ProductNot yet confirmed elsewhere1 publisher3 min readPublished
MinIO went dark on 13 February. Docker will keep patching it until 2031, for a fee.
Archiving a project with a billion Docker pulls turned an object store into an audit finding. Docker's extended support does not remove the migration, it moves the deadline out to 2031.
The Product Desk
What happened
- The MinIO open-source project was archived upstream on 13 February 2026.
- A component with more than a billion Docker pulls stopped shipping releases, bug fixes and security patches on that date.
- Docker now offers a maintained, hardened MinIO image under Extended Lifecycle Support, built and patched for up to five years past upstream end of life.
- The support terms put critical and high-severity CVEs on a 14-day patch SLA.
- ELS is sold as a paid add-on to a Docker Hardened Images subscription.
Why it matters
- cost The in-house alternative is a standing headcount cost: sustained Go security engineering for a codebase with no upstream to merge from, carried until the object store actually moves.
- decision Buying coverage converts an immediate audit scramble into a dated commitment, and the date to plan the petabyte migration against becomes February 2031.
- constraint Coverage that follows one repository at a time constrains how fast a fleet with several expired components can be cleared, because entitlements sequence while end-of-life dates do not.
- precedent Once any archived project can be maintained on request, "upstream stopped shipping" loses its force as the thing that finally gets a migration funded.
An end-of-life finding is a documentary problem before it is a technical one. The auditor is not reading the code, only whether somebody is contractually on the hook for patching it, and that is exactly the surface Docker is selling against: the maintained MinIO image carries SBOMs, VEX statements and SLSA Build Level 3 provenance kept current for the life of the image [11], with critical and high-severity CVEs patched on a 14-day service level [7]. The code does not get younger. The signature on it changes hands.
Do the arithmetic on the offer and you get a date. Five years past 13 February 2026 puts the outer edge of MinIO coverage in February 2031 [18], and that is the number to put in the roadmap, because Docker's own description of the product is that patches and audit evidence keep flowing on the images already in production while the migration happens on the roadmap's schedule [16]. The migration is not cancelled. It is refinanced.
The entitlement mechanics deserve more attention than the SLA. Applied to a repository, it covers every available ELS version there, and when one migration completes you re-point it at the next repository so the coverage follows the risk [9]. That is serial coverage for a problem that arrives in parallel: a shop carrying MinIO alongside Node 18, Python 3.8 and an older Airflow is not solving four findings with one entitlement [19][20]. Docker also does not state a price in the announcement [17], which makes the build-versus-buy comparison hard to run against the alternative it describes, namely staffing sustained Go security engineering for a project that no longer ships fixes [13].
Docker frames three options for MinIO operators, adds that doing nothing is not a fourth [13], and happens to be the vendor for one of the three. The framing is self-serving and still roughly correct about the storage layer, where a move to another object store is measured in petabytes and the CVE exposure grows for the whole length of the project [14]. Docker says it tracks new CVEs across MinIO and its full Go dependency graph, backports, rebuilds and ships [15], which is the part a platform team would otherwise own outright.
The scale claim is worth separating from the sales claim. Docker cites Black Duck's 2026 Open Source Security and Risk Analysis report for the finding that 93% of commercial codebases contain components with no development activity in at least two years [4]. Most of that dormancy never becomes a finding, because dormancy on its own is not a status any framework flags. What the 13 February archive did was convert a condition into a date [1], and frameworks including FedRAMP, DORA and the Cyber Resilience Act read unpatched end-of-life software in production as a finding [5].
Which leaves the question the attestations do not settle. By 2031, a maintained MinIO will be a vendor artifact with five years of backported fixes and no upstream to reconcile against, adopted through a FROM-line change in the same registry teams already use [10]. That is support in the audit sense. It is also a fork with a support contract stapled to it, and the SBOM will not tell you which one you bought.
What to watch
- Whether Docker publishes ELS pricing and per-repository entitlement terms, which is what makes the buy-versus-self-patch comparison runnable.
- Whether assessors under DORA and the Cyber Resilience Act issue guidance on vendor-maintained end-of-life images as remediation rather than as a logged exception.
- Whether Airflow, which Docker names as a live problem but does not list in the catalog, gets an ELS build.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence28
- Adoption24
- Hype gap+34
- Incentives92
- Confidence32
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On 13 February 2026, the MinIO open-source project was archived upstream.
- [2]
MinIO, a project with more than a billion Docker pulls, stopped shipping releases, bug fixes and security patches when it was archived.
- [3]
Docker states that new CVEs in MinIO and its Go dependency tree now arrive with no upstream patch behind them, and that an audit reads that as unsupported software in production.
- [4]
Black Duck's 2026 Open Source Security and Risk Analysis report found that 93% of commercial codebases carry components with no development activity in at least two years.
- [5]
Frameworks including FedRAMP, DORA and the Cyber Resilience Act treat unpatched end-of-life software as an audit finding.
- [6]
Docker Hardened Images Extended Lifecycle Support builds and maintains a requested image for up to five years past upstream end of life.
- [7]
Critical and high-severity CVEs in ELS images are patched on a 14-day SLA, for up to five years past end of life.
- [8]
ELS is a paid add-on to a Docker Hardened Images subscription.
- [9]
Applied to a repository, the ELS entitlement covers every available ELS version in that repository; when one migration completes, the customer re-points it at the next repository so coverage moves with the risk.
- [10]
ELS-tagged images appear in the standard DHI catalog alongside LTS tags, adopted through the same registry and workflow as a FROM-line change.
- [11]
ELS images are built from source and signed, with SBOMs, VEX statements and SLSA Build Level 3 provenance maintained for the life of the image.
- [12]
Nginx, Node and Python ELS images are already in the catalog, Docker says it builds ahead of the end-of-life calendar, and components not in the catalog can be requested.
- [13]
Docker presents three options for teams running MinIO: move to a commercial replacement with new licensing and lock-in, carry the patches in-house by staffing sustained Go security engineering for a project that no longer ships fixes, or keep what they run and put a vendor on the hook; it adds that doing nothing is not a fourth option.
- [14]
Docker notes the archive lands on the storage layer, where migrations are measured in petabytes, moving a production object store is slow and expensive, and CVE exposure keeps growing while that work runs.
- [15]
Docker says it tracks new CVEs across MinIO and its full Go dependency graph, transitive dependencies included at no extra cost, then backports the fixes, rebuilds and ships.
- [16]
Docker says ELS removes the deadline by keeping patches and audit evidence flowing on the images already in production while the migration happens on the roadmap's schedule.
- [17]
The Docker announcement describes ELS as a paid add-on but states no price for it.
- [18]
Five years of ELS coverage from the MinIO archive date places the outer edge of maintenance in February 2031.
- [19]
Node 18, Python 3.8 and older Airflow releases still run in production long after upstream support ended.
- [20]
Because one entitlement is applied to a repository and re-pointed only after a migration completes, a fleet with several end-of-life components in production at once cannot be covered by a single entitlement.
Sources
1 independent publisher whose own reporting we read for this story.
- docker.comMinIO End of Life: How to Stay Patched and Audit-Ready with Docker ELS
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Open Source SustainabilityFollow
- Object StorageFollow
- Software Supply Chain SecurityFollow
- Container Image HardeningFollow
- End-of-Life Software MaintenanceFollow
- Compliance and Audit RiskFollow
Entities
- MinIOFollow
- DockerFollow
- Docker Hardened ImagesFollow
- Docker Extended Lifecycle SupportFollow
- Black DuckFollow
- 2026 Open Source Security and Risk Analysis reportFollow
- FedRAMPFollow
- Digital Operational Resilience ActFollow
- Cyber Resilience ActFollow
- SLSAFollow
- VEXFollow
- SBOMFollow
- GoFollow
- Node.jsFollow
- PythonFollow
- nginxFollow
- Apache AirflowFollow