section 7 of the CSAF standard.

Apache-2.0

CSAF Downloader

A tool to download CSAF content from a specific domain / CSAF provider.

Apache-2.0

CSAF Validator Library

A JavaScript library is intended to include logic that can be shared across application working with CSAF.

MIT

CSAF Validator Service

A service to validate documents against the CSAF standard. It uses the csaf-validator-lib “under-the-hood”.

MIT

BSI Secvisogram CSAF Backend CMS

The CSAF Content Management System (CMS) Secvisogram backend code and documentation

MIT

paikalta

A tool for testing a CSAF Trusted Provider according to Pypi.

MIT

CSAF Walker

A Rust library and command line tool for consuming and analyzing CSAF documents.

Apache-2.0

Clouditor

Clouditor is a tool for the continuous assurance of cloud and other backend services. It supports the conformance check of CSAF (trusted) providers as part of vulnerability management controls.

Apache-2.0

SecObserve

An open source vulnerability management system that can produce and consume CSAF VEX documents.

3-clause BSD

Trivy

A comprehensive and versatile security scanner that look for security issues.

Apache-2.0

Trustify

A collection of software that allow you to store bill of materials (SBOM), vulnerability information (VEX) for your organization and use that information to learn impact of vulnerabilities and dependency changes.

Apache-2.0

CSAF Perl Tookit

A Perl distribution (with modules and command-line tools) for create, validate, convert (in HTML), publish and download CSAF documents.

Artistic-2.0

kotlin-csaf

A Kotlin implementation of the CSAF standard for the JVM. It supports parsing and validation of CSAF 2.0 documents.

Apache-2.0

csaf-rust

A Rust implementation of the CSAF standard. It supports parsing (and partial validation) of CSAF 2.0 and CSAF 2.1 (Draft) documents.

Apache-2.0

DependencyTrack CSAF Integration

An integration for the popular dependency management system DependencyTrack.

Apache-2.0

ISDuBA

A web application for downloading and evaluating security advisories.

Apache-2.0