Skip to content

Add bottlerocket advisories #1828

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
pombredanne opened this issue Mar 22, 2025 · 2 comments
Open

Add bottlerocket advisories #1828

pombredanne opened this issue Mar 22, 2025 · 2 comments

Comments

@pombredanne
Copy link
Member

pombredanne commented Mar 22, 2025

AWS uses Bottlerocket, a Linux distro for containers

Based on:

Security Advisories
Bottlerocket publishes security advisories on the repo’s GitHub’s Security tab and a gzipped updateinfo.xml file at advisories.bottlerocket.aws (make sure you follow redirects: e.g. use curl -LO https://advisories.bottlerocket.aws/updateinfo.xml.gz).

See also this discussion thread by @ginglis13 :

Therefore, sources are:

The purl for this distro is unclear in particular:

Software inventory and security advisories

Since Bottlerocket doesn’t use a package manager, keeping track of the software delivered as part of a variant is a little different. Additionally, the concept of a ‘package’ is only relevant as a part of the build process. In the course of running Bottlerocket, you probably want to keep track of what specific software and versions you are using as well as understand how this software relates to known vulnerabilities.
Note

The best patching strategy for Bottlerocket is to always update to the most recent release. Since packages are only used at build-time and the packages cannot mutate, the inventory will never change for a given version and variant. Updating to the most recent version will patch all packages.

Bottlerocket provides information to both understand the software included in a variant and how it connects to published security advisories.

The packages are likely sourced from updates.bottlerocket.aws ... details are TBD

@kunalsz
Copy link

kunalsz commented Mar 22, 2025

@pombredanne I would like to work on this issue

@pombredanne
Copy link
Member Author

pombredanne commented Apr 3, 2025

@kunalsz see also the details I have added to the description for reference

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants