MinIO was archived upstream on February 13, 2026, ending releases, bug fixes, and security patches for a project with over a billion Docker pulls. Docker now offers MinIO as part of its Extended Lifecycle Support (ELS) program, backporting CVE fixes across MinIO and its Go dependency tree, rebuilding hardened images, and shipping SBOMs, VEX statements, and SLSA Build Level 3 provenance for up to five years past end of life. The same ELS coverage extends to other end-of-life software like Nginx, Node, and Python versions, letting teams keep running unsupported components while staying audit-ready and moving migrations onto their own roadmap.

5m read timeFrom docker.com
Post cover image
Table of contents
MinIO lives on as the newest ELS updateExtended Lifecycle Support for your whole fleet

Questions this post answers

When did MinIO reach end of life and stop receiving updates?

The MinIO open-source project was archived upstream on February 13, 2026, meaning it stopped shipping releases, bug fixes, and security patches from that date. The project had surpassed one billion cumulative Docker pulls prior to being archived, so the change affects a very large installed base of production object storage deployments. Teams tracking end-of-life storage tools can follow patching options for MinIO on daily.dev.

What options do teams have if they are still running MinIO after it was archived?

Teams running MinIO after its archival have three choices: migrate to a commercial replacement and accept new licensing and lock-in, take on staffing an in-house Go security engineering effort to patch it themselves, or pay a vendor to maintain and patch the existing MinIO deployment. Doing nothing is explicitly not a viable fourth option because new CVEs arrive with no upstream fix. Comparing migration versus vendor-supported patching paths is easier with daily.dev tracking storage infrastructure news.

What does Docker's Extended Lifecycle Support (ELS) provide for end-of-life software like MinIO?

Docker ELS builds and maintains hardened images for software after its upstream end of life, for up to five years, patching critical and high-severity CVEs on a 14-day SLA. It covers MinIO and its full Go dependency graph including transitive dependencies, and ships each image with SBOMs, VEX statements, and SLSA Build Level 3 provenance as audit evidence. daily.dev helps engineers stay current on vendor patching options for aging infrastructure dependencies.

169 Impressions