CVEs keep coming, pulling engineers into unplanned maintenance

This is not a backlog you can burn down. With Evergreen, every dependency in your application is monitored, and covered when it reaches end-of-life, whether that is today or two years from now.

Dependabot alerts list showing Angular vulnerabilities with critical, high, and medium severity labels.

Every CVE on an end-of-life package is a project

An engineer needs to assess the exposure, read the upstream fix, backport it to a version it was never written for, test that nothing else breaks, and then ship it. Once open source reaches end-of-life, maintainers stop shipping security patches, so every new CVE against it becomes your team's work rather than an upstream release.

None of this work was planned. It comes out of capacity committed to something else, which you are still accountable for delivering. And as the open source dependency tree grows and CVE volume climbs, so do the interruptions.

What breaks when upstream patches stop

Security

CVE open, no fix

Compliance

No evidence to show

Roadmap & budget

Migration inserted, speed unplanned

Timeline with green check marks for OSS active support and security patches, transitioning to end-of-life with CVE warnings.

How many unsupported open source dependencies are in your stack?

Get a report of every end-of-life dependency across your repositories, direct and transitive.

Software scan summary showing 1701 packages scanned, 218 end-of-life, 1322 not EOL, 157 unknown with risk metrics.

The Problem

The common responses, and why they are not sustainable

Put someone on it permanently

A maintenance rotation makes the work predictable without making it smaller. You have converted an interruption into a standing cost, and the engineer on rotation is not building anything that quarter.

Rely on automated updates

Dependabot and Renovate resolve against what is published. On an end-of-life line there is nothing published above you that carries the fix, so the alert fires and no pull request follows. The tool confirms the exposure and cannot close it.

Generate the fix with AI

Fast, and increasingly common. Independent research finds that nearly half of AI-generated code introduces new vulnerabilities, and an unreviewed patch leaves an open question about who answers for it if it misses the vulnerability or breaks production.

The Solution

Evergreen turns remediation from an interruption into a queue you control

Connect your repositories once

Install the HeroDevs GitHub App across the repositories that make up your application.

Every dependency gets a state

Scanning runs on its own. Every dependency is monitored while supported, and queued for remediation once it reaches end-of-life and a CVE lands.

Replacements arrive as pull requests

One open pull request per dependency, ordered by severity and capped per day. You review and merge on your schedule.

Why HeroDevs?

19M+

package versions tracked

1,000+

vulnerabilities remediated

900+

enterprise customers secured by HeroDevs

Statista logo

We maintained our security posture without compromising our strategic roadmap, all while achieving substantial cost savings compared to a full migration.

Markus Wolf, Architect @ Statista

A pull request you can merge, and a queue you can manage

Evergreen Platform screenshotCoverage status for checkout-service showing three categories with counts 603, 1, and 1 respectively.

What security and compliance teams ask

Get answers to some of our most commonly asked questions.
Of course, if you can't find the answer you're looking for, feel free to contact us.

How many pull requests will this open?
Does this replace Dependabot or Renovate?
Do we have to merge every pull request?
What happens when a dependency isn’t covered yet?
What if we’re behind the version you support?
How much of our stack does this apply to?

Something not covered here? Talk to an expert.