CybersecurityJun 8, 2026, 09:02 AM
Broadcom Boosts Spring & Java Security with Major Investments
AI Summary
Broadcom Inc. announced significant security investments for the Spring and Java ecosystem, which is used by over half of Fortune 500 companies. The company's Tanzu business released the largest set of Spring security updates in the framework's 23-year history and is extending its clean-room build architecture to secure Java dependencies. These efforts aim to combat a 1700% surge in AI-detected security threats reported from March to April 2026, providing customers with day zero access to validated patches and a SLSA Level 3–validated software supply chain.
Key Highlights
- Broadcom released the largest set of Spring security updates in Spring's 23-year history.
- Extending clean-room build architecture to secure Java dependencies for the Spring ecosystem.
- Monthly security advisories to Broadcom from the Spring community increased over 1700% from March to April 2026.
- Tanzu Spring customers gain day zero access to validated CVE patch-only releases.
- Tanzu Spring offers secured, SLSA Level 3–validated software supply chain for Java dependencies.
- Covers over 100,000 validated dependency builds across the full supported Spring portfolio.
- Spring Boot 4.0 alone manages 1,768 dependencies.
Price Impact
More from AVGO