Check what you run

Paste an SBOM, the output of rpm -qa or a list of packages, and see which of these vulnerabilities each is below the fix for, and the version that fixes it.

A CycloneDX or SPDX SBOM as JSON, the output of rpm -qa, package URLs (pkg:npm/lodash@4.17.20), CPEs, name==version from requirements.txt, or name version a line. What you send is checked and dropped: nothing of it is kept, here or anywhere.