Skip to main content
Regulaxy

Lifecycle (EOL/EOS)

Two dates per version rather than one, what the screen does with a version it cannot identify, and what the bundled catalog does not know.

Every version carries two dates, not one: when full support ends, and when security support ends. Between them the vendor no longer ships fixes and features but does still ship security updates — which is exactly the state in which a binary “unsupported” badge would turn a correct finding into a false compliance claim. So the screen renders a phase, and prints the vendor's own name for that phase beside ours, so a reader can check the date against the vendor's published table without translating first.

Five states

StateWhen
Already unsupportedSecurity support has ended
Ends within a yearSecurity support ends within 365 days
No full supportFull support has ended, security support is still far off
SupportedBoth dates are ahead
No lifecycle dataThe catalog does not recognize the version

The four tiles above the table group Supported and No full support together; the Status column separates them. Clicking a tile filters the table to it.

What goes into the table

The screen reads three categories out of the inventory — operating system from the servers, database from the database engine versions, and network equipment — and groups by the version string exactly as it is recorded, because that is the string a reader will search their own inventory for.

ColumnWhat it holds
Version in inventoryThe string itself, exactly as recorded
CategoryOperating system · Database · Network equipment
ProductThe product family and release train the catalog identified
StatusOne of the five states
End of full support / End of security supportThe two dates
Days leftUntil security support ends; negative means overdue
Assets / SystemsHow many assets run this version, and how many systems they belong to
Confidence“From the vendor” or “Estimated”
SourceThe table the date was taken from

Estimated is not a guess: it is stated when the vendor publishes the phase but not one unambiguous date for that release, and the date in the table is the best public reading of it. Saying so is better than rounding it into a fact.

The three-year horizon

The chart counts assets by the quarter in which their security support ends. A Past bar holds everything that has already ended, and a + bar holds everything beyond three years — drawn off the scale deliberately, so it does not read as a measured value. Time runs from past to future in reading order. Clicking a bar filters the table to its range.

Versions with no lifecycle data are not on the axis — they have no date to place there. They are counted in the fourth tile and in the coverage panel below the table.

What the catalog does not know — and the screen says it

The lifecycle dates come from a static catalog bundled with the software version, written from the lifecycle tables vendors publish. It does not update itself and it knows nothing about support contracts the organization bought. The coverage panel prints how many assets it does cover and their share, and names the versions it has no answer for.

An unrecognized version is a row in the table, not an omission. That decision is what makes the coverage percentage readable as a number rather than as a promise.

Updated

This page is the file content/docs/en/v1/risk/lifecycle.mdx