Converter Catalog
The hdf CLI converts security assessment data between formats. This page lists every converter that ships in this build. It is generated from the live converter registry, so it always matches what hdf convert --help reports.
Convert to HDF with an auto-detected input format:
hdf convert scan.json -o results.jsonor name the format explicitly with --from / --to using the format token in the tables below (e.g. --from nessus, --to splunk):
hdf convert --from nessus --to hdf scan.nessus -o results.jsonThe Empty input OK column marks converters that treat empty input as a valid "no findings" signal (exit-code-first scanners) rather than an error; these must be paired with an explicit --from because empty input carries nothing to auto-detect.
Import to HDF (69)
Source formats that convert into HDF. Pass the format token to --from.
| Source format | Converter | Empty input OK |
|---|---|---|
arf | ARF to HDF | ✗ |
asff | AWS Security Finding Format to HDF | ✗ |
aws-config | AWS Config to HDF | ✗ |
burpsuite | BurpSuite to HDF | ✗ |
checkov | Checkov to HDF | ✗ |
ckl | CKL to HDF | ✗ |
cklb | CKLB to HDF | ✗ |
conveyor | Conveyor to HDF | ✗ |
csaf-vex | CSAF VEX to HDF Amendments | ✗ |
cyclonedx | CycloneDX to HDF | ✗ |
cyclonedx-vex | CycloneDX VEX to HDF Amendments | ✗ |
dbprotect | DBProtect to HDF | ✗ |
defectdojo | DefectDojo to HDF | ✗ |
defender-cloud | Microsoft Defender for Cloud to HDF | ✗ |
defender-endpoint | Microsoft Defender for Endpoint to HDF | ✗ |
dependency-track | Dependency-Track to HDF | ✗ |
deptrack | Dependency-Track to HDF | ✗ |
fortify | Fortify to HDF | ✗ |
gitlab | GitLab Security Report to HDF | ✗ |
gitlab-dast | GitLab Security Report to HDF | ✗ |
gitlab-sast | GitLab Security Report to HDF | ✗ |
gosec | gosec to HDF | ✗ |
grype | Grype to HDF | ✗ |
hipcheck | Hipcheck to HDF | ✗ |
inspec | InSpec exec-json to HDF | ✗ |
invicti | Netsparker/Invicti to HDF | ✗ |
ionchannel | Ion Channel to HDF | ✗ |
jfrog-xray | JFrog Xray to HDF | ✗ |
junit | JUnit to HDF | ✗ |
kics | KICS to HDF | ✗ |
legacyhdf | InSpec exec-json to HDF | ✗ |
msdo | Microsoft Defender for DevOps to HDF | ✗ |
msft-defender-cloud | Microsoft Defender for Cloud to HDF | ✗ |
msft-defender-devops | Microsoft Defender for DevOps to HDF | ✗ |
msft-defender-endpoint | Microsoft Defender for Endpoint to HDF | ✗ |
msft-secure-score | Microsoft Secure Score to HDF | ✗ |
nessus | Nessus to HDF | ✗ |
netsparker | Netsparker/Invicti to HDF | ✗ |
neuvector | NeuVector to HDF | ✗ |
nikto | Nikto to HDF | ✗ |
openvex | OpenVEX to HDF Amendments | ✗ |
oscal | OSCAL (auto-detect) to HDF | ✗ |
oscal-assessment-plan | OSCAL Assessment Plan to HDF Plan | ✗ |
oscal-assessment-results | OSCAL Assessment Results to HDF | ✗ |
oscal-catalog | OSCAL Catalog to HDF Baseline | ✗ |
oscal-component | OSCAL Component Definition to HDF Baseline | ✗ |
oscal-component-definition | OSCAL Component Definition to HDF Baseline | ✗ |
oscal-poam | OSCAL POA&M to HDF Amendments | ✗ |
oscal-profile | OSCAL Profile to HDF Baseline | ✗ |
oscal-sap | OSCAL Assessment Plan to HDF Plan | ✗ |
oscal-sar | OSCAL Assessment Results to HDF | ✗ |
oscal-ssp | OSCAL System Security Plan to HDF System | ✗ |
prisma | Prisma Cloud to HDF | ✗ |
sarif | SARIF to HDF | ✗ |
scoutsuite | ScoutSuite to HDF | ✗ |
semgrep | Semgrep to HDF | ✗ |
snyk | Snyk to HDF | ✗ |
sonarqube | SonarQube to HDF | ✗ |
spdx-vex | SPDX VEX to HDF Amendments | ✗ |
splunk | Splunk to HDF | ✗ |
trivy | Trivy to HDF | ✗ |
trufflehog | TruffleHog to HDF | ✓ |
twistlock | Twistlock to HDF | ✗ |
veracode | Veracode to HDF | ✗ |
xccdf | XCCDF to HDF (auto-detect) | ✗ |
xccdf-benchmark | XCCDF Benchmark to HDF Baseline | ✗ |
xccdf-results | XCCDF Results to HDF | ✗ |
xray | JFrog Xray to HDF | ✗ |
zap | OWASP ZAP to HDF | ✗ |
Export from HDF (11)
Formats that HDF Results convert out to. Pass the format token to --to.
| Target format | Converter |
|---|---|
asff | HDF Results to ASFF Findings |
ckl | HDF to CKL |
cklb | HDF to CKLB |
csv | HDF to CSV |
ecs | HDF Results to ECS |
hdf | HDF vauto to HDF v3 |
ocsf | HDF Results to OCSF Findings |
oscal-sar | HDF Results to OSCAL SAR |
splunk | HDF Results to Splunk (CIM/HEC) |
xccdf | HDF to XCCDF |
xml | HDF to XML |
Amendments export (4)
Formats produced from an HDF amendments document (waivers, attestations, POA&Ms).
| Target format | Converter |
|---|---|
csaf-vex | HDF Amendments to CSAF VEX |
cyclonedx-vex | HDF Amendments to CycloneDX VEX |
openvex | HDF Amendments to OpenVEX |
oscal-poam | HDF Amendments to OSCAL POA&M |
Ingesting SBOMs (inventory) — hdf system create
Software Bill of Materials inventory documents are not in the tables above: they carry no assessment results, so they are not converters. They build an HDF System document (its components[]) through hdf system create (or hdf system add-component), not the converter registry. If you are looking for SPDX or an AIBOM, this is the path.
hdf system create --from <format> accepts (omit --from to auto-detect):
| Format token | Input |
|---|---|
cyclonedx | plain CycloneDX SBOM |
cyclonedx-mlbom | CycloneDX ML-BOM (AIBOM — a machine-learning-model component) |
spdx | plain SPDX 2.x SBOM |
spdx-ai | SPDX 3.0 AI/Dataset document (AIBOM) |
Vulnerability-bearing CycloneDX is a converter, not this path. A CycloneDX document that carries vulnerabilities (or VEX) converts to HDF Results via cyclonedx / cyclonedx-vex in the tables above; cyclonedx (to HDF Results) rejects a no-vulnerability inventory SBOM and points you here instead. SPDX has no vulnerability-to-Results path — it only ever flows to the System model.