Security scanners report that Spring Boot and Spring Core libraries used in older versions of the DX Cloud Proxy have reached End-of-Life (EOL). Customers require compatible JARs or updated Cloud Proxy versions to maintain security compliance and support. While open-source (OSS) support for certain Spring versions has ended, Broadcom provides extended commercial support for these libraries.
spring-boot-3.4.10, spring-core-6.2.11The Spring Framework versions bundled with older Cloud Proxy releases have reached their official open-source community EOL dates.
To resolve EOL concerns and update to newer library versions, upgrade to the latest available Cloud Proxy.
spring-boot-3.5.14.jarspring-core-6.2.18.jarBroadcom continues to provide commercial support via "Broadcom Support Tanzu Spring Paid Support," which is currently scheduled to end on June 30, 2032. This coverage applies to all Spring libraries used within the Cloud Proxy environment.
Specific instructions for downloading the proxy are available in How to download cloud proxy.
To be updated on future fix status or library upgrades (such as Spring Boot 4.0), subscribe to this article (reference: ).