Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/.vuepress/components/ELSTechnology.vue
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
<template>
<div class="heading text-center">
<h2>Available Guides for ELS for Libraries</h2>
<h2>Available Guides for ELS for Language Ecosystems</h2>
<p>If something's missing or you have questions, contact <a href="mailto:sales@tuxcare.com">sales@tuxcare.com</a>.</p>
</div>

Expand Down
2 changes: 1 addition & 1 deletion docs/.vuepress/config-client/documents.ts
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ export default [
link: "/els-for-os/",
},
{
title: "ELS for Libraries",
title: "ELS for Language Ecosystems",
description: "provides security fixes for software libraries beyond their official end-of-life date.",
link: "/els-for-libraries/",
},
Expand Down
2 changes: 1 addition & 1 deletion docs/.vuepress/public/llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ The full text of every documentation page, concatenated into a single file, is a
## Extended Lifecycle Support (ELS)

- [ELS for Operating Systems](https://docs.tuxcare.com/els-for-os/): Post-EOL security support for end-of-life Linux distributions.
- [ELS for Libraries](https://docs.tuxcare.com/els-for-libraries/): Extended security fixes for open-source libraries.
- [ELS for Language Ecosystems](https://docs.tuxcare.com/els-for-libraries/): Extended security fixes for open-source libraries across language ecosystems.
- [ELS for Runtimes](https://docs.tuxcare.com/els-for-runtimes/): Extended support for language runtimes (PHP, Python, Node.js, etc.).
- [ELS for Applications](https://docs.tuxcare.com/els-for-applications/): Security patches for end-of-life open-source applications.

Expand Down
2 changes: 1 addition & 1 deletion docs/.vuepress/theme/components/Breadcrumb.vue
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ const siteTitle = computed(() => site.value.title);

const titleMap = {
'/els-for-languages/': 'ELS for Languages',
'/els-for-libraries/': 'ELS for Libraries',
'/els-for-libraries/': 'ELS for Language Ecosystems',
'/els-for-applications/': 'ELS for Applications',
'/els-for-os/': 'ELS for OS',
'/els-for-runtimes/': 'ELS for Runtimes',
Expand Down
24 changes: 21 additions & 3 deletions docs/els-for-libraries/README.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,27 @@
<!-- markdownlint-disable MD029 MD024 MD036 -->

# Endless Lifecycle Support for Libraries
# Endless Lifecycle Support for Language Ecosystems

<ELSTechnology />

## Installation for Language Ecosystems

:::tip
Have a subscription for an individual library or framework? Use the installation instructions on your library's page in the sections below.
:::

An ELS for Language Ecosystems subscription covers an entire language ecosystem rather than an individual library: TuxCare-patched versions of all supported packages for that language are delivered through the TuxCare-managed registry.

* **JavaScript** — covers TuxCare-patched versions of supported npm packages, delivered through the TuxCare npm registry as drop-in replacements for their end-of-life upstream releases. Follow the canonical installation instructions on the [SecureChain + ELS JavaScript page](/securechain/javascript/#ELS).

* **Java** — covers TuxCare-patched versions of supported Java libraries, delivered through a TuxCare-managed Maven repository as drop-in replacements for their end-of-life upstream releases. Installation instructions are provided during onboarding; if you need them again, contact the team through the [TuxCare Support Portal](https://tuxcare.com/support-portal/).

* **Python** — covers TuxCare-patched versions of supported Python packages, delivered through a TuxCare-managed PyPI-compatible index as drop-in replacements for their end-of-life upstream releases. Installation instructions are provided during onboarding; if you need them again, contact the team through the [TuxCare Support Portal](https://tuxcare.com/support-portal/).

* **PHP** — covers TuxCare-patched versions of supported PHP packages, delivered through a TuxCare-managed Composer repository as drop-in replacements for their end-of-life upstream releases. Installation instructions are provided during onboarding; if you need them again, contact the team through the [TuxCare Support Portal](https://tuxcare.com/support-portal/).

* **.NET** — covers TuxCare-patched versions of supported NuGet packages, delivered through a TuxCare-managed NuGet feed as drop-in replacements for their end-of-life upstream releases. Installation instructions are provided during onboarding; if you need them again, contact the team through the [TuxCare Support Portal](https://tuxcare.com/support-portal/).

## Vulnerability Coverage and Target Response Times

TuxCare employs the Common Vulnerability Scoring System (CVSS) to assess the severity of security vulnerabilities. Our severity rating system integrates both NVD scoring and vendor scoring (when available); when the vendor's score is lower than the NVD score, we prioritize the NVD score.
Expand All @@ -21,13 +39,13 @@ Aligning with many industry standards and regulatory requirements, TuxCare is co

Customers can report vulnerabilities by submitting a ticket through the [TuxCare Support Portal](https://tuxcare.com/support-portal/). TuxCare commits to providing an initial response to any reported issue within 3 days.

Requests for customer-directed security patches for CVEs that are outside of the ELS for Libraries scope will be reviewed within 3 working days. If the request is accepted, we will provide the patch within the next 60 days.
Requests for customer-directed security patches for CVEs that are outside of the ELS for Language Ecosystems scope will be reviewed within 3 working days. If the request is accepted, we will provide the patch within the next 60 days.

Handling Multiple Vulnerabilities: In cases where several CVEs are reported simultaneously for fixing, TuxCare will discuss and agree upon resolution timelines separately with the customer.

## Enhanced Transparency & Visibility

TuxCare's commitment to transparency and visibility is foundational to our ELS for Libraries offering. We aim to provide comprehensive details about how each package is built, verified, and distributed, ensuring complete trust in the software supply chain.
TuxCare's commitment to transparency and visibility is foundational to our ELS for Language Ecosystems offering. We aim to provide comprehensive details about how each package is built, verified, and distributed, ensuring complete trust in the software supply chain.

<!-- * **SLSA Compliance**: All packages are built and signed to ensure verifiable Supply-chain Levels for Software Artifacts (SLSA) compliance. They are securely constructed from vetted sources, include attestations for all dependencies, and undergo continuous testing to maintain integrity and security.
-->
Expand Down
10 changes: 5 additions & 5 deletions docs/els-for-libraries/machine-readable-security-data/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ Released fixes are available via [tuxcare.com/cve-tracker](https://tuxcare.com/c

Each package built by TuxCare ships with an SBOM that lists its components, versions, and dependency relationships. SBOMs are provided in industry-standard formats — SPDX and CycloneDX — so they can be consumed by any SBOM-aware scanner or supply-chain tool.

SBOMs are generated across all ELS for Libraries ecosystems (Java, JavaScript, Python, PHP, .NET) and published to [TuxCare Nexus](https://nexus.repo.tuxcare.com/). **Access requires TuxCare credentials.**
SBOMs are generated across all ELS for Language Ecosystems languages (Java, JavaScript, Python, PHP, .NET) and published to [TuxCare Nexus](https://nexus.repo.tuxcare.com/). **Access requires TuxCare credentials.**

SBOM repositories are currently published for:

Expand Down Expand Up @@ -79,7 +79,7 @@ Import the public key once. It can verify every TuxCare-signed package, so this

### Verify a Package

The verification procedure is the same for every ELS for Libraries ecosystem (Java, JavaScript, Python, PHP, .NET): obtain the exact published artifact, download its detached `.asc` signature from TuxCare Nexus, and run `gpg --verify`. Select your ecosystem below.
The verification procedure is the same for every ELS for Language Ecosystems language (Java, JavaScript, Python, PHP, .NET): obtain the exact published artifact, download its detached `.asc` signature from TuxCare Nexus, and run `gpg --verify`. Select your ecosystem below.

:::warning
The signature location and artifact naming vary by ecosystem. The Java, JavaScript, PHP, and Python steps below are confirmed; the .NET steps shown are representative — confirm the exact signatures location and artifact naming for .NET with your TuxCare contact.
Expand Down Expand Up @@ -294,7 +294,7 @@ The signature location and artifact naming vary by ecosystem. The Java, JavaScri
If `gpg` reports `BAD signature`, or cannot find the matching public key, treat the artifact as an integrity violation: stop the installation and re-obtain the package and signature from TuxCare over a trusted channel.

:::tip
All ELS for Libraries ecosystems are signed the same way. If you need a signatures-repository path or the TuxCare public key, contact [sales@tuxcare.com](mailto:sales@tuxcare.com).
All ELS for Language Ecosystems ecosystems are signed the same way. If you need a signatures-repository path or the TuxCare public key, contact [sales@tuxcare.com](mailto:sales@tuxcare.com).
:::

## Integrity Violation Events
Expand All @@ -303,7 +303,7 @@ An **integrity violation** is any event where an artifact obtained from TuxCare

### What Counts as an Integrity Violation

The ELS for Libraries delivery model is a set of per-ecosystem registries hosted on TuxCare Nexus (an npm registry for JavaScript, a PyPI-compatible index for Python, a Maven repository for Java, a Composer repository for PHP, and a NuGet feed for .NET), served exclusively over HTTPS, plus a detached GPG signature published alongside each artifact. Select your ecosystem for the integrity checks — and therefore the violation types — that apply to it:
The ELS for Language Ecosystems delivery model is a set of per-ecosystem registries hosted on TuxCare Nexus (an npm registry for JavaScript, a PyPI-compatible index for Python, a Maven repository for Java, a Composer repository for PHP, and a NuGet feed for .NET), served exclusively over HTTPS, plus a detached GPG signature published alongside each artifact. Select your ecosystem for the integrity checks — and therefore the violation types — that apply to it:

<TableTabs label="Choose ecosystem: " :labels="{ DotNET: '.NET' }">

Expand Down Expand Up @@ -360,7 +360,7 @@ The ELS for Libraries delivery model is a set of per-ecosystem registries hosted
</TableTabs>

:::tip
**Metadata signature mismatch** is an OS-package-manager concept (yum/dnf and apt verify a GPG signature over the *repository metadata index* — `repomd.xml`, `InRelease`). The language registries used by ELS for Libraries — npm, pip, Maven, Composer, and NuGet — do not distribute a separately signed metadata index, so this specific violation type does not map to the setup. The equivalent authenticity and integrity guarantee is provided **per artifact** by the checksum/integrity-hash check and the detached GPG signature listed above.
**Metadata signature mismatch** is an OS-package-manager concept (yum/dnf and apt verify a GPG signature over the *repository metadata index* — `repomd.xml`, `InRelease`). The language registries used by ELS for Language Ecosystems — npm, pip, Maven, Composer, and NuGet — do not distribute a separately signed metadata index, so this specific violation type does not map to the setup. The equivalent authenticity and integrity guarantee is provided **per artifact** by the checksum/integrity-hash check and the detached GPG signature listed above.
:::

### Capturing Integrity Violations in a Dedicated Log
Expand Down
2 changes: 1 addition & 1 deletion docs/endless-lifecycle-support/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ Explore TuxCare’s Endless Lifecycle Support Portfolio:

Keep your apps running safely on the runtimes they were built for, without rushed upgrades or broken code – even after official support ends. [Learn more](/els-for-runtimes/).

* **Endless Lifecycle Support for Libraries**
* **Endless Lifecycle Support for Language Ecosystems**

Keep securely running your apps on end-of-life (EOL) libraries – without rushed upgrades, costly code rewrites, or disruption to your roadmap. [Learn more](/els-for-libraries/).

Expand Down
Loading