Spring Boot 3.5's open-source support ended on June 30, 2026; 3.5.16 was the last free patch. Every 3.x application is now running without community security fixes. Spring Boot 4 is a genuine generational change — Spring Framework 7, Jakarta EE 11, Jackson 3, a modular set of starters and JSpecify null-safety — so this isn't a version bump you do on a Friday afternoon.
Here is the order I'd do it in, based on the official migration guide, with the traps that turn into production incidents called out explicitly.
OSS end of life
version for Boot 4
target line
Step 0: pick the right target
Spring Boot 4.0 was released in November 2025 and 4.1 in June 2026. 4.0's own open-source support window is short, so if you're starting now, target the latest 4.1.x. Boot 4 keeps the Java 17 baseline, though running on Java 25 LTS is encouraged.
Step 1: get clean on the latest 3.5.x first
Upgrade to the newest 3.5 release and fix every deprecation warning. Anything deprecated in 3.x has been removed in 4.0 — so a warning today is a compile error tomorrow. This step alone removes a large share of the migration pain.
Step 2: switch the parent and add the properties migrator
Bump the Spring Boot version, then add the properties migrator temporarily. At startup it reports renamed or removed configuration keys and maps them for you at runtime, so you can see exactly what to change.
Step 3: use the classic starters to get compiling
Boot 4 splits its big auto-configuration jar into focused modules. The fastest way to get a large codebase compiling is to temporarily swap in the classic starters, which restore a Boot 3-like classpath. Fix imports and tests there, then come back and adopt the modular starters properly.
Step 4: move to Jackson 3
This is where most compile errors come from. Jackson 3 changes group IDs and packages from com.fasterxml.jackson to tools.jackson — except annotations, which stay in com.fasterxml.jackson.annotation. Spring Boot now auto-configures a JsonMapper, so an ObjectMapper bean no longer replaces the default.
Also rename @JsonComponent to @JacksonComponent and @JsonMixin to @JacksonMixin. If output differences break clients, spring.jackson.use-jackson2-defaults=true aligns defaults with Boot 3 while you migrate.
Step 5: fix the tests
Three test changes catch almost everyone. @MockBean and @SpyBean are gone — use @MockitoBean and @MockitoSpyBean. @SpringBootTest no longer sets up MockMvc on its own. And TestRestTemplate now needs an explicit annotation (or switch to the new RestTestClient).
Step 6: adopt the modular starters
Remove the classic starters and let the missing imports tell you which starters you need. Several were renamed: spring-boot-starter-web becomes spring-boot-starter-webmvc, spring-boot-starter-aop becomes spring-boot-starter-aspectj, and the OAuth2 starters gain a security- prefix. Technologies that used to need only a third-party jar — Flyway and Liquibase are the common ones — now need their own starter. Each starter also has a -test companion.
spring-boot-starter-batch, job history stops being written to your database — switch to spring-boot-starter-batch-jdbc if you depend on restartability. Undertow is gone (it doesn't support Servlet 6.1); move to Tomcat or Jetty. Optional Maven dependencies are no longer packaged into the uber jar. Custom HttpMessageConverter beans are no longer picked up — use the new converter customizers. Spring Retry's dependency management was removed in favour of the retry support now built into Spring Framework 7. And liveness/readiness probes are now enabled by default — good news for Kubernetes, but check your health endpoint security.
Once you're on Boot 4, two new features are worth adopting straight away: built-in API versioning and, with Spring AI 2.0, MCP servers in a few annotations.
Frequently asked questions
When did Spring Boot 3.5 reach end of life?
Spring Boot 3.5 reached open-source end of life on June 30, 2026. The final free release was 3.5.16. After that date, no further open-source patches are published.
Does Spring Boot 4 require Java 21?
No. Spring Boot 4 requires Java 17 or later, the same baseline as Spring Boot 3. Using the latest LTS, Java 25, is encouraged.
What is the fastest way to migrate a large app to Spring Boot 4?
Upgrade to the latest 3.5.x and clear deprecations, move to Boot 4 using the classic starters and the properties migrator, fix Jackson 3 and test changes, then replace the classic starters with the new modular starters.