<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: endoflife-ai</title>
    <description>The latest articles on DEV Community by endoflife-ai (@endoflifeai).</description>
    <link>https://dev.to/endoflifeai</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3921242%2Fdb4eb42d-6f16-4495-a004-a2711eea3ad9.png</url>
      <title>DEV Community: endoflife-ai</title>
      <link>https://dev.to/endoflifeai</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/endoflifeai"/>
    <language>en</language>
    <item>
      <title>Exploited at CVSS 10.0 - And the Vendor Never Checked Whether EOL Versions Are Affected</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Tue, 28 Jul 2026 16:56:58 +0000</pubDate>
      <link>https://dev.to/endoflifeai/exploited-at-cvss-100-and-the-vendor-never-checked-whether-eol-versions-are-affected-3phg</link>
      <guid>https://dev.to/endoflifeai/exploited-at-cvss-100-and-the-vendor-never-checked-whether-eol-versions-are-affected-3phg</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-arista-velocloud-eol" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;On July 27, CISA added a maximum-severity flaw in Arista's VeloCloud Orchestrator to its Known Exploited Vulnerabilities catalog and gave federal agencies until &lt;strong&gt;July 30&lt;/strong&gt; to fix it — three days.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144" rel="noopener noreferrer"&gt;Arista's advisory&lt;/a&gt; is clear and well written: it names the affected builds, names the fixed builds, publishes attacker IP addresses, and states plainly that the flaw "was discovered externally and is known to be actively exploited." If you run a supported version of VCO, you know exactly what to do.&lt;/p&gt;

&lt;p&gt;And then there is one line, sitting quietly among the version tables, that tells a very different group of people almost nothing:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"End of support software versions have not been assessed."&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Eight words. If you're running an end-of-support VeloCloud Orchestrator, that sentence is the entire answer you're going to get about a CVSS 10.0 vulnerability that attackers are using right now.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Arista actually disclosed
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Field&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CVE&lt;/td&gt;
&lt;td&gt;CVE-2026-16812&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVSS v3.1 / v4.0&lt;/td&gt;
&lt;td&gt;10.0 / 10.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Type&lt;/td&gt;
&lt;td&gt;OS command injection, VeloCloud Orchestrator (VCO) on-prem&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exploitation&lt;/td&gt;
&lt;td&gt;Discovered externally; known to be actively exploited&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Added to CISA KEV&lt;/td&gt;
&lt;td&gt;July 27, 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Federal remediation due&lt;/td&gt;
&lt;td&gt;July 30, 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Affected and fixed builds:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Branch&lt;/th&gt;
&lt;th&gt;Vulnerable&lt;/th&gt;
&lt;th&gt;Fixed in&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;VCO 5.2.x&lt;/td&gt;
&lt;td&gt;before 5.2.3.14&lt;/td&gt;
&lt;td&gt;5.2.3.14&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VCO 6.1.x&lt;/td&gt;
&lt;td&gt;before 6.1.3.4&lt;/td&gt;
&lt;td&gt;6.1.3.4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VCO 6.4.x&lt;/td&gt;
&lt;td&gt;before 6.4.2.4&lt;/td&gt;
&lt;td&gt;6.4.2.4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VCO 7.0.x&lt;/td&gt;
&lt;td&gt;before 7.0.0.1&lt;/td&gt;
&lt;td&gt;7.0.0.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;End-of-support versions&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Not assessed&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Arista also published three IPs observed in attacks: &lt;code&gt;8.19.75.217&lt;/code&gt;, &lt;code&gt;206.72.242.124&lt;/code&gt;, &lt;code&gt;206.72.242.162&lt;/code&gt;. That's genuinely useful disclosure — more than many vendors provide. This isn't a criticism of Arista's handling. It's about what the last row of that table means.&lt;/p&gt;

&lt;h2&gt;
  
  
  "Not assessed" is not "not affected"
&lt;/h2&gt;

&lt;p&gt;These two statements look similar and mean opposite things:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;"Version X is not affected."&lt;/strong&gt; Someone tested it. You're safe. Move on.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;"Version X has not been assessed."&lt;/strong&gt; Nobody tested it. You don't know. Nobody is going to tell you.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The natural reading of an advisory is that anything not listed as vulnerable is fine. That reading is wrong here — and it's wrong the same way across most vendor advisories. Vendors scope security testing to supported releases, because that's what support contracts oblige them to fix. Unsupported releases fall outside the investigation — not because they're believed safe, but because there'd be no patch to ship even if they were found vulnerable.&lt;/p&gt;

&lt;p&gt;So the position for someone on an end-of-support VCO is worse than it first appears. The vulnerability is confirmed exploited in the wild. The code path is old enough to plausibly exist in earlier builds. There's no assessment, no advisory update coming, and no fix. The exposure isn't merely unpatched — it's &lt;strong&gt;unmeasured&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The three-day clock, and what it accidentally reveals
&lt;/h2&gt;

&lt;p&gt;CISA added two vulnerabilities to the KEV catalog on July 27. Their deadlines are not the same:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE&lt;/th&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Due&lt;/th&gt;
&lt;th&gt;Window&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-16812&lt;/td&gt;
&lt;td&gt;Arista VeloCloud Orchestrator&lt;/td&gt;
&lt;td&gt;July 30&lt;/td&gt;
&lt;td&gt;3 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2025-68686&lt;/td&gt;
&lt;td&gt;Fortinet FortiOS&lt;/td&gt;
&lt;td&gt;August 10&lt;/td&gt;
&lt;td&gt;14 days&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Same catalog, same day, deadlines four times apart. This is &lt;a href="https://endoflife.ai/article-cisa-bod-26-04-eol" rel="noopener noreferrer"&gt;BOD 26-04&lt;/a&gt; working as designed: federal remediation deadlines now scale with composite risk — exposure, exploited status, automatability, impact — not a severity number. The VeloCloud flaw needs no credentials, is network-reachable, and hands over the host. The Fortinet issue requires prior filesystem-level compromise. One is a front door; the other is a cupboard inside a house you've already broken into.&lt;/p&gt;

&lt;p&gt;Both KEV entries carry the same required action, and it's worth quoting how it ends: apply vendor mitigations, &lt;em&gt;"or discontinue use of the product if mitigations are unavailable."&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Read that against "end of support software versions have not been assessed." For an unsupported VCO, vendor mitigations &lt;strong&gt;are&lt;/strong&gt; unavailable. CISA's own instruction, followed to its conclusion, says stop using it.&lt;/p&gt;

&lt;h2&gt;
  
  
  If you run VeloCloud Orchestrator today
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;On a supported branch:&lt;/strong&gt; upgrade to 5.2.3.14 / 6.1.3.4 / 6.4.2.4 / 7.0.0.1+. Check logs against the three published attacker IPs first — with active exploitation confirmed, assume you may be looking at an incident, not a maintenance window.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;On an end-of-support branch:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Restrict access to the VCO web interface now.&lt;/strong&gt; The attack needs network reachability and no credentials. Network controls are the one mitigation that doesn't depend on the vendor.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunt before you assume.&lt;/strong&gt; "Not assessed" cuts both ways — you can't rule your version in, but you can't rule it out either.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Don't wait for an advisory update.&lt;/strong&gt; There's no assessment scheduled. Your version's absence from the affected list is not future clearance; it's permanent silence.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Plan the upgrade as an incident cost, not a project.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The pattern this exposes
&lt;/h2&gt;

&lt;p&gt;This isn't really a story about one networking vendor. The usual description of end-of-life is that patches stop. True — and it understates the problem. What actually stops, in order:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Patches stop.&lt;/strong&gt; The well-understood part.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Assessment stops.&lt;/strong&gt; New vulnerabilities are no longer checked against your version — your risk becomes unmeasurable, not just unaddressed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Advisories go quiet.&lt;/strong&gt; Your version stops appearing in affected-product lists — which reads like safety and means absence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scanners lose the thread.&lt;/strong&gt; Tooling keyed to vendor advisories inherits the vendor's scope. No advisory entry, no finding.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That fourth step is the one that catches teams out. A scanner reporting nothing for an EOL system is not evidence of safety — it may just be repeating the vendor's silence back to you.&lt;/p&gt;

&lt;p&gt;The defence isn't a better scanner. It's knowing the lifecycle status of everything you run &lt;em&gt;before&lt;/em&gt; an advisory lands — so when one does, you already know whether you're inside the vendor's field of view or outside it.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;We track end-of-life dates and CVE risk for 490+ products at &lt;a href="https://endoflife.ai" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt; — free checker, API, and risk scores. Sources: &lt;a href="https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144" rel="noopener noreferrer"&gt;Arista Advisory 0144&lt;/a&gt;, &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;CISA KEV catalog&lt;/a&gt; (v2026.07.27).&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>networking</category>
      <category>sysadmin</category>
      <category>devops</category>
    </item>
    <item>
      <title>CISA rewrote how the US government handles dying software — twice this year</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Mon, 27 Jul 2026 14:40:07 +0000</pubDate>
      <link>https://dev.to/endoflifeai/cisa-rewrote-how-the-us-government-handles-dying-software-twice-this-year-17dj</link>
      <guid>https://dev.to/endoflifeai/cisa-rewrote-how-the-us-government-handles-dying-software-twice-this-year-17dj</guid>
      <description>&lt;p&gt;Two binding directives landed in 2026 that most of the private sector hasn't noticed — and together they're the clearest public statement yet of what competent vulnerability management looks like.&lt;/p&gt;

&lt;h2&gt;
  
  
  BOD 26-04 (June 10): severity scores are out, risk is in
&lt;/h2&gt;

&lt;p&gt;Since 2021, federal patching ran on a simple rule: CVE lands in CISA's Known Exploited Vulnerabilities catalog → fixed clock starts. BOD 26-04 supersedes that entirely. Now &lt;strong&gt;four questions&lt;/strong&gt; set the deadline for every vulnerability on every asset:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Asset Exposure&lt;/strong&gt; — is it publicly reachable?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;KEV Status&lt;/strong&gt; — is the CVE actively exploited in the wild?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exploit Automation&lt;/strong&gt; — can an adversary automate the whole attack?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Technical Impact&lt;/strong&gt; — partial or total control after exploitation?&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Worst case on all four: &lt;strong&gt;three calendar days&lt;/strong&gt; to remediate, plus mandatory forensic triage to check whether you're already compromised. Lowest tier: legitimately wait for the next scheduled upgrade. CISA pre-computes three of the four answers for every CVE through its Vulnrichment program.&lt;/p&gt;

&lt;p&gt;The design says the quiet part loudly: &lt;strong&gt;severity is not risk.&lt;/strong&gt; A CVSS 9.8 on an internal box with no exploit in the wild can matter less than a 7.5 being mass-exploited on your edge.&lt;/p&gt;

&lt;h2&gt;
  
  
  BOD 26-02 (February 5): end-of-support became a compliance deadline
&lt;/h2&gt;

&lt;p&gt;The one almost nobody covered. This directive targets a single category — &lt;strong&gt;end-of-support edge devices&lt;/strong&gt;: the firewalls, VPN appliances, and routers that face the internet and no longer receive vendor patches. Agencies got three months to find and remediate them, using a CISA-maintained EOS Edge Device List (yes — the US government now curates its own end-of-life database). The underlying OMB policy is blunt: unsupported systems must be "phased out as rapidly as possible."&lt;/p&gt;

&lt;h2&gt;
  
  
  The gap between the two directives
&lt;/h2&gt;

&lt;p&gt;26-04 optimizes patching for software that &lt;em&gt;can&lt;/em&gt; be patched. 26-02 evicts hardware that no longer can be. The gap: &lt;strong&gt;end-of-life software that isn't an edge device.&lt;/strong&gt; The directive defines remediation as "patching, decommissioning the system, or another action" — but for EOL software, the patching option is permanently gone. Every future KEV entry against a dead product arrives pre-aged: exploited, often automatable, unfixable except by migration. Risk that cannot decay.&lt;/p&gt;

&lt;p&gt;That's why lifecycle status is effectively the fifth risk variable — the one that determines whether the patch-based timelines are achievable at all. (It's the variable we build our &lt;a href="https://endoflife.ai/risk-score" rel="noopener noreferrer"&gt;EOL risk scores&lt;/a&gt; around, so yes, we're biased — but the government got here on its own.)&lt;/p&gt;

&lt;h2&gt;
  
  
  The 20-minute private-sector version
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Inventory with lifecycle status&lt;/strong&gt; — you can't triage what you haven't dated.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Adopt the four questions&lt;/strong&gt; for patch priority; Vulnrichment answers three of them for free.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Treat EOL as its own tier&lt;/strong&gt; — anything past end of support can never satisfy a patch deadline again. Migrate, or bridge with extended support while you do.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Both directives are public, battle-tested at federal scale, and free to copy: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;BOD 26-04&lt;/a&gt; · &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-02-mitigating-risk-end-support-edge-devices" rel="noopener noreferrer"&gt;BOD 26-02&lt;/a&gt;. Full analysis with the FAQ: &lt;a href="https://endoflife.ai/article-cisa-bod-26-04-eol" rel="noopener noreferrer"&gt;endoflife.ai/article-cisa-bod-26-04-eol&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>devops</category>
      <category>cybersecurity</category>
      <category>compliance</category>
    </item>
    <item>
      <title>One badge that tells your users when your dependencies die</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Sun, 26 Jul 2026 22:41:21 +0000</pubDate>
      <link>https://dev.to/endoflifeai/one-badge-that-tells-your-users-when-your-dependencies-die-1gbj</link>
      <guid>https://dev.to/endoflifeai/one-badge-that-tells-your-users-when-your-dependencies-die-1gbj</guid>
      <description>&lt;p&gt;Every README makes claims about support. Almost none of them stay true.&lt;/p&gt;

&lt;p&gt;"Requires Node 18+" — written in 2023, when Node 18 was the fresh LTS. Node 18 died in April 2025. The README didn't notice. Neither did most of the people reading it.&lt;/p&gt;

&lt;p&gt;I run &lt;a href="https://endoflife.ai" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;, a site that tracks end-of-life dates for 488 products, and the most requested thing after the data itself has been: &lt;em&gt;can my README just show this automatically?&lt;/em&gt; So we built badge endpoints for everything we track — here's what they look like and how to use them.&lt;/p&gt;

&lt;h2&gt;
  
  
  The badge
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight markdown"&gt;&lt;code&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;![Node.js end of life&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="sx"&gt;https://img.shields.io/endpoint?url=https%3A%2F%2Fendoflife.ai%2Fbadge%2Fnodejs.json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;](https://endoflife.ai/nodejs)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That renders a standard Shields.io badge showing the current support status of the newest Node.js release line — and it updates itself. When the status changes, the badge changes. Nobody edits the README.&lt;/p&gt;

&lt;p&gt;Here's the live one:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://endoflife.ai/nodejs" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fimg.shields.io%2Fendpoint%3Furl%3Dhttps%253A%252F%252Fendoflife.ai%252Fbadge%252Fnodejs.json" alt="Node.js end of life" width="188" height="20"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Swap &lt;code&gt;nodejs&lt;/code&gt; for whatever your project depends on: &lt;code&gt;python&lt;/code&gt;, &lt;code&gt;postgresql&lt;/code&gt;, &lt;code&gt;django&lt;/code&gt;, &lt;code&gt;spring-boot&lt;/code&gt;, &lt;code&gt;php&lt;/code&gt;, &lt;code&gt;kubernetes&lt;/code&gt; — &lt;a href="https://endoflife.ai/badge" rel="noopener noreferrer"&gt;488 products have endpoints&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Pin it to the version you actually support
&lt;/h2&gt;

&lt;p&gt;The more useful variant for most projects — badge your &lt;em&gt;minimum supported version&lt;/em&gt;, so users can see when your floor goes EOL:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight markdown"&gt;&lt;code&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;![Python 3.10 EOL&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="sx"&gt;https://img.shields.io/endpoint?url=https%3A%2F%2Fendoflife.ai%2Fbadge%2Fpython%2F3.10.json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;](https://endoflife.ai/python/3.10)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://endoflife.ai/python/3.10" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fimg.shields.io%2Fendpoint%3Furl%3Dhttps%253A%252F%252Fendoflife.ai%252Fbadge%252Fpython%252F3.10.json" alt="Python 3.10 EOL" width="220" height="20"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Python 3.10 dies October 31, 2026. The day it does, that badge flips — and your issue tracker finds out why you should bump the floor before your users do.&lt;/p&gt;

&lt;h2&gt;
  
  
  There's also a risk-score version
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight markdown"&gt;&lt;code&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;![EOL risk&lt;/span&gt;&lt;span class="p"&gt;](&lt;/span&gt;&lt;span class="sx"&gt;https://img.shields.io/endpoint?url=https%3A%2F%2Fendoflife.ai%2Fbadge%2Fscore%2Fnodejs.json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;](https://endoflife.ai/score/nodejs)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This one renders a 0–100 EOL risk score (factors: days to EOL, CVE exposure, whether the version appears in CISA's exploited-vulnerabilities catalog). Useful for internal dashboards and platform-team wikis more than public READMEs.&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works (nothing clever)
&lt;/h2&gt;

&lt;p&gt;Each badge is a static JSON file in the &lt;a href="https://shields.io/badges/endpoint-badge" rel="noopener noreferrer"&gt;Shields endpoint format&lt;/a&gt;, regenerated nightly from vendor lifecycle policies — the same dataset behind the site. No tracking, no API key, no rate limits beyond Shields' own caching. If you'd rather consume the raw data, every endpoint has a JSON API equivalent documented &lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The dates come from vendor policy pages and the &lt;a href="https://endoflife.date" rel="noopener noreferrer"&gt;endoflife.date&lt;/a&gt; community dataset (we're contributors), cross-checked nightly. When vendors change dates quietly — Microsoft moved a Windows 10 ESU date a full year with zero announcement in June — we correct loudly.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why I think this matters
&lt;/h2&gt;

&lt;p&gt;An EOL date in a README is a promise that decays. A badge is a promise that keeps itself. If your project pins a runtime, a framework, or a database version, your users deserve to know when that floor rots out from under them — preferably &lt;em&gt;before&lt;/em&gt; the CVEs arrive with no patches behind them.&lt;/p&gt;

&lt;p&gt;If a product you depend on is missing from the list, tell me and we'll add it.&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>github</category>
      <category>devops</category>
      <category>node</category>
    </item>
    <item>
      <title>The Next SharePoint 9.8 Arrived in Eight Days - And It Was the Last One With a Patch</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Fri, 24 Jul 2026 22:09:13 +0000</pubDate>
      <link>https://dev.to/endoflifeai/the-next-sharepoint-98-arrived-in-eight-days-and-it-was-the-last-one-with-a-patch-3db0</link>
      <guid>https://dev.to/endoflifeai/the-next-sharepoint-98-arrived-in-eight-days-and-it-was-the-last-one-with-a-patch-3db0</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-sharepoint-cve-2026-50522" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;On July 14, 2026, two things happened to SharePoint Server 2016 and 2019 at once: they reached end of extended support, and they received their final security update. At the time, the obvious question was how long before the next critical flaw showed up with no fix behind it.&lt;/p&gt;

&lt;p&gt;The answer turned out to be eight days.&lt;/p&gt;

&lt;p&gt;On July 22, CISA added &lt;strong&gt;CVE-2026-50522&lt;/strong&gt; to its Known Exploited Vulnerabilities catalog - a deserialization flaw in SharePoint Server rated &lt;strong&gt;CVSS 9.8&lt;/strong&gt;, yielding remote code execution. A public proof-of-concept exploit appeared on July 20; active exploitation followed within hours. Federal agencies were given until July 25 to remediate. Three days.&lt;/p&gt;

&lt;h2&gt;
  
  
  The twist that matters
&lt;/h2&gt;

&lt;p&gt;This one &lt;em&gt;was&lt;/em&gt; patched for 2016 and 2019 - in the July 14 updates, the same batch that closed CVE-2026-58644, and the same batch that was their last ever.&lt;/p&gt;

&lt;p&gt;So a fully updated 2016 or 2019 farm is covered against CVE-2026-50522. That is exactly why it's worth writing about: &lt;strong&gt;it is the final flaw those versions are on the right side of.&lt;/strong&gt; Every SharePoint vulnerability disclosed from here on has no fix for 2016 and 2019 - at any price.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why "it was patched" is not the reassurance it sounds like
&lt;/h2&gt;

&lt;p&gt;Two things are true at once:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you applied the July 14 updates&lt;/strong&gt;, you are protected against this specific flaw. That update earned its keep twice over - two critical, exploited-in-the-wild RCEs in one drop.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you did not&lt;/strong&gt;, you now have a public exploit and active in-the-wild attacks pointed at a version that can never be patched again. The July 14 update is still available and you should apply it today - but there is no next one. For a supported product, "we're a bit behind on patching" is a scheduling problem. For SharePoint 2016 and 2019 after July 14, it is the difference between the last fix and no fix.&lt;/p&gt;

&lt;p&gt;There is no Extended Security Updates program for SharePoint - unlike Windows 10 or Windows Server. No paid extension, no third-party equivalent, because nobody outside Microsoft can patch proprietary SharePoint code. July 14 was a hard cutoff.&lt;/p&gt;

&lt;h2&gt;
  
  
  This is a base rate, not a bad week
&lt;/h2&gt;

&lt;p&gt;CISA has flagged a run of actively exploited SharePoint vulnerabilities in a matter of months - CVE-2026-56164, CVE-2026-58644, and now CVE-2026-50522 among them - and issued a dedicated SharePoint hardening alert on July 14. SharePoint on-premises is internet-facing, holds the documents worth stealing, and sits inside the Windows identity fabric. That cadence does not slow down because a support date passed. What changed is that, from the next flaw onward, the response option for 2016 and 2019 is gone.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do this week if you're on 2016 or 2019
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Confirm the July 14, 2026 updates are installed&lt;/strong&gt; on every farm. A public exploit is circulating.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check for prior compromise.&lt;/strong&gt; CISA has reported attackers harvesting IIS machine keys from SharePoint to establish persistence - stolen keys survive patching. If a farm was internet-facing and unpatched during the exploitation window, rotate machine keys and treat an incident review as part of the response.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Take internet-facing farms off the public internet.&lt;/strong&gt; Migration is a quarter of work; removing internet exposure is an afternoon, and it converts an unpatchable internet-facing target into an unpatchable internal one.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pick a destination&lt;/strong&gt;: SharePoint Server Subscription Edition (on-premises, subscription licensing), SharePoint Online in Microsoft 365 (farm solutions don't migrate), or another platform. A typical enterprise migration runs 6-18 months - the clock is already running.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The general lesson
&lt;/h2&gt;

&lt;p&gt;An end-of-support date changes nothing about your software and everything about your options. CVE-2026-50522 is the cleanest possible demonstration: identical bug class, identical attacker behavior, identical severity to the flaws before it - and the only variable that moved is whether a fix exists on the other side. On July 13 it would have. Going forward it won't.&lt;/p&gt;

&lt;p&gt;Plan around the last &lt;em&gt;patch&lt;/em&gt; date, not the last release date - and check whether a product even has an ESU-style escape hatch before assuming a deadline is soft. SharePoint doesn't.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Track end-of-life dates and risk for 480+ products at &lt;a href="https://endoflife.ai" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt; - or check the &lt;a href="https://endoflife.ai/sharepoint" rel="noopener noreferrer"&gt;full SharePoint timeline&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>microsoft</category>
      <category>sysadmin</category>
      <category>devops</category>
    </item>
    <item>
      <title>Gold Eagle Can't Patch What Nobody Maintains: The EOL Hole in the White House's New Vulnerability Pipeline</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Mon, 20 Jul 2026 22:29:03 +0000</pubDate>
      <link>https://dev.to/endoflifeai/gold-eagle-cant-patch-what-nobody-maintains-the-eol-hole-in-the-white-houses-new-vulnerability-18bk</link>
      <guid>https://dev.to/endoflifeai/gold-eagle-cant-patch-what-nobody-maintains-the-eol-hole-in-the-white-houses-new-vulnerability-18bk</guid>
      <description>&lt;p&gt;On July 14, the White House launched &lt;strong&gt;Gold Eagle&lt;/strong&gt;, a national vulnerability coordination clearinghouse created by &lt;a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/" rel="noopener noreferrer"&gt;Executive Order 14409&lt;/a&gt;. The premise is sound and the timing is not subtle: AI systems are now discovering software vulnerabilities faster than human processes can verify, prioritize, and fix them, so the government is building machine-speed coordination to match. Gold Eagle is managed by the Treasury Department with contributions from CISA, DHS, and DoD, takes reports through the &lt;a href="https://www.cybersecuritydive.com/news/vulnerability-clearinghouse-ai-white-house-launch-gold-eagle/825298/" rel="noopener noreferrer"&gt;VINCE platform&lt;/a&gt; operated with Carnegie Mellon's Software Engineering Institute, and uses frontier AI models to help find and triage flaws.&lt;/p&gt;

&lt;p&gt;The numbers behind the launch are worth sitting with. The first half of 2026 produced &lt;strong&gt;35,364 CVEs&lt;/strong&gt; — more in six months than any full year before 2024 — with June alone contributing a record &lt;strong&gt;7,454&lt;/strong&gt;. &lt;a href="https://www.first.org/newsroom/releases/20260615" rel="noopener noreferrer"&gt;FIRST's mid-year forecast&lt;/a&gt; now projects roughly &lt;strong&gt;66,000 CVEs for 2026&lt;/strong&gt;, 46% above its own February estimate. One detail from that forecast deserves more attention than it's getting: &lt;em&gt;exploitable&lt;/em&gt; risk has stayed roughly flat. Discovery is what exploded. AI didn't suddenly make software more dangerous — it made the danger visible faster than anyone can respond to it.&lt;/p&gt;

&lt;p&gt;Gold Eagle is a reasonable answer to that problem. But there's a hole in the pipeline.&lt;/p&gt;

&lt;h2&gt;
  
  
  A clearinghouse routes fixes. EOL software has no address.
&lt;/h2&gt;

&lt;p&gt;Strip away the architecture and every vulnerability coordination system does the same thing: it receives a report, verifies it, and routes it to &lt;em&gt;the party who can ship the fix&lt;/em&gt; — the vendor, the maintainer, the project. The entire model rests on someone being at the end of the pipe.&lt;/p&gt;

&lt;p&gt;For end-of-life software, no one is. When a version's support window closes, the maintainer's obligation ends. A vulnerability found in an EOL version doesn't get triaged into a patch queue — it gets triaged into &lt;em&gt;nothing&lt;/em&gt;. Verify it, prioritize it, route it: the pipeline executes perfectly and delivers the report to an empty chair.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The arithmetic of the blind spot:&lt;/strong&gt; AI-assisted discovery doesn't distinguish between supported and unsupported code — if anything, older code yields flaws more readily. So as discovery scales toward 66,000 CVEs a year, the number found in end-of-life versions scales with it. Every one of those is permanent: no patch is coming, ever. Machine-speed discovery plus fixed-at-zero remediation equals a pile of unpatchable, publicly documented vulnerabilities growing at machine speed.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This isn't a design flaw in Gold Eagle — no clearinghouse can compel a maintainer to support software whose lifecycle has ended. It's a boundary condition. But it means the organizations most exposed to the CVE surge are precisely the ones running software the new national pipeline cannot help: the &lt;a href="https://endoflife.ai/centos" rel="noopener noreferrer"&gt;CentOS 7&lt;/a&gt; estates, the &lt;a href="https://endoflife.ai/angularjs" rel="noopener noreferrer"&gt;AngularJS&lt;/a&gt; frontends, the &lt;a href="https://endoflife.ai/spring-framework" rel="noopener noreferrer"&gt;old Spring&lt;/a&gt; services, the &lt;a href="https://endoflife.ai/php" rel="noopener noreferrer"&gt;PHP 7&lt;/a&gt; apps still quietly serving production traffic.&lt;/p&gt;

&lt;h2&gt;
  
  
  The triage question nobody's pipeline asks first
&lt;/h2&gt;

&lt;p&gt;For any newly disclosed vulnerability, the first question that determines everything downstream is not severity, not exploitability — it's &lt;strong&gt;"is the affected version still supported?"&lt;/strong&gt; The answer forks the entire response:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Lifecycle status&lt;/th&gt;
&lt;th&gt;What the disclosure means&lt;/th&gt;
&lt;th&gt;Your move&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Supported version&lt;/td&gt;
&lt;td&gt;A patch exists or is coming — the pipeline works&lt;/td&gt;
&lt;td&gt;Standard triage: assess, prioritize, patch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;End-of-life version&lt;/td&gt;
&lt;td&gt;No patch is coming — the pipeline ends at nothing&lt;/td&gt;
&lt;td&gt;Upgrade, isolate, or bridge with extended support — patching is not on the menu&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EOL version, CVE lists only supported versions as affected&lt;/td&gt;
&lt;td&gt;The worst case: your version is likely vulnerable but appears in no scanner&lt;/td&gt;
&lt;td&gt;Assume affected — &lt;a href="https://endoflife.ai/article-cve-blind-spot" rel="noopener noreferrer"&gt;the CVE blind spot&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;As triage itself becomes AI-driven — which is the whole point of Gold Eagle — that lifecycle question has to be answerable by machines, instantly, per component. Lifecycle data is becoming infrastructure that automated pipelines consume (&lt;a href="https://endoflife.ai/article-future-open-source-eol-ai" rel="noopener noreferrer"&gt;we wrote about exactly this shift two days before the launch&lt;/a&gt;), and Gold Eagle is now the most prominent machine reader in the world.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means if you run infrastructure
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;1. Your lifecycle inventory just became your triage pre-filter.&lt;/strong&gt; With disclosure volume heading toward 66,000 a year, per-CVE handling only scales if you can instantly partition your estate into "patchable" and "not patchable." That partition is your EOL status map — and it changes monthly: the median supported lifespan across the ecosystem is &lt;a href="https://endoflife.ai/article-software-lifespan-study" rel="noopener noreferrer"&gt;just 18 months&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. EOL components need a decision, not a backlog entry.&lt;/strong&gt; Every end-of-life system in your inventory now sits in the path of an accelerating disclosure firehose with no patch valve. The realistic options are the same three as always — upgrade, isolate, or extended support as a bridge — but "we'll get to it next year" now means absorbing a year of permanent CVEs at 2026 discovery rates. And the &lt;a href="https://endoflife.ai/eol-watch" rel="noopener noreferrer"&gt;H2 2026 calendar&lt;/a&gt; is dense with deadlines moving systems into this category: OpenSSL 3.0, Oracle JDK 17, PostgreSQL 14, PHP 8.2, .NET 8 and 9.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Watch the flat-exploitation line, but don't lean on it.&lt;/strong&gt; FIRST's observation that exploitable risk has stayed flat is genuinely reassuring for supported software, where patches drain the pool. For EOL software the pool only fills. The gap between "documented vulnerabilities" and "exploited vulnerabilities" is a lag, not a law — and for unpatchable systems, every documented flaw waits indefinitely for its turn.&lt;/p&gt;

&lt;h2&gt;
  
  
  The bottom line
&lt;/h2&gt;

&lt;p&gt;Gold Eagle is the clearest official acknowledgment yet that vulnerability management has crossed into the machine-speed era. It will likely make patching faster where patches exist. But it also sharpens the line between two kinds of software: the kind connected to a maintainer, which the national pipeline can now help faster than ever — and the kind that isn't, which no pipeline can help at all.&lt;/p&gt;

&lt;p&gt;Knowing which side of that line every component in your stack sits on, at all times, is no longer hygiene. It's the entry ticket to functioning triage. You can &lt;a href="https://endoflife.ai/checker" rel="noopener noreferrer"&gt;check any version in seconds&lt;/a&gt; or &lt;a href="https://endoflife.ai/scanner" rel="noopener noreferrer"&gt;scan your whole stack&lt;/a&gt; — against dates &lt;a href="https://endoflife.ai/accuracy" rel="noopener noreferrer"&gt;verified against vendor sources&lt;/a&gt;.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://endoflife.ai/article-gold-eagle-eol-blind-spot" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt; — the software lifecycle database tracking EOL dates and risk scores for 485 products.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>opensource</category>
      <category>devops</category>
    </item>
    <item>
      <title>The EU Cyber Resilience Act Has an EOL Problem — and the Deadline Isn't the One You Think</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Sat, 18 Jul 2026 02:15:28 +0000</pubDate>
      <link>https://dev.to/endoflifeai/the-eu-cyber-resilience-act-has-an-eol-problem-and-the-deadline-isnt-the-one-you-think-294b</link>
      <guid>https://dev.to/endoflifeai/the-eu-cyber-resilience-act-has-an-eol-problem-and-the-deadline-isnt-the-one-you-think-294b</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-eu-cra-eol-compliance" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Most conversations about the EU Cyber Resilience Act (Regulation (EU) 2024/2847) anchor on one date: the main obligations apply from &lt;strong&gt;December 11, 2027&lt;/strong&gt;. That date is real — and comfortably far away, which is exactly the problem.&lt;/p&gt;

&lt;p&gt;Buried inside the CRA is a much nearer deadline: &lt;strong&gt;the vulnerability and incident reporting obligations begin September 11, 2026.&lt;/strong&gt; That's weeks away, not next year's problem. And the debt those obligations expose is one most teams have never inventoried: every end-of-life component sitting inside a product they ship.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the CRA turns EOL into a regulatory problem
&lt;/h2&gt;

&lt;p&gt;The CRA applies to "products with digital elements" placed on the EU market — software and connected products, regardless of where the manufacturer is based. Under the regulation as adopted, manufacturers must:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Know their components&lt;/strong&gt; (SBOM-style documentation obligations)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Handle vulnerabilities and provide security updates&lt;/strong&gt; through a declared support period&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Report actively exploited vulnerabilities and severe incidents&lt;/strong&gt; — starting September 11, 2026&lt;/li&gt;
&lt;li&gt;Face penalties up to the higher of &lt;strong&gt;€15M or 2.5% of global annual turnover&lt;/strong&gt; for the most serious infringements&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Here's the collision: &lt;strong&gt;you cannot provide security updates for a product whose components no longer receive security updates.&lt;/strong&gt; An EOL library inside a shipped product is a support-period promise you cannot keep. Before the CRA, that was tech debt. Under the CRA, it's a compliance gap with a fine attached.&lt;/p&gt;

&lt;p&gt;(Not legal advice — obligations vary by product category; verify against the regulation text and current guidance.)&lt;/p&gt;

&lt;h2&gt;
  
  
  What a component inventory actually finds
&lt;/h2&gt;

&lt;p&gt;These aren't hypotheticals — they're the most common findings in real dependency scans, with dates verified against vendor lifecycle data:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;EOL date&lt;/th&gt;
&lt;th&gt;Status today&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Debian 10 base images&lt;/td&gt;
&lt;td&gt;Sep 10, 2022&lt;/td&gt;
&lt;td&gt;~4 years unpatched&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AngularJS (any version)&lt;/td&gt;
&lt;td&gt;Dec 31, 2021&lt;/td&gt;
&lt;td&gt;~4.5 years unpatched&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OpenSSL 3.0&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Sep 7, 2026&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;dies 4 days before the CRA reporting deadline&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;.NET 8&lt;/td&gt;
&lt;td&gt;Nov 10, 2026&lt;/td&gt;
&lt;td&gt;dies during the CRA's first reporting quarter&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;That OpenSSL line is worth a second look: the TLS library embedded in half the world's software loses upstream support &lt;strong&gt;four days before&lt;/strong&gt; the CRA's reporting obligations begin.&lt;/p&gt;

&lt;h2&gt;
  
  
  The lead-time trap
&lt;/h2&gt;

&lt;p&gt;The real danger isn't the deadline — it's the arithmetic in front of it. Component inventory takes months. Remediation takes quarters. Migrating off every EOL dependency competes directly with your product roadmap. A team that starts discovery in 2027 has already missed the runway; the reporting obligations will be a year old before their inventory is done.&lt;/p&gt;

&lt;h2&gt;
  
  
  The compliance-ready EOL process
&lt;/h2&gt;

&lt;p&gt;Four working parts, all automatable:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Continuous component inventory&lt;/strong&gt; — scan dependency files with a &lt;a href="https://endoflife.ai/scanner" rel="noopener noreferrer"&gt;stack scanner&lt;/a&gt;, check individual products in a &lt;a href="https://endoflife.ai/checker" rel="noopener noreferrer"&gt;free checker&lt;/a&gt;, and gate CI on the &lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;free API&lt;/a&gt; so an EOL component fails loudly instead of shipping quietly:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.endoflife.ai/v1/status/dotnet/8
&lt;span class="c"&gt;# "is_eol": false — until November 10, 2026.&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Lifecycle dates tracked against a live source, not a spreadsheet&lt;/strong&gt; — vendors move dates; a January export is a liability by June. &lt;a href="https://endoflife.ai/eol-watch" rel="noopener noreferrer"&gt;endoflife.ai/eol-watch&lt;/a&gt; tracks what's coming, and every product page publishes an .ics calendar feed.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Risk-ranked remediation&lt;/strong&gt; — an inventory with two hundred findings needs an ordering. &lt;a href="https://endoflife.ai/risk-score" rel="noopener noreferrer"&gt;Risk scores&lt;/a&gt; rank components by recency, exposure, and exploitation signals, so the migration queue starts with the components most likely to produce exactly the incidents the CRA makes reportable.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;A plan for components you can't migrate in time&lt;/strong&gt; — commercial extended-support vendors keep security patches flowing for EOL components, which maps directly onto the "updates during the support period" obligation. It's a bridge, not a destination — but for a 2026 deadline, bridges matter.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The reframe
&lt;/h2&gt;

&lt;p&gt;The CRA converts lifecycle hygiene from an engineering virtue into a &lt;strong&gt;market-access requirement&lt;/strong&gt; for the EU. The teams treating it as a 2027 problem are the ones who will discover, in 2027, that it was a 2026 problem.&lt;/p&gt;

&lt;p&gt;Full breakdown with verified dates: &lt;a href="https://endoflife.ai/article-eu-cra-eol-compliance" rel="noopener noreferrer"&gt;endoflife.ai/article-eu-cra-eol-compliance&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>devops</category>
      <category>compliance</category>
      <category>opensource</category>
    </item>
    <item>
      <title>We Measured the Lifespan of 7,144 Software Versions. The Median Is 18 Months.</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Fri, 17 Jul 2026 11:36:09 +0000</pubDate>
      <link>https://dev.to/endoflifeai/we-measured-the-lifespan-of-7144-software-versions-the-median-is-18-months-2dh0</link>
      <guid>https://dev.to/endoflifeai/we-measured-the-lifespan-of-7144-software-versions-the-median-is-18-months-2dh0</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-software-lifespan-study" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;We run a database that tracks end-of-life dates for 485 software products — every version, every release date, every day the security patches stop. Which means we're sitting on something nobody else has bothered to assemble: enough lifecycle data to answer a simple question with actual numbers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long does a software version actually live?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We measured every version in the dataset with both a firm release date and a firm end-of-life date — 7,144 versions across 463 products — and computed the span between them.&lt;/p&gt;

&lt;h2&gt;
  
  
  The headline: 18 months
&lt;/h2&gt;

&lt;p&gt;The &lt;strong&gt;median supported lifespan of a software version is 1.5 years&lt;/strong&gt;. The mean is 2.3 years (a long tail of enterprise products drags it up).&lt;/p&gt;

&lt;p&gt;Sit with that. The thing you deployed, integrated, and built muscle memory around has — statistically — about eighteen months of security patches from the day it shipped. If your upgrade cadence is "every two or three years," the math says you spend a meaningful slice of every cycle running unpatched software. Not because you're negligent — because the clock is shorter than most people's mental model of it.&lt;/p&gt;

&lt;h2&gt;
  
  
  By category: cloud dies fastest, hardware lives longest
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Category&lt;/th&gt;
&lt;th&gt;Versions measured&lt;/th&gt;
&lt;th&gt;Median lifespan&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Hardware&lt;/td&gt;
&lt;td&gt;100&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;2.9 yrs&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Operating systems&lt;/td&gt;
&lt;td&gt;370&lt;/td&gt;
&lt;td&gt;1.6 yrs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Databases&lt;/td&gt;
&lt;td&gt;228&lt;/td&gt;
&lt;td&gt;1.6 yrs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security tools&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;td&gt;1.3 yrs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Frameworks&lt;/td&gt;
&lt;td&gt;195&lt;/td&gt;
&lt;td&gt;1.1 yrs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Runtimes&lt;/td&gt;
&lt;td&gt;221&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1.0 yr&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud services&lt;/td&gt;
&lt;td&gt;142&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;0.9 yrs&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Two things jump out:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The stack rots from the top.&lt;/strong&gt; The layers you interact with most — runtimes, frameworks, managed cloud services — turn over fastest. The infrastructure underneath (OS, database, hardware) gives you roughly 60–190% more runway. Your Node version will die before your Postgres version, which will die before your server.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cloud services have the shortest leash of anything we measured.&lt;/strong&gt; A managed service version's median lifespan is under a year — and unlike self-hosted software, when a cloud version dies you don't get to quietly keep running it. The provider migrates you on their schedule.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The extremes
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Longest-lived (median across versions):&lt;/strong&gt; Internet Explorer at &lt;strong&gt;17.0 years&lt;/strong&gt; — say what you want about IE, Microsoft supported it longer than some of its users' entire careers. Then Atlassian Data Center (12.2), Raspberry Pi (11.7), Apache HTTP Server (11.6), and NVIDIA GPUs (11.5).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Shortest-lived:&lt;/strong&gt; a cluster of rolling-release projects — Chrome, Firefox, Rust, Prometheus, Neo4j among them — where each version gets roughly &lt;strong&gt;five weeks&lt;/strong&gt; before the next one replaces it. That model works &lt;em&gt;because&lt;/em&gt; upgrades are continuous and boring. The danger zone isn't rapid release; it's rapid release consumed at an enterprise pace.&lt;/p&gt;

&lt;h2&gt;
  
  
  Methodology, briefly
&lt;/h2&gt;

&lt;p&gt;All data comes from the &lt;a href="https://endoflife.ai" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt; dataset (built on the open-source endoflife.date project plus vendor lifecycle pages). We only measured versions with firm dates on both ends — no TBDs, no estimates — and used medians because enterprise long-tails skew means. Full methodology and tables are in the &lt;a href="https://endoflife.ai/article-software-lifespan-study" rel="noopener noreferrer"&gt;original article&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do with this number
&lt;/h2&gt;

&lt;p&gt;If the median version lives 18 months, then "check lifecycle dates once, at adoption time" is a broken process — the answer changes underneath you. The fix is making the check continuous:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Look up anything in seconds: &lt;a href="https://endoflife.ai/checker" rel="noopener noreferrer"&gt;free checker&lt;/a&gt;, or scan a whole dependency file with the &lt;a href="https://endoflife.ai/scanner" rel="noopener noreferrer"&gt;stack scanner&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Gate it in CI with the &lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;free API&lt;/a&gt;:
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.endoflife.ai/v1/status/python/3.10
&lt;span class="c"&gt;# "is_eol": false — until October 31, 2026.&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Watch the big deadlines: the back half of 2026 alone kills OpenSSL 3.0, Oracle JDK 17, Python 3.10, .NET 8 &lt;em&gt;and&lt;/em&gt; 9, PostgreSQL 14, and PHP 8.2 — the full calendar is at &lt;a href="https://endoflife.ai/eol-watch" rel="noopener noreferrer"&gt;endoflife.ai/eol-watch&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Eighteen months. Plan accordingly.&lt;/p&gt;

</description>
      <category>programming</category>
      <category>devops</category>
      <category>security</category>
      <category>data</category>
    </item>
    <item>
      <title>Your ESXi Hosts Are on Two Clocks Now: Support Dates and the Broadcom Licensing Squeeze</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Thu, 16 Jul 2026 02:22:49 +0000</pubDate>
      <link>https://dev.to/endoflifeai/your-esxi-hosts-are-on-two-clocks-now-support-dates-and-the-broadcom-licensing-squeeze-aaf</link>
      <guid>https://dev.to/endoflifeai/your-esxi-hosts-are-on-two-clocks-now-support-dates-and-the-broadcom-licensing-squeeze-aaf</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-vmware-esxi-eol" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;If you run ESXi, you're managing two countdowns at once — and they interact badly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Clock one: support dates.&lt;/strong&gt; vSphere/ESXi 7.x reached end of general support on &lt;strong&gt;October 2, 2025&lt;/strong&gt; (Broadcom extended it six months from the original April date — a one-time mercy, already spent). After end of general support: no more bug fixes or security patches, no support cases. Hypervisors are a top-tier attack target; an unpatched hypervisor is a very different risk than an unpatched app server, because everything above it inherits the compromise.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Clock two: licensing.&lt;/strong&gt; Broadcom killed perpetual licenses in December 2023. Everything is subscription now, bundles have consolidated, and renewal quotes have become the stuff of sysadmin forum legend. The practical effect: staying current with VMware isn't just an upgrade project anymore, it's a recurring budget line that many orgs are re-evaluating from scratch.&lt;/p&gt;

&lt;h2&gt;
  
  
  The trap between the clocks
&lt;/h2&gt;

&lt;p&gt;Plenty of teams responded to the licensing shock by &lt;em&gt;freezing&lt;/em&gt; — staying on 7.x, skipping the renewal, running on inertia. That converts a licensing problem into a security problem: you're now on an unsupported hypervisor with no patch path, which is strictly worse than either paying up or migrating.&lt;/p&gt;

&lt;h2&gt;
  
  
  The realistic options
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Renew under subscription and move to 8.x&lt;/strong&gt; — least disruption, highest recurring cost. Check current version support windows against Broadcom's own lifecycle matrix before committing; the dates have moved before.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Migrate hypervisors&lt;/strong&gt; — Proxmox VE, Hyper-V, and Nutanix all absorb refugees. Real work (tooling, backup integration, muscle memory), but a one-time cost versus a forever subscription. &lt;a href="https://endoflife.ai/proxmox-ve" rel="noopener noreferrer"&gt;Proxmox's own lifecycle&lt;/a&gt; is worth checking as part of due diligence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hybrid retreat&lt;/strong&gt; — shrink the VMware footprint to the workloads that genuinely need it, move the commodity VMs elsewhere, renew a smaller subscription.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Whatever the choice, it should be made &lt;em&gt;by a date on a calendar&lt;/em&gt;, not by drift. Every ESXi version's current status is tracked live at &lt;a href="https://endoflife.ai/esxi" rel="noopener noreferrer"&gt;endoflife.ai/esxi&lt;/a&gt; — and the rest of your stack's deadlines (SharePoint and SQL Server 2016 just died July 14; OpenSSL 3.0, .NET 8/9, PostgreSQL 14, and PHP 8.2 all go before year-end) are at &lt;a href="https://endoflife.ai/eol-watch" rel="noopener noreferrer"&gt;endoflife.ai/eol-watch&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Free &lt;a href="https://endoflife.ai/checker" rel="noopener noreferrer"&gt;checker&lt;/a&gt;, free &lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;API&lt;/a&gt;, dates verified against vendor lifecycle sources.&lt;/p&gt;

</description>
      <category>vmware</category>
      <category>virtualization</category>
      <category>sysadmin</category>
      <category>devops</category>
    </item>
    <item>
      <title>.NET 8 and .NET 9 Both Die on November 10 - Yes, the LTS Too</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Thu, 16 Jul 2026 02:21:19 +0000</pubDate>
      <link>https://dev.to/endoflifeai/net-8-and-net-9-both-die-on-november-10-yes-the-lts-too-1kig</link>
      <guid>https://dev.to/endoflifeai/net-8-and-net-9-both-die-on-november-10-yes-the-lts-too-1kig</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-dotnet-eol-2026" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Here's a date collision that surprises people: &lt;strong&gt;.NET 8 and .NET 9 reach end of support on the same day — November 10, 2026.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The instinctive reaction is "but 8 is the LTS!" — and that's exactly the trap. LTS doesn't mean &lt;em&gt;long&lt;/em&gt;, it means &lt;em&gt;longer&lt;/em&gt;. The math:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;.NET 8 (LTS)&lt;/strong&gt;: released November 2023, supported 3 years → dies November 10, 2026&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;.NET 9 (STS)&lt;/strong&gt;: released November 2024, supported 2 years → dies November 10, 2026&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Different tracks, same cliff. Anyone who "played it safe" on the LTS and anyone who rode the STS end up in the identical position this November.&lt;/p&gt;

&lt;h2&gt;
  
  
  What end of support actually means
&lt;/h2&gt;

&lt;p&gt;After November 10, Microsoft ships &lt;strong&gt;no security patches&lt;/strong&gt; for either runtime — including for vulnerabilities that get actively exploited later. Your app keeps running; it just stops getting defended. CVEs published against the runtime after that date are permanent for you.&lt;/p&gt;

&lt;p&gt;For teams with compliance obligations, "unsupported runtime in production" is an audit finding, not a philosophical debate.&lt;/p&gt;

&lt;h2&gt;
  
  
  The only forward path is .NET 10
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;.NET 10 (LTS)&lt;/strong&gt; shipped November 11, 2025 and is supported to &lt;strong&gt;November 14, 2028&lt;/strong&gt;. For most 8→10 moves the upgrade is mercifully boring — retarget, run the test suite, chase a handful of breaking changes. The teams that get hurt are the ones who discover a transitive dependency pinned to an EOL runtime in &lt;em&gt;December&lt;/em&gt;, not the ones who retargeted in September.&lt;/p&gt;

&lt;p&gt;Worth separating in your head: &lt;strong&gt;.NET Framework 4.8&lt;/strong&gt; (the old Windows-only one) is a different animal — it has no fixed end date and lives as long as the Windows version hosting it. Modern .NET (Core lineage) is the one on the November clock. If you're still on Framework, your deadline is &lt;a href="https://endoflife.ai/article-windows-server-2012-esu-cliff" rel="noopener noreferrer"&gt;your Windows Server's deadline&lt;/a&gt; instead.&lt;/p&gt;

&lt;h2&gt;
  
  
  Put a date on it
&lt;/h2&gt;

&lt;p&gt;The November 10 cutoff sits inside a brutal H2 2026 calendar: SharePoint 2016/2019 and SQL Server 2016 already died July 14, OpenSSL 3.0 goes September 7, Python 3.10 on October 31, PostgreSQL 14 on November 12, PHP 8.2 on December 31.&lt;/p&gt;

&lt;p&gt;Every date above is verified against vendor lifecycle sources. Full deadline coverage lives at &lt;a href="https://endoflife.ai/eol-watch" rel="noopener noreferrer"&gt;endoflife.ai/eol-watch&lt;/a&gt;, you can check any product's status in seconds with the &lt;a href="https://endoflife.ai/checker" rel="noopener noreferrer"&gt;EOL checker&lt;/a&gt;, or scan a whole project file with the &lt;a href="https://endoflife.ai/scanner" rel="noopener noreferrer"&gt;stack scanner&lt;/a&gt;. There's also a &lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;free API&lt;/a&gt; if you'd rather gate this in CI:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.endoflife.ai/v1/status/dotnet/8
&lt;span class="c"&gt;# "is_eol": false ... until November 10.&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



</description>
      <category>dotnet</category>
      <category>csharp</category>
      <category>programming</category>
      <category>security</category>
    </item>
    <item>
      <title>Windows Server 2012 Loses Its Last Safety Net on October 13 - Here's the Actual Decision Tree</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Thu, 16 Jul 2026 02:19:24 +0000</pubDate>
      <link>https://dev.to/endoflifeai/windows-server-2012-loses-its-last-safety-net-on-october-13-heres-the-actual-decision-tree-2f6a</link>
      <guid>https://dev.to/endoflifeai/windows-server-2012-loses-its-last-safety-net-on-october-13-heres-the-actual-decision-tree-2f6a</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/article-windows-server-2012-esu-cliff" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Windows Server 2012 and 2012 R2 officially left extended support back in &lt;strong&gt;October 2023&lt;/strong&gt;. But almost nobody actually said goodbye — Microsoft sold three years of Extended Security Updates (ESU), and a huge slice of the installed base has been quietly riding that program ever since.&lt;/p&gt;

&lt;p&gt;That ride ends on &lt;strong&gt;October 13, 2026&lt;/strong&gt;. ESU Year 3 is the final year. There is no Year 4.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually stops
&lt;/h2&gt;

&lt;p&gt;ESU was already a reduced diet: Critical and Important security fixes only — no new features, no non-security bug fixes, no design changes. After October 13:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;No security patches of any severity&lt;/strong&gt;, even for actively exploited vulnerabilities&lt;/li&gt;
&lt;li&gt;No Microsoft support tickets for these systems&lt;/li&gt;
&lt;li&gt;Compliance frameworks (PCI, SOC 2, cyber-insurance questionnaires) start flagging the OS as unsupported software&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If the workload matters enough to have paid for ESU three years running, it matters enough to have a plan for October 14.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why these boxes still exist
&lt;/h2&gt;

&lt;p&gt;In most shops it isn't laziness — it's the app layer. The 2012-era server is usually alive because it hosts a legacy &lt;strong&gt;.NET Framework&lt;/strong&gt; application, a line-of-business tool with no vendor, or something with a hardware dongle attached. The OS deadline is really an &lt;em&gt;application&lt;/em&gt; deadline wearing a costume.&lt;/p&gt;

&lt;p&gt;(Related: &lt;a href="https://endoflife.ai/dotnetfx" rel="noopener noreferrer"&gt;.NET Framework's lifecycle&lt;/a&gt; is tied to the Windows version hosting it — so a 2012 box dying can take its runtime support with it.)&lt;/p&gt;

&lt;h2&gt;
  
  
  The decision tree, honestly
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Can you migrate the workload before October?&lt;/strong&gt; Do it. Windows Server 2022/2025, or containerize the app if it will tolerate it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Can't migrate but can lift the VM to Azure?&lt;/strong&gt; ESU is &lt;strong&gt;free on Azure&lt;/strong&gt; (VMs, Azure Stack, Azure VMware Solution) — Microsoft's deliberate carrot. Same server, same app, patches keep flowing, no ESU invoice. It's a bridge, not a destination, but it's a real one.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Stuck on-prem past October?&lt;/strong&gt; Your options narrow to network isolation, compensating controls, and third-party support arrangements — plus a migration plan with an actual date on it.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The bigger picture
&lt;/h2&gt;

&lt;p&gt;October 13 isn't an isolated event. The back half of 2026 is a wall of deadlines: SharePoint 2016/2019 and SQL Server 2016 already hit end-of-support on July 14, then Python 3.10 (Oct 31), .NET 8 &lt;em&gt;and&lt;/em&gt; 9 (both Nov 10), PostgreSQL 14 (Nov 12), and PHP 8.2 (Dec 31).&lt;/p&gt;

&lt;p&gt;We track all of it — dates verified against vendor lifecycle pages — at &lt;a href="https://endoflife.ai/eol-watch" rel="noopener noreferrer"&gt;endoflife.ai/eol-watch&lt;/a&gt;, and there's a free &lt;a href="https://endoflife.ai/checker" rel="noopener noreferrer"&gt;EOL checker&lt;/a&gt; if you want to know where the rest of your stack stands.&lt;/p&gt;

</description>
      <category>windows</category>
      <category>sysadmin</category>
      <category>security</category>
      <category>devops</category>
    </item>
    <item>
      <title>We built a free API for software end-of-life dates and risk scores (460+ products)</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Mon, 13 Jul 2026 03:29:34 +0000</pubDate>
      <link>https://dev.to/endoflifeai/we-built-a-free-api-for-software-end-of-life-dates-and-risk-scores-460-products-3ic1</link>
      <guid>https://dev.to/endoflifeai/we-built-a-free-api-for-software-end-of-life-dates-and-risk-scores-460-products-3ic1</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;endoflife.ai/api&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Every outage post-mortem has a cousin: the "we were running an EOL version and didn't know" security incident. Debian 12 just went EOL this month, Spring Framework 6.2 and Spring Boot 3.5 hit end of support in June, and PostgreSQL 14 goes EOL in November. If your tooling can't answer &lt;em&gt;"is anything in my stack out of support?"&lt;/em&gt;, you find out the hard way.&lt;/p&gt;

&lt;p&gt;We run &lt;a href="https://endoflife.ai" rel="noopener noreferrer"&gt;endoflife.ai&lt;/a&gt;, which tracks end-of-life dates and security-support status for &lt;strong&gt;460+ software products&lt;/strong&gt; and scores every version with a 0-100 &lt;strong&gt;EOL Risk Score&lt;/strong&gt; (factors: how long past EOL, attack surface, CISA KEV exposure, whether extended support exists). Today the whole dataset is queryable over a plain REST API.&lt;/p&gt;

&lt;h2&gt;
  
  
  One request, no auth
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.endoflife.ai/v1/score/nodejs/18
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"product"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"nodejs"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"version"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"18"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"eol_date"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2025-04-30"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"status"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"eol"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"days_past_eol"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;439&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"score"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;85&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"grade"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"F"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"band"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Critical"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"extended_support_available"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  What's in the box
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;GET /v1/score/:slug/:version&lt;/code&gt; - risk score for a specific version&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;GET /v1/status/:slug/:version&lt;/code&gt; - simple is-it-supported check for CI gates&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;POST /v1/batch&lt;/code&gt; - score your whole stack in one call&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;GET /v1/metrics?stack=nodejs:18,python:3.8&lt;/code&gt; - &lt;strong&gt;Prometheus exposition format&lt;/strong&gt;, ready to scrape into Grafana&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;GET /v1/badge/:slug/:version&lt;/code&gt; - Shields.io endpoint badges for your README&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://api.endoflife.ai/openapi.json" rel="noopener noreferrer"&gt;OpenAPI 3.0 spec&lt;/a&gt; - import into Postman/Insomnia or generate a client&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Limits
&lt;/h2&gt;

&lt;p&gt;Anonymous: 100 requests/day. A &lt;a href="https://endoflife.ai/api#free-key" rel="noopener noreferrer"&gt;free API key&lt;/a&gt; (emailed instantly, no card) raises that to 500/day. Paid tiers exist for production volumes.&lt;/p&gt;

&lt;p&gt;Lifecycle data is served live from &lt;a href="https://endoflife.date" rel="noopener noreferrer"&gt;endoflife.date&lt;/a&gt; cycle data (cached at the edge), with our own scoring layer on top: EOL recency, attack-surface weighting, CISA KEV mapping, and extended-support vendor coverage.&lt;/p&gt;

&lt;h2&gt;
  
  
  A CI example
&lt;/h2&gt;

&lt;p&gt;Fail a pipeline when anything in the stack goes EOL:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;STATUS&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-s&lt;/span&gt; https://api.endoflife.ai/v1/status/nodejs/18 | jq &lt;span class="nt"&gt;-r&lt;/span&gt; .is_eol&lt;span class="si"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$STATUS&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;"true"&lt;/span&gt; &lt;span class="o"&gt;]&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;then
  &lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"::error::Node 18 is past end-of-life"&lt;/span&gt;
  &lt;span class="nb"&gt;exit &lt;/span&gt;1
&lt;span class="k"&gt;fi&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;(There's also a ready-made &lt;a href="https://github.com/endoflife-ai" rel="noopener noreferrer"&gt;GitHub Action&lt;/a&gt;, a VS Code extension, and an &lt;a href="https://endoflife.ai/mcp" rel="noopener noreferrer"&gt;MCP server&lt;/a&gt; if you'd rather your AI agent checks for you.)&lt;/p&gt;

&lt;p&gt;Docs and live playground: &lt;strong&gt;&lt;a href="https://endoflife.ai/api" rel="noopener noreferrer"&gt;endoflife.ai/api&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Questions or weird edge cases? Comments welcome.&lt;/p&gt;

</description>
      <category>api</category>
      <category>devops</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>endoflife.ai is now available as an MCP server</title>
      <dc:creator>endoflife-ai</dc:creator>
      <pubDate>Tue, 30 Jun 2026 15:19:43 +0000</pubDate>
      <link>https://dev.to/endoflifeai/endoflifeai-is-now-available-as-an-mcp-server-3do0</link>
      <guid>https://dev.to/endoflifeai/endoflifeai-is-now-available-as-an-mcp-server-3do0</guid>
      <description>&lt;p&gt;AI agents can now query software end-of-life dates and EOL Risk Scores directly from endoflife.ai — 459+ products, 8,000+ versions, updated daily.&lt;/p&gt;

&lt;p&gt;Connect it in one line:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"endoflife"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"url"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"https://mcp.endoflife.ai"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Ask your agent "is Node 18 still supported?" or "what's the risk score for PostgreSQL 14?" and get a live answer pulled from our dataset — including whether the product appears on CISA's Known Exploited Vulnerabilities list.&lt;/p&gt;

&lt;p&gt;No API key required. Full docs at &lt;a href="https://endoflife.ai/mcp" rel="noopener noreferrer"&gt;https://endoflife.ai/mcp&lt;/a&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>devtools</category>
      <category>security</category>
    </item>
  </channel>
</rss>
