DEV Community

Asael Shinder
Asael Shinder

Posted on

Shipping Is Turning Into a Five Year Promise

For a long time the release was the finish line. You shipped, you celebrated, and the version you shipped slowly became something nobody wanted to touch. Old versions were the customer's problem, and upgrade to the latest was an acceptable answer to almost anything.

That is starting to change, and law is one of the reasons. In the European Union, the Cyber Resilience Act covers most products with software in them, from connected devices to plenty of ordinary software sold into that market. Its duty to report actively exploited vulnerabilities starts this month, and from the end of 2027 manufacturers must state a support period and provide security updates throughout it, generally for at least five years. Large buyers were already writing similar terms into contracts, and other regions are heading the same way.

Look at what that means for a working engineer. The version you ship in 2028 may still need a security fix in 2032. Somebody will have to build it, change it safely and release it, long after the people who wrote it have moved on.

Most teams are not ready. Try it on something you own. Could you take the release from two years ago, build it today from its own sources, change one line, and ship a patch without dragging in everything that changed since? For many teams the honest answer is not without a week of archaeology.

So some unglamorous skills are about to become valuable. Keeping old release branches buildable. Knowing what your dependencies are and which of them are still maintained. Writing code a stranger can safely change in five years. Designing updates that customers actually install. Deciding, deliberately and early, how many versions you are willing to support at once, because every extra one multiplies the work.

For your career this is an opening. Most engineers find maintenance dull and avoid it. The people who can say calmly, yes, we can patch that version and here is how, will end up in the rooms where products get planned, because a support period is a commercial promise as much as a technical one.

Monday: pick a release from last year and find out how long it would take you to ship a one line fix to it.

– Asael Shinder

Top comments (0)