Skip to main content

Handling upstream end-of-life

info

The English user guide is currently in beta preview. Most of the documents have been automatically translated from the Japanese version. Should you find any inaccuracies, please reach out to Flatt Security.

When an upstream software version reaches EOL (end-of-life), upstream stops providing fixes for that version. GMO Flatt Security also generally stops providing patches for that version. Once the upstream fixes that form the basis for patching stop, Takumi Images cannot maintain that version's security by itself.

EOL software accumulates vulnerabilities over time. New vulnerabilities continue to be found every day, but EOL versions no longer receive upstream fixes, so disclosed vulnerabilities remain. This is a general property of EOL software, not something specific to Takumi Images.

Current state: upstream EOL is equivalent to Takumi Images EOL

An image does not necessarily disappear from the catalog immediately when the upstream version reaches EOL. However, new builds for that version stop being published. You may still be able to pull the image, but its contents remain frozen at the point where EOL was reached and do not receive fixes for later vulnerabilities. Move to a maintained version as soon as possible.

Future: planned grace period after upstream EOL

After the beta period ends, Takumi Images plans to provide a grace period after upstream EOL during which dependencies other than the main package continue to receive patches for some time. For example, if a container image for main package A contains an updatable dependency package B, Takumi Images may continue to provide patches for B for a period even after A reaches EOL.

This grace period is not part of the current beta offering.