Ross ROSS = Recommend OSS · open-source software intelligence for agents

PatchMon/PatchMon

Linux Patch Management & Automation Platform observed · 2026-08-28

github.com/PatchMon/PatchMon · homepage · Go · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 99
  • Release rhythm 98
  • Longevity 25
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 3
  • age_days: 351
  • days_rel: 18
  • days_push: 7
  • n_releases_24m: 22

Full methodology

Adoption not part of the score

3296 stars · 174 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

PatchMon is a self-hostable, AGPL-licensed Linux patch management and server monitoring platform with a lightweight outbound-only agent and a single Go binary server with an embedded React UI. It provides fleet-wide package inventory, pending update tracking, patch scheduling and approvals, CVE scanning, and OpenSCAP/CIS compliance reporting across Linux, FreeBSD, and Windows hosts.

Use cases

  • manage linux updates across a fleet without ssh scripts
  • track pending apt and dnf updates from a central dashboard
  • scan servers for cves and security updates
  • run openscap and cis compliance scans on hosts
  • schedule and approve patch deployments on debian and rhel servers
  • monitor docker containers and package drift on ubuntu servers
  • auto-enroll proxmox lxc containers for patch monitoring

When to choose

  • you manage many Linux (or mixed Linux/FreeBSD/Windows) servers and need one pane of glass for patching
  • you want outbound-only agents with no inbound firewall or SSH exposure
  • you need self-hosted patch management with CVE scanning and compliance reporting
  • you want patch approval workflows, audit trails, and scheduled reports for auditors

When to avoid

  • you only manage a handful of machines where a simple cron + unattended-upgrades setup suffices
  • you need full configuration management or orchestration rather than patching (use Ansible/Salt)
  • you require non-AGPL licensing for internal distribution
  • you need deep Windows Update or macOS patching as a primary workflow

Facets

application · maturity active

monitoring security deployment configuration-management alerting analytics security self-hosted monitoring infrastructure-as-code self-hosted go cross-platform patch-management linux-fleet vulnerability-management cve-scanning openscap cis-benchmark server-management agent-based compliance apt dnf yum pacman freebsd windows-agents proxmox devops automation linux docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
PatchMon/PatchMonmain84

For agents

markdown · JSON · MCP: product_card(name="PatchMon/PatchMon")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem