The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Star History
Momentum
+44
STARS · LAST 30 DAYS
1
PER DAY
#262
MOST-STARRED Python
| Window | 7 days | 30 days | 90 days |
|---|---|---|---|
| Stars gained | +7 | +44 | +90 |
| Per day | 1 | 1 | 1 |
| Forks gained | +3 | +13 | +32 |
cve-bin-tool gained 44 stars in the last 30 days, about 1 a day, and now has 1.8K. It is about 8 years old and has averaged roughly 221 stars a year. It ranks #262 among Python repositories and #2,012 across all languages on GitHubRepo.
Trending Record
1
DAYS ON TRENDING
#2317
BEST RANK
Sep 28, 2026
FIRST APPEARANCE
Active
STATUS TODAY
cve-bin-tool has maintained a continuous presence across global trending indexes, peaking at #2317. Below is the 30-day activity profile:
💡 Overview
cve-bin-tool is an open-source project written in Python: The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Engineered for speed, consistency, and developer ease, it solves common hurdles in cve, cvss, devsecops. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.
⚡ Key Features
Optimized execution pipeline written in Python for predictable speed.
Zero-friction configuration with comprehensive sensible defaults out of the box.
Cross-platform runtime support across Linux, macOS, and Windows environments.
Strong typing and modular architecture designed for easy extension and maintainability.
Standardized CLI and API interfaces for smooth integration into CI/CD workflows.
Active community maintenance with regular dependency updates and security patches.
📥 Installation
$ pip install cve-bin-tool
⚙ System Requirements
Platforms
- • macOS
- • Linux
- • Windows
Runtime & Dependencies
Python >= 3.9, pip, virtualenv
Architecture
x86_64, ARM64 (Apple Silicon & Graviton)
🧠 How It Works
cve-bin-tool coordinates its core functionality through a modular Python pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.
🎯 Production Use Cases
Command-Line Automation
Execute automated build, deployment, and maintenance tasks directly from the terminal.
CI/CD Workflow Integration
Run non-interactive validation checks in GitHub Actions, GitLab CI, or local pre-commit hooks.
Developer Environment Setup
Standardize local engineering workstations with single-binary utility commands.
Scripting & Pipeline Orchestration
Chain complex multi-stage scripts with reliable error reporting and exits.
🚀 Getting Started
Install cve-bin-tool using your package manager: `pip install cve-bin-tool`
Initialize your project workspace or configuration file for cve-bin-tool.
Import cve-bin-tool into your codebase or invoke it directly from your terminal.
Execute your test suite or run `cve-bin-tool --help` to verify successful setup.
👍 Strengths
⚠️ Considerations
⇄ Alternatives & Direct Competitors
👥 Who Should Use This
Developers and engineering teams building with Python, seeking reliable, tested, and actively maintained tooling for production workloads.
🏆 Nearby in the Rankings
ossf/cve-bin-tool is currently ranked #2,012 by stars across every repository tracked on GitHubRepo. These are adjacent projects:
| Rank | Repository | Language | Stars | Action |
|---|---|---|---|---|
| #2,007 | UI5/webcomponents | TypeScript | ★ 1.8K | Compare ↗ |
| #2,008 | jooby-project/jooby | Java | ★ 1.8K | Compare ↗ |
| #2,008 | open-mercato/open-mercato | TypeScript | ★ 1.8K | Compare ↗ |
| #2,010 | candid82/joker | Go | ★ 1.8K | Compare ↗ |
| #2,011 | DanielLavrushin/b4 | Go | ★ 1.8K | Compare ↗ |
| #2,012 | ossf/cve-bin-tool This Project | Python | ★ 1.8K | |
| #2,012 | Netflix/genie | Java | ★ 1.8K | Compare ↗ |
| #2,014 | WordPress/mcp-adapter | PHP | ★ 1.8K | Compare ↗ |
| #2,015 | owntracks/android | Kotlin | ★ 1.8K | Compare ↗ |
| #2,016 | laravel/fortify | PHP | ★ 1.8K | Compare ↗ |
| #2,017 | clerk/javascript | TypeScript | ★ 1.8K | Compare ↗ |
Frequently Asked Questions
What does cve-bin-tool do? +
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
What language is cve-bin-tool written in? +
The primary language is Python. Topics include: cve, cvss, devsecops, hacktoberfest, python.
Is cve-bin-tool actively maintained? +
Yes, the last recorded push was on Sep 28, 2026 with 243 open issues being tracked.
How many stars does cve-bin-tool have? +
cve-bin-tool has 1,767 stars and 649 forks on GitHub.
How does cve-bin-tool rank among GitHub repositories? +
With 1,767 stars, ossf/cve-bin-tool is ranked #2,012 globally across all repositories tracked on GitHubRepo and #262 among Python projects.
What license is cve-bin-tool distributed under? +
The repository reports a GPL-3.0 license. Always verify the repository LICENSE file for legal terms.