Skip to content

chore: update security docs to mention release frequency and srus - #7013

Open
blackboxsw wants to merge 1 commit into
canonical:mainfrom
blackboxsw:update-release-security-docs
Open

chore: update security docs to mention release frequency and srus#7013
blackboxsw wants to merge 1 commit into
canonical:mainfrom
blackboxsw:update-release-security-docs

Conversation

@blackboxsw

Copy link
Copy Markdown
Collaborator

Proposed Commit Message

docs(security): report security release frequency and srus use gh milestones

Also correct release schedule links

Additional Context

Test Steps

Merge type

  • Squash merge using "Proposed Commit Message"
  • Rebase and merge unique commits. Requires commit messages per-commit each referencing the pull request number (#<PR_NUM>)

@github-actions github-actions Bot added the documentation This Pull Request changes documentation label Aug 19, 2026
Comment thread SECURITY.md Outdated

## Supported versions

Cloud-init upstream creates [4 time-based releases per year](https://github.com/canonical/cloud-init/milestones).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this important to document? It wasn't true last year, maybe we just don't need it.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

consolidated this statement and link into the following sentence

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@blackboxsw
blackboxsw force-pushed the update-release-security-docs branch from f5b9ba1 to 8fd50b7 Compare August 19, 2026 22:43
@blackboxsw
blackboxsw requested a review from holmanb August 19, 2026 22:44
@blackboxsw

Copy link
Copy Markdown
Collaborator Author

Added #7016 due to 340ac74 now causing format issues with separately landed 34c74ef

Comment thread SECURITY.md
Comment on lines +30 to +31
[latest Ubuntu interim release and the two most recent Ubuntu LTS releases](https://ubuntu.com/about/release-cycle) to
ensure security bug fixes are published to stable Ubuntu LTS releases.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

time-based

The word "scheduled" seems more natural here.

is published to the ... Ubuntu ... release

It seems imprecise to say that a cloud-init release is published to an Ubuntu release.

to
ensure security bug fixes are published to stable Ubuntu LTS releases.

I disagree.

Comment thread SECURITY.md
[latest Ubuntu interim release and the two most recent Ubuntu LTS releases](https://ubuntu.com/about/release-cycle) to
ensure security bug fixes are published to stable Ubuntu LTS releases.

If a CVE is of critical CVSS severity and affects older Ubuntu LTS releases, it will be backported to the specific release.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

Why only critical? Is this some Ubuntu-wide policy?

and affects older Ubuntu LTS releases, it will be backported to the specific release.

Are you sure? This statement is unbounded.

To ensure the available security fixes are applied to you VMs images upon
launch, it is recommended by `Ubuntu security team guidelines`_ to update
the packages
To ensure the available security fixes are applied to VM images at launch,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cloud-init is not limited to VM images.

@holmanb holmanb self-assigned this Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation This Pull Request changes documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants