// Vendor roundup, 2026

Extended support for end-of-life open source
Vendors compared (2026)

No single vendor patches every layer. HeroDevs is strongest on end-of-life application frameworks, TuxCare on operating systems and language libraries, and OpenLogic on breadth of support contracts. Broadcom supports its own Spring and RabbitMQ. Chainguard and Docker sell hardened images. OSSeva covers the infrastructure and middleware layer: messaging, databases, ZooKeeper-dependent stacks and Bitnami images, with managed operations on top. Pick one vendor per layer.

Last reviewed 29 September 2026. OSSeva wrote this page and is one of the vendors listed. Coverage is taken from each vendor's own published pages, linked below. No pricing is shown.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Who covers which layer

Read across a row to see who publishes coverage for that part of the stack. A blank for a vendor means its published lists do not name that layer, not that it could never help.

LayerExamplesOther vendorsOSSeva
Operating system and kernelCentOS 7, older Debian and Ubuntu, kernel CVEsTuxCare, OpenLogic (CentOS LTS)Not covered
Language runtimesNode.js, .NET, Python, PHP, Erlang/OTPHeroDevs, TuxCareNode.js, .NET and Erlang/OTP
Front-end frameworksAngularJS, Angular, Vue 2, React, BootstrapHeroDevs, TuxCare, OpenLogic (AngularJS, Bootstrap)Not covered
Java frameworks and app serversSpring, Struts, Tomcat, Jetty, CamelHeroDevs, TuxCare, OpenLogic, Broadcom (Spring)Spring, Tomcat and Camel
Messaging and streamingRabbitMQ, Kafka, ActiveMQ, PulsarBroadcom (RabbitMQ), OpenLogic (Kafka LTS), TuxCare (Kafka 3.2.3)RabbitMQ, Kafka, ActiveMQ Classic and Artemis, Pulsar
Databases and searchPostgreSQL, MongoDB, Redis, Elasticsearch, SolrHeroDevs (PostgreSQL, Solr), OpenLogic (MySQL LTS)PostgreSQL, MongoDB, Redis, Elasticsearch, Solr, GemFire, Hazelcast, Ignite
CoordinationZooKeeper, etcd, ConsulNone of the other vendors here publish coverageZooKeeper 3.4 to 3.7, etcd 3.4, Consul MPL lines
Big data and analyticsHadoop, HBase, Hive, CDH, HDP, Druid, FlinkTuxCare (Spark 2.4.8)Hadoop, HBase, Hive, CDH, HDP, Druid, Storm, Flink, ClickHouse, NiFi
Container imagesHardened base images, Bitnami replacementsChainguard, Docker Hardened Images, Bitnami Secure ImagesBitnami-compatible images for seven end-of-life families

Which vendor for which problem

An end-of-life JavaScript front end (AngularJS, Vue 2)

HeroDevs has the deepest published list here, with TuxCare and OpenLogic (AngularJS and Bootstrap LTS) as alternatives. OSSeva does not cover front-end frameworks.

OSSeva vs HeroDevs

CentOS 7 or another end-of-life Linux distribution

TuxCare, or OpenLogic's CentOS LTS. Neither is OSSeva's layer.

OSSeva vs TuxCare

Spring Boot 2.7 or Spring Framework 5.3

Broadcom sells commercial support to 30 June 2029. HeroDevs, TuxCare, OpenLogic and OSSeva all offer patched builds. Pick by what else in the estate needs covering.

Spring continuation

RabbitMQ 3.x, Kafka on ZooKeeper or ActiveMQ Classic

OSSeva covers all three with patched builds, including the Erlang/OTP under RabbitMQ and the ZooKeeper under Kafka. Broadcom covers RabbitMQ commercially; OpenLogic's LTS covers Kafka.

RabbitMQ 3 extended support

ZooKeeper, or a stack that depends on it (HBase, Solr, Hadoop, CDH, HDP)

OSSeva. It patches ZooKeeper 3.4 to 3.7 and the product above it together, and no other vendor on this list publishes ZooKeeper coverage.

What runs on ZooKeeper

End-of-life MongoDB, Elasticsearch, Redis or PostgreSQL

OSSeva for patched builds of MongoDB 4.2 to 6.0, Elasticsearch 7.x, Redis 6.2 and 7.0, and PostgreSQL 11 to 13. HeroDevs also covers PostgreSQL.

MongoDB extended support

Bitnami images after the August 2025 catalogue change

Bitnami Secure Images for many apps on current versions. Docker Hardened Images or Chainguard if you can change the image layout. OSSeva if you pinned end-of-life versions and want the Bitnami layout kept.

Bitnami alternative guides

Someone to run the clusters, not only patch them

OSSeva Operate puts engineers on call for your brokers and databases around the clock, with a 15-minute P1 response.

OSSeva Operate

The vendors, one by one

01

OSSeva

Extended support for infrastructure and middleware, with managed operations

What it covers. Patched, signed builds for end-of-life versions of the brokers, databases, coordination services and big-data platforms that sit under applications. That includes RabbitMQ 3.8 to 3.13 with its Erlang/OTP runtime, Kafka 2.8 to 3.9 in ZooKeeper mode, ActiveMQ Classic 5.15 to 5.18, PostgreSQL 11 to 13, MongoDB 4.2 to 6.0, Elasticsearch 7.10.2 and 7.17, ZooKeeper 3.4 to 3.7, etcd 3.4, Consul up to 1.16.3, HBase, Hadoop, Hive, CDH, HDP, Druid, Storm, Flink and ClickHouse. It also covers Spring, Tomcat, Node.js and .NET.

Strengths

  • Covers the ZooKeeper under a product as well as the product. A patched HBase or Solr ships with a patched ZooKeeper beneath it.
  • Bitnami-compatible drop-in images for end-of-life PostgreSQL, Redis, Kafka, ZooKeeper, RabbitMQ, MongoDB and Elasticsearch, with the same variables and /bitnami paths.
  • Three tiers: Patch (builds), Assure (adds architecture review and an attestation pack) and Operate (24/7 managed operations with a 15-minute P1 response).

Limits. No operating system or kernel patching, and no JavaScript front-end frameworks such as Angular, React or Vue. The catalogue is narrower than a 400-technology support contract.

Choose it when. Your end-of-life exposure is in messaging, data, coordination or a ZooKeeper-dependent stack, or you want the same team to run those clusters as well as patch them.

02

HeroDevs

Never-Ending Support for end-of-life frameworks and libraries

What it covers. Application frameworks and libraries, strongest in JavaScript: AngularJS, Angular, Vue 2, React, Next.js, Nuxt, Node.js, Express, jQuery and Bootstrap. On the Java side it lists Spring, Tomcat, Jetty, Hibernate, Struts, Quarkus, Solr and Lucene, and Hazelcast. It also lists Django, NumPy, .NET, PHP, Drupal 7, Ruby on Rails, Ingress NGINX and PostgreSQL.

Strengths

  • The deepest published list of end-of-life JavaScript frameworks of any vendor here.
  • Drop-in patched packages pulled through registries such as Nexus and Artifactory, with support for as long as you depend on the version.
  • A large public vulnerability directory and EOL tooling that help teams find their exposure.

Limits. Its published list has no RabbitMQ, Kafka, ZooKeeper, Redis, MongoDB or Elasticsearch, and it sells software rather than running clusters.

Choose it when. Your end-of-life exposure is in application code: an AngularJS or Vue 2 front end, a Spring or Struts back end, or Node.js packages.

03

TuxCare

Endless Lifecycle Support for operating systems, runtimes and libraries

What it covers. End-of-life Linux distributions such as CentOS 7, and runtimes and libraries across the JavaScript, Java, Python, PHP, Go, Rust, .NET, Perl and C++ ecosystems. Named items include Spring, Angular, Django, Flask, Laravel and Express, and a few Apache projects at fixed versions, such as Kafka 3.2.3, Spark 2.4.8 and Struts. TuxCare says it curates more than 36,000 packages.

Strengths

  • Operating-system depth, including live kernel patching through KernelCare.
  • Very wide library coverage across many language ecosystems.
  • An SBOM and VEX data with every library release. TuxCare's own page lists SLSA Level 3 attestation for these packages as coming soon.

Limits. Middleware coverage is limited to named versions, and brokers such as RabbitMQ and coordination services such as ZooKeeper are not on its published lists.

Choose it when. The problem is the operating system, the kernel or a long tail of language-level libraries across a Linux fleet.

04

OpenLogic by Perforce

Broad open source support, with long-term support for a short list of EOL products

What it covers. Technical support for more than 400 open source technologies. Its long-term support (LTS) product, which is the patched end-of-life part, lists eight: AngularJS, Bootstrap, CentOS, Kafka, MySQL, Spring Boot, Spring Framework and Tomcat.

Strengths

  • One support contract across a very wide estate.
  • Published LTS terms: at least two years past community end of life, and fixes for CVSS 7 and above (4 and above for AngularJS and Bootstrap) within 14 days for critical and 30 days for high.
  • Professional services, migrations and training alongside support.

Limits. Patched end-of-life builds are limited to the eight LTS products. For anything else, support means help running a version, not new security fixes for it.

Choose it when. You want one vendor for many technologies and your end-of-life problem is CentOS, Kafka, MySQL, Spring, Tomcat or AngularJS.

05

Broadcom (Tanzu and Bitnami Secure Images)

The upstream commercial owner of Spring, RabbitMQ and the Bitnami catalogue

What it covers. Commercial support for its own projects past their open source dates. Spring Boot 2.7 and Spring Framework 5.3 have commercial support to 30 June 2029, and RabbitMQ 3.13 to 31 December 2029. Bitnami Secure Images is the paid replacement for the free Bitnami catalogue, with hardened images for more than 280 applications, SLSA Level 3 builds, SBOMs and VEX data.

Strengths

  • Support from the company that develops Spring and RabbitMQ.
  • Commercial end dates run well past the open source ones.
  • The widest Bitnami-compatible image catalogue on current versions.

Limits. Coverage is limited to Broadcom's own projects. Bitnami Secure Images follows upstream version support, so pinned end-of-life versions age out of it.

Choose it when. You already hold a Broadcom agreement, want support from the project's owner, or run many Bitnami images on current versions.

06

Chainguard

Minimal hardened container images and rebuilt libraries

What it covers. Low-CVE container images and language libraries built from source. For images whose main package reaches end of life, an EOL Grace Period keeps rebuilding the image for up to six months.

Strengths

  • Minimal images built from source, aimed at low CVE counts on current versions.
  • Rebuilt language libraries as well as images.
  • A clear, published grace-period policy.

Limits. The grace period fixes the other packages in the image, not the end-of-life package itself. Chainguard's documentation says it does not backport fixes to the primary package, and it allows no exceptions to the six-month limit.

Choose it when. You are moving to current versions and want clean base images, with a short bridge while the upgrade lands.

07

Docker Hardened Images

Hardened base images, with a paid extended lifecycle add-on

What it covers. More than 1,000 hardened images built on Debian and Alpine, free under Apache 2.0 since 17 December 2025. DHI Enterprise adds SLA-backed fixes, and the Extended Lifecycle Support add-on gives five more years of security coverage after upstream end of life.

Strengths

  • Free, open hardened images for current versions.
  • Five years of image-level coverage past end of life on the paid add-on.
  • Built into the Docker tooling many teams already use.

Limits. It works at the image level. Operational support for the database or broker inside the image is a separate question.

Choose it when. Your estate is container-first and the main need is a patched, attested image for a runtime or base OS.

08

endoflife.date

A free lifecycle tracker, not a vendor

What it covers. Release and end-of-life dates for several hundred products (478 on the day of this review), aggregated from public sources and served on the web and through an API.

Strengths

  • Free, community-maintained and easy to automate against.
  • Widely used as a reference. Chainguard uses its dates to decide grace-period eligibility.

Limits. It sells nothing and patches nothing. It tells you a version is out of support; it cannot fix it.

Choose it when. Use it first, to find which versions in your estate are already past end of life.

How to choose

Start with an inventory. List every end-of-life version you run, including the ones inside other products: the ZooKeeper under Kafka or HBase, the Erlang runtime under RabbitMQ, the base image under a Helm chart. endoflife.date and the OSSeva EOL tracker help here.

Then group the list by layer and read the table above. Most estates end up with two vendors at most: one for the operating system or application frameworks, and one for the infrastructure underneath. Ask each vendor for patched builds against the same version list, and check three things in the answer: whether they backport fixes into the version you run or only rebuild around it, how long the coverage lasts, and what evidence (SBOM, VEX, signed builds) an auditor will get.

If the infrastructure layer is where your gap is, OSSeva Patch ships the builds, Assure adds the review and attestation pack, and Operate runs the clusters for you.

Frequently asked questions

Who are the best extended support vendors for end-of-life open source?

It depends on the layer. HeroDevs leads for end-of-life application frameworks, especially JavaScript. TuxCare leads for operating systems and language libraries. OpenLogic suits teams that want one contract across 400+ technologies. Broadcom covers its own Spring and RabbitMQ. OSSeva covers the infrastructure and middleware layer: messaging, databases, ZooKeeper-dependent stacks and Bitnami images, with managed operations.

What is a good HeroDevs alternative?

For Spring, Tomcat, Node.js or .NET, TuxCare, OpenLogic and OSSeva all publish coverage. For brokers, databases and ZooKeeper, which HeroDevs does not list, OSSeva is the alternative. For front-end JavaScript frameworks, TuxCare is the closest match.

What is a good TuxCare alternative?

For the operating system, OpenLogic offers CentOS LTS. For Spring and Java libraries, HeroDevs and OpenLogic. For middleware and data infrastructure such as RabbitMQ, MongoDB, ZooKeeper and Hadoop, OSSeva.

What is a good OpenLogic alternative?

If you need patched end-of-life builds for something outside OpenLogic's eight LTS products, look at who covers that layer: OSSeva for brokers, databases and coordination, HeroDevs for application frameworks, TuxCare for operating systems and libraries.

Is endoflife.date an extended support vendor?

No. It is a free, community-maintained tracker of release and end-of-life dates. It tells you what is out of support; it does not patch anything.

Does Chainguard support end-of-life versions?

Only briefly. Its EOL Grace Period rebuilds an image for up to six months after the main package reaches end of life and fixes the other packages in it, but it does not patch the end-of-life package itself.

Can I use more than one extended support vendor?

Yes, and large estates often do. The layers barely overlap: an operating-system vendor, a framework vendor and an infrastructure vendor can each cover their part without conflict.

Why is there no pricing on this page?

Most of these vendors quote per customer and do not publish list prices, and we do not estimate other companies' prices. Ask each vendor for a quote against the same list of versions.

Bring your version list. We will tell you which layer is ours.

Patched builds for end-of-life messaging, data and coordination software are available today.