Hi Seth, I have not verified the XML or tried to compile from source. I tried to reach out to ubuntu-hardened email list before without any response.
I'm just trying to get some help where I can to have this issue resolved. OVAL/CVE scanning within the Ubuntu community must be very very low, or everyone are using other tools. // Johan -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1658759 Title: oscap with com.ubuntu.xenial.cve.oval.xml wrongly reports many unpatched (and unknown) non-installed packages on Ubuntu Xenial 16.04.1 LTS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1658759/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs