Ross ROSS = Recommend OSS · open-source software intelligence for agents

OpenSCAP/openscap

NIST Certified SCAP 1.2 toolkit observed · 2026-08-28

github.com/OpenSCAP/openscap · homepage · XSLT · LGPL-2.1 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

87/100

  • Activity 97
  • Release rhythm 66
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 33
  • age_days: 4509
  • days_rel: 146
  • days_push: 20
  • n_releases_24m: 8

Full methodology

Adoption not part of the score

1806 stars · 449 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

OpenSCAP is a NIST-certified open-source toolkit providing both a C library and the 'oscap' command-line tool for parsing, validating, editing, and evaluating SCAP documents (XCCDF, OVAL, CPE, data streams). It performs configuration and vulnerability scans of local systems against security policies like DISA STIGs and USGCB content.

Use cases

  • scan linux system for security compliance
  • evaluate DISA STIG benchmark on RHEL
  • run OVAL vulnerability scan
  • validate SCAP data stream XML content
  • check system against PCI-DSS security policy
  • generate XCCDF scan results reports
  • audit container security compliance

When to choose

  • you need NIST-certified SCAP 1.2 evaluation on Linux
  • you want to automate configuration and vulnerability compliance scans
  • you need to validate or tailor XCCDF/OVAL content programmatically via a C API

When to avoid

  • you need Windows support, which is officially void since 2022
  • you want a GUI-first scanning experience (consider SCAP Workbench instead)
  • you need continuous/centralized fleet scanning (consider SCAPTimony or OpenSCAP Daemon)

Facets

cli-tool · maturity stable

security vulnerability-scanning cli parser sdk security legal operating-systems cli cpp windows scap xccdf oval cpe nist-certified compliance-scanning security-hardening disa-stig devops linux

10 sources

Member repositories

RepositoryRoleHealth v2
OpenSCAP/openscapmain87

For agents

markdown · JSON · MCP: product_card(name="OpenSCAP/openscap")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem