Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
REVIEWED ORIGINAL-SOURCE CLAIMOFFICIAL VENDOR SOURCEREVIEWED 14 SEP 2026

Gerritcodereview · EDITORIAL PRIMARY-SOURCE REVIEW

Gerrit Code Review 3.6

Gerrit Code Review 3.6 is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This claim was manually scoped and reviewed against the linked original publisher statement. It applies only to the named release and support phase. Confirm edition, device and contract applicability before acting.

Claim scope: Gerrit open-source community 3.6 release line only; best-effort exceptional security backports to old branches remain possible.

Reviewed 14 Sep 2026.

Product overview

Gerrit Code Review 3.6 is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • User-facing application functions
  • Local or managed application deployment
  • Vendor-maintained feature and security updates

Typical use

Used by individuals or organizations for the product-specific tasks described by its publisher.

Deployment

Installed on supported endpoints or supplied through a vendor-managed service, depending on the edition.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductGerrit Code Review 3.6
Release3.6
End of Gerrit community release end of life24 November 2023
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 15 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYManual

Gerrit official lifecycle source

3.6 | EOL | EOL since Nov 24, 2023

Publisher identity used by product-specific official-source collectors.

Original-source claim reviewed 14 Sep 2026

Open official vendor source