{% extends "base.html" %} {% block title %}Reports{% endblock %} {% block heading %}Reports{% endblock %} {% block content %}

Upload Security CVE Report

Expected format
{
  "app-prod-01": ["CVE-2026-12345", "CVE-2026-67890"],
  "database-prod-01": ["CVE-2026-22222"]
}

Each key must be the name of a configured server. Each value must be an array of CVE identifiers.

{% if upload_error %} {% endif %} {% if validation %}

Validation Result

{% if validation.valid %} VALID {% else %} VALIDATION FAILED {% endif %}
Report
{{ validation.filename }}
{% if validation.valid %}
Servers in report
{{ validation.server_count }}
CVEs in report
{{ validation.cve_count }}
Validation
VALID
{% else %}
Validation
FAILED
{% endif %}
{% if validation.valid %}

The report was accepted and saved as the latest report.

{% else %}

The report was not saved.{% if report %} The previously accepted report is still in use.{% endif %}

{% endif %}
{% endif %}

Latest Accepted Report

{% if report %}{{ report.status }}{% endif %}
{% if report %}
Report
{{ report.filename }}
Uploaded
{{ report.uploaded_at|timestamp }}
Servers in report
{{ report.server_count }}
CVEs in report
{{ report.cve_count }}
{% if missing_servers %}
Some servers in this report are no longer configured: {{ missing_servers|join(", ") }}
{% endif %} {% for name, cves in report.servers.items() %} {% endfor %}
ServerCVEsIdentifiers
{{ name }} {{ cves|length }} CVE{{ "" if cves|length == 1 else "s" }} {% for c in cves %}{{ c }}{% endfor %}{% if not cves %}none{% endif %}
{% else %}

No report uploaded yet

Upload the security team's CVE JSON report above.

{% endif %}

Pre-Patch Analysis

{% include "_nvd_key_badge.html" %}{% include "_cache_badges.html" %}{% if analysis_running %}RUNNING{% endif %}

Connects to each server in the latest report (read-only, as the server's SSH user, no sudo), detects the OS, checks installed packages against Canonical's Ubuntu security metadata and APT, and builds a per-server pre-patch report. Servers that do not run Ubuntu are listed as "OS not supported yet". No packages are downloaded, installed or restarted.

{% if report %}
{{ report.filename }} · {{ report.server_count }} server{{ "" if report.server_count == 1 else "s" }} · {{ report.cve_count }} CVE{{ "" if report.cve_count == 1 else "s" }}
{% else %}

Upload a valid report to enable analysis.

{% endif %}
Canonical security metadata
Canonical security data is queried online per CVE during analysis.
{% if metadata_status.warning %}
{{ metadata_status.warning }}
{% endif %} {% if runs %} {% for r in runs %} {% endfor %}
AnalysisReportStartedStatusServers
#{{ r.id }}{% if loop.first %} Latest{% endif %} {{ r.report_filename }} {{ r.started_at|timestamp }} {% include "_run_status.html" %} {{ r.servers|selectattr("status", "equalto", "complete")|list|length }} of {{ r.servers|length }} complete
{% endif %}
{% endblock %}