Product Lifecycle and Security Updates
This page states how long each ONE WARE product receives security updates, how those updates are delivered, and what happens at end of support.
Support periods
Security updates are provided free of charge during the support period.
| Product | Support period | Delivered as |
|---|---|---|
| ONE WARE Studio | At least 5 years from each release | In-app update / new installer |
| OneWare.AI extension | At least 5 years from each release | Extension update through ONE WARE Studio |
| OneWare Self-Hosted Worker | At least 5 years from each release | Updated container image — you pull and redeploy |
| Hosted ONE WARE Cloud | Maintained and security-patched for as long as the service is offered | Applied by ONE WARE, no action required |
The support period runs from each release, not from the date you install. Running an older release means less remaining support, so staying current is the practical way to stay covered.
Five years is the minimum expected support period under the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Art. 13) for products whose expected use time is not shorter. We commit to at least this period for every release. Where the realistic in-service life of a product turns out to be longer, we will extend the commitment rather than shorten the product's life to match.
How updates are delivered
ONE WARE Studio checks for updates and installs them through the application. Keep automatic update checks enabled.
The OneWare.AI extension is updated through ONE WARE Studio's extension management.
The Self-Hosted Worker does not update itself. You are responsible for pulling the new image and redeploying. See Self-Hosted Worker Security.
The hosted ONE WARE Cloud is updated by ONE WARE. Where an update requires a maintenance window or a customer action, affected accounts are notified in advance.
Update integrity
Updates are distributed over authenticated TLS connections from ONE WARE's official channels only:
- ONE WARE Studio and the OneWare.AI extension:
cdn.one-ware.comand the official GitHub releases for the open-source components. - Container images:
oneware.azurecr.io.
Do not install ONE WARE software from mirrors or third-party rebuilds. If you need to verify an artifact, contact security@one-ware.com.
Version support
Security fixes are provided for the current release of each product. If you run an older release within its support period and cannot upgrade immediately, contact us — we will tell you whether a mitigation exists, but the supported remedy is generally to move to the fixed release.
Pre-release, beta and development builds are not covered by the support commitment and should not be used in production.
End of support
When a product or a release reaches end of support:
- We give at least 12 months' notice before security support ends.
- We provide a final security update where technically feasible.
- We publish a migration path to a supported version.
After the end of support, the product continues to function, but it no longer receives security fixes and should not be used where security matters.
Software bill of materials
An SBOM is generated for every release of every product. SBOMs may reveal exploitable detail about systems in the field, so they are not published openly; they are provided to customers and to competent authorities where legally or contractually required. Request one at security@one-ware.com.
Related
- Product Security — reporting a vulnerability
- Security Advisories — how to be notified
- EU Declarations of Conformity