Evidence ledger 38 sources Checked 28 Sep 2026

Evidence ledger

One row per claim in The parts that outlived the product: ten years of Docker, read from its own repositories: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.

Field guide: The parts that outlived the product: ten years of Docker, read from its own repositories. Category platform-and-infrastructure. Research date 2026-09-28. All links checked 2026-09-28.

Reachability note. This session's network policy allowed six hosts: github.com, raw.githubusercontent.com, gitlab.com, pkg.go.dev, pypi.org and hub.docker.com. Every other candidate host (company engineering blogs, kubernetes.io, lwn.net, USENIX, arXiv, YouTube, NVD, access.redhat.com, the Internet Archive) returned a proxy denial, so this guide contains no engineering-blog, talk or paper tier at all. That is a limit of the hunt, not of the public record, and it is stated in the page. The compensation is that everything here sits in tiers 9 to 11 of the hierarchy: source code, decision records and incident advisories.

Repository facts marked git were computed from bare, blobless clones taken on 2026-09-28 (git clone --bare --filter=blob:none) and are reproducible with the commands in the page's "Keep hunting" section.

# Org Title Tier Published Checked URL Claim taken from it Supporting quote or figure
1 Open Container Initiative runc advisory: escape via /proc/self/exe (CVE-2019-5736) postmortem 2019-02-11 2026-09-28 https://github.com/advisories/GHSA-gxmr-w5mj-v8hh The runtime boundary has been escapable from inside a container since the first widely deployed release "runc through 1.0-rc6, as used in Docker before 18.09.2"; allows "attackers to overwrite the host runc binary (and consequently obtain host root access)"; CVSS 8.6
2 Open Container Initiative runc advisory: container breakouts due to internally leaked fds (CVE-2024-21626) postmortem 2024-01-31 2026-09-28 https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv Five years later the same class recurs through a different mechanism "several file descriptors were inadvertently leaked internally within runc into runc init, including a handle to the host's /sys/fs/cgroup"; affected v1.0.0-rc93 to v1.1.11, patched v1.1.12
3 Open Container Initiative runc advisory: escape via masked path abuse (CVE-2025-31133) postmortem 2025-11-05 2026-09-28 https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2 The class was still producing High-severity escapes in late 2025 "when using the container's /dev/null to mask files, runc would not perform sufficient verification that the source of the bind-mount was actually a real /dev/null inode"; CVSS 7.3; patched 1.2.8, 1.3.3, 1.4.0-rc.3
4 Open Container Initiative runc published security advisories, index postmortem 2021-12 to 2026-06 2026-09-28 https://github.com/opencontainers/runc/security/advisories Ten advisories in five years, three of them published on one day Three High advisories dated 5 November 2025; a further advisory 13 June 2026
5 Docker / Moby moby advisory: AuthZ zero length regression (CVE-2024-41110) postmortem 2024-07-23 2026-09-28 https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq A 2018 fix was not carried across the branch lines created by the restructure "A security issue was discovered In 2018 ... Although this issue was fixed in Docker Engine v18.09.1 in January 2019, the fix was not carried forward to later major versions, resulting in a regression"
6 Docker / Moby Commit 2ac8a479c5: "Authz plugin security fixes for 0-length content and path validation" source 2018-11-26 2026-09-28 https://github.com/moby/moby/commit/2ac8a479c53d9b8e67c55f1e283da9d85d2b3415 The fix existed as a commit for six years before reaching a mainline tag git tag --contains puts its first tagged appearance at v28.0.0-rc.1 (2025-02-06); git merge-base --is-ancestor returns false for v27.0.3 and v27.1.0 (git)
7 Docker / Moby Commit bed37b6152: "Merge commit from fork, [master] AuthZ plugin security fixes" source 2024-07-23 2026-09-28 https://github.com/moby/moby/commit/bed37b6152327ae67f37cebf2690b7d746b99fb6 The 2024 fix is a merge whose second parent is the December 2018 commit Merge parents c98f01ecf2 5282cb25d0; 2 files changed, 115 insertions, 7 deletions
8 Docker / Moby Pull request #32691: "A new upstream project to break up Docker into independent components" source 2017-04-18 2026-09-28 https://github.com/moby/moby/pull/32691 The 2017 restructure was announced and argued in the repository itself Hykes: "upstream components (containerd, linuxkit etc) -> Moby -> Docker CE -> Docker EE"; objection: "This is not gonna work nice for all the projects that depend on github.com/docker/docker"
9 Docker / Moby Pull request #13602: "Add checkpoint/restore to docker API" source 2015-05-29, closed 2024-03-04 2026-09-28 https://github.com/moby/moby/pull/13602 A feature deferred across a component boundary can stay deferred for nine years crosbymichael, 2016-02-08: "We are going to work together on this after the containerd integration"; closed unmerged 2024-03-04 with 320 comments
10 Docker / Moby Closed, unmerged pull requests sorted by comments source 2014 to 2024 2026-09-28 https://github.com/moby/moby/pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged+sort%3Acomments-desc The most-argued proposals were closed rather than merged #9176 build-time env vars (475 comments), #13602 checkpoint/restore (320), #34319 private registry mirror, opened 2017-07-31, closed 2024-07-25 (201)
11 Docker / Moby moby/moby repository source 2013-01-18 to 2026-09-28 2026-09-28 https://github.com/moby/moby Engine commit volume fell by 90% between 2016 and 2021, then partly recovered Commits per year (git): 2016:10,133; 2017:4,481; 2018:2,339; 2021:1,065; 2025:4,410. Repo page: 72.1k stars, 58,195 commits
12 Docker / Moby Release tags of the engine source 2015-11-03 to 2025-11-10 2026-09-28 https://github.com/moby/moby/tags A 26-month gap between feature releases, and one release line abandoned Tag dates (git): v1.12.0 2016-07-28; v17.03.0-ce 2017-02-23; v20.10.0 2020-12-09; v22.06.0-beta.0 2022-06-03 (no final); v23.0.0 2023-02-02; docker-v29.0.0 2025-11-10
13 Docker / Moby Commit 7d74269c0d: "Create the containerd image service" source 2022-07-05 2026-09-28 https://github.com/moby/moby/commit/7d74269c0dafb71a760d8c669fca3d2df5778d2e Docker began replacing its own image store with containerd's five years after donating it First commit under daemon/containerd; 282 commits to that path in 2023 (git)
14 Docker / Moby Commit 632de98f75: "Enable containerd snapshotters by default" source 2025-07-09 2026-09-28 https://github.com/moby/moby/commit/632de98f75dc87e0e1900097ee1177aa64c8c45d The default image store became containerd's in the v29 line, eight years after the donation Commit title; follow-up "daemon: Do not default to c8d image store on Windows" 2025-09-01 (git)
15 Docker / Moby Commit a8a1cfd111: "daemon: Add embedded containerd mode" source 2026-06-17 2026-09-28 https://github.com/moby/moby/commit/a8a1cfd1114e7472590206f5ebb8e088beee7a1c The decomposition is being partly reversed: containerd is moving back inside the daemon process Release note quoted on the repository's releases page: "Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process"
16 Docker / Moby Commit 53bd828853: "Remove libnetwork" source 2025-07-31 2026-09-28 https://github.com/moby/moby/commit/53bd828853008b3187545849c1f2000f024861d0 Networking, split out in 2015, was folded back into the daemon tree in 2025 Preceding commit 7a720df61f "Move libnetwork to daemon/libnetwork" (2025-07-14); libnetwork repo last commit 2023-10-20 (git)
17 containerd containerd README and project scope adr 2015-11-05 to 2026 2026-09-28 https://github.com/containerd/containerd/blob/main/README.md The component was defined by what it refuses to do "containerd is designed to be embedded into a larger system, rather than being used directly by developers or end-users"; CNCF graduated
18 containerd SCOPE.md: in scope and explicitly out of scope adr 2017 onward 2026-09-28 https://raw.githubusercontent.com/containerd/containerd/main/SCOPE.md The scope document is an allow-list, and networking, build, logging and volumes are refused "Networking will be handled and provided to containerd via higher level systems"; "Build is a higher level tooling feature and can be implemented in many different ways on top of containerd"
19 containerd ADOPTERS.md source current 2026-09-28 https://raw.githubusercontent.com/containerd/containerd/main/ADOPTERS.md The donated component is the runtime under every major managed Kubernetes service, and Docker is one entry on the list 26 named adopters including GKE, EKS, AKS, AWS Fargate, Bottlerocket, k3s, Kata, Firecracker, and "Docker/Moby engine"
20 containerd Release tags source 2017-12-04 to 2026-09-16 2026-09-28 https://github.com/containerd/containerd/tags Six years and eleven months between major versions; activity flat for a decade v1.0.0 2017-12-04, v2.0.0 2024-11-05, v2.4.0 2026-09-16; commits per year 2017:3,152, 2020:1,356, 2026:1,355 (git)
21 Kubernetes KEP-2221: Removing dockershim from kubelet adr 2020-12 (v1.20) to 2022 (v1.24) 2026-09-28 https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/2221-remove-dockershim/README.md The consumer removed the special case once a standard interface had two implementations "kubelet then has dependency on specific container runtime which leads to maintenance burden"; deprecation v1.20, removal v1.24
22 Mirantis cri-dockerd source repo history from 2016-07-22 2026-09-28 https://github.com/Mirantis/cri-dockerd The removed shim survives as a third-party product, carrying its original history "Mirantis and Docker have agreed to partner to maintain the shim code standalone outside Kubernetes"; first commit "Add a dockershim package" 2016-07-22; commits fell to 17 in 2026 (git)
23 Open Container Initiative image-spec and runtime-spec release tags source 2017-07-19 to 2025-11-04 2026-09-28 https://github.com/opencontainers/image-spec/tags The interface froze, and that is why everything on both sides of it could be replaced image-spec v1.0.0 2017-07-19, v1.1.0 2024-02-15; commits per year 2016:642, 2018:16, 2020:8 (git)
24 Docker docker/roadmap issue #87: "Anti-Abuse Rate Limits" adr 2020-05-07 2026-09-28 https://github.com/docker/roadmap/issues/87 Metering the registry started as an abuse control and became the business model "20,000 pulls per 6 hour window" for anonymous users; "certain IPs pulling in excess of 60,000 times per 6 hour window"
25 Docker docker/roadmap issue #7: "Improve Mac File system performance" adr 2020-03-06, closed 2024-02-06 2026-09-28 https://github.com/docker/roadmap/issues/7 The most-demanded item on the public roadmap was the boundary between the developer's machine and the Linux VM Opened by nebuk89 2020-03-06; closed "Shipped! Enjoy!" with Docker Desktop 4.27, 2024-02-06
26 Docker Docker Hub usage: pull limits vendor current 2026-09-28 https://raw.githubusercontent.com/docker/docs/main/content/manuals/docker-hub/usage/pulls.md The default registry is metered per identity "100 per IPv4 address or IPv6 /64 subnet" per 6 hours unauthenticated; 200 for authenticated personal accounts; unlimited on paid plans
27 Docker Docker Desktop licence terms vendor current 2026-09-28 https://raw.githubusercontent.com/docker/docs/main/content/manuals/subscription-billing/desktop-license.md The client became a paid product above a size threshold Free for "fewer than 250 employees AND less than $10 million in annual revenue", personal use, education and non-commercial open source
28 Docker Docker Hub official image pull counters vendor week of 14-20 September 2026 2026-09-28 https://hub.docker.com/_/nginx The registry is the asset that kept its position nginx: 21,498,949 pulls in the week of 14-20 September, "1B+" total; alpine: 25,142,478 in the same week
29 Red Hat / containers podman source first commit 2017-11-01 2026-09-28 https://github.com/containers/podman A competing implementation of the same interfaces removed the daemon entirely "No manager daemon, for improved security and lower resource utilization at idle"; 28,467 commits, 33k stars
30 abiosoft colima source first commit 2021-09-04 2026-09-28 https://github.com/abiosoft/colima Replacement developer runtimes appeared within weeks of the Desktop licence change First commit 2021-09-04; podman-desktop first commit 2022-03-08; rancher-desktop 2020-10-12 (git)
31 Kubernetes registry.k8s.io casestudy 2022 2026-09-28 https://github.com/kubernetes/registry.k8s.io Large consumers eventually build their own registry rather than depend on someone else's economics "significant egress traffic costs from users on other cloud providers"; migration off k8s.gcr.io announced November 2022
32 GitLab gitlab-org/ci-cd/docker-machine (fork) source tags to v0.16.2-gitlab.9 2026-09-28 https://gitlab.com/gitlab-org/ci-cd/docker-machine Depending on a vendor component means budgeting for the fork you will have to run Upstream docker/machine last commit 2019-09-02 (git); GitLab's fork carries nine patch tags beyond upstream's final 0.16.2
33 GitLab gitlab-runner source 2026 2026-09-28 https://gitlab.com/gitlab-org/gitlab-runner A decade-old consumer is still adding support for the alternatives, not the original Commits "Wire opt-in Podman integration tests into CI" 2026-09-09, "docker machine version 46" 2026-04-30 (git)
34 Docker / Moby Go module path source v29, November 2025 2026-09-28 https://pkg.go.dev/github.com/moby/moby/v2 The import path moved eight years after the repository did "Starting with Docker v29 (released November 2025), the Go module github.com/docker/docker is deprecated and won't be updated"
35 Docker classicswarm: commit 8653f6a "Archive this project" source 2020-06-11 2026-09-28 https://github.com/docker/classicswarm/commit/8653f6a0dadbb821ee701066530d57672018c2a2 The first orchestrator was archived four years after being superseded by the in-engine one Commit title; commits per year 2015:1,739, 2018:37, 2020:13 (git)
36 Docker / Moby swarmkit source 2016-02-11 to 2026 2026-09-28 https://github.com/moby/swarmkit The orchestration bet decayed by 99% without ever being cancelled Commits per year (git): 2016:2,601; 2018:272; 2024:37; 2025:32; latest tag v2.1.2, 2026-04-21
37 Docker / Moby ROADMAP.md history adr last substantive edit 2018-10-28 2026-09-28 https://github.com/moby/moby/blob/master/ROADMAP.md The engine's published roadmap stopped being maintained in 2018 Commit "Update roadmap to reflect reality" 2018-10-28; next touches are typo and link fixes, 2019-01-25 and 2025-08-01 (git)
38 Docker / Moby buildkit source first commit 2015-12-14, first tags 2018-10 2026-09-28 https://github.com/moby/buildkit The build layer became the most active part of the estate "docker build uses Buildx and BuildKit by default since Docker Engine 23.0"; commits per year 2018:952, 2024:1,449, 2026:1,065 (git)
39 Docker Python SDK for the Engine API vendor 7.2.0, 2026-07-09 2026-09-28 https://pypi.org/project/docker/ The client API contract is still shipped and current after a decade "A Python library for the Docker Engine API"; latest 7.2.0 released 2026-07-09