本文へ移動
cccskills
無料GitHub で公開

eol-check

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md3.0 KB
  • evals/evals.json2.5 KB
  • evals/trigger-eval.json1.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix EOL Check Skill

Use when

  • Quarterly upgrade planning: which runtimes hit EOL in the next 90 days?
  • Audit: any past-EOL runtimes in production?
  • CI gate: block deploys if any EOL runtime is detected.
  • Container base-image EOL check (alpine 3.16, debian 10, etc.).
  • Cross-reference: an EOL runtime + an unpatched CVE = critical priority.

Don't use for

  • Vulnerability scanning — use vulnetix scan --sca or repo-impact.
  • License auditing — use license-check.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

Step 1: Load capabilities

Read .vulnetix/capabilities.yaml. Use derived.primary_package_manager and repo.dockerfile to decide which surfaces to scan.

Step 2: Run gated scan

vulnetix scan --block-eol -o json

Exit code is non-zero on EOL hits. Capture findings.

Step 3: Cross-check runtimes

For each detected runtime, fetch authoritative dates:

vulnetix vdb product "<runtime>" -o json   # node, python, java, golang, dotnet

Step 4: Render

| Runtime / package | Installed | EOL date | Days past EOL | Action |
| Node.js          | 16.x      | 2023-09-11 | 600          | upgrade to 20 LTS |

If --strict, also flag versions reaching EOL within 90 days.

Memory update

event: eol-check with EOL items per vuln entry (or a top-level runtimes block in memory.yaml if entries don't exist).

Edge cases & gotchas

  • vulnetix scan --block-eol exits non-zero on EOL hits — wrap with || true to capture without aborting.
  • EOL dates are from vulnetix vdb product — authoritative for major runtimes, less complete for niche libraries.
  • --strict mode flags items reaching EOL within 90 days. Default mode only flags past-EOL.
  • Container base images need a Dockerfile/Containerfile in the repo; the skill cannot scan a --image registry tag without one.
  • For runtimes with overlapping LTS schedules (Node 18 vs 20), EOL dates can shift; re-run periodically rather than caching.
  • Output flags EOL but does not propose an upgrade path — pair with dependency-choice for the recommended target.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する