l3montree-dev / l3montree-dev/devguard

Track End of Life (EOL) as Security Risk

Open
#2,076 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

feature-request needs more info
Dominant language
Go
Stars
161
Forks
43
Avg merge
1d 8h
Merged PRs (30d)
37

Description

Is your feature request related to a problem? Please describe.
Open Source Frameworks / Components often come with a End of Life which is a really important date to identify potential long time risk when no new security patches are available.

Describe the solution you'd like
Make it possible to define org / instance-wide End of LIfe (EOL) times for packages with different threshold, e.g.

  • 3 month until EOL = low risk
  • 1 month until EOL = medium risk
  • EOL reached = high risk
  • 3 month after EOL = critical risk

The risk should be prominent (other tab like license risks..), project owner and company owner should find a summary summaries about nearing EOL times so identify possible migration targets.

*) Projects should have a way to "override" the EOL - if their e.g. have a commercial contract.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by locating the existing license-risk view and summary flow, then determine how package EOL thresholds, project overrides, risk levels, and owner summaries should fit; done means nearing and past-EOL packages are visibly reported with the requested severity and override behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.