Back to blog

// OSSeva Blog

Operations

Who Provides Spring Boot and Spring Framework Support After Open Source End of Life?

Randall McClure9 min read

The short answer

Five vendors sell Spring support after open source (OSS) end of life: Broadcom through Tanzu Spring, from the team that maintains Spring; HeroDevs (Never-Ending Support for Spring); TuxCare (Endless Lifecycle Support); Perforce OpenLogic (long-term support for Spring Boot and Framework); and OSSeva (patched Spring Boot, Framework and Security builds). All of them deliver patched artifacts through Maven or Gradle.

The vendors differ most in which Spring Boot lines they cover. Broadcom extends a few designated lines for years and stops the rest one year after OSS end. The third-party vendors fill different gaps, so the right choice depends on the exact Boot version each application runs. The matrix below answers that line by line.

Which vendor covers which Spring Boot line

OSS and commercial dates come from Spring's own support data on api.spring.io. Vendor columns reflect what each vendor publishes on its own site as of 6 October 2026. "Not listed" means the vendor does not publish that line, not that it would refuse to quote it.

Spring Boot lineOSS support endedBroadcom commercial supportHeroDevsTuxCareOpenLogicOSSeva
2.6.x30 Nov 2022Ended 29 Feb 2024Not listedListedNot listedPatched
2.7.x30 Jun 2023To 30 Jun 2029ListedNot listedTo 31 Oct 2027Patched
3.0.x31 Dec 2023Ended 31 Dec 2024Not listedNot listedNot listedPatched
3.1.x30 Jun 2024Ended 30 Jun 2025Not listedListedTo 30 Jun 2028Patched
3.2.x31 Dec 2024Ended 31 Dec 2025ListedNot listedTo 30 Jun 2028Patched
3.3.x30 Jun 2025Ended 30 Jun 2026ListedNot listedTo 30 Jun 2028Patched
3.4.x31 Dec 2025Ends 31 Dec 2026ListedNot listedTo 30 Jun 2028Patched
3.5.x30 Jun 2026To 30 Jun 2032ListedListedTo 30 Jun 2028Patched
4.0.xEnds 31 Dec 2026To 31 Dec 2027Not listedNot listedNot listedCovered

Two patterns stand out. Broadcom's long commercial windows sit on the last line of each generation, Boot 2.7 and 3.5, while 3.0 to 3.3 are already out of commercial support and 3.4 follows on 31 December 2026. And every Boot line from 2.6 to 3.5 is covered by at least one third-party vendor, though Boot 3.0 appears only on OSSeva's published list. The Spring support calendar has the full date table for Framework and Security as well.

Spring support providers compared

ProviderWhat it coversVersionsDelivery modelSelf-managed?
Broadcom (Tanzu Spring)24x7 support for more than 50 Spring projects plus OpenJDK and Tomcat, private access to releases past OSS support, day-0 patches, Application Advisor for automated upgrades, and Spring Boot extensions for FIPS, PCI-DSS and SBOMLines inside their commercial window: Boot 2.7 and Framework 5.3 to 30 June 2029, Boot 3.5 and Framework 6.x to 30 June 2032, Boot 3.4 to 31 December 2026, and the 4.x linesTanzu Spring Maven repositoryYes
HeroDevs Never-Ending SupportDrop-in patched Spring releases, each Boot line with the Framework and Security versions it managesBoot 1.5, 2.5, 2.7, 3.2, 3.3, 3.4 and 3.5; Framework 4.3 to 6.2 and Security 4.2 to 6.5 alongside themPackages through repository managers such as Nexus and ArtifactoryYes
TuxCare Endless Lifecycle SupportSLA-backed CVE fixes for Spring Framework and Spring Boot, with other Spring modules listedFramework 3.1, 4.0, 4.1, 4.3, 5.2, 5.3 and 6.0 to 6.2; Boot 2.4, 2.6, 3.1 and 3.5; Security 5.0 to 6.5TuxCare-hosted repositories, through Maven and GradleYes
Perforce OpenLogic long-term supportCVE fixes for CVSS 7 and above, with service level objectives of 14 days for critical and 30 days for highBoot 2.7 and Framework 5.3 to 31 October 2027; Boot 3.1 to 3.5 and Framework 6.0 to 6.2 to 30 June 2028Patched artifacts under an LTS subscriptionYes
OSSevaBackported CVE fixes for Spring Boot, Framework and Security, including Framework 5.3 under Boot 2.x; migration readiness assessment and 24/7 application operations on higher tiersBoot 2.6, 2.7 and 3.0 to 3.5, plus 4.0 and 4.1; Framework 5.2, 5.3, 6.0 to 6.2 and 7.0; Security 5.6 to 5.8, 6.0 to 6.5, 7.0 and 7.1Signed Maven artifacts (GPG and Sigstore for Boot) through your repository managerYes

How the vendors differ

Broadcom

Broadcom says Tanzu Spring patches come directly from the maintainers of Spring, with day-0 access and private releases for lines past OSS support. It is the broadest subscription: more than 50 Spring projects, OpenJDK and Tomcat, and Application Advisor, which opens upgrade pull requests in your CI pipeline. The limit is its calendar. A line whose commercial date has passed does not come back by signing, so for Boot 3.0 to 3.3 Broadcom's answer is an upgrade to 3.5 or 4.x. Broadcom announced TrueSource on 31 August 2026 without changing these dates; Broadcom TrueSource explained covers it.

HeroDevs

HeroDevs publishes coverage per Spring Boot line, with the Spring Framework and Spring Security versions that line manages bundled in. Its list includes Boot 3.2, 3.3 and 3.4, which have no Broadcom commercial cover from 2027 onwards. See OSSeva vs HeroDevs.

TuxCare

TuxCare has the longest list of old Spring Framework versions, back to 3.1, and delivers through its own Maven and Gradle repositories. Its Boot list is shorter and skips 2.7 and 3.2 to 3.4. See OSSeva vs TuxCare.

OpenLogic

OpenLogic publishes fixed end dates and response targets, which makes its long-term support easy to put in a plan: Boot 2.7 to 31 October 2027, and Boot 3.1 to 3.5 to 30 June 2028. Its page notes that for Spring these are service level objectives rather than contractual SLAs. See OSSeva vs OpenLogic.

OSSeva

OSSeva for Spring Boot patches every Boot line from 2.6 to 3.5, including 3.0 and 3.1, where Broadcom's commercial support has ended. Boot 2.x coverage includes the Spring Framework 5.3 underneath it, and Spring Framework and Spring Security are covered line by line, with authentication bypass CVEs in Spring Security handled as P1 with an emergency patch within 48 hours. Builds are binary-compatible with upstream, so an application changes its BOM or dependency coordinates and nothing else. Assure adds a Spring Boot 3 or Security 6 migration assessment and SOC 2, HIPAA and PCI attestation material; Operate adds 24/7 monitoring and migration execution. OSSeva publishes Framework, Boot and Security coverage only, so list any Spring Data or Spring Cloud versions you depend on before comparing quotes.

What changes on 31 December 2026

Two Spring Boot lines change status on the same day:

  • Spring Boot 3.4 loses Broadcom commercial support. After that date, Broadcom ships fixes for 3.4 to no one. HeroDevs, OpenLogic (to 30 June 2028) and OSSeva publish 3.4 coverage.
  • Spring Boot 4.0 loses OSS support. Teams on 4.0 can move to 4.1, which keeps OSS fixes to 31 July 2027, or buy Broadcom commercial support to 31 December 2027.

Spring Security 6.4 and 7.0 follow the same dates as the Boot lines they ship with.

Should you upgrade Spring Boot or buy extended support?

Upgrade the applications that can move; buy time for the ones that cannot. The size of the move decides most cases:

Where you areUsual answer
Boot 4.0Move to 4.1 or 4.2; a minor upgrade inside the same major
Boot 3.0 to 3.4Move to 3.5 if you want Broadcom's 2032 window, or to 4.x for OSS fixes; third-party support for applications that cannot move this year
Boot 3.5OSS ended in June 2026. Broadcom, HeroDevs, TuxCare, OpenLogic or OSSeva while you plan Boot 4
Boot 2.6 or 2.7The move to Boot 3 means Java 17 and the javax to jakarta namespace change; extended support usually runs while that project does

For Boot 2.7 specifically, Spring 5 and Boot 2 extended support compared goes deeper into the vendor options, and our Spring Boot 2 to 3 migration guide covers the upgrade. Spring Boot vulnerabilities by version shows what is open on each line.

Where OSSeva fits

OSSeva covers the Spring lines your services run today, independent of Broadcom's commercial dates, and can cover the brokers, databases and Tomcat those applications depend on under the same contract. See Spring continuation for the offer and the extended support vendor roundup for how OSSeva compares by technology layer.

Frequently asked questions

Who provides Spring Boot support after open source end of life?

Broadcom through Tanzu Spring, for lines still inside their commercial window, and four third-party vendors: HeroDevs, TuxCare, Perforce OpenLogic and OSSeva. Each publishes a different list of Spring Boot lines, so match the vendor to the versions you run.

Who supports Spring Boot 3.0 to 3.4 now that Broadcom's commercial support has ended or is ending?

OSSeva publishes patched builds for all of 3.0 to 3.4. HeroDevs lists 3.2, 3.3 and 3.4, OpenLogic lists 3.1 to 3.4 to 30 June 2028, and TuxCare lists 3.1. Broadcom's commercial support for 3.4 ends on 31 December 2026, and for 3.0 to 3.3 it has already ended.

Does Broadcom offer extended support for Spring Framework?

Yes, through Tanzu Spring. Commercial support for Spring Framework 5.3 runs to 30 June 2029 and for 6.0 to 6.2 to 30 June 2032, with private access to releases past OSS support.

Is Spring Boot 3.5 still supported?

Not by the OSS project, which stopped on 30 June 2026. Broadcom supports it commercially to 30 June 2032, and HeroDevs, TuxCare, OpenLogic and OSSeva all list it.

Should we upgrade Spring Boot or buy extended support?

Upgrade applications under active development whose dependencies are ready. Buy extended support for those blocked by Java 17, the jakarta namespace change or a validation cycle, with an upgrade date recorded for each.

Tags

Spring BootSpring FrameworkSpring SecurityEnd of LifeExtended SupportVendor Comparison

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.