METHODOLOGY
How magento.watch data is sourced and checked
magento.watch tracks Magento Open Source, Adobe Commerce and Mage-OS releases. This page states where the data comes from, how often it changes, what each status means and what the data does not cover.
Sources
- Adobe Commerce and Magento Open Source release notes and the Adobe software lifecycle policy: release dates, end-of-support dates and system requirements.
- The Composer repositories repo.magento.com and repo.mage-os.org: which versions exist.
- Adobe security bulletins (APSB): CVEs, severity and the releases that fix them.
- The magento/quality-patches repository, pinned to a tag: quality patches, the releases they apply to and the files they modify.
- Merged pull requests in magento/magento2: upstream fixes that landed after a release line was cut.
- Mage-OS releases: versions, release dates and system requirements.
Update cadence
- Nightly checks look for new releases in the Composer repositories and refresh the quality-patch dataset; the upstream-fix dataset is refreshed weekly.
- A new version opens a draft pull request. Release dates, end-of-support dates and system requirements are filled in by hand from Adobe documentation during review. Patch and upstream-fix refreshes open normal pull requests.
- The maintainer reviews every pull request before it is merged.
- Version statuses are computed from the stored dates when a page or API response is produced, so a release can change status between data updates. The dated heading in /llms.txt shows the date the file was rendered.
Status definitions
- supported
- The newest released patch of a release line that has not reached its end-of-support date. Being inside the support window is not enough: only the newest patch counts.
- outdated
- A release of a line still in support for which a newer patch of the same line exists; the fixes it lacks ship in that newer patch.
- vulnerable
- A tracked Adobe security bulletin affects this release and the release does not include the fix; the remedy is a later release or an Adobe isolated patch.
- end of support
- The release is past its published end-of-support date and no longer receives security fixes. Shown as eol in the API and MCP server.
Supported, outdated and end of support describe the lifecycle axis; vulnerable, secure and unknown describe the security axis, so one release can be supported and vulnerable at once.
- secure
- No tracked security bulletin affects this release without a fix in it.
- unknown
- The tracked bulletins do not cover this distribution, so no security claim is made.
Coverage limits
- Quality patches are published by Adobe for Magento Open Source and Adobe Commerce. They are not published for Mage-OS, so Mage-OS pages carry none.
- Upstream fixes cover bug fixes merged into magento/magento2. Features, refactors and test-only changes are excluded.
- End-of-support dates for Mage-OS releases are unknown and shown as unknown rather than estimated.
- Mage-OS status reflects release order only; end-of-support dates are not published.
- Security status covers the bulletins tracked here; a release marked secure has no tracked unfixed bulletin, which is not a security audit.
Verification
- Checked automatically: new versions in the Composer repositories, quality patches against the pinned tag, and upstream fixes against merged pull requests. Automated validators run before every merge.
- Checked by hand during review: security bulletins, end-of-support dates and system requirements, compared with the Adobe page they come from.
- Requirements are not copied from neighbouring releases; a component Adobe stops listing is shown as no longer supported since the release that dropped it. A missing date is stored as unknown.
- Patch compatibility is resolved from the patch constraints against each release.
Contact
- Corrections and questions: contact Lukasz Bajsarowicz via https://lbajsarowicz.me.
- magento.watch is an independent project and is not affiliated with Adobe Inc.
