End of life

Spring Security 5.8 end of life

Spring Security 5.8 reached the end of open source support on 31 December 2023. The last release on Maven Central is 5.8.16, from November 2024. Broadcom's commercial support for 5.8 runs until 30 June 2029, but its releases are available only to subscribers. Spring Security 5.8 is the bridge release for moving to 6.x.

End of life
31 December 2023
Released
Nov 2022
Final release
5.8.16 (last public release, November 2024)
Successor
Spring Security 6.x with Spring Boot 3

Date published by Spring Security support timeline (spring.io). We do not publish a lifecycle date we cannot source.

What actually stops on 31 December 2023

  • Public releases of Spring Security 5.8. 5.8.16 is the last one on Maven Central.
  • Public fixes for new advisories affecting authentication and authorisation in 5.x applications.
  • Compatibility work with newer Spring Framework and Spring Boot lines, which require Spring Security 6.

What actually breaks in the upgrade

5.8 exists to make 6.0 easier

Spring Security 5.8 added the 6.0 defaults and deprecations as opt-in settings, so applications can adopt them on 5.8 before switching. Teams that stayed on 5.7 or earlier miss that stepping stone.

Security 6 moves with the whole Spring stack

Spring Security 6 requires Spring Framework 6 and Spring Boot 3, which means Java 17 and the javax to jakarta namespace change. The security upgrade cannot be done on its own.

Configuration style changes

WebSecurityConfigurerAdapter is gone in 6.x. Configuration moves to SecurityFilterChain beans and the lambda DSL, which touches every application's security configuration class.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to Spring Security 6Together with Spring Framework 6 and Spring Boot 3.Weeks to quartersEngineering timeThe destination; plan it with the jakarta migration.
Broadcom commercial supportSubscriber-only 5.8 releases until June 2029.ProcurementCommercial subscriptionCovers 5.8 for Tanzu Spring customers.
Third-party extended supportBackported fixes for Spring Security 5.x in step with Framework 5.3 and Boot 2.7.DaysSubscriptionFor applications that cannot move to the Spring 6 stack yet.

What OSSeva does for Spring Security 5.8

OSSeva patches this line

OSSeva patches Spring Security 5.x in step with the Spring Framework 5.3 and Spring Boot 2.7 lines it is pinned to.

Spring Security extended support

What your auditor will say

PCI DSS 4.0

Requirement 6.3.3. The authentication layer of a cardholder-data application is squarely in scope.

SOC 2

CC6.1 and CC7.1. Unpatched authentication and authorisation code is an access-control finding as well as a vulnerability-management one.

Compliance library

Spring Security 5.8: common questions

When did Spring Security 5.8 reach end of life?

Open source support ended on 31 December 2023. Commercial support from Broadcom continues until 30 June 2029 for subscribers.

What was the last public Spring Security 5.8 release?

5.8.16, published to Maven Central in November 2024. Later 5.8 releases are commercial only.

Can I upgrade Spring Security 5.8 to 6 without upgrading Spring Boot?

No. Spring Security 6 requires Spring Framework 6 and Spring Boot 3, so the upgrade moves the whole stack to Java 17 and the jakarta namespace.

Still running Spring Security 5.8?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.