<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Feroz Sheikh</title>
    <description>The latest articles on DEV Community by Feroz Sheikh (@shekh_firoj_6217570f10c6c).</description>
    <link>https://dev.to/shekh_firoj_6217570f10c6c</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4148658%2F55f15a92-469b-4c81-8811-b23424fc4f26.jpg</url>
      <title>DEV Community: Feroz Sheikh</title>
      <link>https://dev.to/shekh_firoj_6217570f10c6c</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/shekh_firoj_6217570f10c6c"/>
    <language>en</language>
    <item>
      <title>Turning phone update policies into dates: precision, minimums and sources</title>
      <dc:creator>Feroz Sheikh</dc:creator>
      <pubDate>Tue, 29 Sep 2026 05:43:33 +0000</pubDate>
      <link>https://dev.to/shekh_firoj_6217570f10c6c/turning-phone-update-policies-into-dates-precision-minimums-and-sources-4fa8</link>
      <guid>https://dev.to/shekh_firoj_6217570f10c6c/turning-phone-update-policies-into-dates-precision-minimums-and-sources-4fa8</guid>
      <description>&lt;p&gt;"When does this phone stop getting security updates?" sounds like a single date. Once you try to store the answer for hundreds of models, it turns out to be at least four different kinds of fact. I run &lt;a href="https://devlifecheck.com" rel="noopener noreferrer"&gt;DevLifeCheck&lt;/a&gt;, which tracks this for phones, tablets, Chromebooks and routers. These are the modelling decisions that mattered most, using phones as the example.&lt;/p&gt;

&lt;h2&gt;
  
  
  Manufacturers publish four different shapes of data
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;A model-specific end date.&lt;/strong&gt; Some manufacturers publish a table or spec line per model. Xiaomi's product software support page lists an end date for each Xiaomi, Redmi and POCO model, HMD lists one for its Nokia and HMD phones, and Samsung UK product pages carry a "Security Update Period (Valid until)" line. For the Galaxy A56 5G (SM-A566B) it says 31 March 2032.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A duration policy.&lt;/strong&gt; Google says Pixel 8 and later get 7 years of OS and security updates "starting from when the device first became available on the Google Store in the US". Samsung announced seven generations of OS upgrades and seven years of security updates for the Galaxy S24 series. There's no date here. You calculate one from the policy and a start event.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A regulatory minimum.&lt;/strong&gt; Under the UK's product security (PSTI) rules, brands such as OPPO, OnePlus, realme and vivo publish the end of a &lt;em&gt;minimum&lt;/em&gt; security-update period for UK models. That is a floor, not a promised last patch.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Only a cadence.&lt;/strong&gt; Samsung's security site lists models on monthly or quarterly update schedules, and vivo and HONOR publish similar lists. Being on the list tells you the phone is being patched now, not when that will stop. Apple publishes no end dates at all.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If you store all four in one &lt;code&gt;end_date&lt;/code&gt; column, your data will be confidently wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  Store the meaning and the precision, not just the date
&lt;/h2&gt;

&lt;p&gt;Each support claim gets a small bundle of fields. Simplified:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;type&lt;/span&gt; &lt;span class="nx"&gt;SupportClaim&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;date&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kr"&gt;string&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;            &lt;span class="c1"&gt;// ISO 8601, e.g. "2030-10-01"&lt;/span&gt;
  &lt;span class="nl"&gt;precision&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;DAY&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;MONTH&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;YEAR&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;RANGE&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;UNKNOWN&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="nl"&gt;meaning&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;OFFICIAL_END&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;MINIMUM_COMMITMENT&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;ESTIMATE&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;UNKNOWN&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="nl"&gt;evidence&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;A&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;B&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;C&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;D&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;U&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="c1"&gt;// A = exact first-party date, B = first-party policy calculation&lt;/span&gt;
  &lt;span class="nl"&gt;region&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kr"&gt;string&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;                 &lt;span class="c1"&gt;// the market or model code the claim covers&lt;/span&gt;
  &lt;span class="nl"&gt;sourceUrl&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kr"&gt;string&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;              &lt;span class="c1"&gt;// first-party page it came from&lt;/span&gt;
  &lt;span class="nl"&gt;checkedAt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kr"&gt;string&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;              &lt;span class="c1"&gt;// when that page was last checked&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Precision matters most for policy-derived dates. Pixel 8 went on sale in the US in October 2023, so seven years lands in &lt;strong&gt;October 2030&lt;/strong&gt;. The stored value is &lt;code&gt;2030-10-01&lt;/code&gt; with &lt;code&gt;MONTH&lt;/code&gt; precision, and the UI must never render it as "1 October 2030". A trimmed response from the public API shows the same idea:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"slug"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"google-pixel-8"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"released"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2023-10-12"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"securityEnd"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2030-10-01"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"securityEndPrecision"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"MONTH"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"evidenceLevel"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"B"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"evidenceLabel"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Policy-derived"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"supportCalculation"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Published policy applied to 2023-10-12; displayed at source-supported precision."&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  A published model date beats a calculation
&lt;/h2&gt;

&lt;p&gt;The Galaxy A56 5G launched in March 2025 with up to six years of security updates, so the policy points to roughly March 2031. Samsung UK's page for the exact SM-A566B says 31 March 2032. When a first-party source gives a date for a specific model and market, it wins over a calculation, and the record keeps the region it applies to. The same phone sold elsewhere may have a different date.&lt;/p&gt;

&lt;h2&gt;
  
  
  Compute status when you read, not when you write
&lt;/h2&gt;

&lt;p&gt;"Supported", "ending soon" and "ended" depend on today's date, so storing them means they go stale. DevLifeCheck derives status at request time from the date, its meaning and a 12-month "ending soon" window. Two rules matter most. When a &lt;strong&gt;minimum&lt;/strong&gt; period has passed, the status becomes &lt;em&gt;unknown&lt;/em&gt;, not &lt;em&gt;ended&lt;/em&gt;, because many phones keep getting patches after their regulatory minimum and "ended" would be a false claim. And a date whose meaning is &lt;code&gt;ESTIMATE&lt;/code&gt; never produces "supported" or "ended" on its own. The status stays &lt;em&gt;unknown&lt;/em&gt; and the date is shown next to its label, so a reader can see how it was derived.&lt;/p&gt;

&lt;h2&gt;
  
  
  Unknown should stay unknown
&lt;/h2&gt;

&lt;p&gt;Of the 712 phones DevLifeCheck currently tracks from 17 brands, 371 have a security end date. The rest have evidence (a cadence list, a UK minimum, an OS-upgrade count) but no final date, and they're shown that way. It's tempting to fill gaps with "the usual" value for a brand. Don't. A blank field with a source link is more useful than a plausible guess, because people use this data to decide whether to buy a used phone.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the data
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://devlifecheck.com/developers" rel="noopener noreferrer"&gt;developer page&lt;/a&gt; documents a read-only API (&lt;code&gt;/api/v1/devices&lt;/code&gt;, with a separate evidence endpoint per device) and a CSV export of the published catalog. Every row carries the precision, the date meaning and the source URL. Attribution is required.&lt;/p&gt;

&lt;p&gt;If you've modelled end-of-life data for other hardware, I'd like to hear how you handled minimums versus final dates.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Disclosure: I build and maintain DevLifeCheck.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>android</category>
      <category>security</category>
      <category>opendata</category>
      <category>database</category>
    </item>
  </channel>
</rss>
