CVE Patching SLA for AWS Deep Learning Containers¶
AWS is committed to keeping Deep Learning Containers images secure and up to date. As part of the shared responsibility model, AWS monitors published Common Vulnerabilities and Exposures (CVEs) that affect Deep Learning Containers images and remediates them within the service level agreements (SLAs) described on this page.
Patch and release cadence¶
AWS rebuilds and re-releases every in-support Deep Learning Containers image with the latest available patches on an approximately weekly cadence. Each rebuild incorporates the most recent operating system and package updates available at build time, ensuring that supported images receive routine security maintenance independent of any individual CVE.
Remediation SLAs¶
In addition to the regular patch cadence, AWS targets the following remediation SLAs for individual vulnerabilities, measured from the date a CVE is published to the date a patched image is released. SLAs are determined by the severity of the vulnerability:
| Severity | Remediation SLA |
|---|---|
| Critical | 14 days |
| High | 28 days |
| Medium | 180 days |
SLA compliance status¶
An image is considered out of SLA if it contains at least one vulnerability that exceeds the remediation SLA for its severity, as defined above. An image that contains no out-of-SLA vulnerabilities is considered within SLA.