Alpine Linux 3.21 End of Life: November 1, 2026
Alpine Linux 3.21 reaches end of support on November 1, 2026. Alpine prints that day itself: the release branches page lists the v3.21 branch (git branch 3.21-stable) with an End of support date of November 1, 2026. Alpine 3.21.0 was released on December 5, 2024, and the most recent 3.21 point release shipped on September 17, 2026, the same day as updates for 3.22, 3.23 and 3.24. For most teams Alpine is not a server operating system but a container base image, so the practical meaning of the date is this: anything built FROM alpine:3.21 stops getting routine security fixes from Alpine's main repository on that day, however often the image is rebuilt.
alpine:3.24 for the longest runway. Live status and the EOL Risk Score are on the Alpine 3.21 page.Alpine's support rule, in Alpine's words
Alpine's release branches page states the whole policy in three sentences. Branches are cut on a fixed rhythm: "Each May and November we make a release branch from edge." Support then splits by repository: the main repository "is typically supported for 2 years", and the community repository "is supported until next stable release". After the end of support date, the page adds, security fixes "can be made on request when there are patches available."
Two consequences matter for 3.21. First, the community repository stopped being maintained for 3.21 when Alpine 3.22 was released on May 30, 2025; Alpine's table now shows the support level of v3.21 as "main". Second, "on request" is real but not a schedule: Alpine 3.20 reached its end of support on April 1, 2026 and still received a point release on April 15, 2026, and the table now lists 3.20's support level as "on request". Treat the date as the end of routine fixes, not as a promise that nothing will ever ship again.
The current branches
End of support dates as Alpine prints them; the support level column is Alpine's own wording from its table as read on October 9, 2026. Each branch links to its live status page here.
| Branch | End of support | Support level (Alpine's table) | Status |
|---|---|---|---|
| Alpine 3.24 | June 1, 2028 | main and community | Supported |
| Alpine 3.23 | November 1, 2027 | main | Supported |
| Alpine 3.22 | May 1, 2027 | main | Approaching |
| Alpine 3.21 | November 1, 2026 | main | Approaching |
| Alpine 3.20 | April 1, 2026 | on request | EOL |
Every Alpine branch back to 2.1 is on our Alpine Linux lifecycle page, with the dates re-checked against Alpine's table at every build.
Key dates
- December 5, 2024: Alpine 3.21.0 released.
- May 30, 2025: Alpine 3.22.0 released. Under Alpine's rule, the community repository of 3.21 stops being supported at the next stable release.
- September 17, 2026: the most recent 3.21 point release, shipped together with updates for 3.22, 3.23 and 3.24.
- November 1, 2026: end of support for Alpine 3.21's main repository. This page.
- May 1, 2027: Alpine 3.22, the next branch to end.
Why it matters for container images
Docker Hub describes Alpine as a distribution built around musl libc and BusyBox. Inside an Alpine image, those, the apk package manager and whatever packages the Dockerfile adds with apk add all come from the repositories of one branch. An image built FROM alpine:3.21 installs from the v3.21 repositories, and so does every apk upgrade run against it later. After November 1, 2026 those repositories stop receiving routine fixes, so rebuilding the image no longer brings in new security patches. The only change that does is a new branch in the FROM line.
The Docker Official Image for alpine is maintained by an Alpine Linux maintainer, according to its Docker Hub page. When we read the page, its supported tags list carried edge, then one entry each for the 3.24, 3.23, 3.22 and 3.21 branches, each with a branch tag such as 3.21 and a full-version tag for that branch's newest point release; the 3.24 entry also carried the 3 and latest tags. Alpine 3.20 was not on the list. Three patterns are worth looking for in your Dockerfiles:
- Pinned to the branch (
alpine:3.21). Stable and reproducible, and the subject of this page: it stays on 3.21 after the date. - Pinned to a full version or digest (a three-part version tag, or an
@sha256:digest). Reproducible, but frozen even before the date: no point release reaches it until someone edits the tag. - Floating (
alpine:latestoralpine:3). Moves to each new branch as Docker Hub retags it, which avoids this deadline but can change musl, apk or package versions under a build without warning.
Language and application images that use Alpine as their base carry their own Alpine branch, and some name it in their tag. Treat each one as two lifecycles: the runtime's and the Alpine branch's. Our guide to end-of-life Docker base images covers that pairing across Debian, Ubuntu and Alpine.
How to check what you are running
Inside a container or on a host, the installed release is in one file:
cat /etc/alpine-release
From the host, without opening a shell in the container:
docker run --rm <image> cat /etc/alpine-release
The first two numbers are the branch; anything starting 3.21. is on the branch ending November 1, 2026. Then check where the system takes updates from, because that is what decides whether fixes keep arriving:
cat /etc/apk/repositories
Lines containing v3.21/main and v3.21/community mean the system is pinned to 3.21. Lines containing latest-stable follow whatever Alpine's newest branch is, which the Alpine wiki warns "may initiate unexpected release upgrades." For a fleet, an SBOM records Alpine packages as pkg:apk purls; our SBOM end-of-life audit guide shows how to read them, and our EOL Checker and API resolve the result against the dates above.
Upgrade path to a supported branch
- Pick the target branch. Alpine 3.24 is supported until June 1, 2028 and is the only branch Alpine's table lists with both main and community supported. Alpine 3.23 runs until November 1, 2027 and Alpine 3.22 until May 1, 2027. Moving to 3.22 means doing this again within months.
- Containers: change the base tag and rebuild. Replace
FROM alpine:3.21with the target branch tag, rebuild, and run the image's tests. The jump from 3.21 crosses the 3.23 release, whose release notes say apk-tools moved to version 3, which "might have breaking changes if you use libapk." The same notes call it "a safe and seamless upgrade from v2" for the package manager itself; anything linking libapk directly needs testing. - Installed systems: follow Alpine's wiki. The Upgrading Alpine Linux to a new release branch page gives three steps: edit the version in
/etc/apk/repositories(or runsetup-apkrepos), refresh the index withapk update, then runapk upgrade --available. The wiki adds that upgrading apk-tools itself first, withapk add --upgrade apk-tools, "shouldn't hurt", says to back up important data and read the release notes before starting, and notes that upgraded services need a restart and a new kernel needs a reboot. - Read each release's notes on the way. Alpine's news archive carries the release announcements for 3.22.0, 3.23.0 and 3.24.0; read each one you cross for changes that affect your packages.
- Check the rest of the image in the same pass. The runtime on top of Alpine (Node.js, Python, Java, PHP) has its own end-of-life date. Our EOL Checker takes both.
Frequently Asked Questions
When does Alpine Linux 3.21 reach end of life?
Alpine Linux 3.21 reaches end of support on November 1, 2026. That is the End of support date Alpine prints for the v3.21 branch on its release branches page at alpinelinux.org/releases.
Is Alpine 3.21 still supported?
Partly, until November 1, 2026. Alpine's release branches table lists the support level of v3.21 as main, not main and community. Under Alpine's rule the community repository is supported only until the next stable release, so packages from community on 3.21 have been unmaintained since Alpine 3.22 shipped. Packages from the main repository keep receiving fixes until the end of support date.
Which Alpine version should I upgrade to?
Alpine 3.24 is the newest branch and is supported until June 1, 2028, and it is the only branch Alpine's table lists with both the main and community repositories supported. Alpine 3.23 is supported until November 1, 2027 and Alpine 3.22 until May 1, 2027. Moving to 3.22 buys the least time; 3.24 avoids another branch upgrade for the longest.
What happens to Docker images based on alpine:3.21 after November 1, 2026?
The images keep running, but the v3.21 main repository they install and update packages from stops receiving routine security fixes. Alpine's page says fixes beyond the end of support can be made on request when patches are available, which is not something to plan a fleet around. Rebuilding an image pinned to alpine:3.21 after that day picks up no new routine fixes; changing the FROM line to a supported branch does.
How do I check which Alpine version a container runs?
Run cat /etc/alpine-release inside the container, or docker run --rm with the image name followed by cat /etc/alpine-release from the host. The first two numbers are the branch. Then check /etc/apk/repositories: the version in those repository lines, such as v3.21, is the branch the system takes updates from.
Related
- Alpine 3.21 — the live status page with its EOL Risk Score
- Alpine Linux — every branch's dates
- Alpine 3.24 · Alpine 3.23 · Alpine 3.22 — the upgrade targets
- End-of-life Docker base images — Debian, Ubuntu and Alpine tags and the operating systems they freeze
- SBOM end-of-life audit — finding Alpine packages in an SBOM
- 2026 EOL calendar — every dated end of support this year
- Alpine release branches — the vendor page these dates were read from
- How we verify our dates — the rules every number on this site is held to