Updated on 2025-10-24 GMT+08:00

Vulnerability Fixing Policies

Cluster Vulnerability Fixing SLA

  • High-risk vulnerabilities:
    • CCE Autopilot fixes vulnerabilities within one month after the Kubernetes community detects them and releases fixing solutions. The fixing policies are the same as those of the community.
    • Emergency vulnerabilities of the operating system are released according to the operating system fixing policies and procedure. Generally, a fixing solution is provided within one month, and you need to fix the vulnerabilities by yourself.
  • Other vulnerabilities:

    Other vulnerabilities can be fixed through a normal upgrade.

Statement

To prevent customers from being exposed to unexpected risks, CCE Autopilot does not provide other information about the vulnerability except the vulnerability background, details, technical analysis, affected functions/versions/scenarios, solutions, and reference information.

In addition, CCE Autopilot provides the same information for all customers to protect all customers equally. CCE Autopilot will not notify individual customers in advance.

CCE Autopilot does not develop or release exploitable intrusive code (or code for verification) using the vulnerabilities in the product.