What you get with NES

Timeline showing AngularJS end of life marked and perpetual support continuing beyond that point.

Your end-of-life framework becomes a supported one

Pick the product and version already in production: AngularJs, Spring, .NET, Angular, Vue 2, Node.js, PostgreSQL and hundreds more - and it starts receiving security patches again. Chose what you need, swap in Never Ending Support binaries, stay secure for as long as you need.

You get the fix, not a 
migration project

You get the fix, not a migration project

Stay secure in place, with drop-in replacements for the versions already in your application. Your team merges them and moves on.

List of software versions with corresponding CVE numbers and release dates in March and January 2026.

A new release every time a CVE lands

Every vulnerability in your covered versions gets found, validated, patched, and shipped as a new NES release — historically within hours of disclosure. NES internal automation is designed to keep pace with AI-driven discovery, backed by engineer maintainers who wrote the frameworks themselves.

Download options for vue 2.7.16 to 2.7.19 from @neverendingsupport, including tgz, json, and pdf files.

You are always audit-ready

Every replacement arrives with a VEX statement and a signed attestation, mapped to the frameworks you report against. The evidence exists before an auditor asks for it.

Companies who can’t compromise on security trust HeroDevs

1,000+

customers across every major industry, from financial services and healthcare to government and technology

50%+

of the Fortune 100 rely on HeroDevs to keep end-of-life open source secure and compliant

10M+

NES package downloads, approaching ten million secured builds shipped to production

Trusted by security and engineering teams at 1000+ companies
Google logo
Microsoft logo
Santander logo
Dropbox logo
Hitachi Logo
Finra logo
General Electric logo
NHS logo
Lilly logo
box logo
Abbot logo
Workday logo
Schneider Electric Logo
Chevron logo

Find it. Fix it. Stay compliant.

Never-Ending Support publishes secure drop-in replacements for the end-of-life open source already running in production. The same version line, the same public API, with CVEs patched and the evidence documented.

Step 1

Find it

Learn More

Your SCA tool flags vulnerabilities. HeroDevs's proprietary EOL Dataset scanning over 19 million packages tells you which of those components are end-of-life, abandoned, or about to be — including your full dependency tree.

Why it matters: you cannot report on risk you cannot see, and SCA tools miss. Detection turns an unknown legacy footprint into a list of immediate remediation solutions, simply turn on NES.

Step 2

Fix it

Learn More

Point your package manager at the NES registry and rebuild - that simple. The replacement carries the same version line and the same public API, so there is no find-and-replace and no code change to review.Every time HeroDevs finds, validates, and fixes a CVE affecting your version, a new NES release ships.

Why it matters: a drop-in replacement is a config change your team can ship this sprint. Migrations are expensive and slow, and NES is not a substitute for eventually making one, it removes the deadline. HeroDevs engineers, including original framework authors and core contributors validate, build and test every version.

Step 3

Prove it

Learn More

Support commitments are written the way procurement and audit need them: SLAs for incident response and remediation, commercial contract assurances, and disclosure practices backed by HeroDevs' status as a CVE Naming Authority. Every delivered remediation adds a VEX statement and a generated legal attestation. These documents are maintained within our public documentation.

Why it matters: an unsupported dependency is a finding. A supported one with a named vendor, an SLA, and a remediation record is a control.

Supported Technologies

36 product lines across JavaScript, Java, Python, PHP, .NET, and databases.
Coverage is priced per product, so a single end-of-life framework does not require a full-suite contract.

Search

Category

Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Product
Category
Versions Covered
Links

1.078+ CVEs remediated.
Here are the recent ones.

Each entry is a vulnerability with no upstream fix for the affected versions, and a shipped NES release that resolves it.
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Category
Version(s) Affected
Published Date
Medium

.NET

Allocation of Resources Without Limits or Throttling
Improper Handling of Highly Compressed Data (Data Amplification)
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.2
Jul 29, 2026
Medium

.NET

Inefficient Algorithmic Complexity
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium

.NET

Uncontrolled Recursion
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium

.NET

Uncontrolled Recursion
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium

.NET

Allocation of Resources Without Limits or Throttling
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium

.NET

Allocation of Resources Without Limits or Throttling
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium

.NET

Inefficient Algorithmic Complexity
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Medium

Deserialization of Untrusted Data
Use of Externally-Controlled Input to Select Classes or Code
MessagePack < 2.5.301; MessagePack >= 3.0 < 3.1.7; NES Essentials Plus MessagePack 2.5.192.x before 2.5.192.3
Jul 29, 2026
Low

.NET

Insufficient Verification of Data Authenticity
.NET SDK >= 6.0.0 <= 6.0.41
Jul 29, 2026
High

Jackson

Authorization Bypass
>=2.15.0 <2.18.8, >=2.19.0 <2.21.4
Jul 29, 2026
High

Quarkus

Authorization Bypass
<3.20.6.1, >=3.21.0 <3.27.3.1, >=3.30.0 <3.33.1.1, >=3.34.0 <3.35.1.1
Jul 29, 2026
Medium

Quarkus

Denial of Service
<3.20.5, >=3.21.0 <3.27.2, >=3.30.0 <3.31.0
Jul 29, 2026

Engineers build the fix.
AI finds the work.

The replacement is the hard part, and a HeroDevs engineer builds it.
Nothing gets built until it is clear what needs replacing, so detection runs on AI at a scale no team could match.

What Engineers do

Confirm the finding is real and reachable in the versions customers actually run

Decide whether a fix can be backported without changing the public API

Write and review the patch, including original framework authors and core contributors

Sign off the release under the SLA and coordinate disclosure as a CVE Naming Authority

What AI does

Scans covered codebases continuously for vulnerability candidates, ahead of any public CVE

Correlates advisories, upstream commits, and transitive dependency graphs across 36 product lines

Assembles the reproduction case and drafts a candidate patch for review

Runs the regression suite against every supported version in the matrix

Ensuring full compliance and security

HeroDevs ensures your unsupported and unmaintained open-source software stays fully compliant with regulations like SOC 2, FedRAMP, PCI, HIPAA, DORA, and CRA. With ongoing security updates and a commitment to audit readiness, you can rest easy knowing your systems remain compliant, secure, and ready for any inspection.

SOC 2 TYPE 1 badgeFedRAMP badgeDSS Compliance badgeHIPAA Compliant badgeGDPR badgeCRA logoDora logoNIST logo

Questions engineering and security teams ask

Full install notes, release histories, and the standard SLA are in the documentation.

What is Never-Ending Support?
What happens when open source software reaches end-of-life?
Which technologies does HeroDevs support?
How is NES installed?
What exactly is in an NES subscription?
How fast do patches ship after a vulnerability is disclosed?
Does this replace migrating?
How does NES affect our scanners and false positives?
What does this cover for compliance and audit?
AI is finding vulnerabilities faster than maintainers can fix them. What does that mean for us?
If AI can find and patch vulnerabilities, why does a support vendor matter?
We are on a community version that is still maintained. Are we covered?
Can we evaluate it before committing?
What about a package that is not on the list?

Find out what has gone end-of-life in your stack

The next wave of CVEs will land against the components you already run. Scan your dependencies for end-of-life and unmaintained software, or talk to the team about coverage for a specific framework and version.