{% extends "base.html" %} {% block title %}{{ analysis.server_name }} - Pre-Patch Report{% endblock %} {% block head %}{% if run.is_running %}{% endif %}{% endblock %} {% block heading %}Pre-Patch Report: {{ analysis.server_name }}{% endblock %} {% block header_actions %}
| CVE | Severity | CVSS | Source RPM | Installed Version | Amazon Fixed Version (Advisory) | Repository Candidate | Remediation Result | Installed Binary Package(s) |
|---|---|---|---|---|---|---|---|---|
| CVE | Severity | CVSS | Ubuntu Source Package | Installed Version | Canonical Fixed Version | Repository Candidate | Remediation Result | Installed Binary Package(s) |
{{ g.cve_count }} CVE{{ "s" if g.cve_count != 1 else "" }}
{% if g.cve_count > 1 %}
Affected CVEs
{{ g.cves[0] }} |
{{ severity_cell(g.highest_row) }} | {{ cvss_cell(g.highest_row) }} | {{ g.source or '-' }} | {{ g.installed_version or "-" }} |
{% if g.fixed_version %}{{ g.fixed_version }}{% for pocket in g.pockets %} ({{ pocket }}){% endfor %}{% else %}-{% endif %} |
{{ g.candidate_version or "-" }} |
{{ status_labels.get(g.status, g.status) }}
{% if g.detail %} {{ g.detail }} {% endif %} |
{% if g.binary_packages|length > 6 %}
{{ g.binary_packages|length }} packages{% for b in g.binary_packages %}{{ b }} {% endfor %}{{ b }} {% else %}-{% endfor %}
{% endif %}
|
None.
{% endif %} {% endmacro %} {% set bucket_classes = {"action": "badge-danger", "investigate": "badge-warning", "no_action": "badge-success"} %} {% if run.is_running and run.progress_message %} {% endif %} {% if not is_latest %}{{ analysis.ip_address or "-" }}{{ patching_unsupported }}
{% else %} {% if patch.not_checked_warning %}Rejected on {{ ex.decided_at|timestamp }}. No packages were downloaded, copied or installed. The report remains available for reference.
{% elif ex %}Approved on {{ ex.decided_at|timestamp }}. View Patch Execution #{{ ex.id }}
{% else %}{{ patch.local_path }}{% else %}unavailable{% endif %}
{{ patch.remote_path or "-" }}Severity (NVD CVSS, per reported CVE): {% for sev in severities %}{{ sev }}: {{ summary.by_severity[sev] }}{% endfor %}
By action (per reported CVE): {% for key, title, n in summary.buckets %}{{ title }}: {{ n }} CVE{{ "s" if n != 1 else "" }}{% endfor %}
{% if summary.by_status %}By status: {% for status, count in summary.by_status|dictsort %} {{ status_labels.get(status, "Not analyzed" if status == "NOT_ANALYZED" else status) }}: {{ count }} {% endfor %}
{% endif %} {% if summary.unresolved %}{% for b in finding_buckets %}{{ b.title }}: {{ b.count }} ({{ b.cve_count }} CVE{{ "s" if b.cve_count != 1 else "" }}){% endfor %}
{% for b in finding_buckets %} {% if b.key == "no_action" %}No findings{% if analysis.status == "failed" %} - the analysis of this server failed before CVEs could be evaluated. Reported CVEs: {{ analysis.reported_cves|join(", ") }}{% elif analysis.status == "unsupported" %} - this operating system is not supported yet, so CVEs were not evaluated. Reported CVEs: {{ analysis.reported_cves|join(", ") }}{% endif %}.
{% endif %}Planned only — nothing has been downloaded. Target versions are the current APT candidates of the Ubuntu archive for this server's release and architecture, resolved on this workstation.
| Binary Package | Current Version | Target Version | .deb Filename | Size | Related CVEs | Reboot Impact |
|---|---|---|---|---|---|---|
| {{ p.binary_package }} {{ p.architecture }}
{% if p.is_dependency %} dependency{% if p.current_version is none %} (new package){% endif %} {% endif %} |
{{ p.current_version or "not installed" }} |
{{ p.target_version }} |
{% if p.deb_filename %}{{ p.deb_filename }}{% else %}Unable to resolve package download plan{{ p.reason }} {% endif %} |
{{ p.size|filesize }} | {% for c in p.cves %}{{ c }}{% else %}required dependency{% endfor %} |
{{ p.reboot_impact or "No reboot expected" }} |
Package planning is not supported yet for this operating system.
{% else %}No package updates are planned for this server{% if patch.not_checked_warning %} for the CVEs that were checked{% endif %}.
{% if patch.not_checked_warning %}APT invocation used for planning on the workstation (simulation / --print-uris only, against the private APT state):
apt-get {{ analysis.apt_arguments|join(" ") }}
{% endif %}
| .deb | Source Package | URI | Checksum |
|---|---|---|---|
{{ p.deb_filename or p.binary_package }} |
{{ p.source_package or "-" }} | {% if p.uri %}{{ p.uri }}{% else %}-{% endif %} |
{% if p.checksum %}{{ p.checksum }}{% else %}-{% endif %} |
Expected reboot: {{ analysis.expected_reboot_reason }}
{% endif %}