Supported distributions
| Distribution | Versions | Advisory data |
|---|---|---|
| Ubuntu LTS | 18.04, 20.04, 22.04, 24.04, 26.04 | Canonical CVE OVAL: packages and the running kernel. OVAL checks DeaconGuard can't evaluate are listed, not treated as clean. |
| Debian | 12 (Bookworm), 13 (Trixie) | Debian Security Tracker: source-package status and fixed versions. |
| Red Hat Enterprise Linux | 8, 9 | Red Hat's official OVAL feeds. OVAL checks DeaconGuard can't evaluate are listed. |
| Amazon Linux | 2023 | ALAS RSS and bulletins, with replacement RPM versions. AWS notes that bulletin pages and repository metadata can briefly disagree. |
All on amd64 and arm64.
Not supported
- CentOS Stream 9 and 10 are recognised but deliberately rejected: their official repositories publish no
updateinfometadata, and RHEL OVAL isn't assumed to match them. - Rocky Linux, AlmaLinux and other RHEL rebuilds aren't supported; the install script won't set up an agent on them.
- RHEL 10 isn't enabled yet: no official RHEL 10 feed was present in Red Hat's feed index.
- Amazon Linux 2, other RPM distributions, and end-of-life releases.
The server itself can run on any Debian- or RHEL-family system; only the machines you scan need a supported distribution.
What a report covers
Package reports cover the packages installed through DPKG or RPM, and the running kernel where the distribution's feed supports it. They don't cover applications installed outside the package manager, or containers.
The optional checks look for common signs of tampering and misconfiguration, not every possible compromise. No report is a claim that a machine is secure.