Not what’s new. What breaks.
Suricate watches the libraries and runtimes in your repository, plus the providers, models and plans you declare — the ones no manifest can reveal. When one of them breaks, is deprecated or shuts down, you get an email with the date it lands and what to do about it.
At most one email a night. Most nights, none.
Watch my repositoryOne repository, free. Read-only, and you pick which one.
We read your manifests and your configuration files. Never your code.
What that looks like on a repository nobody signed up for
4 changes. 7 emails. Every one announced in advance.
vercel/ai-chatbot, 10 Sept 2025 to 10 Sept 2026 — 366 nights, one check each. We took their public manifest as it stood on each of those nights and put it through the engine that would watch your project: same matcher, same nightly cadence, same reminders as a deadline gets close. It proves the engine, not our reflexes: the base did not exist yet.
- critical+ 3 reminders
Node.js 20 reaches end of life
Node.js · 232 days before 30 Apr 2026
Announced 22 Oct 2024 · the vendor’s own page, last checked 7 Sept 2026
Next.js 16 is a major release with breaking changes
Next.js · they were on 15.3.0-canary.31
Announced 21 Oct 2025 · the vendor’s own page, last checked 7 Sept 2026
Vercel AI SDK 6 is a major release with breaking changes
Vercel AI SDK · they were on 6.0.0-beta.159
Announced 22 Dec 2025 · the vendor’s own page, last checked 7 Sept 2026
Drizzle ORM 1.0 is in release candidate with no stable release date
Drizzle ORM · they were on 0.34.1
Announced 27 Jun 2026 · the vendor’s own page, last checked 7 Sept 2026
One repository, free. Read-only, and you pick which one.
How it works
- 1
You connect a repository
Read-only, and you pick which ones. Then you tick the providers and services you use — the ones a manifest cannot reveal.
- 2
We read your manifests and your configuration files. Never your code.
Manifests, lockfile, and the config that states a runtime or a host — .nvmrc, vercel.json, a Dockerfile, a CI workflow. The scan is planned from a fixed list of paths, so nothing else is ever opened.
- 3
You get an email when it concerns you
Not a feed to check. One message a night at most, covering what is new, with the vendor's own announcement, what breaks and what to do — then reminders as a deadline closes in.
What this does not cover
- It is not a claim about our speed. Nobody was being emailed about vercel/ai-chatbot in 2025. Every entry we matched against was written and checked by hand in September 2026, then replayed backwards. It shows the engine picking the right things out of a real stack — not how fast we would have got there.
- Dates before the window land on night one. Node.js's end of life was announced 22 Oct 2024, before this replay starts, so it surfaces on the first night rather than on the day it broke.
- A public repository declares nothing. This replay matched against 20 announcements. Eight are readable from a manifest alone: major versions, no cut-off date, one email each. The other twelve need someone signed in to say which models, plans and providers the project calls — and those twelve are the ones carrying a date. An API model being retired, a plan discontinued, a runtime reaching end of life: none of them could fire here. A manifest gives you major versions with no deadline. A declaration gives you cut-off dates.
- Your own base starts the day you connect. There is no backtest for your repository and there will not be one. You may hear nothing for weeks, which is the product working, and the status page is public so a quiet month never has to be taken on trust.
Coverage is hand-curated and finite. A change nobody has entered is a change you will not hear about from us, and no amount of copywriting changes that — which is why how current the base is is public, with no account, before you sign up rather than after. A quiet month and an abandoned service look identical from the outside; that page is the difference.