Spring Boot
2.7The application line. Boot 2.7 manages the Framework and Security versions beside it, and the libraries a typical enterprise Boot application pulls in.
View the Spring Boot fork →OSERA is now maintaining hardened versions of over 50 libraries in Spring and its transitive closure, with remediations against public CVEs applied to the specific versions prioritized by OSERA Premier Members.
The first wave stays within the Spring lines institutions already have in production, including versions that are past upstream end of life. Fixes are applied directly to those lines — and to the libraries they manage — rather than requiring every firm to upgrade to a major new version before a known CVE is closed.
libraries prioritised by Premier members for the first wave of patches.
Spring lines carry that whole set: Boot, Framework, and Security.
source in a public fork organisation. The inventory lives there, not on this page.
The application line. Boot 2.7 manages the Framework and Security versions beside it, and the libraries a typical enterprise Boot application pulls in.
View the Spring Boot fork →The core framework line those applications run. Maintained as Spring Framework 5.3, on its own, alongside Boot.
View the Spring Framework fork →The security line paired with Boot 2.7 and Framework 5.3, so authentication and access-control fixes land on the version still in production.
View the Spring Security fork →We apply fixes for known CVEs to the exact projects and versions the sector still runs — prioritised across firms in Risk Navigator, and accepted into the repository only through the Remediation Standards gate. The source stays open and is offered upstream. The member-ready release sits behind membership.
Offered back to the original project wherever it is alive — free and public for the whole community.
The canonical, maintained, transparent source — fully auditable, for the cases upstream can't take the fix. Anyone can build from it.
Fully packaged releases members consume through their existing proxy — the coordinates they already use, no CI change.
The public fork is the canonical, maintained, transparent source code. If you are not a member, that source is yours to build from yourself.
Premier members also get the fully packaged releases, with attestations, SBOMs and an audit trail. General members receive those same member releases.
The public fork stays open, whether or not you join. Membership is how institutions take the fully packaged releases — with attestations, SBOMs and an audit trail.