Minimus announced that its image registry will go offline on October 22 2026, ending all upstream updates after a 60‑day maintenance window. Engineers who rely on Minimus images must now replace them with Docker Hardened Images to avoid unpatched vulnerabilities and maintain compliance.
Impact on Build Pipelines
The migration is designed as a simple FROM line change. Docker Hardened Images are compatible with both Alpine and Debian bases, so existing Dockerfiles and CI scripts require minimal alteration. The catalog provides a one‑to‑one mapping for most common images, and a migration guide supplies step‑by‑step instructions and a checklist to verify each swap.
Security and Compliance Implications
Docker Hardened Images ship with near‑zero known CVEs, full SBOMs, SLSA Build Level 3 provenance, and cryptographic signatures. The source claims that teams moving from standard public images can see up to 95 % CVE reduction and up to 90 % attack‑surface reduction. For organizations with stricter compliance needs, paid tiers add SLA‑backed remediation, FIPS and STIG variants, and extended coverage for legacy versions.
Operational Considerations
During the 60‑day window, Minimus images will continue to receive upstream updates, but after the cutoff no new CVE patches will be applied. Docker is offering free migration assistance; practitioners can email minimus@docker.com to receive a technical migration expert, an initial image inventory review, and guidance on compliance requirements. An AI assistant named Gordon can run an initial pass to suggest equivalent Docker Hardened Images.
Related CloudNinjas coverage: hands-on guides.
What This Means For Practitioners
- Audit your current Minimus image list before the maintenance window ends.
- Identify Docker Hardened Image equivalents using the catalog and update the
FROMstatements in your Dockerfiles. - Run the provided migration checklist and verify SBOM and signature integrity after the swap.
- Consider the paid tier if you need SLA‑backed remediation or FIPS/STIG compliance.
- Monitor for any new CVEs post‑migration and ensure your CI pipeline pulls the latest hardened image versions.
