Java 21 Migration Assessment Executive Summary
Based on the processed technical assessment document[cite: 1], below is the breakdown of Java 21 migration readiness across all evaluated application artifacts[cite: 1].
Key Migration Metrics
- Total Number of Artifacts Evaluated: 29[cite: 1]
- Java 21 Ready Artifacts: 11[cite: 1]
- Conditionally Ready Artifacts (Upgrade / Patch Recommended): 10[cite: 1]
- Not Ready / Incompatible Artifacts: 8[cite: 1]
Detailed Readiness Breakdown
1. Java 21 Ready (11 Artifacts)
These artifacts are fully compatible with Java 21 LTS, JPMS modular encapsulation, Virtual Threads (Project Loom), and the Jakarta EE 10/11 ecosystem:
org.slf4j:slf4j-api:2.0.13org.apache.tomcat.embed:tomcat-embed-core:10.1.28com.oracle.database.jdbc:ojdbc11:23.5.0.24.07com.fasterxml.jackson.core:jackson-annotations:2.17.2org.springframework:spring-beans:7.0.9org.springframework:spring-context:7.0.9org.springframework:spring-context-support:7.0.9org.springframework:spring-webmvc:7.0.9org.springframework:spring-jdbc:7.0.9org.springframework:spring-tx:7.0.9org.springframework:spring-expression:7.0.9
2. Conditionally Ready / Upgrade Recommended (10 Artifacts)
These artifacts can run under Java 21 but require version bumps, security patch updates, or JVM configuration tweaks (e.g., --add-opens flags, TLS policy adjustments) to resolve carrier thread pinning, JPMS reflection limits, or security vulnerabilities[cite: 1]:
-
org.apache.logging.log4j:log4j-core(Enforce 2.23.1+) -
org.apache.tomcat.embed:tomcat-embed-jasper:10.1.28(Upgrade to 10.1.34+ for JSP CVE fixes and Java 21 ECJ compiler support) -
com.sun.mail:jakarta.mail:1.6.7(Upgrade to Jakarta Mail 2.x+ to resolvejavax.mailnamespace blocker) -
org.glassfish.jaxb:jaxb-runtime:2.3.9(Upgrade to 4.x forjakarta.xml.bindcompatibility and Unsafe refactoring) -
com.fasterxml.jackson.core:jackson-databind(Enforce 2.17.2+ for Java Record and Virtual Thread support) -
junit:junit(Update to 4.13.2 baseline or migrate to JUnit Jupiter 5.10.x+) -
com.tibco:tibjms:8.2.21(Requires vendor certification confirmation &javax.jmsbridging) -
com.tibco:tibcrypt:8.2.21(Requires TLS/cipher policy overrides or server-side TLS upgrades) -
com.tibco:tibjmsadmin:8.2.21(Followstibjmsstatus; recommend removing from runtime deployables if unused) -
com.tibco:tibrvj:8.2.21(High Risk; dependent on matching 64-bit native JNI libraries on the target OS)
3. Not Ready / Incompatible (8 Artifacts)
These artifacts are severely broken under Java 21 due to hard reliance on removed/deprecated JDK APIs (e.g., sun.misc.Unsafe, SecurityManager, Thread.stop()), obsolete javax.* namespaces, or glibc C-library locks[cite: 1]. They must be replaced or migrated to modern coordinates[cite: 1]:
-
log4j:log4j:1.2.17(End-of-life; replace withlog4j-1.2-apibridge 2.23.1+ andlog4j-core)[cite: 1] -
com.citi.150667.quantum3_7:UMSJMS_5.3.1_Linux-glibc-2.5-x86_64_jdk1.5.0_12(Locked to legacy glibc 2.5 JNI binaries &javax.jms; replace or upgrade to Informatica UM 6.x+) -
jgroups:jgroups-all:2.4.1(Obsolete coordinates, removed thread suspension APIs; migrate toorg.jgroups:jgroups:5.x+) -
com.solacesystems:sol-jms:10.6.0(Usesjavax.jmsnamespace; upgrade tosol-jms-jakarta:10.30.1+)[cite: 1] -
com.ibm:com.ibm.mq.jmqi:7.5.0.6(JPMS encapsulation failures &javax.jmsnamespace; upgrade tocom.ibm.mq.jakarta.client:9.3.0+) -
com.gemstone.gemfire:gemfire:8.2.7(Fails on removed JDK internals &SecurityManager; migrate to Tanzu GemFire 10.x / Apache Geode 1.15+) -
javax.xml.bind:jaxb-api:2.3.1(Blocked byjavax.xml.bindnamespace; replace withjakarta.xml.bind-api:4.x) -
com.google.caliper:caliper:0.5-rc1(Unmaintained; broken by removed internal APIs; migrate to OpenJDK JMH 1.37+)
Top comments (0)