Know when the services you build on change the deal.
Pricing and free-tier changes, licence switches, end-of-life notices and acquisitions, for the hosting, databases, APIs and runtimes you run on. One short email when a change affects you, quoting the source, with your options.
end of life Deno: development of the runtime ends in about a year
Deno is joining Cloudflare. The runtime gets monthly bug-fix and security releases for one more year, then development stops. Deno Deploy shuts down in six months.
We will support the Deno runtime for another year with monthly releases containing bug fixes and security updates. After that year we will end our development of the Deno runtime. deno.com/blog/cloudflare
Takes effect: 2027-10 · Affects you because: you run Deno in production in “api”.
Options: Node.js 24 LTS (medium effort) · Bun (medium) · Cloudflare Workers (high)
What we watch
Pricing and free tiers
Pricing and limits pages, normalised and diffed. You get the old and new numbers side by side, not “the page changed”.
Licences
Licence switches like Redis, Terraform or Bitwarden, from the vendor's own announcement, the registry and the repository's LICENSE file.
End of life and end of development
Runtime and database support dates from endoflife.date, and announcements that a product or service is winding down.
Acquisitions and shutdowns
Vendor blogs and changelogs, read by a classifier that only passes posts that change the deal for customers.
Start from your services, not your manifests
Most of what changes the deal isn't in a package.json: your host's free tier, your database's pricing, your auth provider's terms. Tick what you use from 59 services, runtimes and tools in 13 categories, say how you use each (hosted or self-hosted, commercial or personal, free tier or paid) and we only tell you about changes that apply. Got a repo? Paste it and we pre-tick what we find, from wrangler.toml to docker-compose.yml.
Where it differs from the tools you already have
Keep Dependabot, Snyk or Socket for vulnerabilities; Stackquake doesn't do those. What they check, they mostly check when a pull request changes your dependencies:
- GitHub (Dependabot, dependency review): “The dependency review action scans your pull requests for dependency changes, and will raise an error if any vulnerabilities or invalid licenses are being introduced.” source
- Socket: “Socket currently does not initiate a scan until there is a commit or a pull request (PR) containing manifest files that Socket supports.” source
- Snyk: “For npm only, a warning icon appears next to the package name if a package is deprecated.” source
- It watches the services you run on, not only your packages. None of those tools covers a hosted service's pricing, free tier, terms, end of development or acquisition.
- It tells you when something changes, not when you next open a pull request. A project can relicense or announce its end with no new release, so a manifest scanner often has nothing to see until you upgrade.
- Every alert quotes the source and says what to do. The exact line, whether it affects your usage, the deadline, and two or three ways out. We never publish a note whose quote we can't find in the source.
- Independent. No platform to protect, so it can be blunt about any vendor, GitHub included. Works for GitLab users and self-hosters with no repo at all.
- Quiet by design. We aim for about one alert a week at most; anything that isn't urgent waits for a weekly digest.
Recent changes
endoflife.date lists Kubernetes 1.34 as reaching end of life on 2026-10-27. After that date the 1.34 release line is no longer supported upstream. Clusters running 1.34 would need to move to a newer supported minor version.
Free for one project. Team is $19 a month.
Team adds unlimited projects, private repos through our GitHub App, Slack, up to 10 people and a CSV export of vendor risk for audits and procurement.