Spring Boot Migration Analyzer
Paste a Java class, pom.xml/build.gradle, or
application.properties/.yml, pick your upgrade path
(2.x → 3.x or 3.x → 4.0), and get a line-by-line report of what breaks —
including which javax.* imports are JDK packages you must leave alone.
Runs entirely in your browser. Nothing is uploaded.
Why a blind javax → jakarta find-and-replace breaks your build
The headline change when you upgrade from Spring Boot 2 to Spring Boot 3 is the move from
Java EE to Jakarta EE 9+, which renames the specification packages from
javax.* to jakarta.*. The obvious shortcut — a project-wide
search-and-replace of javax with jakarta — is also the most
common way to break a working codebase. The reason is simple: not every
javax.* package is a Jakarta EE package. A large set of
javax.* packages ship as part of the JDK itself and were never part of Java EE,
so they keep the javax prefix forever.
If your service does TLS, message encryption, database access, JNDI lookups or XML parsing —
the bread and butter of banking and payments integrations — a careless replace will rewrite
javax.crypto, javax.net.ssl, javax.sql,
javax.naming and javax.xml.parsers into packages that do not exist,
and your build stops compiling. The analyzer classifies every import into two lists:
migrate (a genuine Jakarta EE package, with the exact
jakarta.* replacement) and keep (a JDK package, left untouched,
with the reason it is safe). It even handles the tricky sibling splits —
javax.transaction migrates but javax.transaction.xa stays;
javax.xml.bind (JAXB) migrates but javax.xml.parsers (JAXP) stays;
javax.annotation migrates but javax.annotation.processing stays.
What the analyzer checks
The tool has two upgrade paths, selected from the dropdown. Each rule set only fires where it applies, and every finding carries a severity badge (Blocker, Update, Review, Keep, or OK), the line number, a one-line fix, and a before → after code diff where a concrete rewrite exists.
Spring Boot 2.x → 3.x
- Namespace: every
javax.*import classified migrate vs keep. - Java baseline: flags
java.version/sourceCompatibilitybelow 17 (Spring Boot 3 requires Java 17). - Spring Security 6:
WebSecurityConfigurerAdapter,antMatchers(),mvcMatchers(),authorizeRequests(),@EnableGlobalMethodSecurityand their replacements. - Hibernate 6 dialects: versioned dialects such as
MySQL8DialectandPostgreSQL95Dialect, plus storage-engine dialects, are deprecated in favour of the auto-detecting base dialect. - Config properties: renames and removals including
spring.redis.*→spring.data.redis.*,spring.datasource.initialization-mode→spring.sql.init.mode,server.max-http-header-size,spring.sleuth.*(now Micrometer Tracing),spring.session.store-type, and the SAML2 andhttptracerenames. - Removed classes and dependencies:
HttpTraceRepository, type-level@ConstructorBinding,@EnableBatchProcessing, the Elasticsearch high-level REST client, and themysql-connector-java→com.mysql:mysql-connector-jcoordinate change.
Spring Boot 3.x → 4.0
- Modularized starters:
spring-boot-starter-web→-webmvc,-aop→-aspectj, the-oauth2-*starters move under-security-oauth2-*, and Undertow support is removed. - Package moves:
EnvironmentPostProcessor,BootstrapRegistry,@EntityScan,@PropertyMapping,TestRestTemplate, and Spring’s@Nullable→ JSpecify. - Jackson 3:
com.fasterxml.jackson→tools.jackson(the annotations package is correctly excepted), plus@JsonComponent→@JacksonComponent. - Tests:
@MockBean→@MockitoBean,@SpyBean→@MockitoSpyBean. - Properties: the MongoDB connection keys move from
spring.data.mongodb.*tospring.mongodb.*, session and Jackson properties are re-nested, andspring-authorization-server.versionfolds intospring-security.version. - Java baseline: Spring Boot 4 requires Java 17 as a minimum (Java 21+ is recommended for virtual threads — a point several guides get wrong by claiming 21 is mandatory).
How to use it
- Choose your upgrade path from the Upgrade path dropdown.
- Paste a single Java file, your
pom.xmlorbuild.gradle, or anapplication.properties/.ymlblock. Mixed input is fine. - Click Analyze. Findings appear grouped by category with a summary count at the top.
- Work top-down: fix the red Blocker items first, apply the amber Update rewrites, then check each purple Review note by hand.
The four sample buttons load realistic examples for the selected path, so you can see exactly what the output looks like before pasting your own code.
What it deliberately does not do
The analyzer reads imports, configuration keys, starter and dependency artifact IDs, and
well-known annotations and class names. It is a fast static scanner, not a full Java compiler,
so it does not resolve fully-qualified type references buried mid-expression or deeply nested
YAML structures. That is a conscious trade-off: its failure mode is a miss, never a
wrong “fix.” Always compile and run your test suite after migrating, and for the
long tail of renamed configuration keys, add Spring Boot’s own
spring-boot-properties-migrator dependency (runtime scope) to get startup
diagnostics. For automated, repository-wide rewrites, pair this tool with OpenRewrite’s
Spring Boot migration recipes — the analyzer is for understanding and spot-checking; the
recipes are for bulk mechanical change.
Frequently asked questions
Is my code uploaded anywhere?
No. The entire analyzer runs client-side in your browser using JavaScript. Nothing you paste leaves your machine, which makes it safe to check proprietary or internal code.
Which javax packages should I not change to jakarta?
The JDK packages: javax.crypto, javax.net.ssl, javax.sql,
javax.naming, javax.management, javax.xml.parsers,
javax.xml.transform, javax.xml.xpath,
javax.transaction.xa, javax.annotation.processing,
javax.security.auth, and the Swing/AWT/imageio families. These are part of the
Java platform, not Jakarta EE, and the analyzer marks them Keep.
Does Spring Boot 3 really require Java 17?
Yes. Spring Boot 3.0 raised the baseline to Java 17 and moved to Jakarta EE 9+. Spring Boot 4.0 keeps Java 17 as the minimum, with Java 21 or newer recommended for virtual threads. The analyzer flags any source or target below 17 as a blocker.
Can I migrate straight from Spring Boot 2 to Spring Boot 4?
No. The official guidance is to upgrade to the latest Spring Boot 3.5.x first, clear every deprecation warning, and only then move to 4.0. The analyzer flags a direct 2 → 4 jump as a blocker and points you to the 2 → 3 path first.
Does it rewrite my code automatically?
No. It reports what needs changing with an exact before → after suggestion for each finding, so you stay in control. For automated bulk rewrites across a whole repository, use OpenRewrite’s Spring Boot migration recipes alongside this tool.
What is the difference between the 2 → 3 and 3 → 4 paths?
The 2 → 3 path is dominated by the javax → jakarta
namespace change, the Java 17 baseline, Spring Security 6 and Hibernate 6. The
3 → 4 path is about Spring Boot 4’s modularized starters, Jackson 3, JSpecify
nullability, the @MockitoBean test annotations, and a fresh batch of property
renames. Pick the one that matches your current version.