# OS Vendor VEX Publication Status (2026-08-26)
AI Summary
Purpose:
- Record which of the 14 collected OS families publish VEX-format security
data, to drive the multi-OS migration order on Confluence DT/4222189689.
Key points:
- Publishing now: Red Hat (CSAF VEX, v4 in progress), SUSE/openSUSE (CSAF
VEX at ftp.suse.com/pub/projects/security/csaf-vex/, one file per CVE, back-catalog included, since 2023-02), Ubuntu (OpenVEX, see [[2026-08-26-ubuntu-vex-osv-format]]), Azure Linux/Mariner (MSRC announced VEX publication 2025-10; format and path not yet verified).
- Not yet / unclear: Oracle publishes CSAF for Critical Patch Updates, but
ELSA-level CSAF for Oracle Linux is Needs confirmation (TuxCare's ELS CSAF is a third party, not Oracle). AlmaLinux has only announced a CVRF→CSAF transition plan. Amazon Linux and Debian are described as experimenting/planning (OpenSSF state-of-VEX post, 2026-01). No VEX evidence found for Alpine, Rocky, Photon, Fedora, Arch.
- Migration order candidate recorded on the Confluence page: RHEL →
SUSE/openSUSE → Ubuntu → Azure Linux.
Relevant when:
- Deciding which OS collector to migrate next, or re-checking a vendor's
VEX availability (statuses will drift — re-verify before starting work).
Do not read full document unless:
- You need the source URLs.
Linked documents:
ai/sources/web/2026-08-26-ubuntu-vex-osv-format.mdai/wiki/projects/rhel-vex-vuln-collection.md(open question 10)- Confluence DT/4222189689
Open Questions
- Azure Linux VEX: format (OpenVEX vs CSAF) and download path.
- Oracle ELSA-level CSAF existence.
- Re-check Amazon/Debian/Alma status before W40+ planning.
Details
Sources checked 2026-08-26:
- https://www.suse.com/support/security/csaf/ — SUSE CSAF since 2023-02;
VEX per CVE at https://ftp.suse.com/pub/projects/security/csaf-vex/
- https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux
— VEX for Azure Linux announced
- https://openssf.org/blog/2026/01/08/signal-in-the-noise-an-industry-wide-perspective-on-the-state-of-vex/
— Amazon/Debian experimenting-planning
- https://blogs.oracle.com/security/vex-justifications-cpu — Oracle CPU
CSAF/VEX (Oracle-wide, not ELSA-specific)
- https://github.com/AlmaLinux/build-system/milestone/7 — Alma CVRF→CSAF plan