Documentation
CVE monitoring
Installed packages, matched against OSV.dev every twelve hours.
How it works
- The agent inventories installed packages through dpkg/apt or rpm/dnf/yum and sends names and versions with each report.
- The platform matches them against OSV.dev every twelve hours, by the exact distribution release, and caches vulnerability data for a day.
- Each finding is per server and per package: package, installed version, CVE, severity, fixed version where published, summary.
- A package that was removed stops being a vulnerability; its CVEs go with it.
Ecosystems
Ubuntu, Debian, Alpine, Rocky Linux and AlmaLinux, each matched against its own advisories. OSV.dev's Red Hat data is organised by Red Hat product stream rather than by release, and SecAI does not map it yet; on a Red Hat Enterprise Linux server SecAI skips vulnerability matching rather than guess.
Remediation
A package update can be proposed and always waits for approval, because an upgrade that restarts a service is a change to production.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.