sidebar hamburger menu

Machine-Readable Security Data (Errata, OVAL, CSAF)

TuxCare provides machine-readable security data for ELS for Runtimes in the following formats:

  • Errata — qualified security and selected bug-fix errata advisories
  • OVAL — Open Vulnerability and Assessment Language patch definitions for use with OpenSCAP and similar tools
  • CSAF — Common Security Advisory Framework advisories in OASIS CSAF 2.0 format (VEX and Security Advisory)
  • RSS — release feeds for tracking updates

Released fixes are also available via cve.tuxcare.com and security.tuxcare.com.

PHP

OSErrataOVALCSAFRSS
EL 7errataoval.xmlcsafrss
EL 8errataoval.xmlcsafrss
EL 9errataoval.xmlcsafrss
EL 10errataoval.xmlcsafrss
Ubuntu 16.04errataoval.xmlcsafrss
Ubuntu 18.04errataoval.xmlcsafrss
Ubuntu 20.04errataoval.xmlcsafrss
Ubuntu 22.04errataoval.xmlcsafrss
Ubuntu 24.04errataoval.xmlcsafrss
Debian 10errataoval.xmlcsafrss
Debian 11errataoval.xmlcsafrss
Debian 12errataoval.xmlcsafrss
Debian 13errataoval.xmlcsafrss

Python

OSErrataOVALCSAFRSS
EL 7errataoval.xmlcsafrss
EL 8errataoval.xmlcsafrss
EL 9errataoval.xmlcsafrss
EL 10errataoval.xmlcsafrss
Ubuntu 16.04errataoval.xmlcsafrss
Ubuntu 18.04errataoval.xmlcsafrss
Ubuntu 20.04errataoval.xmlcsafrss
Ubuntu 22.04errataoval.xmlcsafrss
Ubuntu 24.04errataoval.xmlcsafrss
Debian 10errataoval.xmlcsafrss
Debian 11errataoval.xmlcsafrss
Debian 12errataoval.xmlcsafrss
Debian 13errataoval.xmlcsafrss

Node.js

OSCSAFRSS
EL 7csafrss
EL 8csafrss
EL 9csafrss
Ubuntu 18.04csafrss
Ubuntu 20.04csafrss
Ubuntu 22.04csafrss
Ubuntu 24.04csafrss
Debian 10csafrss
Debian 11csafrss
Debian 12csafrss
Debian 13csafrss

Ruby

OSCSAFRSS
Debian 12csafrss
Debian 13csafrss

How to use OVAL

OVAL can be used with the OpenSCAP tool.

  1. Install OpenSCAP

    yum install openscap openscap-utils scap-security-guide -y
  2. Download an OVAL stream. For example, Python on EL 8:

    wget https://security.tuxcare.com/oval/els_alt_python/el8/oval.xml
    
  3. Run a scan:

    oscap oval eval --results result.xml --report report.xml oval.xml
    

How to use CSAF

Common Security Advisory Framework (CSAF) is a machine-readable format, standardized by OASIS. TuxCare publishes CSAF VEX and Security Advisory files in CSAF 2.0 format at security.tuxcare.com.

provider-metadata.json is available at:

The CSAF files are published in JSON format — OASIS provides a list of reference tools that support CSAF.