<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Container lifecycle and end of life on</title><link>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/</link><description>Recent content in Container lifecycle and end of life on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Fri, 04 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard Containers product release lifecycle</title><link>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/versions/</link><pubDate>Mon, 08 Jan 2024 08:49:31 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/versions/</guid><description>&lt;p&gt;&lt;a href="https://images.chainguard.dev/?utm_source=cg-academy&amp;amp;utm_medium=referral&amp;amp;utm_campaign=dev-enablement"&gt;Chainguard
Containers&lt;/a&gt;
are able to offer few-to-zero known vulnerabilities because they are updated
frequently. Because of this continuous release cycle, the best way to mitigate
vulnerabilities is to use the newest build of each Chainguard Container
available. Chainguard keeps Containers up to date by doing one or more of the
following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Applying new releases from upstream projects&lt;/li&gt;
&lt;li&gt;Rapidly applying upstream patches to current releases — you can read more
about this in our blog post, “&lt;a href="https://www.chainguard.dev/unchained/how-chainguard-fixes-vulnerabilities?utm_source=cg-academy&amp;amp;utm_medium=referral&amp;amp;utm_campaign=dev-enablement"&gt;How Chainguard fixes vulnerabilities before
they&amp;rsquo;re
detected&lt;/a&gt;”&lt;/li&gt;
&lt;li&gt;Applying Chainguard patches to OSS software&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Upstream projects are updated frequently for many reasons, including to combat
CVEs, and Chainguard ensures that the most up-to-date software is available in
all Chainguard Containers. Additionally, Chainguard often identifies CVEs and
other issues before scanners can detect them, so Chainguard may offer a patch to
a vulnerable dependency to support Chainguard Containers with few-to-zero
vulnerabilities.&lt;/p&gt;</description></item><item><title>Chainguard end-of-life grace period for containers</title><link>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/eol-grace-period/</link><pubDate>Wed, 14 May 2025 08:49:31 +0000</pubDate><guid>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/eol-grace-period/</guid><description>&lt;p&gt;Typically, specific versions of software receive updates on a schedule for a set amount of time. Eventually, though, every version of software will stop receiving support. When project maintainers stop providing updates, it&amp;rsquo;s known as the &lt;em&gt;End-of-Life&lt;/em&gt; (EOL) stage.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s recommended that when a software version reaches the EOL phase, users should migrate their projects to a later version, as &lt;a href="https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/how-eol-software-accumulates-cves/"&gt;EOL software is known to accumulate vulnerabilities&lt;/a&gt;. However, there are cases where an organization may want to continue using a container image after it has reached end-of-life. This could be because an image reaches EOL before the organization&amp;rsquo;s release schedule, or perhaps later image versions have one or more issues that prevent the organization from upgrading.&lt;/p&gt;</description></item><item><title>How end-of-life software accumulates vulnerabilities</title><link>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/how-eol-software-accumulates-cves/</link><pubDate>Wed, 04 Dec 2024 11:07:52 +0200</pubDate><guid>https://edu.chainguard.dev/chainguard/containers/concepts/lifecycle-and-eol/how-eol-software-accumulates-cves/</guid><description>&lt;p&gt;Typically, specific versions of software receive updates on a schedule for a set amount of time. Eventually, though, every version of software will stop receiving support. When project maintainers stop providing updates, it&amp;rsquo;s known as the &lt;em&gt;End-of-Life&lt;/em&gt; (EOL) stage.&lt;/p&gt;
&lt;p&gt;Because it&amp;rsquo;s no longer being actively maintained, software begins to collect vulnerabilities when it reaches EOL. This problem can become compounded when using container images, as they often come with extra components from underlying base images which are all prone to accruing vulnerabilities. This can lead to images with hundreds of components, each collecting vulnerabilities and forming part of the attack surface.&lt;/p&gt;</description></item></channel></rss>