2019-09-30 22:00:26 -04:00
|
|
|
# Security policy
|
2022-08-25 14:05:23 +02:00
|
|
|
|
2019-09-30 22:00:26 -04:00
|
|
|
## Supported versions
|
2022-01-13 09:38:32 +01:00
|
|
|
<!-- Include start supported versions -->
|
|
|
|
|
|
|
|
|
|
LXD has two types of releases:
|
2022-08-25 14:11:27 +02:00
|
|
|
|
|
|
|
|
- Monthly feature releases
|
|
|
|
|
- LTS releases
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2022-01-13 09:38:32 +01:00
|
|
|
For feature releases, only the latest one is supported, and we usually
|
|
|
|
|
don't do point releases. Instead, users are expected to wait until the
|
|
|
|
|
next monthly release.
|
|
|
|
|
|
|
|
|
|
For LTS releases, we do periodic bugfix releases that include an
|
|
|
|
|
accumulation of bugfixes from the feature releases. Such bugfix releases
|
|
|
|
|
do not include new features.
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2022-01-13 09:38:32 +01:00
|
|
|
<!-- Include end supported versions -->
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2022-01-13 09:38:32 +01:00
|
|
|
## What qualifies as a security issue
|
2022-08-25 14:05:23 +02:00
|
|
|
|
2019-09-30 22:00:26 -04:00
|
|
|
We don't consider privileged containers to be root safe, so any exploit
|
2022-01-13 09:38:32 +01:00
|
|
|
allowing someone to escape them will not qualify as a security issue.
|
|
|
|
|
This doesn't mean that we're not interested in preventing such escapes,
|
2019-09-30 22:00:26 -04:00
|
|
|
but we simply do not consider such containers to be root safe.
|
|
|
|
|
|
|
|
|
|
Unprivileged container escapes are certainly something we'd consider a
|
|
|
|
|
security issue, especially if somehow facilitated by LXD.
|
|
|
|
|
|
2023-07-04 18:29:30 +02:00
|
|
|
## Ubuntu Security disclosure and embargo policy
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2023-07-04 18:29:30 +02:00
|
|
|
See the [Ubuntu Security disclosure and embargo
|
|
|
|
|
policy](https://ubuntu.com/security/disclosure-policy) for information
|
|
|
|
|
about how to contact the Ubuntu Security Team, what you can expect when
|
|
|
|
|
you contact us, and what we expect from you.
|