End-of-life Jetty binaries, from the people who write Jetty
Your security scanner flagged Jetty 9, 10 or 11. The fix version in the CVE isn’t on Maven Central. Upgrading isn’t an option this quarter.
Webtide Harbor gives you what you need to close the finding: patched end-of-life Jetty and CometD binaries, built by the Jetty committers, delivered through an authenticated Maven repository your build already knows how to use.
Since January 1, 2026, releases for Jetty 9, 10 and 11 and CometD 5, 6 and 7 are no longer published to Maven Central or other public repositories. We still fix the CVEs in those lines, all of them. Harbor is how you get the fixed builds.
What Harbor Provides
Patched EOL Binaries
Every CVE fix we make to end-of-life Jetty and CometD lines is published to Harbor. When an advisory names a fix version like 9.4.64 or 10.0.32, that is the version you get from Harbor. It isn’t a fork and there’s no proprietary layer. They are upstream builds from the project’s own source.
Early Security Notification
Harbor subscribers are notified proactively about security issues and get early access to releases that address them. You have the fix in hand before the vulnerability is public, so remediation isn’t a scramble. One-on-one
vulnerability analysis is available on request.
A Repository Your Build Already Understands
Harbor is an authenticated Maven repository. Add it to your build or your internal repository manager and keep going. It works with the build and CI tooling you already run.
No Licensing Games
Harbor is a distribution mechanism, not a software license. Jetty and CometD artifacts from Harbor are licensed under exactly the same open-source licenses as they are on Maven Central. You pay for access and for the security service, and never for a license to the software.
What’s Included
- Access to Webtide Harbor, the authenticated repository for EOL Jetty and CometD binaries
- Supported Jetty versions: 9.4.x and later end-of-life lines
- Proactive security notifications and early access to security releases
- One-on-one vulnerability analysis on request
- A private GitHub support repository for two team members
- Standard open-source licensing, with no additional IP or licensing requirements
All for one flat annual subscription.
Harbor or Lifecycle Support?
Choose Harbor if you need patched binaries for an EOL line and your team can handle the upgrade path and day-to-day questions itself. It’s the direct route from “the scanner flagged it” to “the finding is closed.”
Choose Lifecycle Support if Jetty runs deep in your systems: you need production SLAs, direct access to the committers for development questions, or help migrating to Jetty 12. Lifecycle Support includes EOL binaries and adds everything Harbor doesn’t.
Shipping Jetty inside a product you sell? Ask us about Harbor OEM, which extends Harbor to the customers of the product that contains Jetty.
Why Webtide
Webtide is the company behind the Jetty and CometD open-source projects. The people who fix your CVE are the people who wrote the code, maintain the project and publish the advisory. There’s no reseller in the middle and no fork to drift from upstream.