Why We Retire Artifacts
Tyk has published packages and images continuously for many years. Very old artifacts accumulate known CVEs, predate our current security and build standards, and can mislead new users into deploying unsupported versions. Retiring them keeps our public repositories aligned with what we actually support and recommend.What Stays Available
Artifacts remain publicly downloadable for all versions within the supported release windows:- Current feature release — the latest release train
- Current LTS — in full support
- Previous LTS (LTS-1) — and the minor series leading up to it, retained for upgrade paths
How Retirement Works
- Monthly plan: on the first of each month we publish an internal retention plan listing every artifact that has become eligible for retirement.
- Notice period: no artifact is removed until at least 30 days after it first appears in a plan. The initial rollout of this policy carries an extended 90-day notice period.
- Archival before removal: every artifact is copied to a secure long-term archive, and its integrity verified by checksum, before it is removed from public repositories.
- Removal: after the notice period, the artifact is removed from public distribution channels (Packagecloud DEB/RPM repositories and Docker Hub).
Requesting a Retired Version
Archived artifacts are retained for five years from archival. If you need a retired version — for example to reproduce an old environment before upgrading — contact Tyk Support with the product, version, and package type (DEB/RPM/Docker image). Note:- Retrieval from long-term storage is not instant; allow up to 48 hours.
- Retired versions are provided as-is for migration purposes and remain unsupported.
- We will always recommend an upgrade path to a supported version alongside any restored artifact.