Live
GitHub Rewrites Copilot Runtime in Rust via AI‑Guided Incremental MigrationECS auto‑repair for GPU and instance failures shifts remediation to the platformDecision Model API Converges on a Shared Schema – Implications for EngineersR2 dashboard now reports bandwidth per Cloudflare locationMinimum Viable Instrumentation adds gap detection to OllyGarden’s Rose AI agentWarehouse‑Native Extraction with Alteryx Live Query and BigQueryAI Agent Integration on Amazon Bedrock: Lessons from Postman's Production RolloutBedrock AgentCore Runtime Gains Speed, Pay‑As‑You‑Go, and New Model OptionsGitHub Rewrites Copilot Runtime in Rust via AI‑Guided Incremental MigrationECS auto‑repair for GPU and instance failures shifts remediation to the platformDecision Model API Converges on a Shared Schema – Implications for EngineersR2 dashboard now reports bandwidth per Cloudflare locationMinimum Viable Instrumentation adds gap detection to OllyGarden’s Rose AI agentWarehouse‑Native Extraction with Alteryx Live Query and BigQueryAI Agent Integration on Amazon Bedrock: Lessons from Postman's Production RolloutBedrock AgentCore Runtime Gains Speed, Pay‑As‑You‑Go, and New Model Options
Docker

Docker ELS Extends MinIO Patch Coverage Beyond End‑of‑Life

AI SummaryPowered by AI

Docker’s Extended Lifecycle Support now provides a hardened MinIO image that stays patched and audit‑ready for up to five years after the project was archived. This lets engineers keep production object stores compliant without rushing costly migrations.

Docker’s Extended Lifecycle Support (ELS) now supplies a hardened MinIO image that continues to receive security patches and audit artifacts for up to five years after the project was archived on 13 February 2026. This change lets AI engineers, cloud/platform teams, SREs, and security specialists keep production object stores compliant without accelerating costly migrations.

What Changed

MinIO’s open‑source repository was moved to an archive state in February 2026, ending upstream releases, bug fixes, and security updates. Docker responded by adding MinIO to its Hardened Images catalog as an ELS‑tagged image. The ELS model builds the image from source, tracks new CVEs across MinIO and its entire Go dependency graph, back‑ports fixes, and republishes the image on a 14‑day SLA for critical and high‑severity findings. The service is offered as a paid add‑on to an existing Docker Hardened Images subscription and is visible alongside regular LTS tags, requiring only a FROM‑line change in Dockerfiles.

Why It Matters to Engineers

When a widely used component like MinIO becomes unsupported, every deployment inherits exposure to unpatched vulnerabilities. Auditors under frameworks such as FedRAMP, DORA, and the Cyber Resilience Act flag unpatched end‑of‑life software as a compliance finding. The alternative paths—migrating to a commercial alternative, staffing an internal Go security team, or accepting vendor liability—each carry operational or financial overhead. Docker ELS removes the immediate deadline by delivering a maintained image that satisfies both security scanners and audit evidence while teams plan a migration on their own schedule.

Operational and Security Implications

Adopting the ELS‑tagged MinIO image introduces several practical considerations:

  • Patch cadence: Critical and high‑severity CVEs are addressed within 14 days, extending the protection window for up to five years beyond upstream EOL.
  • Supply‑chain attestations: Each image includes a signed SBOM, VEX statement, and SLSA Build Level 3 provenance, providing the artifacts auditors require to verify that known vulnerabilities are mitigated.
  • Dependency coverage: Docker monitors the full Go dependency tree, including transitive dependencies, ensuring that indirect libraries receive the same back‑ported fixes.
  • Catalog integration: The image lives in the same registry as standard Docker Hardened Images, so existing CI/CD pipelines need only update the image tag; no workflow redesign is necessary.
  • Cost model: ELS is an optional, paid extension to a Hardened Images subscription, meaning teams must evaluate the expense against the risk of maintaining patches internally or purchasing a commercial replacement.

Because the ELS service can be requested for any component that reaches EOL, the same pattern can be applied to other archived projects such as Nginx, Node, or Python, reducing the need for ad‑hoc, custom patching processes across a heterogeneous fleet.

Related CloudNinjas coverage: hands-on guides.

What This Means For Practitioners

Practitioners should audit their current MinIO deployments to confirm they are using the ELS‑tagged image or plan a migration to it before the next audit cycle. Evaluate the cost of the ELS add‑on against the effort required to staff a dedicated Go security team or to license a commercial object store. Incorporate the ELS image tag into CI pipelines to ensure future builds automatically inherit the extended support lifecycle. Finally, monitor Docker’s catalog for new ELS offerings that match other end‑of‑life dependencies in your stack, and consider requesting coverage for any gaps that could become audit findings later.

Originally published atDocker Blog