At one place I got this information "With Oracle's new licensing policy you can select any 2 from Stable, Secure, Free." This statement suggests that if I want to select Stable and Secure, then I cannot be free, means I have to use Oracle JDK and pay for license.
Other places I have read that open source community will make sure to update OpenJDK.
If I am using Openjdk 8 in production, then will I get security updates for OpenJDK?
Is updating to newer OpenJDK version the only solution? Even If I move to a newer version (suppose LTS version OpenJDK 11*) for now, then same question in future to get security updates.
I know about the new Oracle release cadence and license policy. I am also aware about the similarity of OpenJDK and Oracle JDK (starting from version 11), but my question is specific to OpenJDK Updates.
LTS version OpenJDK 11: I am not sure if I should call any OpenJDK version as LTS :)