Skip to main content

Component End-of-Life

Sonatype captures the declared End-of-Life (EOL) for open-source software (OSS) projects. Components that are end-of-life are declared either in project metadata, readme files, or in other official locations that they are no longer supported and have reached "end-of-life". For components that have multiple versions, the EOL is tracked only for the latest version of the component.

EOL components do not receive enhancements, security issues may go unreported and unpatched while bug fixes are ignored. The lack of updates to components can create a false sense of security, leaving consumers vulnerable to security exploits.

This dashboard displays a list of applications and the corresponding EOL components detected by Lifecycle. Based on this data, you can strategically plan to retire old OSS components and migrate to the latest supported ones.

Component EOL Dashboard

Data Refresh Frequency: Updated daily at around 15:00 UTC. New scan data can take up to 48 hours to appear due to multi-stage pipeline processing.

Minimum Requirements: None

Applications

This section contains a list of all application IDs (or application names, if available) containing EOL components.

2026-07-01_11h44_16.png

The table includes the following fields:

  • Application - Application ID or application name containing EOL components.

  • EOL Components - Number of EOL components detected for the application within the selected filters.

Filter Options

Select the filtering options located at the top of the page, to view the EOL components for any specific EOL Date, Organization, Application, Component, Dependency type (direct or transitive), Format, and Stage.

2026-07-01_11h24_58.png

You can filter the dashboard using the following options:

  • EOL Date: Filter components by the EOL Date recorded in Lifecycle.

    Note

    The EOL Date filter uses EOL dates already recorded by Lifecycle. When you filter by a future date range, the dashboard only returns components that already have recorded EOL dates in that range. If no matching EOL dates are recorded, the dashboard displays no data. Sonatype does not predict or forecast component EOL dates.

  • Organization: Filter results by organization.

  • Application: Filter results by application.

  • Component: Filter results by component name.

  • Dependency: Filter results by dependency type, such as direct or transitive.

  • Format: Filter results by component package format or ecosystem.

  • Stage: Filter results by stage.

End-of-Life Components

This section contains a list of EOL components found in your applications. The table includes Application, Component, Version In Use, Latest Version, Namespace, Format, Dependency, and EOL Date. The number of occurrences of a component in this table depends on how they are used within the application.

2026-07-01_11h24_46.png

The table includes the following fields:

  • Application - Application where the EOL component was detected.

  • Component - Component identified as End-of-Life within the selected filters.

  • Version In Use - Component version detected in the application.

  • Latest Version - Latest available version identified for the component.

  • Namespace - Component namespace, when available.

  • Format - Component package format or ecosystem, such as npm, Maven, NuGet, golang, or PyPI.

  • Dependency - Dependency type for the component, such as direct or transitive.

  • EOL Date - EOL date recorded for the component. For components with multiple versions, the EOL Date is evaluated against the latest version only.

Note

The EOL Date represents the date when Lifecycle marked the component as End-of-Life in the system, which may differ from the official vendor-announced EOL date. EOL Date values reflect data already recorded by Lifecycle and are not updated from vendors or maintainers in real time. If the EOL Date field is empty, no EOL designation has been applied to that component.

You will be able to view only the EOL components that are found in the applications you have access to.

Note

The EOL dashboard currently displays components of npm, Maven, NuGet, golang and PyPI format/ecosystems.

Note

Cross filtering is enabled between the End-of-Life Components and Applications tables. When you select an application value in the End-of-Life Components table, the Applications table is filtered to show that application.

Other Supported Operations

Download the underlying data by selecting the vertical dots icon on the right top corner of this dashboard.

2026-03-17_18h59_00.png

Using the option, send the data to an email address. Supported formats are PDF, CSV, or PNG.

The recurrence and time fields may be used to set the timing of your data delivery options.

2026-03-17_19h14_04.png

Troubleshooting

Problem

Clicking on the browser Refresh button may give you the following error:

Message displaying that an error occurred loading the Data Insight.

Solution

Click the Back button on your browser, from the page where you see this error, to go back to the Landing page Enterprise Reporting. Select the dashboard you want to view, to reload the visualizations.

To refresh the page, click on the refresh icon on the top right, instead of the Refresh button on your browser.

refresh_page.png

Problem

No data visible on the dashboard or any other issues with the dashboard.

Solution

Click on Copy to Support Info to Clipboard button and contact support with this information.

copy_support_to_clipboard.png

Frequently Asked Questions (FAQs)

Why do some components not have an EOL Date?

An EOL Date is displayed only when Lifecycle has recorded End-of-Life information for that component. If no official EOL declaration has been identified or an EOL date has not yet been recorded, the field may appear empty.

What does the EOL Date represent?

The EOL Date represents the date when Lifecycle marked the component as End-of-Life in the system, which may differ from the official vendor-announced EOL date. For components that have multiple versions, EOL is tracked only for the latest version of the component.

Does Sonatype predict future EOL dates?

No. Sonatype surfaces EOL dates that have already been recorded by Lifecycle. A future EOL Date means the recorded date has not taken effect yet; it is not a Sonatype forecast or estimate.

How does Lifecycle distinguish between End-of-Life and stale components?

Components are categorized as End-of-Life only when an official EOL declaration from the project or maintainer has been identified. Components that are old or have not been updated for a long time are not automatically considered End-of-Life.