How-To Guides/Software End-of-Life
Software Inventory ~10 minutes

How to Track Software End-of-Life in AllowNow

Running unsupported software is one of the most common — and most avoidable — audit findings. AllowNow's Software Inventory lets you record the technologies you run (nginx, PHP, Docker, PostgreSQL, memcached…), resolves each version's end-of-life date automatically from endoflife.date, highlights anything EOL or approaching it, and emails you before support runs out. This is your evidence for PCI DSS Req. 6.3.3, SOC 2 CC7.1, and ISO 27001 A.8.8.

Prerequisites

  • AllowNow owner access — Software lives in the sidebar under Services
  • A list of the technologies and versions running on your servers
  • No credentials or agents required — EOL data comes from the public endoflife.date catalogue
1

Open Software and add an item

1 minute

In the sidebar, open Software and click Add software. The inventory is where every server technology you run lives alongside its version and support status.

2

Search the technology and pick a release cycle

2 minutes

Start typing the technology name — nginx, php, docker, postgresql, redis, memcached — and pick it from the results. AllowNow then loads its release cycles from endoflife.date, each annotated with its status and EOL date.

Select the release cycle you run (for example PHP 8.1 or Ubuntu 22.04). AllowNow resolves and stores its EOL date, latest patch version, and whether it's still maintained — no dates to type by hand.

Not in the catalogue? Internal or niche software can still be added manually — just fill in the name and version. You'll manage its lifecycle yourself, but it stays in one inventory with everything else.
3

Record the deployed version, owner and host

2 minutes

Fill in the exact deployed version (e.g. 1.24.0), set a risk level, and optionally note the host / location it runs on and an owner responsible for keeping it current. Save — it appears in your inventory immediately.

Repeat for each technology in your environment. Web servers, language runtimes, databases, caches, container runtimes and OS versions are all worth tracking.

4

Review EOL highlighting

1 minute

The inventory sorts the most urgent items to the top and badges each one:

  • End of life — no longer receiving security patches. Prioritise these.
  • EOL approaching — support ends within about six months. Plan the upgrade now.
  • Unsupported — the vendor no longer maintains this release.
  • Supported — actively maintained.

Counts at the top show how many items are EOL or approaching, and cards flag when a newer version is available so you know the upgrade target.

5

Recheck EOL and act on reminders

ongoing

Click Recheck EOL any time to re-resolve every item against endoflife.date — useful before an audit or after a maintenance window. AllowNow also emails the owner an automatic digest of software that is EOL or approaching it, so upgrades get planned in advance instead of triggered by an incident.

Audit evidence: a current, dated software inventory directly answers “how do you manage unsupported software?” for PCI DSS 6.3.3, SOC 2 CC7.1 and ISO 27001 A.8.8. For anything you can't upgrade yet, record a compensating control in the notes.

Tips

  • Track the release cycle, not just the patch. EOL applies to the cycle (e.g. PHP 8.1), so selecting it is what drives the dates — the deployed version is your precise record.
  • Assign an owner. An unowned technology is one nobody will upgrade. The owner receives the EOL reminders.
  • Recheck before every audit. One click refreshes all dates so your evidence matches reality on the day.

Stop discovering EOL software during the audit

AllowNow keeps a live inventory of every technology you run, resolves its end-of-life date automatically, and reminds you before support ends.

Get started free