METHODOLOGY

How magento.watch data is sourced and checked

magento.watch tracks Magento Open Source, Adobe Commerce and Mage-OS releases. This page states where the data comes from, how often it changes, what each status means and what the data does not cover.

Sources

Update cadence

Status definitions

supported
The newest released patch of a release line that has not reached its end-of-support date. Being inside the support window is not enough: only the newest patch counts.
outdated
A release of a line still in support for which a newer patch of the same line exists; the fixes it lacks ship in that newer patch.
vulnerable
A tracked Adobe security bulletin affects this release and the release does not include the fix; the remedy is a later release or an Adobe isolated patch.
end of support
The release is past its published end-of-support date and no longer receives security fixes. Shown as eol in the API and MCP server.

Supported, outdated and end of support describe the lifecycle axis; vulnerable, secure and unknown describe the security axis, so one release can be supported and vulnerable at once.

secure
No tracked security bulletin affects this release without a fix in it.
unknown
The tracked bulletins do not cover this distribution, so no security claim is made.

Coverage limits

Verification

Contact

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.