Metadata-Version: 2.4
Name: vuln-prioritizer-workbench
Version: 1.4.0
Summary: Local-first Workbench for explainable CVE prioritization from scanner, SBOM, VEX, and asset-context evidence using CVSS, EPSS, KEV, and curated ATT&CK/TTP context.
Author: vuln-prioritizer-workbench contributors
License-Expression: MIT
Project-URL: Homepage, https://github.com/Noetheon/vuln-prioritizer-workbench
Project-URL: Repository, https://github.com/Noetheon/vuln-prioritizer-workbench
Project-URL: Issues, https://github.com/Noetheon/vuln-prioritizer-workbench/issues
Project-URL: Documentation, https://github.com/Noetheon/vuln-prioritizer-workbench/tree/main/docs
Project-URL: Changelog, https://github.com/Noetheon/vuln-prioritizer-workbench/blob/main/CHANGELOG.md
Project-URL: Security, https://github.com/Noetheon/vuln-prioritizer-workbench/security/policy
Keywords: cve,cvss,epss,kev,cisa-kev,mitre-attack,sbom,vex,sarif,security,vulnerability-management,risk-based-vulnerability-management
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Information Technology
Classifier: Intended Audience :: System Administrators
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: 3.14
Classifier: Topic :: Security
Classifier: Topic :: Utilities
Classifier: Typing :: Typed
Requires-Python: >=3.11
Description-Content-Type: text/markdown
Requires-Dist: alembic<2.0,>=1.13
Requires-Dist: anyio<5.0,>=4.14.2
Requires-Dist: fastapi<1.0,>=0.115
Requires-Dist: defusedxml<1.0,>=0.7
Requires-Dist: filelock<4.0,>=3.20
Requires-Dist: jsonschema<5.0,>=4.23
Requires-Dist: packageurl-python==0.17.6
Requires-Dist: pydantic<3.0,>=2.6
Requires-Dist: psycopg[binary]<4.0,>=3.1
Requires-Dist: python-multipart<1.0,>=0.0.31
Requires-Dist: PyYAML<7.0,>=6.0
Requires-Dist: python-dotenv<2.0,>=1.0
Requires-Dist: requests<3.0,>=2.31
Requires-Dist: sqlalchemy<3.0,>=2.0
Requires-Dist: sqlmodel<1.0,>=0.0.21
Requires-Dist: starlette<2.0,>=1.3.1
Requires-Dist: uvicorn[standard]<1.0,>=0.30
Provides-Extra: dev
Requires-Dist: beautifulsoup4<5.0,>=4.12; extra == "dev"
Requires-Dist: build<2.0,>=1.2; extra == "dev"
Requires-Dist: cryptography<51.0,>=50.0; (platform_machine != "ppc64le" and platform_machine != "s390x" and sys_platform == "linux") and extra == "dev"
Requires-Dist: hypothesis<7.0,>=6.100; extra == "dev"
Requires-Dist: httpx<1.0,>=0.27; extra == "dev"
Requires-Dist: mkdocs<2.0,>=1.6; extra == "dev"
Requires-Dist: msgpack<2.0,>=1.2.1; extra == "dev"
Requires-Dist: mutmut<4.0,>=3.0; extra == "dev"
Requires-Dist: mypy<3.0,>=1.10; extra == "dev"
Requires-Dist: pip-audit<3.0,>=2.7; extra == "dev"
Requires-Dist: pip<27.0,>=26.2; extra == "dev"
Requires-Dist: pre-commit<5.0,>=3.7; extra == "dev"
Requires-Dist: pytest<10.0,>=8.0; extra == "dev"
Requires-Dist: pytest-cov<8.0,>=5.0; extra == "dev"
Requires-Dist: respx<1.0,>=0.21; extra == "dev"
Requires-Dist: ruff<1.0,>=0.5; extra == "dev"
Requires-Dist: setuptools<85.0,>=80.0; extra == "dev"
Requires-Dist: soupsieve<3.0,>=2.9; extra == "dev"
Requires-Dist: twine<8.0,>=6.0; extra == "dev"
Requires-Dist: types-PyYAML<7.0,>=6.0; extra == "dev"
Requires-Dist: types-requests<3.0,>=2.32; extra == "dev"
Requires-Dist: wheel<1.0,>=0.45; extra == "dev"

# Vuln Prioritizer Workbench

Vuln Prioritizer Workbench is a local-first workbench for explainable CVE
prioritization. It imports vulnerability evidence you already have, then ranks
findings with CVSS, EPSS, CISA KEV, asset context, VEX, waivers, and reviewed
defensive ATT&CK context. Every ranking is explained.

- **Inputs:** CVE lists, Trivy, Grype, CycloneDX, SPDX, Dependency-Check,
  GitHub alerts, Nessus, OpenVAS, VEX, and asset context.
- **Outputs:** Markdown, HTML, JSON, CSV, SARIF, ATT&CK Navigator, and Evidence
  ZIP reports.
- **Boundary:** It does not scan networks, run exploits, or patch anything.

## Install And Run

```bash
pipx install vuln-prioritizer-workbench
vpw serve
```

`vpw serve` opens the browser at `http://127.0.0.1:8765`. One process runs the
API, the browser app, database migrations, and the background worker, with
SQLite data in a private per-user directory. No Node.js, PostgreSQL, or Docker
is needed.

Other commands:

- `vpw import`: upload scanner or SBOM files from CI.
- `vpw backup` and `vpw restore`: create and restore verified backups.
- `vpw serve --help`: list runtime options.

A container image is published as
`ghcr.io/noetheon/vuln-prioritizer-workbench`. Small teams can share one
instance behind their own login proxy in team mode.

## Documentation

- [README and product tour](https://github.com/Noetheon/vuln-prioritizer-workbench#readme)
- [Installation](https://github.com/Noetheon/vuln-prioritizer-workbench/blob/main/INSTALL.md)
- [Team mode](https://github.com/Noetheon/vuln-prioritizer-workbench/blob/main/docs/team-mode.md)
- [Changelog](https://github.com/Noetheon/vuln-prioritizer-workbench/blob/main/CHANGELOG.md)

## Package Layout

This distribution ships the `app` package only: the FastAPI Workbench API,
database migrations, packaged browser assets and resources, the supervised
worker, and the internal `app.domain.engine` modules. Repository-level docs,
fixtures, and maintainer tooling stay in the source repository.
