End-of-life calendar
When things stop getting security fixes — and what actually breaks when they do. The dates are published years ahead and are easy to find. The sentence after each one is the part nobody writes.
Dates checked · Notes last edited · Subscribe (.ics) · JSON
The next release to lose support is OpenSSL 3.0 on 7 September 2026. Reaching end of life does not stop software running — it stops the vendor shipping security fixes for it, which is when the surrounding ecosystem starts dropping it too.
Losing support next
Within 30 days3 releases
- 9 days
OpenSSL 3.0LTS
The long-term-support branch most distros pinned to; after this the OpenSSL project ships it no further fixes, so anything vendoring or statically linking 3.0 inherits every later CVE.
What breaks, and what to do → - 17 days
Eclipse Temurin 26
Temurin stops publishing builds for this release, so CI images and Dockerfiles pinned to JDK 26 quietly stop receiving patches while continuing to build fine.
- 19 days
GitLab 19.1
GitLab backports security fixes only to a short window of recent minors, so a self-hosted instance left here stops receiving them entirely.
One to three months13 releases
- 47 days
GitLab 19.2
Self-hosted instances stop receiving security backports at this point; GitLab only patches a short window of recent minors.
- 52 days
Electron 42
Electron supports only its most recent majors, so an app pinned here ships an increasingly out-of-date Chromium with known browser CVEs inside it.
- 53 days
Next.js 15LTS
Security patches stop, and the ecosystem moves faster than the framework: plugins and starters begin requiring 16 well before most teams have migrated.
- 54 days
OpenSSL 3.4
A short-lived branch, not an LTS one -- if you pinned to it deliberately you are on a two-year clock that ends here.
- 59 days
Kubernetes 1.34
Upstream patch releases stop, and the managed providers are the real deadline -- EKS, GKE and AKS force-upgrade clusters past their supported window, several of them charging extended-support rates first.
- 63 days
Python 3.10
python.org stops shipping security fixes. The knock-on is faster than the date suggests: CI base images disappear, and libraries raise their
What breaks, and what to do →Requires-Pythonfloor, so installs start failing on resolution rather than on syntax. - 64 days
Alpine Linux 3.21
The branch stops receiving security updates, which means
FROM alpine:3.21becomes a permanently unpatched base layer in every image built from it. - 64 days
OpenSSL 3.6
Another non-LTS branch reaching its end; check whether you pinned a minor or are tracking the LTS line.
- 70 days
Ruby on Rails 8.0
Security backports stop for this series, so an app left here has no supported path to a patch short of upgrading.
- 73 days
Microsoft .NET 9
Microsoft ends support the same day as .NET 8 -- a Standard Term release expiring alongside the LTS one, which surprises teams who chose 9 for its newer features.
- 73 days
Microsoft .NET 8LTS
The LTS release most enterprises standardised on ends here, on the same day as .NET 9, leaving .NET 10 as the only supported target.
- 75 days
PostgreSQL 14
The final minor release lands and no further security fixes follow. Managed providers force-upgrade after this, and extension authors drop the version from their build matrices.
- 82 days
GitLab 19.3
The last of three GitLab minors expiring inside a quarter -- if you self-host, the upgrade cadence is the product, not an optional extra.
Three to six months6 releases
- 91 days
Angular 20
Long-term support ends, so no further security patches -- and Angular's upgrade path punishes skipped majors, so the longer you sit the worse the jump.
- 94 days
Redis 8.0
Security fixes stop for this series; check whether your managed provider tracks Redis versions or has quietly moved you to a fork.
- 97 days
Docker Engine 25.0
No further patches to the engine itself, which on a host running untrusted workloads is a different risk class from an out-of-date library.
- 124 days
PHP 8.2
Security support ends, and shared hosts tend to be the enforcement mechanism -- they start refusing the runtime, and Composer constraints rise underneath you.
- 124 days
Spring Boot 4.0
Open-source support ends here; continued patches move behind a commercial extended-support agreement.
- 129 days
Electron 43
An Electron app is only as patched as the Chromium it bundles, and this release stops receiving those updates.
Also ending24 more
Tracked and dated; no consequence written yet. Each date links to its endoflife.date row so you can check it at the source.
- HAProxy 3.3
- Grafana 13.0
- Symfony 8.1
- Laravel 12
- Kubernetes 1.35
- Electron 44
- Grafana 13.1
- Ruby 3.3
- Redis 6.2
- HAProxy 2.6
- Node.js 22
- Django 6.0
- Alpine Linux 3.22
- OpenSSL 4.0
- Grafana 13.2
- Grafana 12.4
- Ubuntu 22.04
- Kubernetes 1.36
- Angular 21
- Elasticsearch 8.19
- Spring Boot 4.1
- Spring Framework 7.0
- MongoDB Server 7.0
- Valkey 8.0