RPM

Red Hat Package Manager format used by Red Hat-based Linux distributions

Package analysis

Cataloger + Evidence License Dependencies Package Manager Claims
Depth Edges Kinds Files Digests Integrity Hash
rpm-archive-cataloger
*.rpm
direct complete runtime
rpm-db-cataloger
var/lib/rpmmanifest/container-manifest-2
transitive runtime
rpm-db-cataloger
{var/lib,usr/share,usr/lib/sysimage}/rpm/{Packages,Packages.db,rpmdb.sqlite}
transitive complete runtime

Vulnerability scanning

Data Source Disclosures Fixes Track by
Source
Package
Affected Date Versions Date
Amazon Linux Security Center (ALAS)
Microsoft AzureLinux OVAL
Red Hat Security Data API (RHSA)
Microsoft CBL-Mariner OVAL
Oracle Linux Security (ELSA)
SUSE Security OVAL (SUSE-SU)

Operating systems

Operating System Supported Versions Provider Data Source
Amazon Linux 2, 2022, 2023 amazon Amazon Linux Security Center
Azure Linux 3.0 mariner Microsoft CBL-Mariner OVAL
CentOS 5, 6, 7, 8 rhel Red Hat Security Data API
CBL-Mariner 1.0, 2.0 mariner Microsoft CBL-Mariner OVAL
Oracle Linux 5, 6, 7, 8, 9, 10 oracle Oracle Linux Security
Red Hat Enterprise Linux 5, 6, 7, 8, 9, 10
EUS: 5.9, 6.4+, 7, 8.1, 8.2, 8.4, 8.6, 8.8, 9
rhel Red Hat Security Data API
Rocky Linux 5, 6, 7, 8, 9, 10 rhel Red Hat Security Data API
SUSE Linux Enterprise Server 11, 12, 15 sles SUSE Security OVAL

Next steps

Last modified October 23, 2025: fix section ref (9417a27)