Find What’s End-of-Life.
Fix It In Minutes.
Never Run EOL Software Again.
Whether you need to resolve a specific CVE today or get ahead of EOL risk across your entire open source stack — HeroDevs has you covered.
FOR ENGINEERS & DEV OPS
I need a full EOL picture
Instantly find every end-of-life dependency across your full stack — direct, transitive, and across all your projects.
FOR SECURITY & COMPLIANCE LEADERS
Tired of EOL surprises at audit time?
EOL software is now a named finding in SOC 2, PCI-DSS, and HIPAA audits. Get a plan so your team is never caught off-guard again.
TRUSTED BY SECURITY AND ENGINEERING TEAMS AT
See How It Works
Step through each phase of a real dependency scan.
Choose Your Entry Point
Three ways to start — use one or all of them.
Upload an SBOM
Drop in a CycloneDX or SPDX file. Instant scan, no setup.
CycloneDX · SPDX
Scan a manifest
package.json, pom.xml, .csproj, requirements.txt, go.mod, Cargo.toml — any ecosystem.
npm · maven · pypi · nuget · go · cargo
CI/CD integration
Connect your pipeline for continuous, automated scanning on every build.
GitHub Actions · GitLab · Jenkins · Azure DevOps
Full Tree Resolved
We resolve the complete dependency graph — direct deps, every transitive pull-in, and a clean split between production and dev/test.
Direct deps
What you declared
86
Transitive deps
What your deps pull in
1,161
Production
Surface area that matters
935
Dev / test only
lower priority, still tracked
312
93% of your risk lives in transitive deps. Most SCAs never look there.
EOL Findings Detected
Not just CVEs — we surface whether anyone is still maintaining the software. Results grouped by risk so you know exactly where to focus.
End-of-Life
No more patches. Ever. Top priority.
EOL Upcoming
Approaching end-of-support — plan now.
Vulns, not EOL
Still maintained but carrying active CVEs.
Unknown status
Unmaintained or abandoned — no clear EOL date.
Your SCA reported zero issues. We found 8 — because it tracks CVEs, not lifecycle.
Every Finding Gets A Fix
Upgrade when a supported version exists. For deeply embedded frameworks, activate NES — drop-in security patches. Same package, same API, zero code changes.
6 of 8 findings fixable with NES today. Deploy in minutes.
Fleet-wide Report
A single pane of glass across every project — per-project EOL risk, last scan time, and compliance posture mapped to PCI-DSS, SOC 2, and HIPAA.
Project-level risk
Findings, CVEs, and NES coverage per repo
Scan history
Last scan time and configurable cadence
Compliance per project
PCI, SOC 2, HIPAA — pass / warn / fail
Flexible export
PDF, CSV, Jira push, or API webhook
Audit-ready. Share with your security team, auditors, or leadership in one click.
1,700x
more EOL data than any other source
12M+ package versions tracked · every major registry · the data your scanner doesn't have
Where Do You Want To Start?
FOR ENGINEERS & DEV OPS
I Need A Fix Now
See what's at risk. Get remediation paths — including NES patches you can deploy today.
FREE - NO CREDIT CARD - NO SETUP REQUIERED
FOR SECURITY & COMPLIANCE LEADERS
I Want To Get Ahead Of This
Walk through your full risk profile. Build a remediation plan. Get audit evidence.
USUALLY WITHIN 24 HOURS
Find It. Fix It. Stay Compliant.
The only platform that detects end-of-life risk and remediates it — without forcing a migration.
EOL DS Identifies
Unsupported frameworks in production
Abandoned dependencies with no maintainer
Software approaching EOL before your next release
Transitive deps your SCA doesn't track
Compliance gaps mapped to NIST, SOC 2, ISO 27001
NES Provides
Security patches for EOL frameworks — drop-in, zero code changes
Same package name, same API, deploys in minutes
Compliance continuity without forced migrations
AngularJS, Vue 2, .NET 6, Node 16, Spring 5, Java 8, and more
Modernize on your schedule — not someone else's deadline
Upgrade when you can.
NES when you can’t.
1,078+ CVEs Patched Across EOL Packages
The most comprehensive public database of CVEs affecting end-of-life open source. Search by library, severity, or category.
EOL Software Is Now An Audit Finding In 12+ Jurisdictions.
Regulators aren't just asking if you track vulnerabilities — they're asking if you know what's still supported.
Penalties range from €15M/2.5% global turnover (EU CRA) to loss of Federal contracts (FedRAMP) and payment card acceptance (PCI DSS)
* CRA in force Dec 2024; full obligations apply Dec 2027
*DORA applies to EU financial sector only
*CS&R Bill passing through UK Parliament
Questions From Enterprise Teams
Of course, if you can't find the answer you're looking for, feel free to contact us.
Nothing beyond a dependency file or SBOM. Upload a package.json, pom.xml, requirements.txt, go.mod, or any CycloneDX/SPDX file and you'll have results immediately — no agents, no configuration, no code changes. For CI/CD, connect your pipeline and scans run automatically on every build.
Yes — and this is where most tools fall short. We resolve your full dependency graph, including every transitive pull-in. On average, 93% of EOL risk lives in transitive deps that your declared dependencies introduce. We check all of them.
That's exactly what NES is built for. Never-Ending Support gives you drop-in security patches for EOL frameworks — same package name, same API, zero code changes. You stay compliant and secure while you plan the migration on your own schedule.
Your SCA asks 'is there a CVE?' We ask 'is anyone still maintaining this?' Those are different questions. 81,000+ package versions have known CVEs and zero fix path — your SCA shows them as low-risk because there's no patch to flag. We surface the lifecycle risk your scanner is blind to.
Yes. EOL Dataset integrates with GitHub Actions, GitLab CI, Jenkins, Azure DevOps, and more for automated scanning. Findings push directly to Jira, export as PDF or CSV for auditors, and are available via API for any custom workflow.
Every finding is mapped to PCI-DSS, SOC 2, HIPAA, NIST 800-53, ISO 27001, and FedRAMP out of the box. Reports are formatted for audit submission — no manual translation required.
.png)

