# OpenSCAP/openscap

NIST Certified SCAP 1.2 toolkit

Repository: https://github.com/OpenSCAP/openscap
Canonical: https://ross.abutalabs.com/products/openscap
Homepage: https://www.open-scap.org/tools/openscap-base
Language: XSLT
License: LGPL-2.1
License Family: copyleft
Topics: scap, xccdf, oval, cpe, compliance, openscap, scanning, data-stream
Last push: 2026-08-13T18:15:39+00:00

## Health v2 (maintenance only)
Score: 87/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 66, longevity 100
- inputs: {"age_days": 4509, "days_push": 20, "days_rel": 146, "gap_med": 33, "n_releases_24m": 8}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1806, forks 449 (observed 2026-08-28T04:05:39.119887+00:00)

## What it is
OpenSCAP is a NIST-certified open-source toolkit providing both a C library and the 'oscap' command-line tool for parsing, validating, editing, and evaluating SCAP documents (XCCDF, OVAL, CPE, data streams). It performs configuration and vulnerability scans of local systems against security policies like DISA STIGs and USGCB content.

## Use cases
- scan linux system for security compliance
- evaluate DISA STIG benchmark on RHEL
- run OVAL vulnerability scan
- validate SCAP data stream XML content
- check system against PCI-DSS security policy
- generate XCCDF scan results reports
- audit container security compliance

## When to choose
- you need NIST-certified SCAP 1.2 evaluation on Linux
- you want to automate configuration and vulnerability compliance scans
- you need to validate or tailor XCCDF/OVAL content programmatically via a C API

## When to avoid
- you need Windows support, which is officially void since 2022
- you want a GUI-first scanning experience (consider SCAP Workbench instead)
- you need continuous/centralized fleet scanning (consider SCAPTimony or OpenSCAP Daemon)

## Facets
- artifact type: cli-tool
- maturity: stable
- function: security, vulnerability-scanning, cli, parser, sdk
- domain: security, legal, operating-systems
- platform: cli, cpp, windows
- tags: scap, xccdf, oval, cpe, nist-certified, compliance-scanning, security-hardening, disa-stig, devops, linux

## Member repositories
- OpenSCAP/openscap (main) score 87

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:39.119887+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:21:27.913506+00:00, confidence not recorded.
  - readme: https://github.com/OpenSCAP/openscap (fetched 2026-08-28T04:05:39.119887+00:00, sha a1aae12e2703)
  - homepage: https://www.open-scap.org/tools/openscap-base (fetched 2026-08-29T11:00:48.052324+00:00, sha 457324a3e6b1)
  - site_page: https://www.open-scap.org/resources/documentation (fetched 2026-08-29T11:00:48.054960+00:00, sha a8b6b83fcedf)
  - site_page: https://www.open-scap.org/features (fetched 2026-08-29T11:00:48.056872+00:00, sha c244d411a593)
  - site_page: https://www.open-scap.org/getting-started (fetched 2026-08-29T11:00:48.058538+00:00, sha 528f206044e4)
  - site_page: https://www.open-scap.org/features/standards (fetched 2026-08-29T11:00:48.060201+00:00, sha 12ea8287448c)
  - site_page: https://www.open-scap.org/features/open-source-community (fetched 2026-08-29T11:00:48.061710+00:00, sha 3155026f0352)
  - site_page: https://www.open-scap.org/features/security-compliance (fetched 2026-08-29T11:00:48.063545+00:00, sha 8984aec44452)
  - site_page: https://www.open-scap.org/features/vulnerability-assessment (fetched 2026-08-29T11:00:48.065699+00:00, sha be03dd0613c1)
  - site_page: https://www.open-scap.org/resources/about-team (fetched 2026-08-29T11:00:48.067628+00:00, sha 42ac906058d9)
- Data as of 2026-08-30T08:39:29.467469+00:00.
