---
title: Secure your Open-Source Freedom for 10 years
description: 'If this is your desire, it is Ubuntu Pro’s commitment: “Ubuntu Pro will
  secure your Open-Source Freedom for 10 years”. Security and Freedom shouldn’t be
  a debate, a trade-off, even a dilemma. Security shouldn’t be your concern when you
  embrace Open-Source. A 10-year commitment Canonical backs Ubuntu Pro for 10 years,
  ensuring security upd […]'
url: https://canonical.com/blog/secure-your-open-source-freedom-for-10-years?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Hugo Huang](https://canonical.com/blog/author/hugohuangtao "More about Hugo Huang")

16 November 2021

# Secure your Open-Source Freedom for 10 years

[Apps](https://canonical.com/blog/tag/apps)
[Extended Security Maintenance](https://canonical.com/blog/tag/extended-security-maintenance)
[Google Cloud](https://canonical.com/blog/tag/google-cloud)
[Security](https://canonical.com/blog/tag/security)

---

Share the article

If this is your desire, it is Ubuntu Pro’s commitment: “Ubuntu Pro will secure your Open-Source Freedom for 10 years”. Security and Freedom shouldn’t be a debate, a trade-off, even a dilemma. Security shouldn’t be your concern when you embrace Open-Source.

### A 10-year commitment

Canonical backs Ubuntu Pro for 10 years, ensuring security updates are available throughout, with a guaranteed upgrade path. For example, Ubuntu 16.04 Pro will continue to get security updates until 2026.

Ubuntu Pro automatically entitles Extended Security Maintenance (ESM). Let’s SSH into your Ubuntu Pro virtual machine. If you haven’t yet upgrade your Ubuntu LTS to Ubuntu Pro, please follow [this tutorial](https://ubuntu.com/blog/securing-the-open-source-supply-chain-with-ubuntu-pro-on-google-cloud). In less than One Minute, you will be able to get your Ubuntu Pro machine without losing any of your mission critical workloads. Once you SSH into your Ubuntu Pro, input:

|  |
| --- |
| ua status |

You will see:

| SERVICE | ENTITLED | STATUS | DESCRIPTION |
| --- | --- | --- | --- |
| cis | yes | enabled | Center for Internet Security Audit Tools || esm-apps | yes | enabled | UA Apps: Extended Security Maintenance (ESM) || esm-infra | yes | enabled | UA Infra: Extended Security Maintenance (ESM) |

Wait a second, why are there two “ESM”?

### Open Source Security

ESM-infra guarantees 10-year Extended Security Maintenance (ESM) for packages in the Main repository, which includes Canonical-supported free and open-source software. On the other hand, ESM-apps further extend “Extended Security Maintenance” to the Universe repository, which covers community-maintained free and open-source software. Suppose you want to install Node.js; let’s check if the machine pulls the package from the repo:

|  |
| --- |
| apt-cache policy nodejs |

|  |
| --- |
| nodejs:  Installed: (none)  Candidate: 4.2.6~dfsg-1ubuntu4.2+esm1  Version table:     4.2.6~dfsg-1ubuntu4.2+esm1 500        500 https://esm.ubuntu.com/apps/ubuntu xenial-apps-security/main amd64 Packages     4.2.6~dfsg-1ubuntu4.2 500        500 http://us-central1.gce.archive.ubuntu.com/ubuntu xenial-updates/universe amd64 Packages        500 http://security.ubuntu.com/ubuntu xenial-security/universe amd64 Packages     4.2.6~dfsg-1ubuntu4 500        500 http://us-central1.gce.archive.ubuntu.com/ubuntu xenial/universe amd64 Packages |

Ubuntu Pro adds security coverage for the most important open source applications like Apache Kafka, NGINX, MongoDB, Redis and PostgreSQL.

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
