-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Define policy for when images get rebuilt to address package security vulnerabilities. #2787
Comments
Closed
The content in #4842 should be included with this. |
[Triage] We have something like this in Vulnerability Workflow, but we should have it written down more concretely when precisely we will re-build, and the Vulnerability Workflow should reference it. |
This is a prereq to fixing #1455. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
If there is a vulnerability in a package included in a .NET layer and there is a package patch available that addresses the CVE, when will the image get rebuilt to pick it up? This should be captured in the Image Update Policy. The image update policy only discusses base image and .NET servicing.
The text was updated successfully, but these errors were encountered: