// End-of-life tracker

When your stack stops getting patched

Community end-of-life dates for the enterprise open source layer, each with the source it came from. Other trackers give you the date. These pages give you what stops, what actually breaks in the upgrade, what it costs, and what an auditor will say — including when the honest answer is that you do not need us.

Coming up

Dates still ahead. These are the ones you can still plan around rather than react to.

Already end of life

Most recent first. Every one of these lines still runs somewhere in production.

End-of-life: common questions

What does end of life mean for open source software?

It means the project stops publishing fixes for that version line. The software keeps running exactly as before; what ends is the supply of security patches and, for databases, bug fixes that can prevent data corruption. Nothing breaks on the date. Exposure accumulates from it.

How long do open source projects support a version?

It varies enormously and this is where teams get caught out. PostgreSQL supports each major for five years. Microsoft gives .NET LTS releases three years. Node.js LTS lines get thirty months. RabbitMQ and Apache Kafka support only the current release series, so a version can go end of life the day its successor ships — a window of months, not years.

Is it illegal or non-compliant to run end-of-life software?

Not illegal, but it engages specific controls. PCI DSS 4.0 requirement 6.3.3 expects critical and high vulnerabilities patched within a month. SOC 2 CC7.1 expects a working remediation process. FDA premarket cybersecurity submissions expect a plan for unsupported components. In each case the problem is not the version number, it is the absence of a patch path.

Can you get security patches for end-of-life open source?

Yes. Third-party extended support providers backport fixes from upstream to the end-of-life line. OSSeva does this for the infrastructure layer — RabbitMQ, Kafka, PostgreSQL, Redis, Tomcat, Spring and .NET. HeroDevs and TuxCare cover application frameworks and libraries; OpenLogic covers a broad catalogue.

Where do these end-of-life dates come from?

Each project's own published lifecycle policy, cross-checked against endoflife.date. Every date on this site links to its source. We do not publish a lifecycle date we cannot point at.

Which end-of-life dates are coming up next?

The near-term cluster is November 2026: .NET 8 and .NET 9 both reach end of support on 10 November 2026, and PostgreSQL 14 follows on 12 November 2026. Apache Tomcat 9.0 reaches end of life on 31 March 2027. Estates running both .NET and PostgreSQL should plan those as one programme rather than two.

Tell us what you are still running

Send the versions. We will tell you which need attention first, and which are fine where they are.