Back to blog

// OSSeva Blog

Operations

Who Provides Support for Hazelcast IMDG 3.x, 4.x and Older 5.x Releases?

Randall McClure7 min read

The short answer

For Hazelcast Platform 5.x Enterprise, Hazelcast itself supports each release through standard and extended support windows, with 24x7 support and hot fix patches. For Platform 5.1, 5.2 and 5.3, HeroDevs publishes Never-Ending Support builds that keep the same Maven coordinates. For IMDG 3.12, 4.0 and 4.2, and for Platform 5.3, OSSeva publishes patched builds, with client and member artifacts released together. Perforce OpenLogic sells Hazelcast technical support at all three of its support levels.

The question to settle first is which edition you run. Since Hazelcast Platform 5.4, patch releases go only to Enterprise customers, and the Community Edition gets security fixes only in new minor and major releases. A community cluster on an older release has no patch path from Hazelcast without an upgrade or a subscription.

Where Hazelcast versions stand

Hazelcast development runs on the Platform 5.x line, and the current release is 5.7.0, from 13 May 2026. IMDG 3.x and 4.x deployments sit outside it.

LineStatus on 7 October 2026Patch releases
Platform 5.7CurrentEnterprise only; Community gets fixes in the next minor release
Platform 5.4 to 5.6SupersededEnterprise only, within Hazelcast's support windows
Platform 5.0 to 5.3SupersededNo longer released for Community; Enterprise within support windows
IMDG 4.xSeveral majors behindCommunity fixes ship only in new releases, so none reach 4.x
IMDG 3.12Several majors behindCommunity fixes ship only in new releases, so none reach 3.12

Hazelcast publishes the exact standard and extended support dates for each release in its support portal. The Hazelcast end-of-life chart tracks them, and Hazelcast vulnerabilities by version lists the advisories that reach each line.

Hazelcast support providers compared

Each row reflects what the provider publishes on its own site as of 7 October 2026.

ProviderWhat it coversHazelcast versionsDelivery modelSelf-managed?
Hazelcast24x7 support with a one-hour SLA, hot fix patches and CVE patch releases for Enterprise customers, with standard and extended support optionsPlatform 5.x releases within their support windowsEnterprise subscriptionYes, on Enterprise Edition
HeroDevs (NES for Hazelcast)CVE fixes for Hazelcast core and hazelcast-spring, plus bundled dependencies such as Jackson-core, with VEX statements and SLA-backed delivery5.1.x, 5.2.x and 5.3.xDrop-in Maven artifacts with the same coordinatesYes
Perforce OpenLogicHazelcast technical support at Gold, Silver and Bronze levelsNo version list publishedSupport subscriptionYes
OSSevaSecurity backports with deserialization and cluster protocol advisories prioritised, member and client artifacts released together; grid audit on Assure; 24/7 operations on OperateIMDG 3.12, 4.0 and 4.2, and Platform 5.3Signed Maven and Docker artifactsYes

HeroDevs and OSSeva overlap on Platform 5.3 only. HeroDevs covers the earlier 5.x releases, and OSSeva covers the IMDG 3.x and 4.x lines that came before Platform.

How the providers differ

Hazelcast

For a cluster on Enterprise Edition, or one that can move to it, Hazelcast is the direct answer: patch releases and CVE fixes as soon as they are ready, 24x7 support with a one-hour SLA, and hot fix patches. Its documentation includes upgrade guides from IMDG 4.x and 3.12.x and a Data Migration Tool for moving 3.12 data. The Operator and the CP Subsystem left the Community Edition at 5.5 and remain in Enterprise. The IMDG 3 to 5 migration guide covers that path.

HeroDevs

HeroDevs' Never-Ending Support for Hazelcast covers Platform 5.1, 5.2 and 5.3 with builds that keep the same groupId and artifactId, so only the version string changes. It patches Hazelcast core and the hazelcast-spring integration, includes fixes for bundled dependencies, and ships VEX statements with each release. It suits teams on an early Platform 5.x release that want a drop-in fix. See OSSeva vs HeroDevs.

Perforce OpenLogic

OpenLogic lists Hazelcast at all three of its support levels, which suits teams that want help running and upgrading Hazelcast inside a wider contract. It does not publish patched Hazelcast builds. See OSSeva vs OpenLogic.

OSSeva

OSSeva for Hazelcast patches the line already in production, so the serialization format, cluster protocol and client compatibility your applications depend on stay fixed. Patch delivers security backports for IMDG 3.12, 4.0 and 4.2 and Platform 5.3, with deserialization and cluster protocol advisories prioritised and member and client artifacts built and released together, as signed Maven and Docker artifacts. Assure adds a topology, partition and split-brain review, a member port and join-mechanism audit, a serialization and class filtering review and an assessment of upgrade or migration options. Operate adds 24/7 heap, partition and member monitoring, a 15-minute P1 response, a named data grid engineer and executed rolling upgrades or migrations, and patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days. Pricing is per cluster, not per member, gigabyte or client connection.

How to choose

SituationUsual answer
On Enterprise Edition, or ready to buy itHazelcast, on a release within its support windows
Community Edition and able to upgrade each minor releaseStay on the newest minor, which carries the latest fixes
Community Edition on Platform 5.1 to 5.3HeroDevs NES, or OSSeva for 5.3, while the upgrade is planned
IMDG 3.12 or 4.x that cannot move yetOSSeva patched builds while the migration to 5.x is planned
Need help running the grid more than patchesHazelcast Enterprise support, OpenLogic, or OSSeva Operate

Hazelcast IMDG extended support covers the 3.x and 4.x case in more detail.

Where OSSeva fits

OSSeva covers the IMDG 3.x and 4.x lines that predate Hazelcast Platform, and Platform 5.3, which suits grids whose applications depend on the old serialization format and client protocol. OSSeva also covers GemFire and Ignite, so a comparison of grids is not a sales exercise for one of them.

Frequently asked questions

Who provides extended support for Hazelcast IMDG 3.12 and 4.x?

OSSeva publishes patched builds of IMDG 3.12, 4.0 and 4.2. OpenLogic sells Hazelcast technical support. HeroDevs' Hazelcast coverage starts at Platform 5.1.

Does Hazelcast Community Edition still get security patches?

Only in new minor and major releases. Since Platform 5.4, patch releases such as 5.4.1 or 5.5.2 are available only to Enterprise customers, and Community Edition CVE fixes arrive in the next minor release. The Community Edition remains under the Apache 2.0 licence.

Which companies offer Hazelcast support besides Hazelcast?

HeroDevs, for patched Platform 5.1 to 5.3 builds. Perforce OpenLogic, for technical support. OSSeva, for patched IMDG 3.12, 4.x and Platform 5.3 builds with optional 24/7 operations.

Can I patch Hazelcast 5.3 without upgrading?

Yes. HeroDevs and OSSeva both publish patched 5.3 builds, and Hazelcast Enterprise customers get 5.3 fixes for as long as 5.3 is inside Hazelcast's support windows.

Is it hard to upgrade from IMDG 3.12 to Platform 5?

It is a migration rather than a rolling upgrade. Hazelcast documents separate upgrade paths from IMDG 4.x and 3.12.x and provides a Data Migration Tool for moving 3.12 data, and client compatibility has to be checked across the jump.

Tags

HazelcastIn-Memory Data GridEnd of LifeExtended SupportVendor Comparison

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.