{% extends "base.html" %} {% block title %}Settings{% endblock %} {% block heading %}Settings{% endblock %} {% block content %}
Security lookups are cached in the application database: NVD CVSS data per CVE (table nvd_cache), Canonical security data per CVE (cve_metadata_cache) and Amazon Linux updateinfo per repository (amazon_updateinfo_cache). An entry younger than its TTL is used without a request; an older one is refreshed on its next lookup and only used as a fallback when the source cannot be reached. Changing a TTL never deletes entries. Failed lookups are never cached.
Clear Security Cache empties all three caches (NVD, Canonical and Amazon updateinfo) and the in-memory lookup state.
Optional key for faster CVSS lookups (50 instead of 5 NVD requests per 30 s). A key saved here is stored encrypted and is used instead of the NVD_API_KEY environment variable. Only its last 4 characters are ever shown.
{{ nvd_key.masked }}{% else %}none{% endif %}{{ db_path }}ubuntu)sshpass; passwords are stored per server, encrypted{{ secret_key_path }} (mode 0600, never in the database; without it stored secrets must be entered again)Canonical security data is queried online per CVE during analysis. Each fetched CVE is also cached in the application database (see Caches for the TTLs); an expired copy is used (and marked with its age) only when ubuntu.com cannot be reached.
cve_metadata_cache in {{ metadata_status.cache_db }}APT candidates and the .deb plan are resolved on this workstation against private package lists per Ubuntu release and architecture (release, -updates and -security pockets). Servers are only read (dpkg-query); the system APT configuration is never used or changed.
{{ apt_state_dir }}Permanently removes servers, reports, analyses, and settings.