DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

SBOM Enrichment Walkthrough: End-of-Life Data in a CycloneDX SBOM

Send a CycloneDX or SPDX SBOM to POST /v1/sbom?enrich=1 and get it back with end-of-life dates, status and risk on every component. Real input and output.

3. Reading the seven answers

Component What came back What it means
log4j-core 2.14.1 Line active, risk 10 (A), matched by purl The build is the Log4Shell build and any vulnerability scanner will say so. The lifecycle answer is different and just as true: the Log4j 2 line is still maintained, so a fix exists and upgrading inside the line is the whole remediation. The two signals are complementary, not redundant.
jackson-databind 2.13.4 version-not-tracked The product is tracked and matched by purl; the 2.13 line is not a cycle we carry. The response says so instead of guessing a date from a neighbouring line.
lodash 4.17.21 Line active, risk 10 (A) Supported line, extended support available if it ever stops being.
moment 2.29.4 Line active, risk 40 (B) Moment is in maintenance mode by its own maintainers' statement; still on a supported line, but the risk score reflects a project that has stopped moving.
django 3.2.25 eol, date April 1, 2024, risk 60 (C), source upstream, confidence medium Past end of life. The date came from the community dataset rather than a page we read at the vendor, and the response says so: a consumer can decide whether medium confidence is enough for its purpose.
postgres:13 (container) eol, date November 13, 2025, source vendor-fetched from postgresql.org, confidence high, scored: false Past end of life, with the date read from PostgreSQL's own versioning page and the day it was last verified. It carries no risk score only because this request was anonymous: the free tiers score the first five matched lines of a document and return lifecycle facts for all of them; a key raises the cap.
left-pad 1.3.0 not-tracked, reason purl not tracked Nobody publishes a lifecycle for it, so the response has nothing to say and says nothing. The summary block counts it under not_tracked.

What's covered

  • 1. The input: a seven-component SBOM
  • 2. The output: the same SBOM, annotated
  • 3. Reading the seven answers
  • 4. SPDX, and where the data lands
  • 5. Running it against your own SBOM

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-sbom-enrichment-walkthrough

Top comments (0)