Title
Page icon
Create new category
Edit page index title
Edit category
Edit link
Bulletin and Data Source
Patch Management shows the full security story behind every patch, not just that an update exists. Two new pieces of information make this possible: Bulletin and Data Source.
How We Collect Bulletin Information?
For detailed information about how bulletin is collected, please see How OESIS Supports Bulletin for Patch Management document.
What Is a Bulletin?
A Bulletin is the security advisory behind a patch. It describes what the patch fixes, how serious the issue is, and which vulnerabilities it closes. One bulletin can cover several patches at once. For example, a single Microsoft advisory may apply to every edition and system architecture it was released for.
Note The Bulletin ID is shown for OS patches only, it does not appear on application patches.
What Is a Data Source?
Data Source shows where a patch record's information came from, such as OPSWAT or WinGet. It describes the patch itself, not the advisory attached to it. Because of this, it is separate from who issued the bulletin and does not change based on which vendor makes the product.
Where You'll See This
The Missing Patches list displays the data source for every OS and application patch. However, the bulletin is shown for OS patches only.
OS Missing Patches | ![]()
![]() |
Application Missing Patches | ![]() |
Patch Details | The patch details also show the data source, and the bulletin ID for OS patches: ![]() |
Current Availability
Bulletin and Data Source metadata is only captured for patch records from May 26, 2026 onward. Patches recorded before this date will not have this metadata.



