Security Policy

Supported Versions#

As same as Fluentd's security policy

See Supported Versions in Fluentd

Reporting a Vulnerability#

If you find a vulnerability of docker.io/fluent/fluentd:SOMETHING with the default configuration, report it from the following page:

[!IMPORTANT] fluentd-docker-image images are downstream of ruby or alpine container. Thus, even though security scanner reports a pile of vulnerabilities, the updated container image can't be shipped until updated container image is deployed from upstream first.

[!NOTE] In most cases, even though security scanner reports vulnerabilities, they are false-positive because fluentd doesn't use the vulnerable component.

Was this page helpful?