Sourcegraph 4
Sourcegraph 4
The Sourcegraph 4 reached end of service life on May 22, 2023 — Sourcegraph no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Sourcegraph 4 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- sourcegraph
- release
- 4
- product Label
- Sourcegraph
- release Label
- 4
- codename
- lts
- latest Version
- 4.5.1
- release Date
- 2022-09-22
- maintained
- source Url
- https://endoflife.date/sourcegraph
Lifecycle Dates
- End of Service Life
- May 22, 2023
- Last OEM Support
- May 22, 2023
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Sourcegraph 4 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Sourcegraph 4?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Sourcegraph 4 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Sourcegraph 4 Support: Frequently Asked Questions
Is the Sourcegraph 4 still supported?
Sourcegraph ended support for the Sourcegraph 4 on May 22, 2023 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Sourcegraph 4 end of service life (EOSL) date?
Sourcegraph lists the end of service life for the Sourcegraph 4 as May 22, 2023.
Can I keep using the Sourcegraph 4 after its EOSL date?
Yes. EOSL means Sourcegraph stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Sourcegraph 4 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Sourcegraph 4
2 published CVEs affect the Sourcegraph 4, including 2 rated critical or high severity. Sourcegraph no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-41943 | CRITICAL | 9.0 | Nov 22, 2022 | sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0. |
| CVE-2022-41942 | HIGH | 7.9 | Nov 22, 2022 | Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send a crafted request to gitserver that would execute commands inside the container. Successful exploitation requires the ability to send local requests to gitserver. The issue is patc |