Product Update: OS End-of-Life Visibility
Overview
Operating System End-of-Life (EOL) visibility introduces new lifecycle attributes in both the API and UI, allowing customers to easily identify whether the operating system used by an image or host is actively supported by its vendor.
This feature is available as part of the U14 release.
What is changing
Aqua is adding OS End-of-Life (EOL) information to the vulnerability dataset. Where available, customers can view whether an operating system is still supported by its vendor directly in the platform UI and through API responses.
This enhancement includes:
- New OS lifecycle attributes in vulnerability data
- Corresponding UI fields and filtering capabilities
- Improved visibility into vendor support status for images and hosts
Why this change is being made
Today, customers have limited visibility into the support lifecycle of operating systems running in their images and hosts. This can lead to security and compliance risks because:
- Unsupported operating system releases no longer receive security updates or patches
- Customers may assume an image is secure while the underlying OS has already reached End of Life (EOL)
- Many compliance frameworks (such as PCI-DSS, ISO 27001, and SOC 2) discourage or prohibit the use of unsupported software
By surfacing OS lifecycle information, customers can make more informed decisions, prioritize remediation efforts, and maintain compliance with organizational and regulatory requirements.
Customer impact
This is a new feature and does not impact existing customer workflows. It adds new OS lifecycle attributes to the vulnerability dataset, along with corresponding UI fields and filtering capabilities.
Prerequisites
Customers should upgrade all scanner instances to a version that supports this feature.
Because scan requests are distributed across available scanners, environments running a mix of upgraded and older scanner versions may experience inconsistent OS EOL data. Older scanners do not collect or report the new lifecycle attributes.
Important notes:
- Once an image or host is scanned by an upgraded scanner, the OS lifecycle information is stored in the database and will remain available
- Until every workload has been scanned at least once by an upgraded scanner, customers may observe incomplete or inconsistent EOL information across their environment
- To ensure complete and consistent results, upgrade all scanner instances before relying on this feature
Frequently Asked Questions
Q: Will this change affect my existing vulnerability workflows?
A: No. This is a new capability that enriches vulnerability data. Existing workflows are not disrupted.
Q: Why am I not seeing EOL information for all images or hosts?
A: Ensure all scanner instances are upgraded and that affected workloads have been rescanned by an upgraded scanner.
Q: Which compliance frameworks does this help address?
A: OS EOL visibility supports compliance efforts aligned with frameworks such as PCI-DSS, ISO 27001, and SOC 2 that discourage use of unsupported software.
Q: Do I need to upgrade only some scanners?
A: We strongly recommend upgrading all scanner instances. Mixed scanner versions can produce inconsistent EOL data.
Did you find it helpful? Yes No
Send feedback