Skip to content

SunsetScan v2.2.0 — Expanded hardware lifecycle coverage

Choose a tag to compare

@NoCoderRandom NoCoderRandom released this 22 Sep 22:40
· 2 commits to main since this release

SunsetScan v2.2.0 — hardware lifecycle expansion

SunsetScan 2.2.0 expands the offline hardware lifecycle database and improves the evidence shown in security reports. The release focuses on broader vendor coverage without treating every end-of-life or end-of-sale label as proof that security updates have stopped.

Highlights

  • 86,276 hardware lifecycle records across 224 vendors, with 81,738 model summaries. The validated Stage 105 database is now the production split database and powers the home, office, enterprise, industrial, service-provider, and full smart profiles.
  • Cautious lifecycle interpretation. End-of-sale, retired, discontinued, and similar vendor labels remain review signals unless the source establishes an actual end to support or security updates. Records with ambiguous evidence keep receives_security_updates unknown.
  • Cleaner findings and reports. SSH checks use the server's advertised algorithms rather than the scanner client's algorithm list. Reports avoid uncertain OS-version guesses, generic remediation unrelated to the finding, router catch-all pages misidentified as admin panels, and ASUS httpd/2.0 misidentified as Apache.
  • Auditable data build. The source importer, duplicate handling, validators, and focused tests are included in the repository. Raw vendor captures and historical intermediate builds are intentionally excluded from the release.

Downloads

System Download Installation
Debian, Ubuntu, Raspberry Pi OS, Linux Mint, Pop!_OS .deb package and SHA-256 checksum Verify the checksum, then run sudo apt install ./sunsetscan_2.2.0-1_all.deb.
Other Linux distributions and WSL2 GitHub's source .tar.gz or .zip for this tag Extract, then run ./install.sh in the project directory.

The .deb is architecture-independent Python code with the compressed hardware database. Its install script creates a virtual environment and installs Python dependencies, so first installation requires network access. nmap is required; masscan remains an optional recommended package. Scans themselves use local data and do not require an internet connection.

curl -fLO https://github.com/NoCoderRandom/sunsetscan/releases/download/v2.2.0/sunsetscan_2.2.0-1_all.deb
curl -fLO https://github.com/NoCoderRandom/sunsetscan/releases/download/v2.2.0/sunsetscan_2.2.0-1_all.deb.sha256
sha256sum -c sunsetscan_2.2.0-1_all.deb.sha256
sudo apt install ./sunsetscan_2.2.0-1_all.deb
sunsetscan --version
sudo sunsetscan --setup

The system package stores runtime caches under root-owned /opt/sunsetscan; run packaged scans and data updates with sudo sunsetscan. Source installs in your home directory support non-root quick scans and user-owned cache updates.

Verification

  • 318 focused hardware lifecycle tests passed; 402 tests passed in the full suite.
  • The candidate and production database validated with zero duplicate record IDs and zero duplicate import keys.
  • All 30 smart-pack manifest file hashes matched, with one-to-one coverage of all 86,276 records.
  • Functional scans against a Debian test host and an ASUS RT-AX92U router completed, and their generated HTML reports were reviewed. The ASUS lifecycle finding remains lifecycle_review; it does not claim security updates have ended.
  • The Debian package checksum and package contents are verified as part of this release build.

The four raw source directories homematic_eq3, hp_poly, lupus_electronics, and xerox_printers remain unrepresented because the available evidence was insufficient for safe exact lifecycle records.

Licensing: application code is MIT licensed. The hardware lifecycle database has a separate CC BY-NC 4.0 license.