Dependency health Workspace

org.springframework:spring-beansMaven Central · Java

⚠ Known vulnerability history

These advisories relate to this package’s identity. We have not verified your installed version or deployment. This context is separate from its maintenance score.

CVE-2022-22965 · Spring4Shell ↗

Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory.

How these vulnerabilities relate to package checks →
What the project says about itself
  • Security policypublished. Source: the repository.
  • Open milestonesGeneral Backlog 0/160 done; 7.0.x 0/5 done; 7.x 0/14 done; 7.1.x 0/42 done; 7.1.0-M2 43/46 done. Source: the repository's milestones.
  • OpenSSF Scorecard6 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-05 first verdict: active

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/maven/org.springframework:spring-beans.svg)](https://isitdeadyet.dev/maven/org.springframework:spring-beans)

Watch it

Get told when org.springframework:spring-beans changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.