Skip to content
Discussion options

You must be logged in to vote

CVEs are patched in CNCF Flux as part of the development lifecycle, i.e. every quarter of the year we release a new minor release (2.x). That's when we patch CVEs in Flux upstream. CVEs in the Flux code or that actually affect Flux are patched immediately.

If you need a faster cadence, I suggest you to purchase a subscription of ControlPlane Enterprise for Flux CD, which gives you a 24h SLA for CVE patching, 24/7 support from Flux Core Maintainers, TAA consultancy, etc. The best support for Flux in the world. This is how you can make Flux sustainable. Do not buy Chainguard, they just leech OSS projects without giving anything back. Other OSS projects are also trying to survive from CVE pa…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by matheuscscp
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants