# Patch Notification: Patch Finder vs Update Advisories

**URL:** https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523
**Category:** SLES Updates
**Created:** [March 21, 2017, 2:56am UTC](https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523 "2017-03-21T02:56:00Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![kkaren](https://avatars.discourse-cdn.com/v4/letter/k/d78d45/32.png) [@kkaren](https://forums.suse.com/u/kkaren)
#### Post date: [March 21, 2017, 2:56am UTC](https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523/1 "2017-03-21T02:56:00Z")

</div>

Hi,

I’m quite new here, so please bear with me. 🙂

Which is the official channel for the patch announcements?

Patch Finder: [https://download.suse.com/patch/finder/](https://download.suse.com/patch/finder/)  
Update Advisories: [https://www.suse.com/support/update/](https://www.suse.com/support/update/)

The Update Advisories seem to be more complete due to the additional information on Security Rating. This piece of information doesn’t seem to be available in Patch Finder. Is there a way to retrieve the rating from Patch Finder? Is it possible to request to include the rating in the notifications?

For the advisories, is there a way to subscribe to it? I can’t seem to find a way to do this. Any APIs that I can use? Am I missing something?

Thanks,  
Karen

---

<div class="post-metadata">

### Author: ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)
#### Post date: [March 21, 2017, 3:15am UTC](https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523/2 "2017-03-21T03:15:11Z")

</div>

kkaren wrote:  
[color=blue]

> For the advisories, is there a way to subscribe to it? I can’t seem to  
> find a way to do this.[/color]

You can get email notification for patches here:  
[https://www.suse.com/email/notification/ctrl](https://www.suse.com/email/notification/ctrl)

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are logged into the web interface,  
please show your appreciation and click on the star below this post.  
Thank you.

---

<div class="post-metadata">

### Author: ![kkaren](https://avatars.discourse-cdn.com/v4/letter/k/d78d45/32.png) [@kkaren](https://forums.suse.com/u/kkaren)
#### Post date: [April 3, 2017, 9:00am UTC](https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523/3 "2017-04-03T09:00:36Z")

</div>

Thanks Kevin. I have already subscribed to the patch notifications. What I’m trying to achieve is to subscribe to the advisories.

I was wondering if there are plans to include or map the severity rating and announcement ID for each security alert to the corresponding patch?

---

<div class="post-metadata">

### Author: ![KEVIN1](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@KEVIN1](https://forums.suse.com/u/KEVIN1)
#### Post date: [April 3, 2017, 6:33pm UTC](https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523/4 "2017-04-03T18:33:41Z")

</div>

kkaren wrote:  
[color=blue]

> What I’m trying to achieve is to subscribe to the advisories.[/color]

I have inquired about that and currently there doesn’t appear to be any  
way to do so.

Have you checked out the SUSE Security Resources?  
[https://www.suse.com/support/security/](https://www.suse.com/support/security/)

SUSE provides OVAL Descriptions for SUSE Linux Enterprise Products  
[https://www.suse.com/support/security/oval/](https://www.suse.com/support/security/oval/)

[color=blue]

> OVALÂ® is a XML description and reporting format used to assess and  
> report the state of an operating system. More in depth information  
> about OVAL can be found on the Mitre OVAL website.[/color]  
> [color=blue]  
> SUSE is currently providing OVAL information for SUSE Linux  
> Enterprise products that allows to assess and report on the RPM  
> package versions affected by known security issues in a CVE to RPM  
> name/version mapping.[/color]  
> [color=blue]  
> The OVAL data is provided by SUSE under the Creative Commons License  
> 4.0 with Attribution for Non-Commercial usage (CC-BY-NC-4.0).[/color]

It would seem that the XML file has the information you are looking for  
if you have some way to extract it.

–  
Kevin Boyle - Knowledge Partner  
If you find this post helpful and are logged into the web interface,  
please show your appreciation and click on the star below this post.  
Thank you.

---

<div class="post-metadata">

### Author: ![kkaren](https://avatars.discourse-cdn.com/v4/letter/k/d78d45/32.png) [@kkaren](https://forums.suse.com/u/kkaren)
#### Post date: [April 5, 2017, 1:08pm UTC](https://forums.suse.com/t/patch-notification-patch-finder-vs-update-advisories/29523/5 "2017-04-05T13:08:59Z")

</div>

Cool, I’ll look into that. Thanks again for the help, Kevin. Appreciate it!
