OVAL and Data Stream (DS) v1 deprecation announcement

Updated -


In 2006 Red Hat started publishing security data using the Open Vulnerability and Assessment Language (OVAL) and Data Stream (DS) format. Over the years, the OVAL data format evolved significantly, and in 2019, the v2 version of our OVAL data was made available. This is the most current version of the OVAL security data. Red Hat customers use v2, including various security scanners vendors, and it is considered a default security data format for the Red Hat Vulnerability Scanner Certification program.

OVAL and DS v1 changes

Red Hat OVAL v1 security data has been considered deprecated since 2019. An announcement was made in the Evolving OVAL blog post and the Red Hat Vulnerability Scanner Certification requirements. Even though v1 was deprecated, Red Hat continued publishing new content in the old data format.

The following upcoming changes and effective dates for deprecating OVAL v1 content are now set:

The above changes also impact the com.redhat.rhsa-all.xccdf.xml file that is considered as a part of the now deprecated OVAL v1 data. This file is available under the /data/archive/com.redhat.rhsa-all.xccdf_20230706.xml path.

Please contact Red Hat Product Security with any questions about these changes at secalert@redhat.com or file an issue in the SECDATA Jira project.