Vulnerability-free images, even after EOL
Stay with the image and library versions your business depends on, without sacrificing security.
Stay with the image and library versions your business depends on, without sacrificing security.

Stay on the image versions your applications depend on, even after upstream support ends.
Echo backports fixes without changing behavior, so workloads can continue to run as expected.
Critical and high CVEs are triaged within 24 hours and fixed in up to 7 days, even after upstream support ends.
Despite upstream support ending, Echo’s EOL images are continuously rebuilt so new pulls are always clean.
EOL versions remain available without forced migrations or breaking changes.
All fixed and unresolved vulnerabilities are clearly reported for accurate risk assessment.

EOL images use Echo’s controlled build infrastructure (SLSA L3), signed and attested for verification, and delivered with SBOM, provenance, and VEX metadata.
Echo removes the security trade-off from legacy and long-lived workloads to ensure you’re not accepting unnecessary risk.