Security parity with upstream is a first-class requirement, not an afterthought — from same-day errata to formal FIPS and Common Criteria evaluation.
Security advisories are published as soon as upstream fixes are available and rebuilt, cross-referenced by CVE ID, and machine-readable via our errata feed.
Browse errataA maintained SCAP security guide and OVAL definitions let you scan FinLinux OS systems for compliance drift automatically.
Get SCAP contentEvery release publishes a full SPDX-format SBOM covering every package and its provenance.
Download SBOMsFinLinux OS's cryptographic modules track the same FIPS-validated modules used upstream, and the OS can be booted in FIPS mode at install time.
Formal Common Criteria evaluation follows the applicable Protection Profile once the matching upstream evaluation completes, given our binary compatibility.
Email security@finlinux.org (PGP key published below) with details and, if possible, a proof of concept. Do not open a public GitHub issue or post to a public mailing list for an unpatched vulnerability. We aim to acknowledge reports within 48 hours and coordinate a disclosure timeline with the reporter.
Signing key fingerprint: 4F3A 9C2E 88D1 7B60 2E14 55A9 0C3F D821 6E7B 91AA (illustrative — verify the live key on the release page before trusting it).