Read across a row to see who publishes coverage for that part of the stack. A blank for a vendor means its published lists do not name that layer, not that it could never help.
01
OSSeva
Extended support for infrastructure and middleware, with managed operations
What it covers. Patched, signed builds for end-of-life versions of the brokers, databases, coordination services and big-data platforms that sit under applications. That includes RabbitMQ 3.8 to 3.13 with its Erlang/OTP runtime, Kafka 2.8 to 3.9 in ZooKeeper mode, ActiveMQ Classic 5.15 to 5.18, PostgreSQL 11 to 13, MongoDB 4.2 to 6.0, Elasticsearch 7.10.2 and 7.17, ZooKeeper 3.4 to 3.7, etcd 3.4, Consul up to 1.16.3, HBase, Hadoop, Hive, CDH, HDP, Druid, Storm, Flink and ClickHouse. It also covers Spring, Tomcat, Node.js and .NET.
Strengths
- Covers the ZooKeeper under a product as well as the product. A patched HBase or Solr ships with a patched ZooKeeper beneath it.
- Bitnami-compatible drop-in images for end-of-life PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB and Elasticsearch, with the same variables and /bitnami paths.
- Three tiers: Patch (builds), Assure (adds architecture review and an attestation pack) and Operate (24/7 managed operations with a 15-minute P1 response).
Limits. No operating system or kernel patching, and no JavaScript front-end frameworks such as Angular, React or Vue. The catalogue is narrower than a 400-technology support contract.
Choose it when. Your end-of-life exposure is in messaging, data, coordination or a ZooKeeper-dependent stack, or you want the same team to run those clusters as well as patch them.
02
HeroDevs
Never-Ending Support for end-of-life frameworks and libraries
What it covers. Application frameworks and libraries, strongest in JavaScript: AngularJS, Angular, Vue 2, React, Next.js, Nuxt, Node.js, Express, jQuery and Bootstrap. On the Java side it lists Spring, Tomcat, Jetty, Hibernate, Struts, Quarkus, Solr and Lucene, and Hazelcast. It also lists Django, NumPy, .NET, PHP, Drupal 7, Ruby on Rails, Ingress NGINX and PostgreSQL.
Strengths
- The deepest published list of end-of-life JavaScript frameworks of any vendor here.
- Drop-in patched packages pulled through registries such as Nexus and Artifactory, with support for as long as you depend on the version.
- A large public vulnerability directory and EOL tooling that help teams find their exposure.
Limits. Its published list has no RabbitMQ, Kafka, ZooKeeper, Redis, MongoDB or Elasticsearch, and it sells software rather than running clusters.
Choose it when. Your end-of-life exposure is in application code: an AngularJS or Vue 2 front end, a Spring or Struts back end, or Node.js packages.
03
TuxCare
Endless Lifecycle Support for operating systems, runtimes and libraries
What it covers. End-of-life Linux distributions such as CentOS 7, and runtimes and libraries across the JavaScript, Java, Python, PHP, Go, Rust, .NET, Perl and C++ ecosystems. Named items include Spring, Angular, Django, Flask, Laravel and Express, and a few Apache projects at fixed versions, such as Kafka 3.2.3, Spark 2.4.8 and Struts. TuxCare says it curates more than 36,000 packages.
Strengths
- Operating-system depth, including live kernel patching through KernelCare.
- Very wide library coverage across many language ecosystems.
- An SBOM and VEX data with every library release. TuxCare's own page lists SLSA Level 3 attestation for these packages as coming soon.
Limits. Middleware coverage is limited to named versions, and brokers such as RabbitMQ and coordination services such as ZooKeeper are not on its published lists.
Choose it when. The problem is the operating system, the kernel or a long tail of language-level libraries across a Linux fleet.
04
OpenLogic by Perforce
Broad open source support, with long-term support for a short list of EOL products
What it covers. Technical support for more than 400 open source technologies. Its long-term support (LTS) product, which is the patched end-of-life part, lists eight: AngularJS, Bootstrap, CentOS, Kafka, MySQL, Spring Boot, Spring Framework and Tomcat.
Strengths
- One support contract across a very wide estate.
- Published LTS terms: at least two years past community end of life, and fixes for CVSS 7 and above (4 and above for AngularJS and Bootstrap) within 14 days for critical and 30 days for high.
- Professional services, migrations and training alongside support.
Limits. Patched end-of-life builds are limited to the eight LTS products. For anything else, support means help running a version, not new security fixes for it.
Choose it when. You want one vendor for many technologies and your end-of-life problem is CentOS, Kafka, MySQL, Spring, Tomcat or AngularJS.
05
Broadcom (Tanzu and Bitnami Secure Images)
The upstream commercial owner of Spring, RabbitMQ and the Bitnami catalogue
What it covers. Commercial support for its own projects past their open source dates. Spring Boot 2.7 and Spring Framework 5.3 have commercial support to 30 June 2029, and RabbitMQ 3.13 to 31 December 2029. Bitnami Secure Images is the paid replacement for the free Bitnami catalogue, with hardened images for more than 280 applications, SLSA Level 3 builds, SBOMs and VEX data.
Strengths
- Support from the company that develops Spring and RabbitMQ.
- Commercial end dates run well past the open source ones.
- The widest Bitnami-compatible image catalogue on current versions.
Limits. Coverage is limited to Broadcom's own projects. Bitnami Secure Images follows upstream version support, so pinned end-of-life versions age out of it.
Choose it when. You already hold a Broadcom agreement, want support from the project's owner, or run many Bitnami images on current versions.
06
Chainguard
Minimal hardened container images and rebuilt libraries
What it covers. Low-CVE container images and language libraries built from source. For images whose main package reaches end of life, an EOL Grace Period keeps rebuilding the image for up to six months.
Strengths
- Minimal images built from source, aimed at low CVE counts on current versions.
- Rebuilt language libraries as well as images.
- A clear, published grace-period policy.
Limits. The grace period fixes the other packages in the image, not the end-of-life package itself. Chainguard's documentation says it does not backport fixes to the primary package, and it allows no exceptions to the six-month limit.
Choose it when. You are moving to current versions and want clean base images, with a short bridge while the upgrade lands.
07
Docker Hardened Images
Hardened base images, with a paid extended lifecycle add-on
What it covers. More than 1,000 hardened images built on Debian and Alpine, free under Apache 2.0 since 17 December 2025. DHI Enterprise adds SLA-backed fixes, and the Extended Lifecycle Support add-on gives five more years of security coverage after upstream end of life.
Strengths
- Free, open hardened images for current versions.
- Five years of image-level coverage past end of life on the paid add-on.
- Built into the Docker tooling many teams already use.
Limits. It works at the image level. Operational support for the database or broker inside the image is a separate question.
Choose it when. Your estate is container-first and the main need is a patched, attested image for a runtime or base OS.
08
endoflife.date
A free lifecycle tracker, not a vendor
What it covers. Release and end-of-life dates for several hundred products (478 on the day of this review), aggregated from public sources and served on the web and through an API.
Strengths
- Free, community-maintained and easy to automate against.
- Widely used as a reference. Chainguard uses its dates to decide grace-period eligibility.
Limits. It sells nothing and patches nothing. It tells you a version is out of support; it cannot fix it.
Choose it when. Use it first, to find which versions in your estate are already past end of life.
Start with an inventory. List every end-of-life version you run, including the ones inside other products: the ZooKeeper under Kafka or HBase, the Erlang runtime under RabbitMQ, the base image under a Helm chart. endoflife.date and the OSSeva EOL tracker help here.
Then group the list by layer and read the table above. Most estates end up with two vendors at most: one for the operating system or application frameworks, and one for the infrastructure underneath. Ask each vendor for patched builds against the same version list, and check three things in the answer: whether they backport fixes into the version you run or only rebuild around it, how long the coverage lasts, and what evidence (SBOM, VEX, signed builds) an auditor will get.
If the infrastructure layer is where your gap is, OSSeva Patch ships the builds, Assure adds the review and attestation pack, and Operate runs the clusters for you.