{% extends "base.html" %} {% block title %}{{ analysis.server_name }} - Pre-Patch Report{% endblock %} {% block head %}{% if run.is_running %}{% endif %}{% endblock %} {% block heading %}Pre-Patch Report: {{ analysis.server_name }}{% endblock %} {% block header_actions %}
{% if analysis.server_id and not run.is_running %}
{% endif %} Export to Excel All Servers
{% endblock %} {% block content %} {% set amazon = analysis.os_id == "amzn" %} {% macro severity_cell(f) %}{{ f.severity }}{% if f.priority %}
{{ "ALAS Severity" if analysis.os_id == "amzn" else "Ubuntu Priority" }}: {{ f.priority }}
{% endif %}{% endmacro %} {% macro cvss_cell(f) %}{% if f.cvss_score is not none %}{{ f.cvss_label }}{% else %}—{% endif %}
{% if f.nvd_status is none %}not captured{% elif f.nvd_status in ("ok", "stale") %}Source: {{ "NVD" if f.cvss_source == "nvd@nist.gov" else (f.cvss_source or "unknown") }}{% if f.cvss_source_type and f.cvss_source != "nvd@nist.gov" %} ({{ f.cvss_source_type }}){% endif %}{% if f.nvd_status == "stale" %} · stale cache{% endif %}{% else %}{{ nvd_status_labels.get(f.nvd_status, f.nvd_status) }}{% endif %}
{% endmacro %} {% macro findings_table(groups) %} {% if groups %}
{% if analysis.os_id == "amzn" %} {% else %} {% endif %} {% for g in groups %} {% endfor %}
CVESeverityCVSSSource RPMInstalled VersionAmazon Fixed Version (Advisory)Repository CandidateRemediation ResultInstalled Binary Package(s)
CVESeverityCVSSUbuntu Source PackageInstalled VersionCanonical Fixed VersionRepository CandidateRemediation ResultInstalled Binary Package(s)
{{ g.cve_count }} CVE{{ "s" if g.cve_count != 1 else "" }} {% if g.cve_count > 1 %}
Affected CVEs
    {% for f in g.rows %}
  • {{ f.cve }} {{ severity_cell(f) }} {{ cvss_cell(f) }}
  • {% endfor %}
{% else %}
{{ g.cves[0] }}
{% endif %}
{{ severity_cell(g.highest_row) }} {{ cvss_cell(g.highest_row) }} {{ g.source or '-' }} {{ g.installed_version or "-" }} {% if g.fixed_version %}{{ g.fixed_version }}{% for pocket in g.pockets %} ({{ pocket }}){% endfor %}{% else %}-{% endif %} {{ g.candidate_version or "-" }} {{ status_labels.get(g.status, g.status) }} {% if g.detail %}
{{ g.detail }}
{% endif %}
{% if g.binary_packages|length > 6 %}
{{ g.binary_packages|length }} packages{% for b in g.binary_packages %}{{ b }} {% endfor %}
{% else %} {% for b in g.binary_packages %}{{ b }} {% else %}-{% endfor %} {% endif %}
{% else %}

None.

{% endif %} {% endmacro %} {% set bucket_classes = {"action": "badge-danger", "investigate": "badge-warning", "no_action": "badge-success"} %} {% if run.is_running and run.progress_message %}

{{ run.progress_message }}… (this page refreshes automatically)

{% endif %} {% if not is_latest %}
This is a historical report from analysis #{{ run.id }}. A newer analysis exists.
{% endif %}

Server

{% if analysis.status == "complete" %}ANALYSIS COMPLETE {% elif analysis.status == "failed" %}ANALYSIS FAILED {% elif analysis.status == "unsupported" %}{{ "OS NOT SUPPORTED" if (analysis.error or "").endswith("(end of life)") else "OS NOT SUPPORTED YET" }} {% else %}{{ analysis.status|upper }}{% endif %}
{% if analysis.error and analysis.status == "unsupported" %}
{{ analysis.error }}
{% elif analysis.error %}
{{ analysis.error }}
{% endif %}
Server Name
{{ analysis.server_name }}
{% if analysis.display_name %}
Display Name
{{ analysis.display_name }}
{% endif %}
IP
{{ analysis.ip_address or "-" }}
Remote Hostname
{{ analysis.remote_hostname or "-" }}
{{ "Ubuntu" if analysis.os_id in (none, "ubuntu") else "Operating System" }}
{{ analysis.os_pretty_name or "-" }}
{{ "Releasever" if amazon else "Codename" }}
{{ analysis.os_codename or "-" }}
Architecture
{{ analysis.architecture or "-" }}
Running Kernel
{{ analysis.running_kernel or "-" }}
Analysis Time
{{ (analysis.completed_at or analysis.started_at or run.started_at)|timestamp }}
{% if amazon %}
Security Advisories
Amazon Linux 2023 updateinfo (ALAS) of releasever {{ analysis.os_codename or "?" }} and the latest release, fetched on this workstation
{% else %}
Canonical Security Metadata
{% include "_metadata_status.html" %}
{{ run.metadata_source or "" }}
{% endif %}
Cache Lookups (whole run)
{% set r = run %}{% include "_cache_stats.html" %}
APT Metadata
{% if analysis.apt_updated_at %}Workstation private lists{% if analysis.os_codename %} ({{ analysis.os_codename }}, {{ analysis.os_codename }}-updates, {{ analysis.os_codename }}-security{% if analysis.architecture %}; {{ analysis.architecture }}{% endif %}){% endif %} updated {{ analysis.apt_updated_at|timestamp }}{% if analysis.apt_age_hours is not none %} ({{ "%.1f"|format(analysis.apt_age_hours) }} hours before analysis){% endif %}{% else %}not used{% endif %}
Current Reboot Required
{% if analysis.current_reboot_required is none %}unknown{% elif analysis.current_reboot_required %}YES{% if analysis.reboot_required_packages %} ({{ analysis.reboot_required_packages|join(", ") }}){% endif %}{% else %}NO{% endif %}
Expected Reboot After Planned Patch
{% if analysis.expected_reboot is none %}unknown{% elif analysis.expected_reboot %}YES EXPECTED{% else %}NO EXPECTED REBOOT{% endif %}
{{ reboot_help }}
{% if analysis.warnings %}
    {% for w in analysis.warnings %}
  • {{ w }}
  • {% endfor %}
{% endif %}

Patch Decision

{% set ex = patch.execution %} {% if ex %}{{ patch_labels.get(ex.state, ex.state)|upper }} {% else %}PENDING REVIEW{% endif %}
{% if patching_unsupported %}

{{ patching_unsupported }}

{% else %} {% if patch.not_checked_warning %}
{{ patch.not_checked_warning }}
{% endif %} {% if patch.excluded_warning %}
{{ patch.excluded_warning }}
{% endif %} {% if ex and ex.decision == "REJECTED" %}

Rejected on {{ ex.decided_at|timestamp }}. No packages were downloaded, copied or installed. The report remains available for reference.

{% elif ex %}

Approved on {{ ex.decided_at|timestamp }}. View Patch Execution #{{ ex.id }}

{% else %}
Local Staging
{% if patch.local_path %}{{ patch.local_path }}{% else %}unavailable{% endif %}
From Settings → Local Patch Download Directory
Remote Staging
{{ patch.remote_path or "-" }}
Expected Reboot
{% if analysis.expected_reboot is none %}unknown{% elif analysis.expected_reboot %}YES EXPECTED{% else %}NO{% endif %}
Packages to Update
{{ patch.packages }} ({{ patch.debs }} .deb file{{ "" if patch.debs == 1 else "s" }})
Download Size
{{ patch.download_bytes|filesize }}
{% if patch.reasons %}
Patching is not available for this report.
    {% for r in patch.reasons %}
  • {{ r }}
  • {% endfor %}
{% endif %} {% if patch.unpatched_notes %}
{{ patch.unpatched_notes|length }} finding(s) cannot be fixed by this patch
    {% for n in patch.unpatched_notes %}
  • {{ n }}
  • {% endfor %}
{% endif %}
{% if patch.allowed %} Approve & Patch {% else %} {% endif %}
{% endif %} {% endif %}

Summary

{{ summary.reported }}Reported CVEs
{{ summary.count("PATCH_AVAILABLE") }}Patch available
{{ summary.count("ALREADY_FIXED") }}Already fixed
{{ summary.count("NOT_AFFECTED") }}Not affected
{{ summary.count("PACKAGE_NOT_INSTALLED") }}Package not installed
{{ summary.count("FIX_NOT_IN_CONFIGURED_REPOS", "PRO_OR_ESM_REQUIRED") }}Published fix requires repository access
{{ summary.count("NO_FIX_PUBLISHED", "PENDING_OR_DEFERRED") }}No published fix / deferred
{{ summary.packages }}Binary packages to update
{{ summary.debs }}.deb files required
{{ summary.download_bytes|filesize }}Estimated download size
{% if analysis.expected_reboot is none %}?{% elif analysis.expected_reboot %}YES{% else %}NO{% endif %}Expected reboot

Severity (NVD CVSS, per reported CVE): {% for sev in severities %}{{ sev }}: {{ summary.by_severity[sev] }}{% endfor %}

By action (per reported CVE): {% for key, title, n in summary.buckets %}{{ title }}: {{ n }} CVE{{ "s" if n != 1 else "" }}{% endfor %}

{% if summary.by_status %}

By status: {% for status, count in summary.by_status|dictsort %} {{ status_labels.get(status, "Not analyzed" if status == "NOT_ANALYZED" else status) }}: {{ count }} {% endfor %}

{% endif %} {% if summary.unresolved %}
{{ summary.unresolved }} package(s) in the plan could not be resolved to an exact .deb file. See the package plan below.
{% endif %}

CVE Findings

{% if analysis.findings %}

{% for b in finding_buckets %}{{ b.title }}: {{ b.count }} ({{ b.cve_count }} CVE{{ "s" if b.cve_count != 1 else "" }}){% endfor %}

{% for b in finding_buckets %} {% if b.key == "no_action" %}
{{ b.title }} ({{ b.count }}) {{ findings_table(b.groups) }}
{% else %}

{{ b.title }} ({{ b.count }})

{% if b.key == "investigate" and b.count and analysis.server_id and not run.is_running %}
Fetches these CVEs from Canonical again (bypassing the cache) and re-analyzes this server. {% endif %} {{ findings_table(b.groups) }} {% endif %} {% endfor %} {% else %}

No findings{% if analysis.status == "failed" %} - the analysis of this server failed before CVEs could be evaluated. Reported CVEs: {{ analysis.reported_cves|join(", ") }}{% elif analysis.status == "unsupported" %} - this operating system is not supported yet, so CVEs were not evaluated. Reported CVEs: {{ analysis.reported_cves|join(", ") }}{% endif %}.

{% endif %}

Package / .deb Plan

{% if analysis.plan %}

Planned only — nothing has been downloaded. Target versions are the current APT candidates of the Ubuntu archive for this server's release and architecture, resolved on this workstation.

{% for p in analysis.plan %} {% endfor %}
Binary PackageCurrent VersionTarget Version.deb FilenameSizeRelated CVEsReboot Impact
{{ p.binary_package }} {{ p.architecture }} {% if p.is_dependency %}
dependency{% if p.current_version is none %} (new package){% endif %}
{% endif %}
{{ p.current_version or "not installed" }} {{ p.target_version }} {% if p.deb_filename %}{{ p.deb_filename }}{% else %}Unable to resolve package download plan
{{ p.reason }}
{% endif %}
{{ p.size|filesize }} {% for c in p.cves %}{{ c }}{% else %}required dependency{% endfor %} {{ p.reboot_impact or "No reboot expected" }}
{% elif patching_unsupported %}

Package planning is not supported yet for this operating system.

{% else %}

No package updates are planned for this server{% if patch.not_checked_warning %} for the CVEs that were checked{% endif %}.

{% if patch.not_checked_warning %}
{{ patch.not_checked_warning }}
{% endif %} {% endif %}
{% if analysis.plan or analysis.apt_arguments %}
Technical details (download URIs, checksums, APT invocation) {% if analysis.apt_arguments %}

APT invocation used for planning on the workstation (simulation / --print-uris only, against the private APT state):

apt-get {{ analysis.apt_arguments|join(" ") }}
{% endif %}
{% for p in analysis.plan %} {% endfor %}
.debSource PackageURIChecksum
{{ p.deb_filename or p.binary_package }} {{ p.source_package or "-" }} {% if p.uri %}{{ p.uri }}{% else %}-{% endif %} {% if p.checksum %}{{ p.checksum }}{% else %}-{% endif %}
{% if analysis.expected_reboot_reason %}

Expected reboot: {{ analysis.expected_reboot_reason }}

{% endif %}
{% endif %} {% endblock %}