Extend Vigiles Coverage Across Your Software Ecosystems

Your product may combine a Linux distribution with application languages, package managers, containers, and other software ecosystems. Vigiles can apply relevant ecosystem-specific vulnerability feeds alongside Vigiles Curated intelligence so you can align vulnerability analysis with the software in your products and SBOMs.

gpu-hero-gradient

Your Product May Include More Than One Vulnerability Ecosystem

Embedded products rarely contain software from only one source or technology stack.

A Linux-based product might also include Python packages, npm dependencies, Java/Maven components, Rust crates, distribution packages, container images, or other software with its own package and release model. Each ecosystem may publish or maintain vulnerability information for its packages, versions, and release process.

The practical question is not whether you need every available feed. It is:

Which ecosystem-specific vulnerability feeds are relevant to the software in your product?

Start with Vigiles Curated. Extend with Relevant Ecosystem Feeds.

Vigiles Curated

The baseline vulnerability intelligence used by Vigiles, drawing on vulnerability, vendor, and distribution sources with curation and engineering analysis.

Depending on the issue and available source material, that work can add corrections, applicability context, improved references, and links to fixes or remediation resources.

Relevant ecosystem feeds

Additional vulnerability intelligence associated with the operating systems, distributions, languages, package managers, containers, and other ecosystems represented in your product.

The result

Vigiles analysis informed by the technologies that are actually present in your product and SBOM.

This page is about extending relevant coverage. It is not a claim that baseline Vigiles only uses one source, or that selecting more feeds automatically produces better results.

Supported Ecosystem Feeds

Baseline

Vigiles Curated

The baseline vulnerability intelligence used by Vigiles. The entries below represent selectable ecosystem coverage in the current product interface.

Operating systems and distributions

Linux and Distribution Feeds

  • AlmaLinux
  • Alpaquita
  • Alpine
  • Android
  • Debian
  • Linux
  • Mageia
  • openEuler
  • openSUSE
  • Red Hat
  • Rocky Linux
  • SUSE
  • Ubuntu
  • Wolfi
Containers

Container Ecosystems

  • BellSoft Hardened Containers
  • Bitnami
  • Chainguard
  • CleanStart
  • Echo
  • Root ecosystem coverage
Development and specialized feeds

Specialized Feeds

  • GitHub Actions
  • GIT
  • GSD
  • MinimOS
  • OSS-Fuzz
  • SwiftURI
  • UVI
  • VSCode
Languages

Language Ecosystems

  • CRAN
  • GHC
  • Go
  • Hackage
  • Hex
  • Julia
Packages and dependencies

Package Ecosystems

  • crates.io
  • Maven
  • npm
  • NuGet
  • opam
  • Packagist
  • Pub
  • PyPI
  • RubyGems

Choose Coverage Based on What Your Product Uses

Review the software represented in your product and SBOM:

  • Which operating systems or distributions are present?
  • Which programming languages are used?
  • Which package managers supply application dependencies?
  • Do container images or specialized container distributions form part of the product?
  • Which ecosystems appear in your SBOM?

You do not necessarily need every feed in the selector. The relevant coverage depends on the technologies in your software. Lynx can help map that stack to the ecosystem-specific vulnerability feeds available for your Vigiles deployment.

How Ecosystem Coverage Fits into Vigiles

At a high level, the workflow is:

  1. Generate or upload an SBOM.
  2. Identify the ecosystems represented in the product.
  3. Apply the relevant ecosystem-specific vulnerability feeds.
  4. Generate and monitor vulnerability results in Vigiles.

This workflow helps align Vigiles vulnerability analysis with the ecosystems represented in your product.

Find the Right Coverage for Your Software Stack

If your product includes several of the ecosystems listed above, talk with Lynx about the coverage relevant to your Vigiles deployment. We can help identify which feeds correspond to the operating systems, languages, package managers, containers, and other software ecosystems represented in your products and SBOMs.