Featured Posts
All Posts

Compliance
Jun 25, 2026
Japan's Active Cyber Defense Law: What It Means for Open Source and EOL Software
How Japan's landmark Active Cyber Defense Law creates new obligations around unsupported software — and how HeroDevs keeps you compliant.
James Yi

EOL Software
Jun 24, 2026
The Ghost in the Dependency Tree: The End-of-Life Risk Your Scanners Miss
HeroDevs' Isaac Wuest joined the OpenSSF's "What's in the SOSS" podcast to talk about the blind spot in CVE-based scanning, the difference between attested end of life and maintainer abandonment, and what to do about the end-of-life packages hiding in your dependency tree.
Taylor Corbett
.png)
Security
Jun 23, 2026
CVE-2026-54512/54513: Jackson PolymorphicTypeValidator Bypass
How generic type parameters and array component types slip past a correctly configured BasicPolymorphicTypeValidator allowlist to reach gadget instantiation
Greg Allen

EOL Software
Jun 23, 2026
PostgreSQL EOL Dates: Every Version's Release & End-of-Life Timeline
A complete reference for every PostgreSQL major version, its five-year support window, and what end-of-life means for the teams still running older releases in production.
Greg Allen
.png)
Security
Jun 23, 2026
AryStinger Turns 4,300 Forgotten Routers Into a Recon-and-Proxy Network
When end-of-life stops being a software problem and becomes the whole device, and nobody is shipping firmware anymore.
Allison Vorthmann

Risk Mitigation
Jun 23, 2026
What a Disaster Recovery Gameday Taught Us About Resilience
How Controlled Failure Simulations Build Engineering Confidence and Process Reliability
Justin Gorny
.png)
Compliance
Jun 23, 2026
Your EOL Open Source Is a PCI DSS Compliance Problem — Here's How to Fix It
PCI DSS 4.0's Requirement 12.3.4 is now fully enforceable, and it targets end-of-life open source directly — here's what it means for teams handling payment card data, and how to close the audit gap.
Rob Nalen

EOL Software
Jun 23, 2026
Node.js Version Support: EOL Dates and Latest Releases (July 2026)
End-of-life means a technology no longer receives support, like vulnerability fixes, from the original creator.
Taylor Corbett
.png)
EOL Software
Jun 23, 2026
What You Need to Know: Spring Framework’s End-of-Life Dates
A complete reference for every Spring Framework release timeline, and what end-of-life actually means for the enterprise Java teams still running 5.3 and 6.1 in production.
HeroDevs
.png)
Announcements
Jun 22, 2026
HeroDevs Joins Commonhaus Foundation Open Source Sustainability Initiative as Founding Member
HeroDevs joins as a founding Gold Partner, bringing Never-Ending Support to end-of-life software across the Commonhaus ecosystem
HeroDevs

Risk Mitigation
Jun 18, 2026
Spring CVEs Didn't Slow Down. June 2026 Brought 67.
The spring surge kept climbing, and the versions Broadcom no longer evaluates are where the real exposure now lives.
Bob McNees

Security
Jun 17, 2026
CVE-2026-41855: Spring Framework JMS Jackson Deserialization Flaw
How Jackson-based JMS message converters allow gadget class instantiation in untrusted broker environments
Greg Allen
.png)
Compliance
Jun 17, 2026
Spring Boot 3.5 EOL: Scanner Findings, Audit Risk, and Remediation Options
Migrate, self-patch, get covered, or accept the risk — each is right in the right situation, and each breaks when the timeline doesn't match
Mark Szymanski

Security
Jun 16, 2026
CVE-2026-41003: Spring Security SAML XSS via RelyingPartyRegistration
CWE-79 in Spring Security's SAML 2.0 service-provider components writes unencoded values into auto-generated HTML forms
Greg Allen
.png)
EOL Software
Jun 16, 2026
NumPy 2.0 Reaches End of Life on June 17, 2026
Why an unsupported version of the library beneath pandas, scikit-learn, and PyTorch is a foundational risk
Taylor Corbett
.png)
.png)