DEV Community

Query Filter
Query Filter

Posted on

desktop-2

Java 21 Migration Assessment Executive Summary

Based on the processed technical assessment document[cite: 1], below is the breakdown of Java 21 migration readiness across all evaluated application artifacts[cite: 1].


Key Migration Metrics

  • Total Number of Artifacts Evaluated: 29[cite: 1]
  • Java 21 Ready Artifacts: 11[cite: 1]
  • Conditionally Ready Artifacts (Upgrade / Patch Recommended): 10[cite: 1]
  • Not Ready / Incompatible Artifacts: 8[cite: 1]

Detailed Readiness Breakdown

1. Java 21 Ready (11 Artifacts)

These artifacts are fully compatible with Java 21 LTS, JPMS modular encapsulation, Virtual Threads (Project Loom), and the Jakarta EE 10/11 ecosystem:

  • org.slf4j:slf4j-api:2.0.13
  • org.apache.tomcat.embed:tomcat-embed-core:10.1.28
  • com.oracle.database.jdbc:ojdbc11:23.5.0.24.07
  • com.fasterxml.jackson.core:jackson-annotations:2.17.2
  • org.springframework:spring-beans:7.0.9
  • org.springframework:spring-context:7.0.9
  • org.springframework:spring-context-support:7.0.9
  • org.springframework:spring-webmvc:7.0.9
  • org.springframework:spring-jdbc:7.0.9
  • org.springframework:spring-tx:7.0.9
  • org.springframework:spring-expression:7.0.9

2. Conditionally Ready / Upgrade Recommended (10 Artifacts)

These artifacts can run under Java 21 but require version bumps, security patch updates, or JVM configuration tweaks (e.g., --add-opens flags, TLS policy adjustments) to resolve carrier thread pinning, JPMS reflection limits, or security vulnerabilities[cite: 1]:

  • org.apache.logging.log4j:log4j-core (Enforce 2.23.1+)
  • org.apache.tomcat.embed:tomcat-embed-jasper:10.1.28 (Upgrade to 10.1.34+ for JSP CVE fixes and Java 21 ECJ compiler support)
  • com.sun.mail:jakarta.mail:1.6.7 (Upgrade to Jakarta Mail 2.x+ to resolve javax.mail namespace blocker)
  • org.glassfish.jaxb:jaxb-runtime:2.3.9 (Upgrade to 4.x for jakarta.xml.bind compatibility and Unsafe refactoring)
  • com.fasterxml.jackson.core:jackson-databind (Enforce 2.17.2+ for Java Record and Virtual Thread support)
  • junit:junit (Update to 4.13.2 baseline or migrate to JUnit Jupiter 5.10.x+)
  • com.tibco:tibjms:8.2.21 (Requires vendor certification confirmation & javax.jms bridging)
  • com.tibco:tibcrypt:8.2.21 (Requires TLS/cipher policy overrides or server-side TLS upgrades)
  • com.tibco:tibjmsadmin:8.2.21 (Follows tibjms status; recommend removing from runtime deployables if unused)
  • com.tibco:tibrvj:8.2.21 (High Risk; dependent on matching 64-bit native JNI libraries on the target OS)

3. Not Ready / Incompatible (8 Artifacts)

These artifacts are severely broken under Java 21 due to hard reliance on removed/deprecated JDK APIs (e.g., sun.misc.Unsafe, SecurityManager, Thread.stop()), obsolete javax.* namespaces, or glibc C-library locks[cite: 1]. They must be replaced or migrated to modern coordinates[cite: 1]:

  • log4j:log4j:1.2.17 (End-of-life; replace with log4j-1.2-api bridge 2.23.1+ and log4j-core)[cite: 1]
  • com.citi.150667.quantum3_7:UMSJMS_5.3.1_Linux-glibc-2.5-x86_64_jdk1.5.0_12 (Locked to legacy glibc 2.5 JNI binaries & javax.jms; replace or upgrade to Informatica UM 6.x+)
  • jgroups:jgroups-all:2.4.1 (Obsolete coordinates, removed thread suspension APIs; migrate to org.jgroups:jgroups:5.x+)
  • com.solacesystems:sol-jms:10.6.0 (Uses javax.jms namespace; upgrade to sol-jms-jakarta:10.30.1+)[cite: 1]
  • com.ibm:com.ibm.mq.jmqi:7.5.0.6 (JPMS encapsulation failures & javax.jms namespace; upgrade to com.ibm.mq.jakarta.client:9.3.0+)
  • com.gemstone.gemfire:gemfire:8.2.7 (Fails on removed JDK internals & SecurityManager; migrate to Tanzu GemFire 10.x / Apache Geode 1.15+)
  • javax.xml.bind:jaxb-api:2.3.1 (Blocked by javax.xml.bind namespace; replace with jakarta.xml.bind-api:4.x)
  • com.google.caliper:caliper:0.5-rc1 (Unmaintained; broken by removed internal APIs; migrate to OpenJDK JMH 1.37+)

Top comments (0)