# Advisory Source Connector Coverage Matrix
Last updated: 2026-06-02
Coverage terms used by the UI/API:
- Complete means the source has its own runnable fetch/parse/map pipeline.
- Covered by OSV means the catalog retains the ecosystem source key for filtering/attribution, but ingestion runs through the parent
osvconnector. - Covered by GHSA means the catalog retains the package ecosystem source key for filtering/attribution, but ingestion runs through the parent
ghsaconnector. - Canonical alias means the catalog retains the alias key for filtering/attribution but coverage is served by another source key such as
redhatormicrosoft. - Missing means there is no runnable connector or parent coverage.
Summary
Live source counts are served by /api/v1/advisory-sources/catalog. This matrix documents coverage semantics, source families, and known connector gaps so the UI can distinguish parent-covered rows from true missing connectors.
Setup UI Row Model
The setup page renders only actionable parent rows for parent-covered sources. Alias and ecosystem source keys remain in the catalog/API for attribution, search, policy filters, historical source-state cleanup, and imports, but they are not separate operator rows. The parent row carries an “Also covering …” summary instead:
osv: also coveringnpm,pypi,go,rubygems,maven,crates,packagist,hex,rustsec,pypa,govuln,bundler-audit,chainguard, andwolfi.ghsa: also coveringnuget.redhat: also coveringrhel.microsoft: also coveringazure.
Search still matches hidden alias rows and returns the parent row. For example, searching for rhel returns Red Hat Security, and searching for nuget returns GitHub Security Advisories.
Decision Matrix For Concern Rows
| Decision bucket | Source IDs | UI/current treatment | Next action |
|---|---|---|---|
| Fully dropped / cleansed | arm, poc-github, docker-official | No catalog row; no project reference; no active seed row | Done. Startup migrations purge existing DB rows and mirror-domain exports. |
| Mark as covered by OSV | npm, pypi, go, rubygems, maven, crates, packagist, hex, rustsec, pypa, govuln, bundler-audit, chainguard, wolfi | Folded into the osv row as “Also covering …” | Done for catalog/API/UI. Do not count these as missing connectors. |
| Mark as covered by GHSA | nuget | Folded into the ghsa row as “Also covering nuget” | Done for catalog/API/UI. |
| Mark as canonical alias | rhel, azure | Folded into redhat and microsoft/MSRC rows as “Also covering …” | Done for catalog/API/UI. Keep source keys for filtering/attribution, not direct sync. |
| Implemented but previously not wired on UI | arch, astra, stella-mirror | Now syncSupported=true and supportsConfiguration=true; setup page renders connector-owned controls | Fixed in AVEX-004. No sync-supported advisory source should remain without configuration support. |
| Implemented exploit metadata connectors | exploitdb, metasploit | syncSupported=true and supportsConfiguration=true; metadata-only connector controls render in setup | Done. Do not fetch or persist arbitrary exploit bodies or module source files. |
| Implemented national CERT connectors | cert-at, cert-be, cert-eu, cert-ua, cert-pl | syncSupported=true and supportsConfiguration=true; setup page renders connector-owned RSS/Atom endpoint controls | Done. Shared NationalCert connector uses official RSS/Atom feeds plus fixture-friendly endpoint overrides. |
| Implemented distro advisory connectors | amazon, fedora | syncSupported=true and supportsConfiguration=true; setup page renders connector-owned endpoint controls | Done. Amazon Linux uses ALAS RSS/detail pages; Fedora uses Bodhi stable security updates. Both support fixture-friendly endpoint overrides. |
| Keep unsupported / not implemented now | centos, juniper, cert-ch, google | Catalog-visible unsupported rows with missing-connector detail | Keep out of sync success goals. google must be narrowed to Android/Pixel/etc. before implementation; juniper and cert-ch need stable official machine-readable feeds. |
Coverage by Category
Primary Databases (6/6 — 100%)
| Source | Display Name | Connector | Status |
|---|---|---|---|
| nvd | NVD (NIST) | Connector.Nvd | Complete |
| osv | OSV (Google) | Connector.Osv | Complete |
| ghsa | GitHub Security Advisories | Connector.Ghsa | Complete |
| cve | CVE.org (MITRE) | Connector.Cve | Complete |
| epss | EPSS (FIRST) | Connector.Epss | Complete |
| kev | CISA KEV | Connector.Kev | Complete |
Linux Distributions
| Source | Display Name | Connector | Status |
|---|---|---|---|
| debian | Debian Security | Connector.DistroDebian | Complete |
| ubuntu | Ubuntu Security | Connector.DistroUbuntu | Complete |
| alpine | Alpine Security | Connector.DistroAlpine | Complete |
| amazon | Amazon Linux Security | Connector.DistroAmazon | Complete |
| suse | SUSE Security | Connector.DistroSuse | Complete |
| rhel | RHEL Security | Connector.RedHat | Canonical alias covered by redhat |
| astra | Astra Linux | Connector.DistroAstra | Complete |
| wolfi | Wolfi Security | OSV-backed alias | Covered by OSV |
| centos | CentOS Security | - | Unsupported/deprecated; no current connector plan |
| fedora | Fedora Security | Connector.DistroFedora | Complete |
| arch | Arch Security | Connector.DistroArch | Complete |
| gentoo | Gentoo Security | Connector.DistroGentoo | Complete |
Vendor Advisories
| Source | Display Name | Connector | Status |
|---|---|---|---|
| oracle | Oracle Security | Connector.VndrOracle | Complete |
| apple | Apple Security | Connector.VndrApple | Complete |
| cisco | Cisco Security | Connector.VndrCisco | Complete |
| vmware | VMware Security | Connector.Vmware | Complete |
| redhat | Red Hat Security | Connector.RedHat | Complete |
| microsoft | Microsoft MSRC | Connector.VndrMsrc | Complete |
| Google Security | - | Needs scope decision before implementation | |
| fortinet | Fortinet PSIRT | Connector.VndrFortinet | Complete |
| juniper | Juniper Security | - | Unsupported until stable official JSA feed/API exists |
| paloalto | Palo Alto Security | Connector.VndrPaloAlto | Complete |
Language Ecosystems
Ecosystem advisories are routed through OSV/GHSA. These rows remain visible so operators can filter policy and attribution by ecosystem without triggering fake per-ecosystem fetch jobs.
| Source | Display Name | Coverage | Status |
|---|---|---|---|
| npm | npm Advisories | OSV | Covered by OSV |
| pypi | PyPI Advisories | OSV | Covered by OSV |
| maven | Maven Advisories | OSV | Covered by OSV |
| go | Go Advisories | OSV | Covered by OSV |
| rubygems | RubyGems Advisories | OSV | Covered by OSV |
| nuget | NuGet Advisories | GHSA | Covered by GHSA |
| crates | Crates.io Advisories | OSV | Covered by OSV |
| packagist | Packagist Advisories | OSV | Covered by OSV |
| hex | Hex.pm Advisories | OSV | Covered by OSV |
Cloud Providers
| Source | Display Name | Coverage | Status |
|---|---|---|---|
| aws | AWS Security Bulletins | Direct | Complete (RSS fetcher) |
| azure | Azure Security Advisories | MSRC | Canonical alias covered by microsoft |
| gcp | GCP Security Bulletins | Direct | Complete (Atom fetcher) |
National CERTs
| Source | Display Name | Connector | Status |
|---|---|---|---|
| us-cert | CISA (US-CERT) | Connector.IcsCisa | Complete |
| cert-fr | CERT-FR (France) | Connector.CertFr | Complete |
| cert-de | CERT-Bund (Germany) | Connector.CertBund | Complete |
| jpcert | JPCERT/CC (Japan) | Connector.Jvn | Complete |
| auscert | AusCERT (Australia) | Connector.Acsc | Complete |
| krcert | KrCERT (South Korea) | Connector.Kisa | Complete |
| cert-in | CERT-In (India) | Connector.CertIn | Complete |
| fstec-bdu | FSTEC BDU (Russia) | Connector.RuBdu | Complete |
| nkcki | NKCKI (Russia) | Connector.RuNkcki | Complete |
| cert-at | CERT.at (Austria) | Connector.NationalCert | Complete |
| cert-be | CERT.be (Belgium) | Connector.NationalCert | Complete |
| cert-ch | NCSC-CH (Switzerland) | - | Unsupported; no current official machine-readable advisory feed found |
| cert-eu | CERT-EU | Connector.NationalCert | Complete |
| cert-ua | CERT-UA (Ukraine) | Connector.NationalCert | Complete; disabled by default |
| cert-pl | CERT.PL (Poland) | Connector.NationalCert | Complete; disabled by default |
ICS/SCADA (2/3)
| Source | Display Name | Connector | Status |
|---|---|---|---|
| kaspersky-ics | Kaspersky ICS-CERT | Connector.IcsKaspersky | Complete |
| us-cert | CISA ICS | Connector.IcsCisa | Complete |
| siemens | Siemens ProductCERT | Connector.VndrSiemens | Complete |
Exploit Databases
| Source | Display Name | Priority | Status |
|---|---|---|---|
| exploitdb | Exploit-DB | P2 | Complete; metadata-only CSV connector, no exploit body ingestion |
| metasploit | Metasploit Modules | P2 | Complete; metadata-only module metadata connector, no module source ingestion |
Container/Supply Chain
| Source | Display Name | Priority | Status |
|---|---|---|---|
| chainguard | Chainguard Advisories | OSV | Covered by OSV |
Hardware/Firmware
| Source | Display Name | Coverage | Status |
|---|---|---|---|
| intel | Intel PSIRT | Direct | Complete - official Intel Security Center CSAF JSON via intel/security-center |
| amd | AMD Security | Direct | Complete |
Legacy arm catalog/project rows were removed in Sprint 20260601_001 because the old production backend failed closed and no approved machine-readable Arm feed has been identified.
poc-github and docker-official were also removed in Sprint 20260601_001. Git history shows both entered in 3931b7e2cf (“Expand advisory source catalog to 75 sources and add mirror management backend”) as source-definition and HttpClient rows during catalog expansion, without runnable fetch/parse/map jobs. poc-github was removed because repository search would be token-gated, metadata-only at best, and safety/legal ambiguous. docker-official was removed because Docker Hub/Official Images metadata is not an official CVE/VEX advisory feed.
Unsupported Rows And Solutions
These rows are intentionally not part of the “sync all reachable sources” success goal until their scope or upstream feed shape changes.
| Source | Why not runnable now | Practical solution |
|---|---|---|
centos | CentOS Linux is EOL and the historical announce-list surface is not a current first-class machine-readable advisory feed. CentOS Stream is upstream/development for future RHEL, not a direct replacement for released CentOS Linux security advisories. | Keep centos unsupported/deprecated. For legacy CentOS Linux estates, allow operators to compare against Red Hat/RHSA history with reduced confidence and explicit RHEL-major mapping. Do not mark CentOS Stream as covered by Red Hat history. |
juniper | Broad Juniper JSA coverage is routed through Support Portal / customer-context dashboards, and no stable official public machine-readable all-Juniper JSA feed/API was identified. Mist has a narrower RSS feed, but it is not broad Juniper PSIRT coverage. | Keep broad juniper unsupported. Add a separate juniper-mist/mist connector only if Mist-only scope is accepted, or add an operator-managed Juniper export importer with explicit operator-checked provenance. Do not scrape Support Portal pages as production authority. |
cert-ch | NCSC-CH publishes useful warning pages, but the checked generated feed did not provide advisory entries and press-release RSS is not an advisory feed. | Keep cert-ch unsupported. Implement only after an official CSAF/JSON/RSS advisory feed or licensed API exists, or support operator-managed offline mirror imports labeled as operator-checked, not public CERT authority. |
google | The catalog key is too broad. Google Cloud is already represented by gcp; Chromium/Chrome is represented by chromium; Android and Pixel are separate product families with different bulletin formats. | Do not implement generic google. Split into scoped sources such as android and pixel if those product advisories are needed, and rely on existing gcp/chromium rows for cloud/browser coverage. |
Other (remaining)
| Source | Display Name | Connector | Status |
|---|---|---|---|
| stella-mirror | StellaOps Mirror | Connector.StellaMirror | Complete (internal) |
| csaf | CSAF Aggregator | — | Missing (P3) |
| csaf-tc | CSAF TC Trusted Publishers | — | Missing (P4) |
| vex | VEX Hub | — | Missing (P4) |
| — | Removed (Sprint 20260513_008, Path 2 — zero downstream consumers) | ||
| — | Removed (Sprint 20260513_008, Path 2 — zero downstream consumers) | ||
| rustsec | RustSec Advisory DB | OSV | Covered by OSV |
| pypa | PyPA Advisory DB | OSV | Covered by OSV |
| govuln | Go Vuln DB | OSV | Covered by OSV |
| bundler-audit | Ruby Advisory DB | OSV | Covered by OSV |
Implementation Priority
Recently Implemented Distro Connectors
These rows now have runnable Concelier connectors, fixture-backed parser/fetch tests, and WebService job anchors:
amazon- Amazon Linux ALAS RSS/detail pages, mapped as RPM NEVRA fixes.fedora- Fedora Bodhi stable security updates, mapped as RPM NEVRA fixes.
P3 - Regional CERT Connectors
These are implemented through the shared Connector.NationalCert RSS/Atom pipeline. Tests use local feed fixtures and no network access:
cert-at- CERT.at warning feed.cert-be- Belgian CCB advisories RSS.cert-eu- CERT-EU security advisories RSS.cert-ua- CERT-UA official article RSS; disabled by default.cert-pl- CERT Polska RSS; disabled by default.
Out Of Scope Until Re-scoped
centos,juniper,cert-ch, andgoogleremain catalog-visible but unsupported for the reasons listed above.- OSV/GHSA/canonical aliases are not missing connector work.
arm,poc-github, anddocker-officialare dropped rows, not implementation backlog.
Future Federation
csaf, csaf-tc, and vex are federation placeholders. They should either be repurposed into concrete CSAF/VEX aggregation contracts or removed after product decision; they should not be treated as failed source sync rows.
Notes
- Language ecosystem source keys are covered through OSV/GHSA parent rows in the setup UI, not separate source rows.
- CentOS legacy assessment may use Red Hat/RHSA history only with explicit reduced-confidence wording and operator-provided RHEL-major mapping.
- CSAF federation would unlock more vendor advisories, but needs a concrete trusted-publisher contract before it becomes an operator-facing source.
