Sample Migration Risk Report
This is the actual document a $150 Migration Risk Report produces, shown in full so you can judge it before paying for one. The company is invented. Every version, date, day count and source link below is real and resolved from the live dataset — you can click through and verify any line.
Northwind Freight Systems
Executive summary
14 of 25 technologies are running versions that are already past their published end-of-life date and no longer receive security patches. A further 2 lose support within 90 days.
The most exposed component is spring boot 2.7, unsupported since 2023-06-30 — 1127 days ago.
Nothing here requires an emergency response tonight. It does require an owner and a date, because 14 unsupported components is the kind of finding that appears in a security questionnaire or SOC 2 evidence request without warning, and then has to be answered in a week rather than a quarter.
1. Unsupported versions — action required
Past their published end-of-life date. Negative day counts show how long each has been unsupported.
| Technology | Version | End of life | Days | Source |
|---|---|---|---|---|
| spring boot | 2.7 | 2023-06-30 | -1127 | verify |
| terraform | 1.5 | 2024-01-17 | -926 | verify |
| rabbitmq | 3.12 | 2024-02-21 | -891 | verify |
| django | 3.2 | 2024-04-01 | -851 | verify |
| nginx | 1.24 | 2024-04-23 | -829 | verify |
| go | 1.21 | 2024-08-13 | -717 | verify |
| kubernetes | 1.28 | 2024-10-28 | -641 | verify |
| mongodb | 5.0 | 2024-10-31 | -638 | verify |
| nodejs | 18 | 2025-04-30 | -457 | verify |
| alpine linux | 3.18 | 2025-05-09 | -448 | verify |
| ubuntu | 20.04 | 2025-05-31 | -426 | verify |
| python | 3.9 | 2025-10-31 | -273 | verify |
| php | 8.1 | 2025-12-31 | -212 | verify |
| mysql | 8.0 | 2026-04-30 | -92 | verify |
2. Losing support within 90 days
3. Losing support within 12 months
| Technology | Version | End of life | Days | Source |
|---|---|---|---|---|
| postgresql | 14 | 2026-11-12 | +104 | verify |
| docker engine | (version not specified; next tracked release 25.0) | 2026-12-04 | +126 | verify |
| redis | 6.2 | 2027-04-01 | +244 | verify |
| elasticsearch | 7.17 | 2027-07-15 | +349 | verify |
4. Not found in the dataset
Reported honestly as unknown. This means nothing was found — not that these are safe. Verify them against the vendor directly.
| Technology | Version | End of life | Source |
|---|---|---|---|
| java | 11 | — | — |
| vault | 1.14 | — | — |
5. Recommended order of action
Ordered by exposure, then by deadline. This is a suggested sequence, not a prescription — your dependency constraints and release calendar override it.
- Patch or upgrade spring boot 2.7Unsupported since 2023-06-30. Every day it runs is a day without security fixes, and it is the finding an auditor reaches first.
- Patch or upgrade terraform 1.5Unsupported since 2024-01-17. Every day it runs is a day without security fixes, and it is the finding an auditor reaches first.
- Patch or upgrade rabbitmq 3.12Unsupported since 2024-02-21. Every day it runs is a day without security fixes, and it is the finding an auditor reaches first.
- Patch or upgrade django 3.2Unsupported since 2024-04-01. Every day it runs is a day without security fixes, and it is the finding an auditor reaches first.
- Patch or upgrade nginx 1.24Unsupported since 2024-04-23. Every day it runs is a day without security fixes, and it is the finding an auditor reaches first.
- Schedule the prometheus 2.45 upgradeSupport ends 2026-07-31 — 0 days. Long enough to plan, short enough that it needs an owner now.
- Schedule the grafana 10 upgradeSupport ends 2026-08-19 — 19 days. Long enough to plan, short enough that it needs an owner now.
- Put the remaining watch items on the roadmap4 technologies lose support within 12 months. None is urgent today; all become urgent without a decision.
- Confirm the unknown items manually2 technologies are not in the dataset. That is an absence of information, not a clean result — check them against the vendor directly.
6. Limitations and assumptions
- Versions are as you reported them. Nothing was scanned, discovered or verified against your infrastructure. If the version list is wrong, the report is wrong.
- Dates are re-published, not original. Support dates come from endoflife.date, an open dataset citing vendor announcements. Use the vendor's own notice as the authority for a compliance decision. Every row above links to its source.
- Unknown is not clear. Items not in the dataset are reported as unknown. Coverage is strongest for languages, databases, infrastructure and developer tooling, and weak for business SaaS.
- Extended and paid support is not modelled. If you hold a commercial support contract, your real dates may be later than shown.
- This is not a security assessment. Unsupported does not mean exploited, and supported does not mean safe. It reports support status only.
- Point-in-time. Accurate on 2026-07-31. Vendors change dates.
What this would cost you to produce
Twenty-five technologies, each checked against its vendor's published lifecycle page, cross-referenced for shutdown and acquisition events, then written up. It is roughly two to three hours of careful work that nobody schedules, which is why it usually gets discovered by an auditor instead.
Get this for your own stack
$150, paid after delivery. If it tells you nothing you did not already know, do not pay.