Security patch compliance on Windows container images
Security patch compliance is a day 0 priority, and we must ensure that all the components within the Windows container image are still receiving security patches, as containers are not security boundaries and exposure in the container could compromise the entire host.
Let’s start from the bottom, that is, the Windows container image, which can be Windows Server 2019- or 2022-based. Windows container images basically follow the main operating system support life cycle; by following the official Windows Server Support life cycle, we have this:
Windows Server OS |
Mainstream End Date |
Extended End Date |
Windows Server 2019 |
Jan 9, 2024 |
Jan 9, 2029 |
Windows Server 2022 |
Oct 13, 2026 |
Oct... |