A patched host may still need a restart.
Check whether the host needs another package update, a service restart, a reboot, no action—or whether the evidence is incomplete.
Usually under a minute after upload · No card required
Patch Truth report preview for one redacted host: the selected outcome, the installed package version compared with the vendor-fixed version, the evidence status, and the next action.
Runtime signals separate package-update debt from restart debt when that evidence is available.
oxharden uses available runtime evidence to separate package update debt from restart or reboot debt.
Three steps, one host.
Create a one-time command
A single-use pairing code is created for this browser tab.
Run it on one supported host
The collector reads the evidence needed for matching. It does not change packages or configuration.
Review the secure report
oxharden identifies the next action and shows the evidence behind it — usually under a minute after upload.
$ curl -fsSLO https://get.oxharden.com/snapshot.sh $ less snapshot.sh $ sudo sh snapshot.sh --pair ABC12345
Read the script before you run it, or .
Every check resolves to one of four states.
Each state is labelled in text and in colour, with its own icon. Nothing is inferred from colour alone.
Package update required
The installed EVR is older than the vendor-fixed EVR for the advisory. The report names the package and the update to apply.
Restart / reboot required
The fix is installed, but runtime evidence shows the old code is still loaded. The report separates a service restart from a reboot.
No action
Installed versions match or exceed the vendor-fixed versions and no restart signal was found for the packages checked.
Incomplete evidence
Evidence needed for the comparison was missing. The report says which evidence is missing and what to re-run.
Missing evidence is never turned into a clean result. Incomplete is reported as its own outcome, with the reason attached.
Exactly what the snapshot collects.
The package evidence is uploaded to create the hosted report. Here is the full list, before you run anything.
The collector uploads the minimum host and package evidence required to build the report, so this is not a local-only scan. What happens to that evidence is described in the privacy policy.
Which hosts the snapshot supports.
Before you run it.
It makes no package or configuration changes and installs no persistent agent. The collector runs once and exits after upload.
Package records (name, epoch/version/release, architecture, vendor, install state), a redacted host label, distribution and version, kernel release, collector version, available runtime signals, and run metadata. That evidence is uploaded to build the hosted report, so this is not a local-only scan. See the privacy policy.
No. There is no persistent agent. The command downloads and runs a collector once, then exits. Nothing is scheduled and nothing stays resident.
RHEL, Rocky Linux, AlmaLinux and Oracle Linux 8, 9 and 10, plus Amazon Linux 2023. Unsupported hosts stop with a clear unsupported result; no clean outcome is produced.
The report URL is token protected, and the pairing code used to create it is single use and expires quickly. The token-protected report link expires after seven days.
Some evidence needed for the comparison could not be collected — for example, runtime process maps when the collector ran without the required privileges. The report shows Incomplete as its own outcome and names the missing evidence. It is not reported as clean.
Yes. Inspect first is the default: download the script, read it, and run it yourself. A one-line run is available if you prefer it. The full list of collected evidence is on this page under “See what the snapshot collects”.
The snapshot compares the installed package EVR with the vendor-fixed version for one host and shows the evidence behind the resulting action, including whether a restart or reboot is still needed when that runtime evidence is available. It is one read-only run on one host, not continuous fleet monitoring, and it does not replace a scanner.
Run a free one-host snapshot
One host. One read-only run. A clear next action with the evidence behind it.
RHEL, Rocky, Alma, Oracle Linux 8/9/10 · Amazon Linux 2023