2019-09-30 22:00:26 -04:00
|
|
|
# Security policy
|
2022-08-25 14:05:23 +02:00
|
|
|
|
2019-09-30 22:00:26 -04:00
|
|
|
## Supported versions
|
2022-01-13 09:38:32 +01:00
|
|
|
<!-- Include start supported versions -->
|
|
|
|
|
|
2023-08-29 23:35:59 -04:00
|
|
|
Incus has two types of releases:
|
2022-08-25 14:11:27 +02:00
|
|
|
|
2023-08-29 23:35:59 -04:00
|
|
|
- Feature releases
|
2022-08-25 14:11:27 +02:00
|
|
|
- LTS releases
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2022-01-13 09:38:32 +01:00
|
|
|
For feature releases, only the latest one is supported, and we usually
|
|
|
|
|
don't do point releases. Instead, users are expected to wait until the
|
2023-08-29 23:35:59 -04:00
|
|
|
next release.
|
2022-01-13 09:38:32 +01:00
|
|
|
|
|
|
|
|
For LTS releases, we do periodic bugfix releases that include an
|
|
|
|
|
accumulation of bugfixes from the feature releases. Such bugfix releases
|
|
|
|
|
do not include new features.
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2022-01-13 09:38:32 +01:00
|
|
|
<!-- Include end supported versions -->
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2022-01-13 09:38:32 +01:00
|
|
|
## What qualifies as a security issue
|
2022-08-25 14:05:23 +02:00
|
|
|
|
2019-09-30 22:00:26 -04:00
|
|
|
We don't consider privileged containers to be root safe, so any exploit
|
2022-01-13 09:38:32 +01:00
|
|
|
allowing someone to escape them will not qualify as a security issue.
|
|
|
|
|
This doesn't mean that we're not interested in preventing such escapes,
|
2019-09-30 22:00:26 -04:00
|
|
|
but we simply do not consider such containers to be root safe.
|
|
|
|
|
|
|
|
|
|
Unprivileged container escapes are certainly something we'd consider a
|
2023-08-29 23:35:59 -04:00
|
|
|
security issue, especially if somehow facilitated by Incus.
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2023-08-29 23:35:59 -04:00
|
|
|
## Reporting security issues
|
2019-09-30 22:00:26 -04:00
|
|
|
|
2023-08-29 23:35:59 -04:00
|
|
|
Security issues can be reported by e-mail to security@linuxcontainers.org.
|
|
|
|
|
Alternatively security issues can also be reported through Github at: https://github.com/lxc/incus/security/advisories/new
|