OpenSCAP/openscap

NIST Certified SCAP 1.2 toolkit

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 24 minutes ago
Added to GitGenius on September 1st, 2021
Created on April 29th, 2014
Open Issues & Pull Requests: 61 (+0)
Number of forks: 449
Total Stargazers: 1,802 (+0)
Total Subscribers: 69 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 28.5 days
Mean response time: 423.0 days
90th percentile: 1373.8 days
Tracked items: 119

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 70% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "content" is answered fastest, typically in under an hour, while "triaged" waits about 14 days. Only 9% of issues opened in the past year have been closed. Three people close 91% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 50
New in 7 days: 1
Closed in 7 days: 0
Avg open age: 875 days
Stale 30+ days: 47
Stale 90+ days: 46

Recent activity

Opened in 7 days: 1
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • stale (120)
  • bug (96)
  • enhancement (55)
  • help wanted (54)
  • triaged (33)
  • 1.2 (28)
  • content (28)
  • windows (27)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

OpenSCAP is an open source security compliance solution that implements the NIST Certified SCAP 1.2 toolkit. The project provides the oscap command line tool, which enables users to load, scan, validate, edit, and export SCAP documents. The toolkit supports multiple SCAP components including XCCDF, OVAL, OCIL, CPE, and data streams, making it a comprehensive solution for security compliance assessment and management.

The primary language of the repository is XSLT, reflecting its focus on document processing and transformation within the SCAP ecosystem. The project is classified across multiple security and compliance domains including configuration management, benchmarking, vulnerability assessment, policy automation, and auditing. Its topic tags explicitly cover scap, compliance, cpe, data-stream, oval, scanning, xccdf, and openscap, indicating the breadth of SCAP-related functionality it addresses.

OpenSCAP supports several key use cases in security compliance workflows. For SCAP content validation, the tool can validate all components within a data stream including XCCDF, OVAL, OCIL, and CPE elements. For scanning operations, users can evaluate OVAL definitions from standalone files or from OVAL components within data streams, evaluate specific profiles in XCCDF files, and evaluate specific XCCDF benchmarks that are part of data stream collections. The tool also supports document generation capabilities, allowing users to generate reports both with and without XCCDF rules and to generate reports from scanning results.

The project explicitly welcomes contributions and provides comprehensive documentation including a user manual, developer manual, and contribution guide. Community engagement is facilitated through an IRC channel at libera.chat #openscap and a mailing list. It is worth noting that official Microsoft Windows support was discontinued as of February 1, 2022, reflecting a shift in platform support priorities. The project is maintained at www.open-scap.org and represents a significant open source effort in the security compliance and SCAP tooling space.