The Spring team is now releasing all updates on one day to give people a leg up in patching:
Historically, we spread releases over a two-week period with each level of the Spring portfolio dependency tree shipping on a different day. While that approach has served us well over the years, in a world where CVEs are exploited in hours instead of days, it now seems archaic. In the past two release trains as an example, the old model would have had new CVE fixes released every day of each train.
Also, there’s a new tool to see and search for security problems (CVEs) in Spring.
If you want/need commercial support for Spring (and other open source Java), getting you patches earlier than the general public, we sell that now as well.
Leave a Reply