# Advisory Source Connector Coverage Matrix

Last updated: 2026-06-02

Coverage terms used by the UI/API:

Summary

Live source counts are served by /api/v1/advisory-sources/catalog. This matrix documents coverage semantics, source families, and known connector gaps so the UI can distinguish parent-covered rows from true missing connectors.

Setup UI Row Model

The setup page renders only actionable parent rows for parent-covered sources. Alias and ecosystem source keys remain in the catalog/API for attribution, search, policy filters, historical source-state cleanup, and imports, but they are not separate operator rows. The parent row carries an “Also covering …” summary instead:

Search still matches hidden alias rows and returns the parent row. For example, searching for rhel returns Red Hat Security, and searching for nuget returns GitHub Security Advisories.

Decision Matrix For Concern Rows

Decision bucketSource IDsUI/current treatmentNext action
Fully dropped / cleansedarm, poc-github, docker-officialNo catalog row; no project reference; no active seed rowDone. Startup migrations purge existing DB rows and mirror-domain exports.
Mark as covered by OSVnpm, pypi, go, rubygems, maven, crates, packagist, hex, rustsec, pypa, govuln, bundler-audit, chainguard, wolfiFolded into the osv row as “Also covering …”Done for catalog/API/UI. Do not count these as missing connectors.
Mark as covered by GHSAnugetFolded into the ghsa row as “Also covering nuget”Done for catalog/API/UI.
Mark as canonical aliasrhel, azureFolded into redhat and microsoft/MSRC rows as “Also covering …”Done for catalog/API/UI. Keep source keys for filtering/attribution, not direct sync.
Implemented but previously not wired on UIarch, astra, stella-mirrorNow syncSupported=true and supportsConfiguration=true; setup page renders connector-owned controlsFixed in AVEX-004. No sync-supported advisory source should remain without configuration support.
Implemented exploit metadata connectorsexploitdb, metasploitsyncSupported=true and supportsConfiguration=true; metadata-only connector controls render in setupDone. Do not fetch or persist arbitrary exploit bodies or module source files.
Implemented national CERT connectorscert-at, cert-be, cert-eu, cert-ua, cert-plsyncSupported=true and supportsConfiguration=true; setup page renders connector-owned RSS/Atom endpoint controlsDone. Shared NationalCert connector uses official RSS/Atom feeds plus fixture-friendly endpoint overrides.
Implemented distro advisory connectorsamazon, fedorasyncSupported=true and supportsConfiguration=true; setup page renders connector-owned endpoint controlsDone. Amazon Linux uses ALAS RSS/detail pages; Fedora uses Bodhi stable security updates. Both support fixture-friendly endpoint overrides.
Keep unsupported / not implemented nowcentos, juniper, cert-ch, googleCatalog-visible unsupported rows with missing-connector detailKeep out of sync success goals. google must be narrowed to Android/Pixel/etc. before implementation; juniper and cert-ch need stable official machine-readable feeds.

Coverage by Category

Primary Databases (6/6 — 100%)

SourceDisplay NameConnectorStatus
nvdNVD (NIST)Connector.NvdComplete
osvOSV (Google)Connector.OsvComplete
ghsaGitHub Security AdvisoriesConnector.GhsaComplete
cveCVE.org (MITRE)Connector.CveComplete
epssEPSS (FIRST)Connector.EpssComplete
kevCISA KEVConnector.KevComplete

Linux Distributions

SourceDisplay NameConnectorStatus
debianDebian SecurityConnector.DistroDebianComplete
ubuntuUbuntu SecurityConnector.DistroUbuntuComplete
alpineAlpine SecurityConnector.DistroAlpineComplete
amazonAmazon Linux SecurityConnector.DistroAmazonComplete
suseSUSE SecurityConnector.DistroSuseComplete
rhelRHEL SecurityConnector.RedHatCanonical alias covered by redhat
astraAstra LinuxConnector.DistroAstraComplete
wolfiWolfi SecurityOSV-backed aliasCovered by OSV
centosCentOS Security-Unsupported/deprecated; no current connector plan
fedoraFedora SecurityConnector.DistroFedoraComplete
archArch SecurityConnector.DistroArchComplete
gentooGentoo SecurityConnector.DistroGentooComplete

Vendor Advisories

SourceDisplay NameConnectorStatus
oracleOracle SecurityConnector.VndrOracleComplete
appleApple SecurityConnector.VndrAppleComplete
ciscoCisco SecurityConnector.VndrCiscoComplete
vmwareVMware SecurityConnector.VmwareComplete
redhatRed Hat SecurityConnector.RedHatComplete
microsoftMicrosoft MSRCConnector.VndrMsrcComplete
googleGoogle Security-Needs scope decision before implementation
fortinetFortinet PSIRTConnector.VndrFortinetComplete
juniperJuniper Security-Unsupported until stable official JSA feed/API exists
paloaltoPalo Alto SecurityConnector.VndrPaloAltoComplete

Language Ecosystems

Ecosystem advisories are routed through OSV/GHSA. These rows remain visible so operators can filter policy and attribution by ecosystem without triggering fake per-ecosystem fetch jobs.

SourceDisplay NameCoverageStatus
npmnpm AdvisoriesOSVCovered by OSV
pypiPyPI AdvisoriesOSVCovered by OSV
mavenMaven AdvisoriesOSVCovered by OSV
goGo AdvisoriesOSVCovered by OSV
rubygemsRubyGems AdvisoriesOSVCovered by OSV
nugetNuGet AdvisoriesGHSACovered by GHSA
cratesCrates.io AdvisoriesOSVCovered by OSV
packagistPackagist AdvisoriesOSVCovered by OSV
hexHex.pm AdvisoriesOSVCovered by OSV

Cloud Providers

SourceDisplay NameCoverageStatus
awsAWS Security BulletinsDirectComplete (RSS fetcher)
azureAzure Security AdvisoriesMSRCCanonical alias covered by microsoft
gcpGCP Security BulletinsDirectComplete (Atom fetcher)

National CERTs

SourceDisplay NameConnectorStatus
us-certCISA (US-CERT)Connector.IcsCisaComplete
cert-frCERT-FR (France)Connector.CertFrComplete
cert-deCERT-Bund (Germany)Connector.CertBundComplete
jpcertJPCERT/CC (Japan)Connector.JvnComplete
auscertAusCERT (Australia)Connector.AcscComplete
krcertKrCERT (South Korea)Connector.KisaComplete
cert-inCERT-In (India)Connector.CertInComplete
fstec-bduFSTEC BDU (Russia)Connector.RuBduComplete
nkckiNKCKI (Russia)Connector.RuNkckiComplete
cert-atCERT.at (Austria)Connector.NationalCertComplete
cert-beCERT.be (Belgium)Connector.NationalCertComplete
cert-chNCSC-CH (Switzerland)-Unsupported; no current official machine-readable advisory feed found
cert-euCERT-EUConnector.NationalCertComplete
cert-uaCERT-UA (Ukraine)Connector.NationalCertComplete; disabled by default
cert-plCERT.PL (Poland)Connector.NationalCertComplete; disabled by default

ICS/SCADA (2/3)

SourceDisplay NameConnectorStatus
kaspersky-icsKaspersky ICS-CERTConnector.IcsKasperskyComplete
us-certCISA ICSConnector.IcsCisaComplete
siemensSiemens ProductCERTConnector.VndrSiemensComplete

Exploit Databases

SourceDisplay NamePriorityStatus
exploitdbExploit-DBP2Complete; metadata-only CSV connector, no exploit body ingestion
metasploitMetasploit ModulesP2Complete; metadata-only module metadata connector, no module source ingestion

Container/Supply Chain

SourceDisplay NamePriorityStatus
chainguardChainguard AdvisoriesOSVCovered by OSV

Hardware/Firmware

SourceDisplay NameCoverageStatus
intelIntel PSIRTDirectComplete - official Intel Security Center CSAF JSON via intel/security-center
amdAMD SecurityDirectComplete

Legacy arm catalog/project rows were removed in Sprint 20260601_001 because the old production backend failed closed and no approved machine-readable Arm feed has been identified.

poc-github and docker-official were also removed in Sprint 20260601_001. Git history shows both entered in 3931b7e2cf (“Expand advisory source catalog to 75 sources and add mirror management backend”) as source-definition and HttpClient rows during catalog expansion, without runnable fetch/parse/map jobs. poc-github was removed because repository search would be token-gated, metadata-only at best, and safety/legal ambiguous. docker-official was removed because Docker Hub/Official Images metadata is not an official CVE/VEX advisory feed.

Unsupported Rows And Solutions

These rows are intentionally not part of the “sync all reachable sources” success goal until their scope or upstream feed shape changes.

SourceWhy not runnable nowPractical solution
centosCentOS Linux is EOL and the historical announce-list surface is not a current first-class machine-readable advisory feed. CentOS Stream is upstream/development for future RHEL, not a direct replacement for released CentOS Linux security advisories.Keep centos unsupported/deprecated. For legacy CentOS Linux estates, allow operators to compare against Red Hat/RHSA history with reduced confidence and explicit RHEL-major mapping. Do not mark CentOS Stream as covered by Red Hat history.
juniperBroad Juniper JSA coverage is routed through Support Portal / customer-context dashboards, and no stable official public machine-readable all-Juniper JSA feed/API was identified. Mist has a narrower RSS feed, but it is not broad Juniper PSIRT coverage.Keep broad juniper unsupported. Add a separate juniper-mist/mist connector only if Mist-only scope is accepted, or add an operator-managed Juniper export importer with explicit operator-checked provenance. Do not scrape Support Portal pages as production authority.
cert-chNCSC-CH publishes useful warning pages, but the checked generated feed did not provide advisory entries and press-release RSS is not an advisory feed.Keep cert-ch unsupported. Implement only after an official CSAF/JSON/RSS advisory feed or licensed API exists, or support operator-managed offline mirror imports labeled as operator-checked, not public CERT authority.
googleThe catalog key is too broad. Google Cloud is already represented by gcp; Chromium/Chrome is represented by chromium; Android and Pixel are separate product families with different bulletin formats.Do not implement generic google. Split into scoped sources such as android and pixel if those product advisories are needed, and rely on existing gcp/chromium rows for cloud/browser coverage.

Other (remaining)

SourceDisplay NameConnectorStatus
stella-mirrorStellaOps MirrorConnector.StellaMirrorComplete (internal)
csafCSAF Aggregator—Missing (P3)
csaf-tcCSAF TC Trusted Publishers—Missing (P4)
vexVEX Hub—Missing (P4)
mitre-attackMITRE ATT&CK—Removed (Sprint 20260513_008, Path 2 — zero downstream consumers)
mitre-d3fendMITRE D3FEND—Removed (Sprint 20260513_008, Path 2 — zero downstream consumers)
rustsecRustSec Advisory DBOSVCovered by OSV
pypaPyPA Advisory DBOSVCovered by OSV
govulnGo Vuln DBOSVCovered by OSV
bundler-auditRuby Advisory DBOSVCovered by OSV

Implementation Priority

Recently Implemented Distro Connectors

These rows now have runnable Concelier connectors, fixture-backed parser/fetch tests, and WebService job anchors:

  1. amazon - Amazon Linux ALAS RSS/detail pages, mapped as RPM NEVRA fixes.
  2. fedora - Fedora Bodhi stable security updates, mapped as RPM NEVRA fixes.

P3 - Regional CERT Connectors

These are implemented through the shared Connector.NationalCert RSS/Atom pipeline. Tests use local feed fixtures and no network access:

  1. cert-at - CERT.at warning feed.
  2. cert-be - Belgian CCB advisories RSS.
  3. cert-eu - CERT-EU security advisories RSS.
  4. cert-ua - CERT-UA official article RSS; disabled by default.
  5. cert-pl - CERT Polska RSS; disabled by default.

Out Of Scope Until Re-scoped

Future Federation

csaf, csaf-tc, and vex are federation placeholders. They should either be repurposed into concrete CSAF/VEX aggregation contracts or removed after product decision; they should not be treated as failed source sync rows.


Notes