Skip to content

Security: datopsis/clickhouse-ubi

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest published image line. Older ClickHouse or UBI combinations may be rebuilt when practical, but are not supported unless explicitly documented in a release.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub's Security tab and select Report a vulnerability to submit a private security advisory.

Include the affected image tag or digest, architecture, scanner output or reproduction steps, and whether the issue appears to originate in this packaging, ClickHouse, or UBI.

Upstream vulnerabilities should also be reported under the applicable upstream policy:

Image verification

Tagged releases are scanned before publication and signed keylessly with Cosign after publication. They include an SBOM and build-provenance attestation generated by BuildKit. Production deployments should use verified image digests.

Scanner results require context. Red Hat often backports security fixes without changing an upstream version string; consult Red Hat's vulnerability data before treating a version-only scanner result as authoritative.

There aren't any published security advisories