Skip to main content
Patching is not always the final action

A patched host may still need a restart.

Check whether the host needs another package update, a service restart, a reboot, no action—or whether the evidence is incomplete.

Run a free one-host snapshot

Usually under a minute after upload · No card required

Supported hosts · RHEL, Rocky, Alma, Oracle Linux 8/9/10 · Amazon Linux 2023
Read-onlyNo package changesNo config writesNo persistent agent

Patch Truth report preview for one redacted host: the selected outcome, the installed package version compared with the vendor-fixed version, the evidence status, and the next action.

Patch Truth Snapshot
host-8f2c•••• · rocky 9.4 · kernel 5.14.0-427.13.1 · collector 0.9.3
token-protected · link expires in 7 days
Restart required
The package is at the vendor-fixed version, but runtime evidence shows the old library is still mapped.
Evidence1 of 4 outcomes
Packageopenssl · x86_64 · vendor Rocky Linux
Installed EVR1:3.0.7-28.el9_4.1
Vendor-fixed EVR1:3.0.7-28.el9_4.1
Runtime signalnginx pid 1182 → libssl.so.3 (deleted)
Next action
sudo systemctl restart nginx — package update already applied
completeRuntime evidence available on this host

Runtime signals separate package-update debt from restart debt when that evidence is available.

oxharden uses available runtime evidence to separate package update debt from restart or reboot debt.

How it works

Three steps, one host.

01

Create a one-time command

A single-use pairing code is created for this browser tab.

02

Run it on one supported host

The collector reads the evidence needed for matching. It does not change packages or configuration.

03

Review the secure report

oxharden identifies the next action and shows the evidence behind it — usually under a minute after upload.

patch-truth-snapshot
$ curl -fsSLO https://get.oxharden.com/snapshot.sh
$ less snapshot.sh
$ sudo sh snapshot.sh --pair ABC12345
Download and read the script, or use the one-line run. Your single-use pairing code is created when you start the snapshot; it expires quickly and works once.

Read the script before you run it, or .

Four outcomes

Every check resolves to one of four states.

Each state is labelled in text and in colour, with its own icon. Nothing is inferred from colour alone.

Package update required

The installed EVR is older than the vendor-fixed EVR for the advisory. The report names the package and the update to apply.

amber · package

Restart / reboot required

The fix is installed, but runtime evidence shows the old code is still loaded. The report separates a service restart from a reboot.

violet · runtime

No action

Installed versions match or exceed the vendor-fixed versions and no restart signal was found for the packages checked.

green · clear

Incomplete evidence

Evidence needed for the comparison was missing. The report says which evidence is missing and what to re-run.

gray · unknown

Missing evidence is never turned into a clean result. Incomplete is reported as its own outcome, with the reason attached.

Evidence & trust

Exactly what the snapshot collects.

The package evidence is uploaded to create the hosted report. Here is the full list, before you run anything.

Collected from the host
Package records — name, epoch/version/release, architecture, vendor, and install state
Host context — redacted host label, distribution and version, kernel release, collector version
Runtime signals — the evidence used to separate package debt from restart or reboot debt, when available
Run metadata — collector duration, record counts, unsupported-distribution status, incomplete-evidence flags
One-time read-only scan
No package changes
No configuration writes
No persistent daemon or agent
Collector exits after upload
Pairing code is single use and expires quickly
Report URL is token protected
Report link expires after seven days

The collector uploads the minimum host and package evidence required to build the report, so this is not a local-only scan. What happens to that evidence is described in the privacy policy.

Supported hosts

Which hosts the snapshot supports.

RHEL
8910
Rocky Linux
8910
AlmaLinux
8910
Oracle Linux
8910
Amazon Linux
2023
Unsupported hosts stop with a clear unsupported result; no clean outcome is produced.
FAQ

Before you run it.

It makes no package or configuration changes and installs no persistent agent. The collector runs once and exits after upload.

Package records (name, epoch/version/release, architecture, vendor, install state), a redacted host label, distribution and version, kernel release, collector version, available runtime signals, and run metadata. That evidence is uploaded to build the hosted report, so this is not a local-only scan. See the privacy policy.

No. There is no persistent agent. The command downloads and runs a collector once, then exits. Nothing is scheduled and nothing stays resident.

RHEL, Rocky Linux, AlmaLinux and Oracle Linux 8, 9 and 10, plus Amazon Linux 2023. Unsupported hosts stop with a clear unsupported result; no clean outcome is produced.

The report URL is token protected, and the pairing code used to create it is single use and expires quickly. The token-protected report link expires after seven days.

Some evidence needed for the comparison could not be collected — for example, runtime process maps when the collector ran without the required privileges. The report shows Incomplete as its own outcome and names the missing evidence. It is not reported as clean.

Yes. Inspect first is the default: download the script, read it, and run it yourself. A one-line run is available if you prefer it. The full list of collected evidence is on this page under “See what the snapshot collects”.

The snapshot compares the installed package EVR with the vendor-fixed version for one host and shows the evidence behind the resulting action, including whether a restart or reboot is still needed when that runtime evidence is available. It is one read-only run on one host, not continuous fleet monitoring, and it does not replace a scanner.

Start with one host

Run a free one-host snapshot

One host. One read-only run. A clear next action with the evidence behind it.

RHEL, Rocky, Alma, Oracle Linux 8/9/10 · Amazon Linux 2023