Skip to content

ProductNot yet confirmed elsewhere1 publisher3 min readPublished

MinIO went dark on 13 February. Docker will keep patching it until 2031, for a fee.

Archiving a project with a billion Docker pulls turned an object store into an audit finding. Docker's extended support does not remove the migration, it moves the deadline out to 2031.

The Product Desk

How we use AISend a correction

What happened

  • The MinIO open-source project was archived upstream on 13 February 2026.
  • A component with more than a billion Docker pulls stopped shipping releases, bug fixes and security patches on that date.
  • Docker now offers a maintained, hardened MinIO image under Extended Lifecycle Support, built and patched for up to five years past upstream end of life.
  • The support terms put critical and high-severity CVEs on a 14-day patch SLA.
  • ELS is sold as a paid add-on to a Docker Hardened Images subscription.

Why it matters

  • cost The in-house alternative is a standing headcount cost: sustained Go security engineering for a codebase with no upstream to merge from, carried until the object store actually moves.
  • decision Buying coverage converts an immediate audit scramble into a dated commitment, and the date to plan the petabyte migration against becomes February 2031.
  • constraint Coverage that follows one repository at a time constrains how fast a fleet with several expired components can be cleared, because entitlements sequence while end-of-life dates do not.
  • precedent Once any archived project can be maintained on request, "upstream stopped shipping" loses its force as the thing that finally gets a migration funded.

An end-of-life finding is a documentary problem before it is a technical one. The auditor is not reading the code, only whether somebody is contractually on the hook for patching it, and that is exactly the surface Docker is selling against: the maintained MinIO image carries SBOMs, VEX statements and SLSA Build Level 3 provenance kept current for the life of the image [11], with critical and high-severity CVEs patched on a 14-day service level [7]. The code does not get younger. The signature on it changes hands.

Do the arithmetic on the offer and you get a date. Five years past 13 February 2026 puts the outer edge of MinIO coverage in February 2031 [18], and that is the number to put in the roadmap, because Docker's own description of the product is that patches and audit evidence keep flowing on the images already in production while the migration happens on the roadmap's schedule [16]. The migration is not cancelled. It is refinanced.

The entitlement mechanics deserve more attention than the SLA. Applied to a repository, it covers every available ELS version there, and when one migration completes you re-point it at the next repository so the coverage follows the risk [9]. That is serial coverage for a problem that arrives in parallel: a shop carrying MinIO alongside Node 18, Python 3.8 and an older Airflow is not solving four findings with one entitlement [19][20]. Docker also does not state a price in the announcement [17], which makes the build-versus-buy comparison hard to run against the alternative it describes, namely staffing sustained Go security engineering for a project that no longer ships fixes [13].

Docker frames three options for MinIO operators, adds that doing nothing is not a fourth [13], and happens to be the vendor for one of the three. The framing is self-serving and still roughly correct about the storage layer, where a move to another object store is measured in petabytes and the CVE exposure grows for the whole length of the project [14]. Docker says it tracks new CVEs across MinIO and its full Go dependency graph, backports, rebuilds and ships [15], which is the part a platform team would otherwise own outright.

The scale claim is worth separating from the sales claim. Docker cites Black Duck's 2026 Open Source Security and Risk Analysis report for the finding that 93% of commercial codebases contain components with no development activity in at least two years [4]. Most of that dormancy never becomes a finding, because dormancy on its own is not a status any framework flags. What the 13 February archive did was convert a condition into a date [1], and frameworks including FedRAMP, DORA and the Cyber Resilience Act read unpatched end-of-life software in production as a finding [5].

Which leaves the question the attestations do not settle. By 2031, a maintained MinIO will be a vendor artifact with five years of backported fixes and no upstream to reconcile against, adopted through a FROM-line change in the same registry teams already use [10]. That is support in the audit sense. It is also a fork with a support contract stapled to it, and the SBOM will not tell you which one you bought.

What to watch

  • Whether Docker publishes ELS pricing and per-repository entitlement terms, which is what makes the buy-versus-self-patch comparison runnable.
  • Whether assessors under DORA and the Cyber Resilience Act issue guidance on vendor-maintained end-of-life images as remediation rather than as a logged exception.
  • Whether Airflow, which Docker names as a live problem but does not list in the catalog, gets an ELS build.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence28
Adoption24
Hype gap+34
Incentives92
Confidence32
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On 13 February 2026, the MinIO open-source project was archived upstream.

    ReportedSupportedSource: Docker blogView cited source
  2. [2]

    MinIO, a project with more than a billion Docker pulls, stopped shipping releases, bug fixes and security patches when it was archived.

    ReportedSupportedSource: Docker blogView cited source
  3. [3]

    Docker states that new CVEs in MinIO and its Go dependency tree now arrive with no upstream patch behind them, and that an audit reads that as unsupported software in production.

    ReportedSupportedSource: Docker blogView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. docker.com

    1 article · August 24, 2026

    MinIO End of Life: How to Stay Patched and Audit-Ready with Docker ELS

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories