Evidence ledger
One row per claim in The parts that outlived the product: ten years of Docker, read from its own repositories: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.
Field guide: The parts that outlived the product: ten years of Docker, read from its own repositories.
Category platform-and-infrastructure. Research date 2026-09-28. All links checked 2026-09-28.
Reachability note. This session's network policy allowed six hosts: github.com,
raw.githubusercontent.com, gitlab.com, pkg.go.dev, pypi.org and hub.docker.com. Every
other candidate host (company engineering blogs, kubernetes.io, lwn.net, USENIX, arXiv,
YouTube, NVD, access.redhat.com, the Internet Archive) returned a proxy denial, so this guide
contains no engineering-blog, talk or paper tier at all. That is a limit of the hunt, not of the
public record, and it is stated in the page. The compensation is that everything here sits in
tiers 9 to 11 of the hierarchy: source code, decision records and incident advisories.
Repository facts marked git were computed from bare, blobless clones taken on 2026-09-28
(git clone --bare --filter=blob:none) and are reproducible with the commands in the page's
"Keep hunting" section.
| # | Org | Title | Tier | Published | Checked | URL | Claim taken from it | Supporting quote or figure |
|---|---|---|---|---|---|---|---|---|
| 1 | Open Container Initiative | runc advisory: escape via /proc/self/exe (CVE-2019-5736) |
postmortem | 2019-02-11 | 2026-09-28 | https://github.com/advisories/GHSA-gxmr-w5mj-v8hh | The runtime boundary has been escapable from inside a container since the first widely deployed release | "runc through 1.0-rc6, as used in Docker before 18.09.2"; allows "attackers to overwrite the host runc binary (and consequently obtain host root access)"; CVSS 8.6 |
| 2 | Open Container Initiative | runc advisory: container breakouts due to internally leaked fds (CVE-2024-21626) | postmortem | 2024-01-31 | 2026-09-28 | https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv | Five years later the same class recurs through a different mechanism | "several file descriptors were inadvertently leaked internally within runc into runc init, including a handle to the host's /sys/fs/cgroup"; affected v1.0.0-rc93 to v1.1.11, patched v1.1.12 |
| 3 | Open Container Initiative | runc advisory: escape via masked path abuse (CVE-2025-31133) | postmortem | 2025-11-05 | 2026-09-28 | https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2 | The class was still producing High-severity escapes in late 2025 | "when using the container's /dev/null to mask files, runc would not perform sufficient verification that the source of the bind-mount was actually a real /dev/null inode"; CVSS 7.3; patched 1.2.8, 1.3.3, 1.4.0-rc.3 |
| 4 | Open Container Initiative | runc published security advisories, index | postmortem | 2021-12 to 2026-06 | 2026-09-28 | https://github.com/opencontainers/runc/security/advisories | Ten advisories in five years, three of them published on one day | Three High advisories dated 5 November 2025; a further advisory 13 June 2026 |
| 5 | Docker / Moby | moby advisory: AuthZ zero length regression (CVE-2024-41110) | postmortem | 2024-07-23 | 2026-09-28 | https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq | A 2018 fix was not carried across the branch lines created by the restructure | "A security issue was discovered In 2018 ... Although this issue was fixed in Docker Engine v18.09.1 in January 2019, the fix was not carried forward to later major versions, resulting in a regression" |
| 6 | Docker / Moby | Commit 2ac8a479c5: "Authz plugin security fixes for 0-length content and path validation" | source | 2018-11-26 | 2026-09-28 | https://github.com/moby/moby/commit/2ac8a479c53d9b8e67c55f1e283da9d85d2b3415 | The fix existed as a commit for six years before reaching a mainline tag | git tag --contains puts its first tagged appearance at v28.0.0-rc.1 (2025-02-06); git merge-base --is-ancestor returns false for v27.0.3 and v27.1.0 (git) |
| 7 | Docker / Moby | Commit bed37b6152: "Merge commit from fork, [master] AuthZ plugin security fixes" | source | 2024-07-23 | 2026-09-28 | https://github.com/moby/moby/commit/bed37b6152327ae67f37cebf2690b7d746b99fb6 | The 2024 fix is a merge whose second parent is the December 2018 commit | Merge parents c98f01ecf2 5282cb25d0; 2 files changed, 115 insertions, 7 deletions |
| 8 | Docker / Moby | Pull request #32691: "A new upstream project to break up Docker into independent components" | source | 2017-04-18 | 2026-09-28 | https://github.com/moby/moby/pull/32691 | The 2017 restructure was announced and argued in the repository itself | Hykes: "upstream components (containerd, linuxkit etc) -> Moby -> Docker CE -> Docker EE"; objection: "This is not gonna work nice for all the projects that depend on github.com/docker/docker" |
| 9 | Docker / Moby | Pull request #13602: "Add checkpoint/restore to docker API" | source | 2015-05-29, closed 2024-03-04 | 2026-09-28 | https://github.com/moby/moby/pull/13602 | A feature deferred across a component boundary can stay deferred for nine years | crosbymichael, 2016-02-08: "We are going to work together on this after the containerd integration"; closed unmerged 2024-03-04 with 320 comments |
| 10 | Docker / Moby | Closed, unmerged pull requests sorted by comments | source | 2014 to 2024 | 2026-09-28 | https://github.com/moby/moby/pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged+sort%3Acomments-desc | The most-argued proposals were closed rather than merged | #9176 build-time env vars (475 comments), #13602 checkpoint/restore (320), #34319 private registry mirror, opened 2017-07-31, closed 2024-07-25 (201) |
| 11 | Docker / Moby | moby/moby repository | source | 2013-01-18 to 2026-09-28 | 2026-09-28 | https://github.com/moby/moby | Engine commit volume fell by 90% between 2016 and 2021, then partly recovered | Commits per year (git): 2016:10,133; 2017:4,481; 2018:2,339; 2021:1,065; 2025:4,410. Repo page: 72.1k stars, 58,195 commits |
| 12 | Docker / Moby | Release tags of the engine | source | 2015-11-03 to 2025-11-10 | 2026-09-28 | https://github.com/moby/moby/tags | A 26-month gap between feature releases, and one release line abandoned | Tag dates (git): v1.12.0 2016-07-28; v17.03.0-ce 2017-02-23; v20.10.0 2020-12-09; v22.06.0-beta.0 2022-06-03 (no final); v23.0.0 2023-02-02; docker-v29.0.0 2025-11-10 |
| 13 | Docker / Moby | Commit 7d74269c0d: "Create the containerd image service" | source | 2022-07-05 | 2026-09-28 | https://github.com/moby/moby/commit/7d74269c0dafb71a760d8c669fca3d2df5778d2e | Docker began replacing its own image store with containerd's five years after donating it | First commit under daemon/containerd; 282 commits to that path in 2023 (git) |
| 14 | Docker / Moby | Commit 632de98f75: "Enable containerd snapshotters by default" | source | 2025-07-09 | 2026-09-28 | https://github.com/moby/moby/commit/632de98f75dc87e0e1900097ee1177aa64c8c45d | The default image store became containerd's in the v29 line, eight years after the donation | Commit title; follow-up "daemon: Do not default to c8d image store on Windows" 2025-09-01 (git) |
| 15 | Docker / Moby | Commit a8a1cfd111: "daemon: Add embedded containerd mode" | source | 2026-06-17 | 2026-09-28 | https://github.com/moby/moby/commit/a8a1cfd1114e7472590206f5ebb8e088beee7a1c | The decomposition is being partly reversed: containerd is moving back inside the daemon process | Release note quoted on the repository's releases page: "Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process" |
| 16 | Docker / Moby | Commit 53bd828853: "Remove libnetwork" | source | 2025-07-31 | 2026-09-28 | https://github.com/moby/moby/commit/53bd828853008b3187545849c1f2000f024861d0 | Networking, split out in 2015, was folded back into the daemon tree in 2025 | Preceding commit 7a720df61f "Move libnetwork to daemon/libnetwork" (2025-07-14); libnetwork repo last commit 2023-10-20 (git) |
| 17 | containerd | containerd README and project scope | adr | 2015-11-05 to 2026 | 2026-09-28 | https://github.com/containerd/containerd/blob/main/README.md | The component was defined by what it refuses to do | "containerd is designed to be embedded into a larger system, rather than being used directly by developers or end-users"; CNCF graduated |
| 18 | containerd | SCOPE.md: in scope and explicitly out of scope | adr | 2017 onward | 2026-09-28 | https://raw.githubusercontent.com/containerd/containerd/main/SCOPE.md | The scope document is an allow-list, and networking, build, logging and volumes are refused | "Networking will be handled and provided to containerd via higher level systems"; "Build is a higher level tooling feature and can be implemented in many different ways on top of containerd" |
| 19 | containerd | ADOPTERS.md | source | current | 2026-09-28 | https://raw.githubusercontent.com/containerd/containerd/main/ADOPTERS.md | The donated component is the runtime under every major managed Kubernetes service, and Docker is one entry on the list | 26 named adopters including GKE, EKS, AKS, AWS Fargate, Bottlerocket, k3s, Kata, Firecracker, and "Docker/Moby engine" |
| 20 | containerd | Release tags | source | 2017-12-04 to 2026-09-16 | 2026-09-28 | https://github.com/containerd/containerd/tags | Six years and eleven months between major versions; activity flat for a decade | v1.0.0 2017-12-04, v2.0.0 2024-11-05, v2.4.0 2026-09-16; commits per year 2017:3,152, 2020:1,356, 2026:1,355 (git) |
| 21 | Kubernetes | KEP-2221: Removing dockershim from kubelet | adr | 2020-12 (v1.20) to 2022 (v1.24) | 2026-09-28 | https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/2221-remove-dockershim/README.md | The consumer removed the special case once a standard interface had two implementations | "kubelet then has dependency on specific container runtime which leads to maintenance burden"; deprecation v1.20, removal v1.24 |
| 22 | Mirantis | cri-dockerd | source | repo history from 2016-07-22 | 2026-09-28 | https://github.com/Mirantis/cri-dockerd | The removed shim survives as a third-party product, carrying its original history | "Mirantis and Docker have agreed to partner to maintain the shim code standalone outside Kubernetes"; first commit "Add a dockershim package" 2016-07-22; commits fell to 17 in 2026 (git) |
| 23 | Open Container Initiative | image-spec and runtime-spec release tags | source | 2017-07-19 to 2025-11-04 | 2026-09-28 | https://github.com/opencontainers/image-spec/tags | The interface froze, and that is why everything on both sides of it could be replaced | image-spec v1.0.0 2017-07-19, v1.1.0 2024-02-15; commits per year 2016:642, 2018:16, 2020:8 (git) |
| 24 | Docker | docker/roadmap issue #87: "Anti-Abuse Rate Limits" | adr | 2020-05-07 | 2026-09-28 | https://github.com/docker/roadmap/issues/87 | Metering the registry started as an abuse control and became the business model | "20,000 pulls per 6 hour window" for anonymous users; "certain IPs pulling in excess of 60,000 times per 6 hour window" |
| 25 | Docker | docker/roadmap issue #7: "Improve Mac File system performance" | adr | 2020-03-06, closed 2024-02-06 | 2026-09-28 | https://github.com/docker/roadmap/issues/7 | The most-demanded item on the public roadmap was the boundary between the developer's machine and the Linux VM | Opened by nebuk89 2020-03-06; closed "Shipped! Enjoy!" with Docker Desktop 4.27, 2024-02-06 |
| 26 | Docker | Docker Hub usage: pull limits | vendor | current | 2026-09-28 | https://raw.githubusercontent.com/docker/docs/main/content/manuals/docker-hub/usage/pulls.md | The default registry is metered per identity | "100 per IPv4 address or IPv6 /64 subnet" per 6 hours unauthenticated; 200 for authenticated personal accounts; unlimited on paid plans |
| 27 | Docker | Docker Desktop licence terms | vendor | current | 2026-09-28 | https://raw.githubusercontent.com/docker/docs/main/content/manuals/subscription-billing/desktop-license.md | The client became a paid product above a size threshold | Free for "fewer than 250 employees AND less than $10 million in annual revenue", personal use, education and non-commercial open source |
| 28 | Docker | Docker Hub official image pull counters | vendor | week of 14-20 September 2026 | 2026-09-28 | https://hub.docker.com/_/nginx | The registry is the asset that kept its position | nginx: 21,498,949 pulls in the week of 14-20 September, "1B+" total; alpine: 25,142,478 in the same week |
| 29 | Red Hat / containers | podman | source | first commit 2017-11-01 | 2026-09-28 | https://github.com/containers/podman | A competing implementation of the same interfaces removed the daemon entirely | "No manager daemon, for improved security and lower resource utilization at idle"; 28,467 commits, 33k stars |
| 30 | abiosoft | colima | source | first commit 2021-09-04 | 2026-09-28 | https://github.com/abiosoft/colima | Replacement developer runtimes appeared within weeks of the Desktop licence change | First commit 2021-09-04; podman-desktop first commit 2022-03-08; rancher-desktop 2020-10-12 (git) |
| 31 | Kubernetes | registry.k8s.io | casestudy | 2022 | 2026-09-28 | https://github.com/kubernetes/registry.k8s.io | Large consumers eventually build their own registry rather than depend on someone else's economics | "significant egress traffic costs from users on other cloud providers"; migration off k8s.gcr.io announced November 2022 |
| 32 | GitLab | gitlab-org/ci-cd/docker-machine (fork) | source | tags to v0.16.2-gitlab.9 | 2026-09-28 | https://gitlab.com/gitlab-org/ci-cd/docker-machine | Depending on a vendor component means budgeting for the fork you will have to run | Upstream docker/machine last commit 2019-09-02 (git); GitLab's fork carries nine patch tags beyond upstream's final 0.16.2 |
| 33 | GitLab | gitlab-runner | source | 2026 | 2026-09-28 | https://gitlab.com/gitlab-org/gitlab-runner | A decade-old consumer is still adding support for the alternatives, not the original | Commits "Wire opt-in Podman integration tests into CI" 2026-09-09, "docker machine version 46" 2026-04-30 (git) |
| 34 | Docker / Moby | Go module path | source | v29, November 2025 | 2026-09-28 | https://pkg.go.dev/github.com/moby/moby/v2 | The import path moved eight years after the repository did | "Starting with Docker v29 (released November 2025), the Go module github.com/docker/docker is deprecated and won't be updated" |
| 35 | Docker | classicswarm: commit 8653f6a "Archive this project" | source | 2020-06-11 | 2026-09-28 | https://github.com/docker/classicswarm/commit/8653f6a0dadbb821ee701066530d57672018c2a2 | The first orchestrator was archived four years after being superseded by the in-engine one | Commit title; commits per year 2015:1,739, 2018:37, 2020:13 (git) |
| 36 | Docker / Moby | swarmkit | source | 2016-02-11 to 2026 | 2026-09-28 | https://github.com/moby/swarmkit | The orchestration bet decayed by 99% without ever being cancelled | Commits per year (git): 2016:2,601; 2018:272; 2024:37; 2025:32; latest tag v2.1.2, 2026-04-21 |
| 37 | Docker / Moby | ROADMAP.md history | adr | last substantive edit 2018-10-28 | 2026-09-28 | https://github.com/moby/moby/blob/master/ROADMAP.md | The engine's published roadmap stopped being maintained in 2018 | Commit "Update roadmap to reflect reality" 2018-10-28; next touches are typo and link fixes, 2019-01-25 and 2025-08-01 (git) |
| 38 | Docker / Moby | buildkit | source | first commit 2015-12-14, first tags 2018-10 | 2026-09-28 | https://github.com/moby/buildkit | The build layer became the most active part of the estate | "docker build uses Buildx and BuildKit by default since Docker Engine 23.0"; commits per year 2018:952, 2024:1,449, 2026:1,065 (git) |
| 39 | Docker | Python SDK for the Engine API | vendor | 7.2.0, 2026-07-09 | 2026-09-28 | https://pypi.org/project/docker/ | The client API contract is still shipped and current after a decade | "A Python library for the Docker Engine API"; latest 7.2.0 released 2026-07-09 |