Base Image EOL Lint - Dockerfile and CI end-of-life check

Marks every base image in your Dockerfiles, compose files and CI workflows whose security patches have already stopped - or stop before 13 November 2026 - and prints the tag that replaces it.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Marks every base image in your Dockerfiles, compose files and CI workflows whose security patches have already stopped - or stop before 13 November 2026 - and prints the tag that replaces it

Snyk's Team tier is $25 per contributing developer per month.

Buy the full version — $29

Questions people ask

What does Base Image EOL Lint actually do?

It reads the image references written in your repository - Dockerfile FROM lines, docker-compose image keys, GitHub Actions runner labels and container images - and marks every one whose vendor has stopped shipping security patches, or stops soon, with the exact tag that replaces it and the date behind the finding.

Who is it for?

Platform, DevOps and backend engineers who own the Dockerfiles and CI workflows in a repository: the person who answers when an auditor asks which base images are still supported, and the person who has to do the upgrade. If you maintain a multi-stage Dockerfile or a compose file, this reads your files.

Why will a free image scanner not do this?

Free scanners test an image that has already been built and pushed, and they report the vulnerable packages inside it. They cannot open the Dockerfile on your screen and tell you that FROM python:3.10-slim names a runtime whose final security release lands on 31 October 2026. Nothing that needs a built image can.

What is free and what needs a licence?

Free covers one whole file: open a Dockerfile, run the check, and all 21 rules report every finding with its severity and its replacement tag. Nothing is watermarked, timed or locked after N runs. The licence changes the scope only - every file in the repository at once, a dated exported report, and JSON for CI.

What would this cost otherwise?

Snyk's Team tier is $25 per contributing developer per month, and it still starts from a built image rather than the file you are editing. Auditing FROM lines by hand means grepping every repository each time a vendor retires a branch, which happens several times a year. This is $29 once.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool