Comparison · Support

Open Source and Vendor Support Windows Compared

How long is a version actually supported? The answer varies from six weeks to seven years depending on the technology, and it is usually shorter than the time that version stays in production. This page sets 21 data, platform, observability and integration technologies side by side, using each vendor's or project's own published policy.

Tyler Eastridge

By Tyler Eastridge, Head of Operations

LinkedIn · Updated

6 min read6 sections
On this page
Short answer

Short answer

Community projects patch a version for a fixed period and offer no response time: five years for PostgreSQL, one year of high-severity fixes for a Prometheus LTS, nothing for Airflow 2 since April 2026. Vendors support a version for a set window that is often short: nine months for Grafana, one year for Kong and Starburst LTS, two years for Splunk. When the window closes, the software keeps running and the fixes stop. Independent support is what covers a version after that point.

Published support window per version, as of September 2026

Published support window per version, as of September 2026
TechnologyWho supports itSupport windowExample
PostgreSQLCommunity project, no vendor5 years per major versionPostgreSQL 14 ends 12 November 2026; 13 ended 13 November 2025
MongoDBMongoDB, Inc.Set per release in the lifecycle schedule6.0 ended 31 July 2025; 7.0 runs to 31 August 2027
ElasticsearchElasticLonger of 30 months from GA or 18 months after the next major7.17 support ended 15 January 2026; 8.x ends 15 July 2027
OpenSearchOpenSearch Software Foundation (Linux Foundation)Until the next major enters maintenance, or 1 year, whichever is longer1.x ended after 6 May 2025; 2.x maintained until 4.0
ClickHouseClickHouse, Inc.Current and 2 prior stable releases (3 months); current and prior LTS (1 year)LTS releases typically March and August
Splunk EnterpriseSplunk, a Cisco company24 months per minor version9.2 ended 31 January 2026; 10.0 runs to 28 July 2027
GrafanaGrafana Labs9 months per minor; 15 months for the last minor of a majorMinor release every other month
PrometheusCNCF project, no vendor6 weeks per minor; 1 year for LTS, high-severity fixes only3.13 LTS to 31 July 2027; 2.53 ended 31 July 2025
Apache AirflowApache project, no vendorCurrent major maintained; previous major limited, then end of lifeAirflow 2 ended 22 April 2026
Kong Gateway EnterpriseKong Inc.1 year per minor; 3 years for LTS; up to 12 months sunset3.10 LTS to 31 March 2028; 3.14 LTS to 7 April 2029
Starburst EnterpriseStarburst12 months for LTS; STS until the next STS477-e LTS ends 30 November 2026
WSO2WSO2Minimum 3 years per version; 7 years per release line from March 2024Extended Life Support at extra cost
PentahoPentahoActive patching until the next release, then about 6 months limited10.2 to March 2028 or later; 11.0 to July 2029 or later
GreenplumBroadcom (VMware Tanzu Greenplum)Broadcom lifecycle matrix, customer login requiredOpen-source repositories archived May 2024
GemFireBroadcom (VMware Tanzu GemFire)Broadcom lifecycle matrix per versionGemFire 10 runs on JDK 8, 11, 17 and 21
AirbyteAirbyteCloud supported; self-hosted open source is community onlySelf-Managed Enterprise no longer sold
MySQLOracleOracle Lifetime Support: Premier, Extended, then Sustaining with no new fixes8.0 ended 21 April 2026; 5.7 ended 25 October 2023
Apache CassandraApache project, no vendorTied to releases: each line maintained until a later major ships5.0 until 8.0 ships; 3.x unmaintained
KubernetesCNCF project, no vendorThree most recent minor releases, about 1 year each1.35 ends 28 February 2027
Apache SparkApache project, no vendor6 months per release branch; 18 months for the LTS of each major3.5.x security fixes only to November 2027
Apache FlinkApache project, no vendorCurrent and previous minor release only2.3.0 current; 1.20 is the 1.x LTS
Table · Published support window per version, as of September 2026. Scroll sideways on small screens.

How to read the table

Every date and rule here comes from the vendor's or project's own lifecycle page, checked in September 2026. Policies change, so treat the table as a map and confirm your exact version at the source, which each linked article cites. Two patterns stand out. Projects with no vendor (PostgreSQL, Prometheus, Airflow, OpenSearch) publish patches for a fixed window and offer no response time at all. Vendors publish a window that is usually shorter than the time enterprises keep a version in production: one year for Kong and Starburst, nine months for Grafana, two years for Splunk.

Databases and search

PostgreSQL gives the longest and most predictable window, five years per major version, and no contract. MongoDB and Elasticsearch both retire versions faster than most estates upgrade: MongoDB 6.0 and Elasticsearch 7.17 are already out of vendor support and still common in production. OpenSearch 1.x and the open-source Greenplum builds have no upstream at all now. ClickHouse supports only recent releases even under a paid agreement. MySQL 8.0 joined that list in April 2026, and Cassandra 3.x is unmaintained by its project.

Observability

Observability tools have the shortest windows of all, because they release fastest. Grafana ships a minor version every other month and supports each for nine months. Prometheus stops fixing a minor release after six weeks, and its LTS line accepts only high-severity security fixes. Splunk gives each version two years. The practical result is that the monitoring stack is often the least supported system in the estate, and it is the one you depend on during every other incident.

Data pipelines, processing and platforms

Airflow 2 reached end of life in April 2026, and the move to Airflow 3 is a real migration. Airbyte no longer sells a self-managed enterprise edition, so self-hosted users have community support only, and support also varies by connector. Starburst supports an LTS release for twelve months. Pentaho's window is tied to its next release, which makes it hard to plan around. WSO2 is the long-window exception, with a minimum of three years per version, but only for subscribers. Spark maintains a release branch for six months, Flink supports only its two newest minor releases, and Kubernetes patches a version for about a year.

Messaging and caching

Message brokers and caches follow the same pattern and have their own comparison. RabbitMQ patches only its newest release series, Kafka fixes roughly its last three releases, and Redis publishes end-of-life dates per version.

What to do with a version outside its window

There are three honest options. Upgrade, if the application and change calendar allow it. Buy the vendor's extended support where one exists, accepting that it is limited and temporary. Or put an independent support contract behind the version you actually run, which covers incident response, mitigation and the upgrade plan, though not new vendor patches. Most estates need the third for at least some systems, because not everything can be upgraded this year.

Frequently asked questions

Which open source software has the longest support window?

Of the 21 compared here, PostgreSQL, at five years per major version from the community, and WSO2, with a minimum of three years per version and seven per release line for subscribers.

Which has the shortest?

Prometheus. A minor release generally stops receiving bug fixes after six weeks. Its LTS versions last one year and accept only fixes for issues rated CVSS 7.0 or higher. Grafana is next at nine months per minor version.

What happens when a version passes its support window?

The software keeps running. The vendor or project stops releasing fixes for it, and vendor support contracts generally stop covering it. Splunk's policy, for example, says end of support versions are not eligible for support services.

Can I get support for a version the vendor no longer supports?

Yes, from an independent provider. AceMQ supports all 21 technologies on this page on any version, covering incident response, mitigation and upgrade planning. It cannot supply new vendor patches.

Where do these dates come from?

From each vendor's or project's own lifecycle or support policy page, checked in September 2026. Each linked article cites its source. Confirm your exact version at the source before planning around a date.

Support services

Where this gets done

The work behind this page, run by the same engineers who wrote it.

Next step

Talk to an engineer

AceMQ supports 130+ enterprise clients in 26+ countries. Tell us what you are running and we will come back within a business day.