// Competitive Comparison
Spring Framework 5 and Spring Boot 2 extended support compared
Open source support ended on 30 June 2023 for Spring Boot 2.7 and on 31 August 2024 for Spring Framework 5.3. Broadcom's Tanzu Spring covers both commercially to 30 June 2029, and HeroDevs, TuxCare, OpenLogic and OSSeva all sell patched builds. This page sets out who covers which versions.
Where OSSeva is stronger
- ✓Spring Boot 2.6, 3.0 and 3.1, where Broadcom's commercial dates have passed
- ✓Spring Security 5.6, 6.0 and 6.1 patched alongside Spring Framework 5.2 and 5.3
- ✓Fixes for the dependency set the Spring Boot 2.7 BOM manages, such as Jackson, Netty and Logback
- ✓Spring in the same contract as the brokers and databases the application uses, with 24/7 managed operations on the Operate tier
Where Broadcom Tanzu Spring is stronger
- →Patches straight from the Spring maintainers, with day-0 access
- →Commercial support for Boot 2.7 and Framework 5.3 to 30 June 2029, and for Boot 3.5 and Framework 6.x to 30 June 2032
- →24x7 support for more than 50 Spring projects, plus OpenJDK and Tomcat
- →Application Advisor for automated upgrades, and Spring Boot extensions for FIPS, PCI-DSS and SBOM
Trusted globally by enterprises




Capability comparison
Comparison based on publicly available product information as of Q3 2026. Verify current coverage with each vendor.
| Capability | OSSeva | Broadcom Tanzu Spring |
|---|---|---|
| Spring Framework 5.3 | To 30 Jun 2029 | |
| Spring Framework 5.2 | To 30 Jun 2029 | |
| Spring Boot 2.7 | To 30 Jun 2029 | |
| Spring Boot 2.6 | Ended 29 Feb 2024 | |
| Spring Boot 3.0 and 3.1 | Ended Dec 2024 and Jun 2025 | |
| Spring Security 5.7 and 5.8 | To 30 Jun 2029 | |
| Spring Security 5.6, 6.0 and 6.1 | Ended | |
| Spring Boot 3.5 and Framework 6.2 | To 30 Jun 2032 | |
| Patches from the Spring maintainers | ||
| Spring Data, Spring Cloud and 50+ Spring projects | Framework, Boot, Security | |
| Fixes for Boot 2.7 managed dependencies | Not stated | |
| Delivery through your Maven repository | ||
| Automated upgrade tooling | Application Advisor | |
| 24/7 managed operations with 15-min P1 | Operate tier | 24x7 support, not managed ops |
| Brokers and databases in the same contract | Separate Tanzu products |
Why teams choose OSSeva
The Spring lines between Broadcom's extended releases
Broadcom's commercial dates, published on spring.io, extend a few designated lines for years: Spring Boot 2.7, Framework 5.3 and 5.2, and Security 5.7 and 5.8 run to 30 June 2029. The lines in between get a shorter commercial window. Boot 2.6 ended on 29 February 2024, 3.0 on 31 December 2024 and 3.1 on 30 June 2025. OSSeva ships patched builds for Boot 2.6, 3.0 and 3.1 and for Security 5.6, 6.0 and 6.1 today.
The dependencies are where the findings are
A scanner report for a Spring Boot 2.7 application is mostly transitive libraries the BOM manages: Jackson, Netty, Logback and embedded Tomcat. OSSeva backports fixes to that managed dependency set as well as to Spring itself, delivers them as signed Maven artifacts through your repository manager, and states in writing which projects and dependencies the agreement covers.
Spring is rarely the only end-of-life part
The application pinned to Boot 2.7 usually talks to a RabbitMQ 3.x broker, Kafka on ZooKeeper or PostgreSQL 11 to 13. OSSeva covers those under the same contract, and the Operate tier puts engineers on call 24/7 for the clusters with a 15-minute P1 response.
Why teams choose Broadcom Tanzu Spring
Patches from the maintainers
Broadcom states that all committers for Spring Boot, Spring Framework and the wider open source Spring portfolio are part of the Tanzu team. Tanzu Spring gives day-0 access to patches for enterprise versions and private access to releases that are no longer under open source support.
The longest dates on the designated lines
Commercial support runs to 30 June 2029 for Boot 2.7 and Framework 5.3, and to 30 June 2032 for Boot 3.5 and Framework 6.0 to 6.2. For an application that can reach one of those lines, Broadcom's window is long and comes from the source.
Tooling and breadth in one subscription
Tanzu Spring includes 24x7 support for more than 50 Spring projects plus OpenJDK and Tomcat, Application Advisor for automated upgrades that open pull requests, Spring Boot extensions for FIPS, PCI-DSS, SBOM and TLS cipher checks, Tanzu tc Server, and enterprise Spring Cloud components such as Spring Cloud Gateway.
Which is right for your situation?
Choose OSSeva when…
Your applications sit on Spring Boot 2.6, 3.0 or 3.1, or on Spring Security 5.6, 6.0 or 6.1, or you want Spring covered in the same contract as the brokers and databases the application depends on.
Talk to an engineerConsider Broadcom Tanzu Spring when…
You are on a designated extended line such as Boot 2.7 or 3.5, want patches from the Spring maintainers, or need Application Advisor, Spring Cloud components, OpenJDK and Tomcat under one Broadcom subscription.
Vendor facts checked on 29 September 2026 against spring.io and enterprise.spring.io (Broadcom), herodevs.com, tuxcare.com and openlogic.com.
Frequently asked questions
Who offers extended support for Spring Boot 2.7?
Broadcom Tanzu Spring, with commercial support to 30 June 2029. HeroDevs lists Boot 2.7 with Framework 5.3 in its Never-Ending Support for Spring. OpenLogic lists Boot 2.7 in its long-term support product to 31 October 2027. OSSeva covers Boot 2.7 and its managed dependencies. TuxCare's Spring page lists Boot 2.4, 2.6, 3.1 and 3.5, but not 2.7.
What does HeroDevs cover for Spring?
Its Never-Ending Support for Spring lists Spring Boot 1.5, 2.5, 2.7, 3.2, 3.3, 3.4 and 3.5, each with the Spring portfolio that Boot version manages, including Framework, Security, Data and Cloud, plus managed dependencies such as Jackson, Netty and Log4j2. It is the widest published Spring portfolio coverage among the third-party vendors here.
What does TuxCare cover for Spring?
TuxCare's Spring page lists Spring Framework 3.1, 4.0, 4.1, 4.3, 5.2, 5.3, 6.0, 6.1 and 6.2, and Spring Boot 2.4, 2.6, 3.1 and 3.5. Fixes arrive through Maven and Gradle, transitive dependencies are patched as well, and TuxCare offers 24/7 expert assistance with CVE triage.
What does OpenLogic cover for Spring?
OpenLogic's long-term support lists Spring Boot 2.7 and Framework 5.3 to 31 October 2027, and Boot 3.1 to 3.5 and Framework 6.0 to 6.2 to 30 June 2028. It patches CVEs scored 7 and above, within 14 days of disclosure for critical (CVSS 9 and above) and 30 days for high.
Which Spring versions does OSSeva cover?
Spring Framework 5.2 and 5.3, Spring Boot 2.6, 2.7, 3.0 and 3.1, and Spring Security 5.6, 5.7, 5.8, 6.0 and 6.1, plus the dependency set the Boot 2.7 BOM manages. Builds are signed Maven artifacts delivered through your repository manager. Our published Spring coverage is Framework, Boot and Security. If Spring Data or Spring Cloud versions matter to you, list them before comparing quotes, since HeroDevs and Broadcom publish coverage for both.
Why is there no pricing on this page?
None of these vendors is priced here. Most quote per customer, and we do not estimate other companies' prices. Ask each vendor to quote against the same list of Spring versions and applications.
Ready to see if OSSeva covers your stack?
Book a 30-minute discovery call. We'll confirm version coverage and scope a proposal within 5 business days.