Advisory sources

The vulnerability and advisory sources SBOM Observer matches components against.

SBOM Observer matches components against the advisory sources below, listed with the software each one covers. Components are rescanned in the background, so a vulnerability published after an SBOM was uploaded still shows up.

SourceCovers
AlmaLinux ErrataAlmaLinux packages
Alpine secdbAlpine Linux packages
Amazon Linux Security CenterAmazon Linux packages
Amazon Linux 2 Security CenterAmazon Linux 2 packages
Arch Linux Security TrackerArch Linux packages
Debian Security Bug TrackerDebian packages
GitHub Advisory Database (GHSA)Open-source packages in language ecosystems
GitLab Advisory DatabaseOpen-source packages in language ecosystems
Kubernetes Official CVE FeedKubernetes, from the Kubernetes Security Response Committee
National Vulnerability Database (NVD)CVEs across all software, run by NIST
Oracle Linux OVALOracle Linux packages
Photon Security AdvisoryVMware Photon OS packages
RHEL/CentOS OVALRed Hat Enterprise Linux and CentOS packages
RHEL/CentOS Security DataRed Hat Enterprise Linux and CentOS packages
Rocky Linux UpdateInfoRocky Linux packages
SUSE Security CVRFSUSE and openSUSE packages
Ubuntu CVE TrackerUbuntu packages