Advisory sources
The vulnerability and advisory sources SBOM Observer matches components against.
SBOM Observer matches components against the advisory sources below, listed with the software each one covers. Components are rescanned in the background, so a vulnerability published after an SBOM was uploaded still shows up.
| Source | Covers |
|---|---|
| AlmaLinux Errata | AlmaLinux packages |
| Alpine secdb | Alpine Linux packages |
| Amazon Linux Security Center | Amazon Linux packages |
| Amazon Linux 2 Security Center | Amazon Linux 2 packages |
| Arch Linux Security Tracker | Arch Linux packages |
| Debian Security Bug Tracker | Debian packages |
| GitHub Advisory Database (GHSA) | Open-source packages in language ecosystems |
| GitLab Advisory Database | Open-source packages in language ecosystems |
| Kubernetes Official CVE Feed | Kubernetes, from the Kubernetes Security Response Committee |
| National Vulnerability Database (NVD) | CVEs across all software, run by NIST |
| Oracle Linux OVAL | Oracle Linux packages |
| Photon Security Advisory | VMware Photon OS packages |
| RHEL/CentOS OVAL | Red Hat Enterprise Linux and CentOS packages |
| RHEL/CentOS Security Data | Red Hat Enterprise Linux and CentOS packages |
| Rocky Linux UpdateInfo | Rocky Linux packages |
| SUSE Security CVRF | SUSE and openSUSE packages |
| Ubuntu CVE Tracker | Ubuntu packages |