For enterprise teams, the "latest and greatest" does not always mean to implement "right now." While we always encourage staying on the latest and greatest version of Vaadin, we recognize that in complex ecosystems, a minor version bump is rarely just a one-line change in a pom.xml.
Today, we are evolving our Extended Maintenance (EM) program to provide broader coverage. We are extending long-term support to individual minor versions of Vaadin 24. Whether you are on 24.1, 24.3, or 24.7, you can now secure your application for 15 years without the pressure of triggering an immediate security reassessment.
Extended Maintenance used to cover only major versions (such as 24.0). However, as developers, we know that "minor" upgrades aren't always minor. Upgrading from Vaadin 24.2 to 24.4 requires more than just updating your pom.xml.
You no longer have to choose between a "risky" upgrade and an insecure application. You can now lock your application to a specific Vaadin 24 minor version and receive:
Note: Extended Maintenance focuses on security and stability. While it includes backports for essential fixes, for teams that want to leverage the latest features and functional enhancements, we recommend staying current with the most recent version of Vaadin.
Stability and security are not optional. We recently fixed two serious vulnerabilities. If you were stuck on an old minor version that didn't have the Extended Maintenance, you had to choose between remaining vulnerable and forcing a potentially breaking upgrade.
Recent high-severity vulnerabilities illustrate the risk:
Both issues have been fixed in our Extended Maintenance (EM) releases. Previously, you had to upgrade to the latest version to fix an older minor version.
Now, with Extended Maintenance, you can apply these specific security patches directly to your current version (for example, 24.7).
This lets you eliminate the threat without going through the lengthy and often painful upgrade process. Your team can avoid the manual work of untangling dependency conflicts or running extensive regression tests, all in the name of security.
We are committing to the longest support lifecycle in the industry to ensure your application remains a secure, compliant, and high-value asset for your organization.
|
Feature |
Specification |
|
Supported Versions |
All Vaadin 24 minor versions (currently 24.0 through 24.8 and all future minor releases) |
|
Support Duration |
15 years from the initial release of the major version (e.g., if you are on 24.3, you can stay on 24.3 for 15 years with security patches). |
|
Tech Stack Compatibility |
Java 17+, Spring Boot 3.x, Jakarta EE 10 |
Vaadin 24 (the major version) remains under standard free maintenance until June 2026.
Extended Maintenance is included in the Enterprise Tier at no additional cost. If you are already an Enterprise customer, you can add Extended Maintenance for minor versions today at no extra cost.
For more details, check out vaadin.com/maintenance
We are rolling this out first for Vaadin 24 to support the thousands of teams currently building on this LTS (Long-Term Support) foundation. If you are on an older minor version, you have three options:
Want to see which Vaadin version you're currently using?? Check your pom.xml (or build.gradle) to see exactly where you stand:
</propertiesContact us if you want to enable Extended Maintenance for your current version today.