What are the security risks of staying with loopback 3 after EOL in December 2020?

Viewed 102

My company is using loopback3 for our backend and the effort to upgrade to loopback4 seems very high. I'm not sure I can justify the business value to my boss. What are the risks of continuing to use it after EOL in December 2020? I assume I can regularly check npm audit + keep an eye on snyk alerts and upgrade any dependencies which have security issues. (This might include forking loopback/loopback-component-storage etc.)

1 Answers

Hi from the LoopBack team!

You're right that migrating your LoopBack 3 applications to LoopBack 4 is not always a straightforward effort. If you haven't done so, I'd encourage you to take a look at our migration guide: https://loopback.io/doc/en/lb4/migration-overview.html. We believe it covers most of the common use cases.

Regarding EOL, after LoopBack 3 reaches EOL, we won't be applying any security fixes. I believe that would be the biggest impact.

Hope it helps.

Related