Component End-of-Life
Sonatype captures the declared End-of-Life (EOL) for open-source software (OSS) projects. Components that are end-of-life are declared either in project metadata, readme files, or in other official locations that they are no longer supported and have reached "end-of-life". For components that have multiple versions, the EOL is tracked only for the latest version of the component.
EOL components do not receive enhancements, security issues may go unreported and unpatched while bug fixes are ignored. The lack of updates to components can create a false sense of security, leaving consumers vulnerable to security exploits.
This dashboard displays a list of applications and the corresponding EOL components detected by Lifecycle. Based on this data, you can strategically plan to retire old OSS components and migrate to the latest supported ones.
Component EOL Dashboard
Data Refresh Frequency: Updated daily at around 15:00 UTC. New scan data can take up to 48 hours to appear due to multi-stage pipeline processing.
Minimum Requirements: None
Applications
This section contains a list of all application IDs (or application names, if available) containing EOL components.

The table includes the following fields:
Application - Application ID or application name containing EOL components.
EOL Components - Number of EOL components detected for the application within the selected filters.
Filter Options
Select the filtering options located at the top of the page, to view the EOL components for any specific EOL Date, Organization, Application, Component, Dependency type (direct or transitive), Format, and Stage.

You can filter the dashboard using the following options:
EOL Date: Filter components by the EOL Date recorded in Lifecycle.
Note
The EOL Date filter uses EOL dates already recorded by Lifecycle. When you filter by a future date range, the dashboard only returns components that already have recorded EOL dates in that range. If no matching EOL dates are recorded, the dashboard displays no data. Sonatype does not predict or forecast component EOL dates.
Organization: Filter results by organization.
Application: Filter results by application.
Component: Filter results by component name.
Dependency: Filter results by dependency type, such as direct or transitive.
Format: Filter results by component package format or ecosystem.
Stage: Filter results by stage.
End-of-Life Components
This section contains a list of EOL components found in your applications. The table includes Application, Component, Version In Use, Latest Version, Namespace, Format, Dependency, and EOL Date. The number of occurrences of a component in this table depends on how they are used within the application.

The table includes the following fields:
Application - Application where the EOL component was detected.
Component - Component identified as End-of-Life within the selected filters.
Version In Use - Component version detected in the application.
Latest Version - Latest available version identified for the component.
Namespace - Component namespace, when available.
Format - Component package format or ecosystem, such as npm, Maven, NuGet, golang, or PyPI.
Dependency - Dependency type for the component, such as direct or transitive.
EOL Date - EOL date recorded for the component. For components with multiple versions, the EOL Date is evaluated against the latest version only.
Note
The EOL Date represents the date when Lifecycle marked the component as End-of-Life in the system, which may differ from the official vendor-announced EOL date. EOL Date values reflect data already recorded by Lifecycle and are not updated from vendors or maintainers in real time. If the EOL Date field is empty, no EOL designation has been applied to that component.
You will be able to view only the EOL components that are found in the applications you have access to.
Note
The EOL dashboard currently displays components of npm, Maven, NuGet, golang and PyPI format/ecosystems.
Note
Cross filtering is enabled between the End-of-Life Components and Applications tables. When you select an application value in the End-of-Life Components table, the Applications table is filtered to show that application.
Other Supported Operations
Download the underlying data by selecting the vertical dots icon on the right top corner of this dashboard.

Using the option, send the data to an email address. Supported formats are PDF, CSV, or PNG.
The recurrence and time fields may be used to set the timing of your data delivery options.

Troubleshooting
Problem
Clicking on the browser Refresh button may give you the following error:

Solution
Click the Back button on your browser, from the page where you see this error, to go back to the Landing page Enterprise Reporting. Select the dashboard you want to view, to reload the visualizations.
To refresh the page, click on the refresh icon on the top right, instead of the Refresh button on your browser.

Problem
No data visible on the dashboard or any other issues with the dashboard.
Solution
Click on Copy to Support Info to Clipboard button and contact support with this information.

Frequently Asked Questions (FAQs)
Why do some components not have an EOL Date?
An EOL Date is displayed only when Lifecycle has recorded End-of-Life information for that component. If no official EOL declaration has been identified or an EOL date has not yet been recorded, the field may appear empty.
What does the EOL Date represent?
The EOL Date represents the date when Lifecycle marked the component as End-of-Life in the system, which may differ from the official vendor-announced EOL date. For components that have multiple versions, EOL is tracked only for the latest version of the component.
Does Sonatype predict future EOL dates?
No. Sonatype surfaces EOL dates that have already been recorded by Lifecycle. A future EOL Date means the recorded date has not taken effect yet; it is not a Sonatype forecast or estimate.
How does Lifecycle distinguish between End-of-Life and stale components?
Components are categorized as End-of-Life only when an official EOL declaration from the project or maintainer has been identified. Components that are old or have not been updated for a long time are not automatically considered End-of-Life.