Skip to content

Converter Catalog ​

The hdf CLI converts security assessment data between formats. This page lists every converter that ships in this build. It is generated from the live converter registry, so it always matches what hdf convert --help reports.

Convert to HDF with an auto-detected input format:

bash
hdf convert scan.json -o results.json

or name the format explicitly with --from / --to using the format token in the tables below (e.g. --from nessus, --to splunk):

bash
hdf convert --from nessus --to hdf scan.nessus -o results.json

The Empty input OK column marks converters that treat empty input as a valid "no findings" signal (exit-code-first scanners) rather than an error; these must be paired with an explicit --from because empty input carries nothing to auto-detect.

Import to HDF (69) ​

Source formats that convert into HDF. Pass the format token to --from.

Source formatConverterEmpty input OK
arfARF to HDF✗
asffAWS Security Finding Format to HDF✗
aws-configAWS Config to HDF✗
burpsuiteBurpSuite to HDF✗
checkovCheckov to HDF✗
cklCKL to HDF✗
cklbCKLB to HDF✗
conveyorConveyor to HDF✗
csaf-vexCSAF VEX to HDF Amendments✗
cyclonedxCycloneDX to HDF✗
cyclonedx-vexCycloneDX VEX to HDF Amendments✗
dbprotectDBProtect to HDF✗
defectdojoDefectDojo to HDF✗
defender-cloudMicrosoft Defender for Cloud to HDF✗
defender-endpointMicrosoft Defender for Endpoint to HDF✗
dependency-trackDependency-Track to HDF✗
deptrackDependency-Track to HDF✗
fortifyFortify to HDF✗
gitlabGitLab Security Report to HDF✗
gitlab-dastGitLab Security Report to HDF✗
gitlab-sastGitLab Security Report to HDF✗
gosecgosec to HDF✗
grypeGrype to HDF✗
hipcheckHipcheck to HDF✗
inspecInSpec exec-json to HDF✗
invictiNetsparker/Invicti to HDF✗
ionchannelIon Channel to HDF✗
jfrog-xrayJFrog Xray to HDF✗
junitJUnit to HDF✗
kicsKICS to HDF✗
legacyhdfInSpec exec-json to HDF✗
msdoMicrosoft Defender for DevOps to HDF✗
msft-defender-cloudMicrosoft Defender for Cloud to HDF✗
msft-defender-devopsMicrosoft Defender for DevOps to HDF✗
msft-defender-endpointMicrosoft Defender for Endpoint to HDF✗
msft-secure-scoreMicrosoft Secure Score to HDF✗
nessusNessus to HDF✗
netsparkerNetsparker/Invicti to HDF✗
neuvectorNeuVector to HDF✗
niktoNikto to HDF✗
openvexOpenVEX to HDF Amendments✗
oscalOSCAL (auto-detect) to HDF✗
oscal-assessment-planOSCAL Assessment Plan to HDF Plan✗
oscal-assessment-resultsOSCAL Assessment Results to HDF✗
oscal-catalogOSCAL Catalog to HDF Baseline✗
oscal-componentOSCAL Component Definition to HDF Baseline✗
oscal-component-definitionOSCAL Component Definition to HDF Baseline✗
oscal-poamOSCAL POA&M to HDF Amendments✗
oscal-profileOSCAL Profile to HDF Baseline✗
oscal-sapOSCAL Assessment Plan to HDF Plan✗
oscal-sarOSCAL Assessment Results to HDF✗
oscal-sspOSCAL System Security Plan to HDF System✗
prismaPrisma Cloud to HDF✗
sarifSARIF to HDF✗
scoutsuiteScoutSuite to HDF✗
semgrepSemgrep to HDF✗
snykSnyk to HDF✗
sonarqubeSonarQube to HDF✗
spdx-vexSPDX VEX to HDF Amendments✗
splunkSplunk to HDF✗
trivyTrivy to HDF✗
trufflehogTruffleHog to HDF✓
twistlockTwistlock to HDF✗
veracodeVeracode to HDF✗
xccdfXCCDF to HDF (auto-detect)✗
xccdf-benchmarkXCCDF Benchmark to HDF Baseline✗
xccdf-resultsXCCDF Results to HDF✗
xrayJFrog Xray to HDF✗
zapOWASP ZAP to HDF✗

Export from HDF (11) ​

Formats that HDF Results convert out to. Pass the format token to --to.

Target formatConverter
asffHDF Results to ASFF Findings
cklHDF to CKL
cklbHDF to CKLB
csvHDF to CSV
ecsHDF Results to ECS
hdfHDF vauto to HDF v3
ocsfHDF Results to OCSF Findings
oscal-sarHDF Results to OSCAL SAR
splunkHDF Results to Splunk (CIM/HEC)
xccdfHDF to XCCDF
xmlHDF to XML

Amendments export (4) ​

Formats produced from an HDF amendments document (waivers, attestations, POA&Ms).

Target formatConverter
csaf-vexHDF Amendments to CSAF VEX
cyclonedx-vexHDF Amendments to CycloneDX VEX
openvexHDF Amendments to OpenVEX
oscal-poamHDF Amendments to OSCAL POA&M

Ingesting SBOMs (inventory) — hdf system create ​

Software Bill of Materials inventory documents are not in the tables above: they carry no assessment results, so they are not converters. They build an HDF System document (its components[]) through hdf system create (or hdf system add-component), not the converter registry. If you are looking for SPDX or an AIBOM, this is the path.

hdf system create --from <format> accepts (omit --from to auto-detect):

Format tokenInput
cyclonedxplain CycloneDX SBOM
cyclonedx-mlbomCycloneDX ML-BOM (AIBOM — a machine-learning-model component)
spdxplain SPDX 2.x SBOM
spdx-aiSPDX 3.0 AI/Dataset document (AIBOM)

Vulnerability-bearing CycloneDX is a converter, not this path. A CycloneDX document that carries vulnerabilities (or VEX) converts to HDF Results via cyclonedx / cyclonedx-vex in the tables above; cyclonedx (to HDF Results) rejects a no-vulnerability inventory SBOM and points you here instead. SPDX has no vulnerability-to-Results path — it only ever flows to the System model.

Released under the Apache 2.0 License.