About patchletter
You list Proxmox VE, FortiOS and Veeam Backup & Replication as things you run, and you get an email the moment one of them ships a new release. That email costs nothing. Currently 1286 products across browsers, operating systems, virtualization, firewalls, network gear, NAS, servers, databases, monitoring and DACH business software. Version data comes from official vendor sources (release feeds, GitHub and GitLab releases, package repositories) and is checked daily. Product pages also carry the support cycles from endoflife.date and the CISA KEV catalog of actively exploited vulnerabilities — free to read, no account needed; the alert emails about them are part of patchletter Pro. patchletter never touches your systems; there is no agent and no scanner. The only required datum is an email address, and the service runs data-minimal and ad-free, without tracking. It runs on our own server in Nuremberg (EU).
Where does the version data come from?
For every product we track one or more official, public sources: vendor release feeds and RSS, GitHub and GitLab releases and tags, package repositories (WinGet, Chocolatey), the endoflife.date support-cycle data, and structured vendor pages. Our crawler checks them daily, uses conditional requests (ETag/Last-Modified) to be gentle, and keeps generous rate limits. New versions are normalized and sorted so the latest release sits at the top and the history below it in the right order.
Our crawler is transparent — see the patchletterBot crawler policy.
How does patchletter flag actively exploited vulnerabilities?
Product pages cross-reference the CISA Known Exploited Vulnerabilities (KEV) catalog. When a product has a vulnerability that is being actively exploited in the wild, it sits at the top of the product page: with the CVE, a link to the authoritative entry and, where applicable, a ransomware marker.
What data does patchletter store?
patchletter is deliberately data-minimal: the only required datum is an email address. There are no tracking pixels in emails, no advertising cookies and no consent banner; the analytics run cookieless on the very same instance as the application. We operate that instance ourselves, with database and object storage on it, at netcup in Nuremberg (Germany). Every email has a one-click unsubscribe, and you can delete your account and all data with one click at any time.
Who runs patchletter?
patchletter is operated by patchletter UG (haftungsbeschränkt) in Germany; its Managing Director is Kolja Sagorski. Full details and contact in the legal notice. Missing a tool? Suggest it.