Security
What a ring serves that has an open advisory — and how sure we are
Five feeds — the Arch and Debian security trackers, OSV, CISA KEV, EPSS — matched every three hours against what each ring serves. A package with an open advisory also exposes what depends on it; a confident fix already in edge is fast-tracked. The feeds and the confidences, explained →
Open advisories per ring
by severity, a package once — edge catches fixes first, stable last
reading the three rings' reports — a few seconds…
The feeds
what each one contributes to this ring's report
Packages with open advisories
exact: the tracker knows this distribution's version, or the build information names the embedded module's version. name-version: Debian fixed it in a version newer than ours. name-only: still open upstream, no version to compare — possibly affected. Fixed in lists rings already serving a version with no open advisory (the fast-track candidate).
| Severity | Package | Version | Advisories | Confidence | Exposes | Fixed in |
|---|