惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
美团技术团队
D
Docker
WordPress大学
WordPress大学
T
Tailwind CSS Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
The Cloudflare Blog
Y
Y Combinator Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
I got burned by an EOL Node.js version in prod. So I buil...
Nico Devai · 2026-06-15 · via DEV Community

Last year, a security audit uncovered a vulnerability in our production environment. The finding: we were using Node.js 21, a version that had been nearing its end of life for several months. No active exploits, no incidents, but a growing list of unpatched CVE vulnerabilities, still open and with no planned fix. The kind of problem that goes unnoticed until it becomes obvious.

The most frustrating part wasn't the discovery itself, but realizing that no one on the team had been informed about the impending end of life of Node.js 16. No alerts, no reminders, nothing. Yet, we needed to be aware. And apparently, we weren't.

I looked for a simple tool that would allow me to declare my technology stack and be notified when a version is approaching its end of life or when a new critical CVE vulnerability is detected. I couldn't find exactly what I was looking for: most tools required connecting to a GitHub repository, installing an agent, or charged for basic alerts.

So, I created it. EOLCanary tracks end-of-life (EOL) dates and CVEs for 459 technologies: Node.js, Redis, PHP, PostgreSQL, Ubuntu, Kubernetes, and more. No agent or repository connection is required. You simply check your stack.

Regarding data sources: complete transparency

The end-of-life date data comes from endoflife.date, an excellent open-source project I wanted to mention. If you simply want to check a date, go to endoflife.date: it's a fantastic tool.

I also wanted to add two features missing from endoflife.date:

CVE tracking by version. Data is extracted daily from the NVD, including EPSS scores and CISA KEV indicators. The EPSS score indicates the likelihood of a CVE being exploited within the next 30 days: far more actionable information than a simple CVSS score. The KEV list includes confirmed active exploits. If your stack has one of these vulnerabilities, the risk is no longer theoretical.

Alerts and a dashboard dedicated to your stack are also available. Here's what I'm currently developing. The principle is simple: you create an account, declare your infrastructure (Node 20, Redis 7, Ubuntu 22.04, etc.), and EOLCanary monitors it for you. You are notified when a version reaches its end of life, when a new CVE vulnerability is detected in a component you use, or when a dependency is added to the CISA Key Vulnerabilities (KEV) list. Notifications are initially sent via email, then later via Slack and webhooks.

No GitHub repository to connect. No installation required. Just a list of your applications and important alerts.

Would this be useful to you? I'm trying to determine if the alert system solves a real problem or if most users simply check manually from time to time. If you manage a production infrastructure and this seems relevant (or if you think the approach is flawed), please leave a comment.

Viewing the site is free today. Stack monitoring and alerts will be available in the coming weeks.

eolcanary.com Feel free to ask me your questions: about the stack (Nuxt 3 + Supabase), the difficulties related to the NVD API, or why I think declarative stack monitoring is an underestimated concept.

Thx