OSSEVA FOR APACHE PULSAR
Apache Pulsar — patched, protected, operated.
Apache Pulsar is the multi-tenant, cloud-native messaging and streaming platform powering financial services and enterprise data pipelines globally. OSSeva provides CVE-patched builds, hardened configurations, and 24/7 managed operations for 2.10.x and 3.x.
Why now
StreamNative Cloud pricing mirrors Confluent's model
StreamNative, the primary commercial Pulsar vendor, charges enterprise-scale pricing that rivals Confluent. For teams running community Pulsar, StreamNative support requires expensive SaaS migration or per-cluster fees that don't match the workload.
Pulsar's rapid release cadence creates EOL exposure
Apache Pulsar releases major versions frequently, with community support windows shorter than most enterprise upgrade cycles. Pulsar 2.10.x and 2.11.x are already past active community support, but remain in production at hundreds of enterprises.
ZooKeeper dependency creates compounded CVE risk
Older Pulsar versions depend heavily on ZooKeeper for metadata. ZooKeeper has its own CVE stream — OSSeva monitors and patches both Pulsar and its ZooKeeper dependency, closing a gap that community support leaves open.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 2.10.x(Full CVE coverage) | Extended | Clean |
| 2.11.x(Full CVE coverage) | Extended | Clean |
| 3.0.x | Extended | Clean |
| 3.1.x | Current | Clean |
| 3.2.x | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
CVE patches for Pulsar 2.10.x–3.x. Includes ZooKeeper coverage.
- Quarterly CVE patches for Pulsar 2.10.x–3.x
- ZooKeeper dependency CVE coverage included
- Docker / Helm delivery
- Signed artifacts (GPG)
- CVE disclosure notifications
- Architecture review
- 24/7 managed operations
OSSeva Assure
Patch plus multi-tenant security audit and compliance documentation.
- Everything in Patch
- Multi-tenant namespace isolation audit
- Authentication (JWT/TLS) configuration review
- SOC 2 / HIPAA attestation package
- ZooKeeper → KIP-500 migration planning
- Geo-replication security review
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 monitoring, 15-min SLA, named Pulsar engineers.
- Everything in Assure
- 24/7 broker, bookie, and ZooKeeper monitoring
- 15-minute P1 incident response SLA
- Named senior Pulsar engineer on your account
- Backlog and consumer lag alerting
- Quarterly architecture reviews
- Pulsar Functions and IO connector support
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
helm repo add osseva https://charts.osseva.io
helm repo update
helm install pulsar osseva/pulsar \
--version 3.1.2-1 \
--namespace messaging \
--set broker.replicaCount=3 \
--set bookkeeper.replicaCount=3 \
--set zookeeper.replicaCount=3docker pull artifacts.osseva.io/apache-pulsar:3.1.2-osseva-1
docker run -d \
--name pulsar-standalone \
-p 6650:6650 \
-p 8080:8080 \
artifacts.osseva.io/apache-pulsar:3.1.2-osseva-1 \
bin/pulsar standaloneMigrate from StreamNative Cloud
StreamNative Cloud requires migrating your Pulsar workloads to their managed platform. OSSeva keeps your Pulsar deployment on your infrastructure — your cloud account, your control plane — with CVE patching and operations support at a fraction of StreamNative's platform cost.
Pricing model
OSSeva for Pulsar is priced per cluster — not per topic, per message, or per storage tier. Contact for scoping.
Compliance library
Frequently asked questions
Which versions of RabbitMQ are past community end-of-life?
RabbitMQ 3.8.x, 3.9.x, 3.10.x, 3.11.x, and 3.12.x have all reached community EOL — meaning no further security patches or CVE fixes are released by the RabbitMQ maintainers for those versions. RabbitMQ 3.13.x reached EOL in late 2024. OSSeva delivers backported CVE patches for 3.11 through 3.13.
Which PostgreSQL versions are no longer receiving community security patches?
PostgreSQL 9.6 through 13 have all reached community EOL. PostgreSQL 11 reached EOL November 2023, PostgreSQL 12 reached EOL November 2024, and PostgreSQL 13 reaches EOL November 2025. OSSeva provides extended security patching for PostgreSQL 11, 12, and 13 for teams that cannot immediately migrate to PG 14 or later.
Is Spring Framework 5.3.x still supported?
Spring Framework 5.3.x reached its community OSS EOL on December 31, 2024. Broadcom's commercial support for Spring 5.3.x is also no longer available under standard terms. OSSeva delivers backported CVE patches for Spring Framework 5.3.x and Spring Boot 2.7.x under our extended lifecycle support program.
Which versions of Apache Kafka are EOL?
Apache Kafka versions 2.x and 3.0 through 3.4 are past their community supported window, meaning no further patch releases. Kafka 3.5 and 3.6 have reached or are approaching EOL. OSSeva supports Kafka 2.8 through 3.5 with backported security patches and compliance documentation.
What happened to Redis licensing? Can I still use Redis for free?
In March 2024, Redis Ltd. changed the Redis license from BSD-3-Clause to the Business Source License (BSL 1.1), which restricts use in competing database products. The Valkey project (a Linux Foundation fork) continues under BSD-3-Clause. OSSeva maintains BSD-licensed, CVE-patched builds of Redis 6.2 and 7.0 for enterprises that need verifiable open-source licensing alongside security coverage.
Is Node.js 18 still receiving security patches?
Node.js 18 (LTS 'Hydrogen') reached its end-of-life date in April 2025 and no longer receives security releases from the Node.js project. OSSeva delivers CVE patches for Node.js 18 for enterprise teams that have not yet migrated to Node.js 20 or 22.
Is Apache Tomcat 8.5 still supported?
Apache Tomcat 8.5 reached its community EOL in March 2024. OSSeva provides extended security patching for Tomcat 8.5.x for teams running Java EE 7 workloads that cannot immediately migrate to Tomcat 9.0 or 10.1.
What .NET versions does OSSeva support?
.NET 6 reached Microsoft end-of-support in November 2024. .NET 7 reached EOL in May 2024. OSSeva delivers CVE patches for .NET 6 and .NET 7 for teams that have not yet migrated to .NET 8 (LTS, supported through November 2026).
Ready to get Apache Pulsar patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.