---
title: Ubuntu Security Notices now available in OSV format
description: Canonical is now issuing Ubuntu Security Notices (USNs) in the open source
  OSV format to simplify vulnerability management for Ubuntu users.
url: https://canonical-com-2950.demos.haus/blog/ubuntu-security-notices-now-available-in-osv-format?format=md
---

1. [Blog](https://canonical-com-2950.demos.haus/blog)
2. Article

---

[Canonical](https://canonical-com-2950.demos.haus/blog/author/canonical "More about Canonical")

11 June 2024

# Ubuntu Security Notices now available in OSV format

---

Share the article

Canonical is now issuing Ubuntu Security Notices (USNs) in the open source [OSV format](https://github.com/ossf/osv-schema). Using the information provided, developers can identify known third-party, open source dependency vulnerabilities that pose a genuine risk to their application and its environment. This collaboration between Canonical and OSV aims to simplify vulnerability management and further enhance security for Ubuntu users.

“Making sure that Ubuntu Security Notices are actionable and available to 3rd party tools is a key goal for our security engineering team”, said Lech Sandecki, Product Manager at Canonical,  “By collaborating with OSV, we will provide accurate and actionable information about open source software vulnerabilities and fixes available for thousands of open source applications and dependencies maintained by our team”.

This integration is a testament to the ongoing collaboration happening within the [OpenSSF Vulnerability Disclosures Working Group](https://github.com/ossf/wg-vulnerability-disclosures?tab=readme-ov-file#vulnerability-disclosures). Participation in this working group, facilitates contributions to the OSV project, and enhances the overall security posture of the open source community.

OSV (Open Source Vulnerability) seeks to reduce the complexities of vulnerability management by providing an open, precise, and distributed approach to producing and consuming vulnerability information for open source. By adopting OSV, Canonical helps expand the comprehensiveness of vulnerability data available in this format, making the combined data set more valuable to open source users for broad open source software vulnerability management. This data unlocks future scanning capabilities in Ubuntu containers.

OSV is not only a format for describing vulnerabilities but also a set of tools and integration opportunities that can consume such information. Tools like [OSV-Scanner](https://google.github.io/osv-scanner/)  provide assessment and remediation guidelines to  users as well . The Ubuntu Security team packaged OSV-Scanner as a [snap](https://snapcraft.io/osv-scanner) so users can make use of the tool on Ubuntu as well.

“With the move towards containerisation, it is important to enable accurate vulnerability scanning of container images using Ubuntu. Having USNs available in OSV.dev unlocks OSV-Scanner to scan Ubuntu-based container images for known vulnerabilities. We look forward to working further on extending OSV-Scanner’s capabilities scanning Ubuntu-based container images in the future” said Oliver Chang from the OSV team.

With this data available, OSV-Scanner will soon be able to provide an automated remediation path for vulnerabilities in Ubuntu containers by pointing to a publicly available fix or a fix available in [Ubuntu Pro](https://ubuntu.com/pro).

Learn more about:

* [OSV.dev](https://github.com/google/osv.dev/blob/master/CONTRIBUTING.md#contributing-data)
* [Ubuntu Pro](https://ubuntu.com/pro)
* [Open source vulnerability management](https://ubuntu.com/engage/vulnerability-management)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical-com-2950.demos.haus/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Network disaggregation in telecommunication transport networks](https://canonical-com-2950.demos.haus/blog/network-disaggregation)

Telecommunications networks have traditionally been built from tightly integrated systems. A router vendor supplies the forwarding hardware, network operating system (NOS),...

[Benjamin Ryzman](https://canonical-com-2950.demos.haus/blog/author/benjaminryzman)

16 September 2026

[### Bring Zenoh to ROS 2 with snaps](https://canonical-com-2950.demos.haus/blog/bring-zenoh-to-ros-2-with-snaps)

ROS 2 gives robotics developers the freedom to choose the middleware that fits their system. As a communication protocol for ROS, Zenoh has gained strong traction. It delivers...

[gbeuzeboc](https://canonical-com-2950.demos.haus/blog/author/gbeuzeboc)

15 September 2026

[### Canonical and CIX Technology announce strategic collaboration for edge innovation](https://canonical-com-2950.demos.haus/blog/canonical-and-cix-technology-announce-strategic-collaboration-for-edge-innovation)

Canonical, the publisher of Ubuntu, and CIX Technology, a semiconductor innovator, today announced a strategic collaboration to deliver an optimized Ubuntu experience on CIX...

[Jonathan Mok](https://canonical-com-2950.demos.haus/blog/author/jmok027)

11 September 2026

[### What the Cyber Resilience Act (CRA) means for Android™ development](https://canonical-com-2950.demos.haus/blog/what-the-cyber-resilience-act-cra-means-for-android-development)

The CRA starts now: 24 hours to respond Picture this: a critical Android vulnerability is reportedly being exploited. Based on initial analysis, the compromised component is...

[Bertrand Boisseau](https://canonical-com-2950.demos.haus/blog/author/bboisseau)

10 September 2026
