OSSEVA FOR REDIS
Redis and Valkey support: patched, protected, operated.
OSSeva provides Redis and Valkey support for Redis 6.2.x, 7.0.x and 7.2.x and Valkey 7.2.x and 8.x, including patched builds for Redis 7.0.x, which no longer receives upstream fixes, and for 6.2.x after Redis Ltd. stops fixing it on 1 April 2027. Drop-in CVE patches keep your Redis stack patched, compliant, and under a clear operational SLA.
Last reviewed
Trusted globally by enterprises




Why now
The 2024 licence change, and what it actually was
In March 2024 Redis Ltd. moved Redis off BSD-3-Clause to a dual RSALv2 / SSPLv1 licence — not the Business Source License it is frequently reported as. Valkey was forked to BSD by Linux Foundation contributors eight days later, and Redis 8 has since added AGPLv3 as a third option. Redis 6.x and 7.0.x remain BSD-licensed: for those estates the constraint was never the licence, it is that upstream no longer patches them.
Redis Ltd. patches the current line, not the one you are on
Fixes land on the actively maintained releases. Redis 7.0.x already sits outside that window and 6.2.x leaves it on 1 April 2027, and Redis is written in C — memory-safety advisories in command processing are the recurring class here, and they are reachable from any client that can issue a command.
Redis licensing changed twice in two years
Redis moved from BSD to RSALv2/SSPL with 7.4 and added AGPLv3 as an option in Redis 8, while Valkey continues the BSD line from 7.2. Teams that only need a fast cache can keep community Redis or move to Valkey, and get enterprise support for the version they run without buying a commercial platform.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 6.2.x(Full CVE coverage) | Extended | Clean |
| 7.0.x(1 patch in test) | Extended | 1 open |
| 7.2.x | Current | Clean |
| Valkey 7.2.x(BSD fork) | Current | Clean |
| Valkey 8.x | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
CVE patches for Redis 6.2.x–7.0.x under the original BSD license.
- Quarterly CVE patches for Redis 6.2.x and 7.0.x
- Heap overflow and memory corruption priority coverage
- Docker / apt / yum delivery
- Signed artifacts (GPG)
- CVE disclosure notifications
- Architecture review
- 24/7 managed operations
OSSeva Assure
Patch plus Redis security hardening and compliance documentation.
- Everything in Patch
- Redis ACL and authentication configuration audit
- Persistence (RDB/AOF) security configuration review
- SOC 2 / PCI DSS attestation package
- Redis Cluster topology security review
- TLS/SSL configuration hardening guide
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 monitoring, 15-min SLA, named Redis engineers.
- Everything in Assure
- 24/7 instance and cluster health monitoring
- 15-minute P1 incident response SLA
- Named senior Redis engineer on your account
- Memory usage and eviction policy alerting
- Replication lag monitoring
- Quarterly performance reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
docker pull artifacts.osseva.io/redis:7.0.15-osseva-1
docker run -d \
--name redis \
-p 6379:6379 \
-v redis-data:/data \
artifacts.osseva.io/redis:7.0.15-osseva-1 \
redis-server --requirepass yourpassword --appendonly yes# Add OSSeva apt repository
curl -fsSL https://packages.osseva.io/gpg | sudo gpg --dearmor -o /usr/share/keyrings/osseva.gpg
echo "deb [signed-by=/usr/share/keyrings/osseva.gpg] https://packages.osseva.io/apt stable main" \
| sudo tee /etc/apt/sources.list.d/osseva.list
sudo apt-get update
sudo apt-get install -y osseva-redis=7.0.15-osseva-1Migrate from Redis Enterprise
Redis Enterprise is a separate commercial product with its own licensing. For teams that run community Redis for caching and session stores, OSSeva provides CVE coverage and operational support for the version already deployed, without a platform change.
Pricing model
OSSeva for Redis is priced per instance cluster — not per GB of memory, not per operation. Book a discovery call for a quote.
Frequently asked questions
Does OSSeva use the original BSD Redis license?
Yes. OSSeva patches and distributes Redis 6.2.x and 7.0.x — the versions released under the original BSD 3-Clause license before Redis moved to RSALv2 and SSPLv1 in 2024. Your Redis deployment remains under the BSD license.
Does OSSeva also support Valkey?
Yes. Valkey is the Linux Foundation fork of Redis 7.2.x and maintains the BSD license. OSSeva supports Valkey 7.2.x and 8.x as the forward-looking path for teams that want to stay on BSD-licensed Redis-compatible builds.
Do OSSeva Redis builds support Redis Cluster and Redis Sentinel?
Yes. OSSeva builds are binary-compatible with upstream Redis and support Redis Cluster, Redis Sentinel, and standalone modes. Cluster configuration, Sentinel monitoring setup, and replication topology are not affected by the OSSeva patches.
What Redis modules are covered?
Core Redis and the bundled modules (Redis Search, Redis JSON, Redis TimeSeries via RedisStack) are within scope where included in the patched distribution. Third-party external modules require separate assessment.
What kinds of vulnerability affect Redis 6.2.x and 7.0.x?
Redis is written in C, so the recurring classes are memory safety issues in command processing — buffer and integer handling in the data-type implementations — reachable by any client permitted to issue the relevant command. Lua scripting and module loading add further surface. On 7.0.x these no longer receive upstream fixes, and 6.2.x stops receiving them after 1 April 2027, because Redis Ltd. patches only the actively maintained lines. OSSeva backports them to the line you run.
We use Redis as a session store in a PCI DSS environment. What compliance docs do you provide?
OSSeva Assure includes: PCI DSS Requirement 6.3.3 patch attestation, network segmentation configuration review, TLS encryption configuration documentation, ACL access control documentation, and a data retention policy template for session token storage.
Who provides Redis support besides Redis Ltd.?
Redis Ltd. sells Redis Enterprise, a separate commercial product with its own licensing. Cloud providers run managed Redis and Valkey services inside their own platforms, and third-party support companies cover the community builds you run yourself. OSSeva is a third-party provider: one contract can cover Redis and Valkey alongside the rest of your open source stack, end-of-life Redis 7.0.x is included, and the patched builds run on your own servers and clusters.
Does OSSeva support current Redis versions or only end-of-life ones?
Both. OSSeva covers Redis 7.2.x, Valkey 7.2.x and Valkey 8.x as current lines, and Redis 6.2.x and 7.0.x on extended support. OSSeva Patch ships quarterly CVE patches for 6.2.x and 7.0.x, Assure adds ACL, persistence and TLS hardening reviews, and Operate adds 24/7 monitoring with a 15-minute P1 incident response SLA.
How is OSSeva Redis support priced?
OSSeva for Redis is priced per instance cluster, not per GB of memory or per operation. The tier you choose (Patch, Assure or Operate) sets what is included. To compare against your current contract, use the database support cost calculator at /tools/database-support-cost-calculator. Book a discovery call for a quote.
Ready to get Redis patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.