We are pleased to announce general availability of a significant expansion of VMware Tanzu Spring’s secure software supply chain capabilities for Spring Boot applications. Following the recent announcement of Broadcom’s expanded R&D investments to improve security of the Spring and Java ecosystems, Tanzu Spring customers now have access to secure, clean room builds of the entire Java dependency tree for Spring Boot 2.7.x, 3.x, and 4.x. This release marks a meaningful milestone and delivers on Broadcom’s continued commitment to the health and security of Spring.
Transitive dependencies represent a major attack surface in modern Java applications, posing security risks to the majority of enterprises and governments worldwide. This Spring Boot release significantly reduces that attack surface by including artifacts with a provenance for more than 5,000 verified Java library dependencies–from a single trusted source. As the stewards of Spring, Broadcom provides Tanzu Spring customers with these artifacts to help them deliver on software supply chain integrity required for regulated industries and security-conscious enterprises.
Secure and compliant Java dependencies from the stewards of Spring
This most recent open source and enterprise-supported patch release for Spring Boot 2.7.x, 3.x, and 4.x, includes the entire transitive Java dependency tree. Meaning, this effort encompasses not just the top-level Spring Boot dependencies, but every artifact those dependencies pull-in, transitively.
Artifacts in this Spring Boot release are built to meet SLSA level 3 standards, providing cryptographically verifiable build provenance, tamper-resistant build infrastructure, and hardened pipeline controls (with the exception of less than 5% of artifacts due to licensing restrictions). In contrast, openly available dependencies in Maven Central do not have cryptographically verifiable build provenance by default, nor does an artifact link back to the exact source code, build environment or build script used to create it. To achieve our rigorous build and provenance standards, the Spring engineering team leverages a proven, clean room build approach, foundational to our Bitnami Secure Images offering. These enhancements give Tanzu Spring customers access to libraries from a trusted, auditable source that meets SLSA level 3 compliance standards.
Tanzu Spring customers can feel more confident knowing their enterprise-grade artifacts are engineered directly by the Spring R&D team in the Tanzu Division of Broadcom, who serve as the primary maintainers and committers to Spring. The Spring team brings decades of deep experience in the Java and Spring ecosystems and a holistic view of the Spring roadmap to everything they do. This unique vantage point, combined with their careful practice of tracking the Spring Boot BOM (bill of materials) to the dependency tree minor and major releases, provides customers with a prioritized set of artifacts that can have the greatest impact while remaining compatible with future versions.
How to improve your Java and Spring security posture
These newly released clean room builds of Java dependencies are available exclusively through the Spring Enterprise Repository, available to all customers entitled to VMware Tanzu Platform or VMware Tanzu Spring.
To take advantage of this security release, we strongly recommend that entitled customers re-configure their internal artifact repositories (Artifactory, Nexus, etc.) to prefer Spring Enterprise Repository artifacts over those from public repositories, such as Maven Central. By routing dependency resolution through the Spring Enterprise Repository first, users ensure they consistently consume Broadcom-verified, SLSA-compliant builds rather than unverified public artifacts — closing a common and often overlooked gap in supply chain security. This is a straightforward configuration change in your artifact proxy or virtual repository settings, and it is one of the highest-leverage steps a team can take to harden their Spring application builds going forward.
More details on accessing the Spring Enterprise Repository and configuring your artifact proxy can be found in the Tanzu documentation. And for a list of Spring Boot dependencies for the current patch releases based on version, please refer to the Spring OSS documentation.
If you would like to discuss your Spring application security and support approach, please contact us.
Learn more
- Read about Broadcom’s Investment in Spring to Combat AI-Fueled Security Challenges in the Enterprise
- Read the Spring team’s blog on Spring and Security in the Times of AI
- Read recommendations from Tanzu Division General Manager, Purnima Padmanabhan on How to Prepare for the World of AI Driven Exploits