Lifecycle (EOL/EOS)
Two dates per version rather than one, what the screen does with a version it cannot identify, and what the bundled catalog does not know.
Every version carries two dates, not one: when full support ends, and when security support ends. Between them the vendor no longer ships fixes and features but does still ship security updates — which is exactly the state in which a binary “unsupported” badge would turn a correct finding into a false compliance claim. So the screen renders a phase, and prints the vendor's own name for that phase beside ours, so a reader can check the date against the vendor's published table without translating first.
Five states
| State | When |
|---|---|
| Already unsupported | Security support has ended |
| Ends within a year | Security support ends within 365 days |
| No full support | Full support has ended, security support is still far off |
| Supported | Both dates are ahead |
| No lifecycle data | The catalog does not recognize the version |
The four tiles above the table group Supported and No full support together; the Status column separates them. Clicking a tile filters the table to it.
What goes into the table
The screen reads three categories out of the inventory — operating system from the servers, database from the database engine versions, and network equipment — and groups by the version string exactly as it is recorded, because that is the string a reader will search their own inventory for.
| Column | What it holds |
|---|---|
| Version in inventory | The string itself, exactly as recorded |
| Category | Operating system · Database · Network equipment |
| Product | The product family and release train the catalog identified |
| Status | One of the five states |
| End of full support / End of security support | The two dates |
| Days left | Until security support ends; negative means overdue |
| Assets / Systems | How many assets run this version, and how many systems they belong to |
| Confidence | “From the vendor” or “Estimated” |
| Source | The table the date was taken from |
Estimated is not a guess: it is stated when the vendor publishes the phase but not one unambiguous date for that release, and the date in the table is the best public reading of it. Saying so is better than rounding it into a fact.
The three-year horizon
The chart counts assets by the quarter in which their security support ends. A Past bar holds everything that has already ended, and a + bar holds everything beyond three years — drawn off the scale deliberately, so it does not read as a measured value. Time runs from past to future in reading order. Clicking a bar filters the table to its range.
Versions with no lifecycle data are not on the axis — they have no date to place there. They are counted in the fourth tile and in the coverage panel below the table.
What the catalog does not know — and the screen says it
The lifecycle dates come from a static catalog bundled with the software version, written from the lifecycle tables vendors publish. It does not update itself and it knows nothing about support contracts the organization bought. The coverage panel prints how many assets it does cover and their share, and names the versions it has no answer for.
An unrecognized version is a row in the table, not an omission. That decision is what makes the coverage percentage readable as a number rather than as a promise.
Updated
This page is the file content/docs/en/v1/risk/lifecycle.mdx