Component End-of-Life

Component End-of-Life

Sonatype captures the declared End-of-Life (EOL) for open-source software (OSS) projects. Components that are end-of-life are declared either in project metadata, readme files, or in other official locations that they are no longer supported and have reached "end-of-life". For components that have multiple versions, the EOL is tracked only for the latest version of the component.

EOL components do not receive enhancements, security issues may go unreported and unpatched while bug fixes are ignored. The lack of updates to components can create a false sense of security, leaving consumers vulnerable to security exploits.

This dashboard displays a list of applications and the corresponding EOL components detected by Lifecycle. Based on this data, you can strategically plan to retire old OSS components and migrate to the latest supported ones.

Component EOL Dashboard

Data Refresh Frequency: Updated daily at around 15:00 UTC. New scan data can take up to 48 hours to appear due to multi-stage pipeline processing.

Minimum Requirements: None

Applications

This section contains a list of all application IDs (or application names, if available) containing EOL components.

Filter Options

Select the filtering options located at the top of the page, to view the EOL components for any specific EOL Date, Organization, Application, Component, Dependency type (direct or transitive), Format, and Stage.

End-of-Life Components

This section contains a list of EOL components found in your applications. The table includes Application, Component, Version In Use, Latest Version, Namespace, Format, Dependency, and EOL Date. The number of occurrences of a component in this table depends on how they are used within the application.

Note

The EOL Date represents the date when Lifecycle marked the component as End-of-Life in the system, which may differ from the official vendor-announced EOL date. If the EOL Date field is empty, no EOL designation has been applied to that component.

You will be able to view only the EOL components that are found in the applications you have access to.

Note

The EOL dashboard currently displays components of npm, Maven, NuGet, golang and PyPI format/ecosystems.

Note

Cross filtering is enabled between the End-of-Life Components and Applications tables. When you select an application value in the End-of-Life Components table, the Applications table is filtered to show that application.

Other Supported Operations

Download the underlying data by selecting the vertical dots icon on the right top corner of this dashboard.

Using the option, send the data to an email address. Supported formats are PDF, CSV, or PNG.

The recurrence and time fields may be used to set the timing of your data delivery options.

Troubleshooting

Problem
Clicking on the browser Refresh button may give you the following error:

Solution
Click the Back button on your browser, from the page where you see this error, to go back to the Landing page Enterprise Reporting. Select the dashboard you want to view, to reload the visualizations.

To refresh the page, click on the refresh icon on the top right, instead of the Refresh button on your browser.

Problem
No data visible on the dashboard or any other issues with the dashboard.

Solution
Click on Copy to Support Info to Clipboard button and contact support with this information.

Frequently Asked Questions (FAQs)

Why do some components not have an EOL Date?

An EOL Date is displayed only when Lifecycle has recorded End-of-Life information for that component. If no official EOL declaration has been identified or an EOL date has not yet been recorded, the field may appear empty.

What does the EOL Date represent?

The EOL Date represents when Lifecycle recorded the component as End-of-Life based on Sonatype’s EOL data. This date may differ from the official vendor-announced EOL date.

How does Lifecycle distinguish between End-of-Life and stale components?

Components are categorized as End-of-Life only when an official EOL declaration from the project or maintainer has been identified. Components that are old or have not been updated for a long time are not automatically considered End-of-Life.