Vulnerability Feeds

Sysdig Vulnerability Management Data Sources and Feeds

Sysdig Secure continuously checks against a wide range of vulnerability databases. The current database list includes:

Supported Operating Systems

Operating SystemVersionsSourceCVSS ScoreSeverity
Alpine Linux3.2+Alpine LinuxNVDNVD
CentOS7
8-stream
9-stream
CentOSNVDNVD
Debian10 (Buster)
11 (Bullseye)
12 (Bookworm)
Trixie (unstable)
DebianNVDDebian Urgency
Red Hat7
8
9
RedHat CSAF-VEXRedHatRedHat Impact
Rocky Linux8
9
Rocky ERRATANVDNVD
Ubuntu18.04 LTS (Bionic)
20.04 LTS (Focal)
22.04 LTS (Jammy)
23.04 (Lunar)
UbuntuNVDUbuntu Priority
Amazon Linux2
2022
2023
Amazon LinuxNVDAmazon Severity
Alibaba Linux2Alibaba LinuxAlibabaAlibaba Severity
Oracle Linux7
8
9
Oracle LinuxOracleOracle Severity
ChainguardN/AChainguardNVDNVD
WolfiN/AWolfiNVDNVD
Amazon BottleRocket1.10
1.11
Amazon BottleRocketNVDNVD
Google DistrolessTracks Debian 12 (Bookworm)Debian CVE TrackerNVDNVD
FlatcarAll versionsGentoo GLSANVDGentoo Impact

Non-OS-Based Sources and Supported Package Types

Non-OS-Based SourcesMatched Package TypesSourceCVSS ScoreSeverity
NPM (JavaScript)NPM (JavaScript)NPMNVDNVD
Python (Pypi)PythonPython Advisory > GitHub > GitLabNVDNVD
RubyRuby GemsGitHub > GitLab > Ruby AdvisoryNVDNVD
RustCargo (Rust)GitHub > GitLabNVDNVD
GoGolang (built with Go 1.13+)
Go Runtime
GitHub > GitLab > Go Vulnerability DatabaseNVDNVD
JavaJava JAR
WAR
EAR
GitHub > GitLabNVDNVD
PHPComposer (PHP)PHP Advisory > GitHub > GitLabNVDNVD
C#NuGet (.Net)GitHub > GitLabNVDNVD

Column Legend

ColumnDescription
SourceThe specific database or advisory where Sysdig matches vulnerabilities, whether it’s from a vendor, an operating system, or a non-OS package.
Matched Package Types / VersionsThe programming languages or operating system versions that are scanned for vulnerabilities, matched against specific sources. For packages, it indicates supported types, and for OS, the supported versions.
CVSS ScoreThe primary vulnerability score, such as NVD, displayed in the UX or reports. Additional scores from vendor-specific sources may also be available.
SeverityThe primary severity level derived from the score, shown in the UX or reports. Vendor-specific severities may also be displayed where applicable.