Updating SAS Viya
SAS releases updates to SAS Viya on a continuous basis. This guide is aimed at providing guidance on what types of updates are available and in which situation you need to update your Viya environment.
Scenario
Terminology
To understand how SAS manages updates, it is important to understand the terminology used in this guide.
- Cadence: Refers to the frequency that versioned SAS Viya 4 software is released to customers. Cadence names are Stable (released every month) and Long-Term Support (released every six months).
- Version: A number that indicates the year and month when the SAS Viya 4 software is released to customers. The format is yyyy.mm, such as 2025.08.
- Release: A specific number that indicates the exact timestamp the SAS Viya 4 software is released to customers. Releases can be used to differentiate between two different patch updates of the same version.
As you can see above, we differentiate two different types of updates: Version updates and Patch updates.
- Version update: An update that changes the deployed version of SAS Viya from one version to another.
- Patch update: An update within the same deployed version of SAS Viya.
When to update?
There are a number of reasons why you might want to update your SAS Viya software. We will list the most common reasons for updating:
Updating to a new version
- New Functionality: SAS constantly releases new functionality into their existing products. New functionality is only introduced in new versions of the software and is not retroactively added into previous versions of the software. To get access to this new functionality, upgrading to a new version is therefore required.
- SAS Viya Support: SAS supports the current version and the previous three versions of the SAS Viya software for both the Stable and Long-Term Support cadences. It is therefore required to regularly update your SAS Viya platform to remain supported under Standard Support. For deployments following the Stable cadence, this means updating at least every three months. For deployments following the Long-Term Support cadence, this means updating at least every two years.
- Third-Party Support: Even though your SAS version may still be receiving standard support, some of your third-party dependencies such as Kubernetes, the Ingress controller, or data sources may stop being supported before your SAS version stops being supported. This is especially common when you deploy the Long-Term Stable cadence, which remains in support for a long period of time. In order to be able to use newer versions of these dependencies, you may have to update SAS Viya to a later version.
Applying a Patch update
- Fix critical issues in existing functionality: When critical issues are discovered in existing SAS Viya functionality, SAS may produce a Patch for these issue in between versions. You may learn that these updates exist through a SAS Knowledge Base article or through interaction with SAS Technical Support.
Security Issues
SAS provides security vulnerability remediation through SAS Viya cadence releases and patch updates. Determining whether you need to apply a Patch update, or update to a new version will depend on your security posture and the availability of security fixes in these releases.
For major CVE announcements, SAS publishes security bulletins which are official SAS statements and advisories about the applicability and recommended remediation of these CVEs.
SAS provides data about security vulnerabilities addressed in each cadence version and patch updates. Licensed customers may request access to this data by contacting SAS Technical Support. For any further detail and resources around SAS Viya security, also contact SAS Technical Support.
Solution overview
Update availability
SAS ships a CronJob that regularly checks whether software updates are available for your Viya environment. This Update Checker Report can be accessed once it has been enabled. The Update Checker Report will inform you of both the availability of new software versions as well as available patch updates.
Preparing for an update
Regardless of whether you are updating to a new version or applying a patch update, it is important to ensure your environment is ready for an update. A pre-update checklist can be found here. In addition, a number of best practices have been documented here. It is recommended to familiarize yourself with both of these documents before proceeding.
Updating to a new version
The instructions for updating to a new version can be found here.
Applying a patch update
The instructions for applying a patch update can be found here.
After the update
Once you have applied the software update, you may want to perform a number of additional actions based on the type of update you performed.
New version
If you updated to a new version, you may want to run a set of regression tests on those parts of the Viya platform that are critical to your operation. Although uncommon, version updates may alter the behavior of some components that mean that some adjustments may be required. This is especially true if the last update was a while ago. In addition, if you updated to a new version to get access to specific new functionality, you may want to test that functionality and inform users that it is now available.
Patch update
If you applied a patch update, you likely did this to resolve a specific issue or security vulnerability. To verify whether the patch was applied correctly, test that the issue you were experiencing or the vulnerability that you were seeing has now indeed been resolved. Extensive testing of existing functionality should not be required as patch updates do not introduce new functionality or change existing functionality.