LLM WikiAccess-protected knowledge portal

WIKI

[os 패키지 취약점 - v4] Red Hat

AI Summary Purpose Preserve the current 2026 08 20 Confluence design for rebuilding RHEL OS package vulnerability collection on Red Hat CSAF/VEX. Key points Confluence 4149674090 VEX를 이용한 RHEL 취약점 수집 방법 is the design source. DT/4209377355 i

경로ai/sources/confluence/2026-08-20-rhel-vex-redesign.md
카테고리Source
태그#ai-review #confluence #crawler #infra #mysql #portfolio #redesign #rhel #security #source #vex

# [os 패키지 취약점 - v4] Red Hat

AI Summary

Purpose:

OS-package vulnerability collection on Red Hat CSAF/VEX.

Key points:

source. DT/4209377355 implements its collection model and records the remaining decisions instead of silently changing the source scope.

roughly 4.87M vulnerability facts, and roughly 63K per-document collection states. The document-state table stays in gathering; the other two are also needed for serving.

visible because the same package and CVE can have different fixed EVRs for MAIN, EUS, AUS, and TUS products.

gathering copy at 3.71M rows / 14.7 GB. This is a design estimate and must be confirmed on the trial load.

measurement put that miss at 38.2%. Matching therefore derives OS major and support channel from the host CPE, expands to the target repo streams, and then applies module conditions.

support-channel detection is part of correctness rather than presentation.

write is a row diff. On 120 republished documents, 22.7% of fact rows changed and 75% changed no fact row. The design estimates about 7K row events/day for the diff versus 61.6K for delete-and-reinsert; this matters because the serving DB emits binlogs to customer on-premise servers.

load, cutover, and the production false-positive reduction are not complete.

Relevant when:

Do not read full document unless:

Linked documents:

Open Questions

known_not_affected storage still require team decisions.

confirmed across the fleet.

Details

details were not copied.

23). Mermaid diagrams now render as the team's Mermaid diagram macro with source code in expands, per-subscription descriptions moved into the subscription table, secondary tables (subscription × stream combinations, document-state examples) moved into expands, and a new section 6-5 adds three subscription-judgment scenarios (MAIN / TUS 8.6 / unreadable certificate) walked through the CPE dictionary and fact table. Design facts and measured numbers are unchanged; see ai/worklog/2026/2026-W35.md for the change record.