Dependency-Track end-of-life: support & EOL dates for every release
OWASP · Security / SCA · 1 supported · 7 end-of-life · updated June 2026 · what is end-of-life? →
This is when each Dependency-Track release line stops receiving security updates. 1 release line is still supported — the next to reach end-of-life is Dependency-Track 4.14 on 9 Dec 2026. Running an end-of-life version means new vulnerabilities stay unpatched.
Dependency-Track support timeline
Each release line and the date it reaches end-of-life — newest first.
| Release | Latest version | End-of-life | Status |
|---|---|---|---|
| Dependency-Track 4.14 | 4.14.2 | 9 Dec 2026 · in 6 mo | Supported |
| Dependency-Track 4.13 | 4.13.6 | 9 Mar 2026 | End of life |
| Dependency-Track 4.12 | 4.12.7 | 7 Apr 2025 | End of life |
| Dependency-Track 4.11 | 4.11.7 | 1 Oct 2024 | End of life |
| Dependency-Track 4.10 | 4.10.1 | 7 May 2024 | End of life |
| Dependency-Track 4.9 | 4.9.1 | 8 Dec 2023 | End of life |
| Dependency-Track 4.8 | 4.8.2 | 16 Oct 2023 | End of life |
| Dependency-Track 4.7 | 4.7.1 | 18 Apr 2023 | End of life |
Which Dependency-Track version should I run?
The safest choice is the latest supported release, 5.0.1. If you're on an end-of-life line, plan an upgrade to a supported one before security updates stop. See Dependency-Track's full security status →
Get warned before Dependency-Track reaches end-of-life
End-of-life dates are easy to miss until it's too late. Monitor Dependency-Track on IsItPatched and we'll email you before the release line you run stops getting security updates — free, no account needed to start.
Dependency-Track end-of-life — frequently asked
What Dependency-Track versions are still supported?
As of June 2026, these Dependency-Track release lines still receive security updates: 4.14. The latest supported release is 5.0.1. Versions older than these (4.13, 4.12, 4.11, 4.10, 4.9, 4.8, 4.7) are end-of-life and no longer patched.
When does Dependency-Track 4.14 reach end of life?
Dependency-Track 4.14 reaches end-of-life on 9 Dec 2026 — about 6 months away. After that date it stops receiving security patches.
Is Dependency-Track end-of-life?
No — Dependency-Track still has supported release lines (4.14). But individual older versions are end-of-life, so what matters is the specific version you run.
How do I know when my Dependency-Track version reaches end of life?
Check the version you run on its product page, or monitor Dependency-Track on IsItPatched to get an email alert before the release line you use reaches end-of-life — so you can upgrade in time.
EOL dates aggregated from endoflife.date and vendor sources, and can change — always confirm with OWASP. See related: Dependency-Track security status · full EOL calendar · what is end-of-life software? · disclaimer.