NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #911 by repository stars
Last release 3 days ago
03 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 15 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
1093 releases · first in 2023
11804 : Enable fine-grained merging for adaptive JSON Recognize the JsonAdaptiveEnc storage encoding in the prolly-row JSON merge path, enabling the e
dolt_checkout() call in noninteractive SQL changes only the SQL session's branch, leaving the CLI branch unchanged.sql_mode as string and reload on server startupVECTOR type.JSON_EXTRACT does not preserve large JSON integer values.\commit uses static time stampdolt dumpif db contains a (non-empty) table with virtual columnsdolt cherry-pick --abort reverts ignored tables.reset --soft behavior doesn't match Git'sas ofSUM/AVG windowsRANGE BETWEEN 1 PRECEDING AND CURRENT ROW over BIGINT UNSIGNED loses the current row at the lower boundary.RANGE boundaries for a correlated computed order keyNTILE(column).dolt sql -q "call dolt_checkout(...);"INT input.One column per month.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
See full diff in compare view 
- Special Thanks:
@winklemad
030ee8b Update version to 1.83.2 (#9375)8668b69 cherry-pick #9365 to v1.83.x (#9366)a3e952d cherry-pick #9346 to v1.83.x and update x/net dependency (#9369)58f8fd9 Change version to 1.83.2-dev (#9337)git fetch of the whole data ref, so a burst of concurrent readers opened a connection each and every probe for a key that does not exist fetched again. Concurrent read-path fetches now share one fetch, and a key missing from a cache already merged from a commit is reported absent without fetching. A fetch that finds the head unchanged now also refreshes the dedup window, which previously never renewed against a quiet remote.taskkill /T -- and set cmd.WaitDelay as a backstop for a holder that left the group, such as an ssh ControlMaster. Cancellation and expired-wait errors now report ctx.Err() rather than a bare kill signal, and skip the credential hints NormalizeError appends.dolt pushold...new, and when forced are explicitly marked (forced update).
actions.Push. to capture OldHash, NewHash, and existence.PushRefResult to distinguish new branches, fast-forward, updates, forced updates, deletions, and tags.formatPushSuccess to format push success messages.Sourced from google.golang.org/grpc's releases.
Release 1.83.1
Security
- xds/rbac: Fix a bug where nested
PrincipalorPermissionrules with:schemeorgrpc-prefixed header matchers were not rejected, which could cause DENY rules to fail open. (#9258)
- Special Thanks:
@nvxbug- xds/rbac: Fix a bug where the
hostheader matcher was not being replaced with:authorityin nestedPrincipalorPermissionrules. (#9258)
- Special Thanks:
@nvxbug- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as
X-Role, matched no header, which could cause DENY rules to fail open. (#9332)
- Special Thanks:
@alimony- xds/rbac: Fix a bug where a
:schemeorgrpc-prefixed header matcher was accepted when its name was not lowercase. (#9332)
- Special Thanks:
@alimony- xds/rbac: Fix a bug where a
Hostheader matcher was not replaced with:authority. (#9332)
- Special Thanks:
@alimonyPerformance
- transport: Restrict memory overhead of buffering small data frames. (#9331)
Release 1.83.0
Security
- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable
GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT.- xds/rbac: Support
MetadataandRequestedServerNamepermissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.- xds/rbac: Fix panic when parsing unsupported fields in
NotRule/NotIdpermissions.- xds/rbac: Support the deprecated
source_ipprincipal identifier by treating it as equivalent todirect_remote_ip.- xds: Fix panic when parsing route header matchers configured with empty
exact_match,prefix_match, orsuffix_matchstrings. (#9223)New Features
- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the
force-xdstarget URI query parameter. (#9133)- xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (#9145)
- authz: Add
OnPolicyUpdatecallback toFileWatcherOptionsto notify when an authz policy is loaded or updated. (#9142)
- Special Thanks:
@hnefatl- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true. (#9119)- xds: Add support for xDS-based HTTP CONNECT proxies.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true. (#9151)- xds: Add support for
contains_matchin route header matchers. (#9223)Bug Fixes
- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (#9197)
- grpc: Fix compilation on Plan 9 targets (
GOOS=plan9), broken since v1.81.0. (#9255)
- Special Thanks:
@YusufihsangorgelRelease 1.82.2
Security
- server: Reject requests missing both
:authorityandHostheaders with HTTP 400 and statusInternal. (grpc/grpc-go#9365)
... (truncated)
Commits1550d9e Change version to 1.83.1 (#9336)ebba6f3 Cherry-pick #9258 and #9332 into v1.83.x (#9335)8cfeca0 Cherry-pick #9331 to v1.83.x (#9333)dec6951 Change version to 1.83.1-dev (#9229)4c226da Change version to 1.83.0 (#9228)c198988 Cherrypick 9223 into v1.83.x (#9279)8ce3ebf Cherrypick PR 9255 into v1.83.x (#9263)e393849 Cherry-pick recent changes from master (#9240)2a112a8 authz: add onPolicyUpdate callback to authz file watcher (#9142)1a80fca vet: adds a check to disallow usage of regex.Compile in xDS code (#9216)COUNT field ordinals past that hidden value so COUNT(column) examines the requested column.Sourced from mysql2's releases.
v3.23.1
3.23.1 (2026-07-19)
Bug Fixes
- security: fix unbounded decompression of server-supplied compressed packets, reported by alanturing881 (7c48343)
- parser: call typeCast for NULL values in the binary protocol (#4394) (01f1092)
v3.23.0
3.23.0 (2026-07-13)
Features
- return unsafe integers inside JSON columns as exact strings with supportBigNumbers (#4388) (a26ff14)
- sql-escaper: add Temporal support when escaping values (#4392) (6b933f6)
- support MariaDB data types (UUID, INET4, INET6, VECTOR, JSON) via extended type metadata; run CI against MariaDB (#4373) (5034e57)
v3.22.6
3.22.6 (2026-07-07)
Bug Fixes
v3.22.5
3.22.5 (2026-06-06)
Bug Fixes
v3.22.4
3.22.4 (2026-05-24)
Bug Fixes
v3.22.3
3.22.3 (2026-04-24)
Bug Fixes
... (truncated)
ChangelogSourced from mysql2's changelog.
3.23.1 (2026-07-19)
Bug Fixes
- security: fix unbounded decompression of server-supplied compressed packets, reported by alanturing881 (7c48343)
- parser: call typeCast for NULL values in the binary protocol (#4394) (01f1092)
3.23.0 (2026-07-13)
Features
- return unsafe integers inside JSON columns as exact strings with supportBigNumbers (#4388) (a26ff14)
- sql-escaper: add Temporal support when escaping values (#4392) (6b933f6)
- support MariaDB data types (UUID, INET4, INET6, VECTOR, JSON) via extended type metadata; run CI against MariaDB (#4373) (5034e57)
3.22.6 (2026-07-07)
Bug Fixes
3.22.5 (2026-06-06)
Bug Fixes
3.22.4 (2026-05-26)
Bug Fixes
3.22.3 (2026-04-24)
Bug Fixes
3.22.2 (2026-04-21)
Bug Fixes
... (truncated)
Commits3de28fb chore(master): release 3.23.1 (#4408)01f1092 fix(parser): call typeCast for NULL values in the binary protocol (#3368) (#4...534c552 build(deps): bump lucide-react from 1.24.0 to 1.25.0 in /website (#4407)7c48343 Merge commit from fork3e13d7b docs: establish security charter (#4404)26c135b build(deps): bump websocket-driver from 0.7.4 to 0.7.5 in /website (#4403)f86cfb1 chore(master): release 3.23.0 (#4387)6316492 build(deps): bump the docusaurus group in /website with 2 updates (#4396)6b933f6 feat(sql-escaper): add Temporal support when escaping values (#4392)457c316 build(deps): bump lucide-react from 1.23.0 to 1.24.0 in /website (#4391)This version was pushed to npm by GitHub Actions, a new releaser for mysql2 since your current version.
Sourced from github.com/apache/thrift's releases.
ChangelogVersion 0.24.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Sourced from github.com/apache/thrift's changelog.
0.24.0
Build Process
- THRIFT-5000 - Thrift docker image publish on releases
- THRIFT-5855 - Improve fuzzing support
- THRIFT-5952 - Optimize MSVC Docker image to reduce size and speed up CI
- THRIFT-5965 - Add zizmor for GitHub Actions workflows security analysis
- THRIFT-5967 - Refactor SCA GitHub workflow for better extensibility
- THRIFT-5973 - Automated CHANGELOG creation
- THRIFT-6002 - Add netstd codegen test script and GitHub Actions CI matrix job (.NET 8/9/10)
- THRIFT-6003 - Add Haxe codegen test script and GitHub Actions CI job
- THRIFT-6077 - improve CHANGES.md generator section assignment
- #3613 - Bump rubygems/release-gem from 1.2.0 to 1.4.0
- #3616 - Bump ruby/setup-ruby from 1.310.0 to 1.314.0
- #3617 - Bump rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5
- #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
- #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin
- #3615 - Bump actions/setup-go from 6.4.0 to 6.5.0
- THRIFT-6092 - fix off-by-ten header bounds check in readHeaderFormat
- #3593 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/js
- #3591 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/ts
- #3589 - Update MSVC CI to windows-2025-vs2026 runner and start Docker service explicitly
- #3581 - Run the Haxe library unit tests (neko) in CI
- #3576 - Bump ruby/setup-ruby from 1.306.0 to 1.310.0
- #3575 - Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6
- #3577 - Bump actions/setup-dotnet from 4.3.1 to 5.2.0
- #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin
- #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin
- #3578 - Harden the MSVC build workflow against transient Docker daemon unavailability
- #3564 - Enable Copilot reviews
- #3565 - Allow CI to fail on ruby-head
- #3517 - Bump uuid and nyc
- #3513 - Remove Ruby known failures from cross-test list
- #3501 - Fix netstd CI .NET SDK setup
- #3496 - Add generator paths to mergeable labels
- #3430 - Updated projects settings in .asf.yaml (features, merge buttons, Jira autolinking)
- #3487 - Update to setup-php 2.37.1
- #3471 - Update build.yml
- #3461 - Migration *.sln to *.slnx (except c++ libs)
- #3454 - Fixing bundler on ruby-head build
- #3440 - Removed deprecated 'publish' workflow
- #3439 - Pin all actions to a specific SHA consistently
- #3437 - Validate GitHub workflows against the ASF allowlist
- #3433 - Pin actions/upload-artifact to a specific SHA consistently
- #3433 - Bump actions/upload-artifact from 7.0.0 to 7.0.1
- #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
- #3423 - Bump uuid from 13.0.0 to 14.0.0
- #3424 - Bump json from 2.18.1 to 2.19.2 in /lib/rb
- #3404 - Cleanup Adobe Flex SDK installation following AS3 library removal
... (truncated)
Commits6d2ec95 Tune make dist: drop generated/build artifacts, add missing sources4f303a2 Strip node_modules from dist to fix make dist symlink recursion270b81e Fix stale EXTRA_DIST references that broke make distc1df044 Fix Go and Rust version detection for multi-digit version numbers342a803 updated CHANGES.md0d66913 bump doap & debian changelogf961cdb fix info-header string bound check in THeaderTransport::readString0ab16e3 enforce max_string_size on non-strict binary message name817e0f1 Bump rubygems/release-gem from 1.2.0 to 1.4.06dfb0b2 THRIFT-6073: Allow injecting external SSL_CTX into C++ SSLContextlocalhost resolves through DNS on MacOS but not on Ubuntu, which doesn't have this problem. This PR changes all localhost definitions in the test to the loopback address instead.dolt sql shell, two related edge cases around empty/comment-only statements produced confusing output instead of clear, MySQL-consistent behavior:
;) silently printed Empty set, 1 warning with a warning body of query was empty after trimming comments, instead of a clear client-side error.-- foo ;) behaved the same way — a spurious "empty" warning — instead of being silently skipped the way dolt sql < file.sql (batch mode) already treats it.sqlparser.ErrEmpty explicitly in execShell's Uninterpreted callback (go/cmd/dolt/commands/sql.go):; is stripped) now prints a MySQL-style No query specified error, matching how the real mysql CLI responds to a bare ;.ErrEmpty because it's all comment) is now skipped silently — no output, no warning — which mirrors the existing behavior of execBatchMode, where err == sqlparser.ErrEmpty is already a silent continue.execBatchMode, sql.go) and processQuery (used by scripting/non-interactive paths) both already treat sqlparser.ErrEmpty as "silently skip." The interactive shell was the only place papering over this with a fake Empty set, 1 warning result, which is misleading — there's no result set, and the "warning" concept here doesn't correspond to anything the query actually did. This change brings the shell in line with the rest of the codebase's handling of empty statements while adding a genuinely useful error for the truly-empty case (bare ;), since that's a real MySQL client-side error dolt users would expect to see.go build ./cmd/dolt/... — passesgo vet ./cmd/dolt/... — passesgofmt -l go/cmd/dolt/commands/sql.go — cleanintegration-tests/bats/sql-shell.bats:sql-shell: bare empty query gives MySQL-style error, not a warning (uses new sql-shell-empty-query.expect)sql-shell: comment-only query is skipped silently, no warning (uses new sql-shell-comment-only-query.expect)dolt binary and pass:ok 1 sql-shell: bare empty query gives MySQL-style error, not a warning
ok 1 sql-shell: comment-only query is skipped silently, no warning
sql-shell.bats suite regression run was kicked off locally to check for unrelated breakage; not gating this PR description on it since the two new/targeted cases already passed cleanly and no other test in the file touches this code path.0A000 feature-not-supported error for DISTINCT aggregate window calls, including COUNT, SUM, AVG, MIN, and MAX.SUM(COALESCE(amount, 0)) can return unknown type received *apd.Decimal result over the PostgreSQL protocol.numeric after plan construction, but its projected GetField retains the earlier unknown type. Although the aggregate correctly produces an *apd.Decimal, wire encoding consequently routes that value through unknownout.OptimizeFunctions project pass when their matching aggregate ColumnId has acquired a concrete type. Projection changes use Project.WithExpressions so the cached schema is invalidated. Regression coverage includes grouped, ungrouped, all-NULL, windowed, and correlated scalar-subquery forms.DO statements for executing anonymous PL/pgSQL blocks. Supports the default language and LANGUAGE plpgsql before or after the body, propagates PostgreSQL SQLSTATEs, and executes blocks atomically.GRANT example, errors and rollback, dynamic EXECUTE, and nested DO blocks in stored PL/pgSQL functions.NEW, OLD and TG_OP by the casing in which they appeared in the source code. In 3743010, doltgres was changed to correctly fold unquoted identifiers at both declaration time and when they appear as variable references. This had the unintended side effect of breaking existing compiled triggers which referenced these special variables --- the variables started being introduced by the interpret in their folded form, but the references to them existed as compiled opcodes that already had the variable name persisted, and that name was not going through folding again as part of interpretation.DEFAULT VALUES, stored generated and identity columns, equal-width multi-row defaults, empty-tuple syntax errors, exact SQLSTATEs, extended-protocol execution, and statement atomicity.varchar_pattern_ops), DESC indexes, and NULL ordering (nulls can be set to be first or last).3858: Cover vector index nullability across DDL paths
Extends vector-index nullability regression coverage to JSON columns and ALTER TABLE, complementing Dolt's engine coverage in dolthub/dolt#11785.
Fixes dolthub/dolt#10448
3857: Set return type for population statistic aggregate functions
Fixes dolthub/dolt#11391
3855: Implement Numeric to Date conversions
Implements conversions from numeric types (int, float, decimal) to DATETIME types.
Partially addresses: dolthub/dolt#10278
Fixes: dolthub/dolt#10088
3852: Reject unsupported DISTINCT window aggregates
Rejects DISTINCT window aggregates with MySQL 8.4-compatible error 1235 / SQLSTATE 42000 for COUNT, SUM, and AVG, including multi-argument COUNT, while preserving accepted MIN and MAX behavior.
Adds engine coverage for the exact customer reproduction and adjacent aggregate behavior.
Fixes dolthub/dolt#11392
3847: Remove schema length check when analyzing subquery aliases
Fixes
Note truncated.
…tps://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolv…
Sourced from google.golang.org/grpc's releases.
Release 1.83.1
Security
- xds/rbac: Fix a bug where nested
PrincipalorPermissionrules with:schemeorgrpc-prefixed header matchers were not rejected, which could cause DENY rules to fail open. (#9258)
- Special Thanks:
@nvxbug- xds/rbac: Fix a bug where the
hostheader matcher was not being replaced with:authorityin nestedPrincipalorPermissionrules. (#9258)
- Special Thanks:
@nvxbug- xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as
X-Role, matched no header, which could cause DENY rules to fail open. (#9332)
- Special Thanks:
@alimony- xds/rbac: Fix a bug where a
:schemeorgrpc-prefixed header matcher was accepted when its name was not lowercase. (#9332)
- Special Thanks:
@alimony- xds/rbac: Fix a bug where a
Hostheader matcher was not replaced with:authority. (#9332)
- Special Thanks:
@alimonyPerformance
- transport: Restrict memory overhead of buffering small data frames. (#9331)
Release 1.83.0
Security
- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable
GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT.- xds/rbac: Support
MetadataandRequestedServerNamepermissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.- xds/rbac: Fix panic when parsing unsupported fields in
NotRule/NotIdpermissions.- xds/rbac: Support the deprecated
source_ipprincipal identifier by treating it as equivalent todirect_remote_ip.- xds: Fix panic when parsing route header matchers configured with empty
exact_match,prefix_match, orsuffix_matchstrings. (#9223)New Features
- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the
force-xdstarget URI query parameter. (#9133)- xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (#9145)
- authz: Add
OnPolicyUpdatecallback toFileWatcherOptionsto notify when an authz policy is loaded or updated. (#9142)
- Special Thanks:
@hnefatl- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true. (#9119)- xds: Add support for xDS-based HTTP CONNECT proxies.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true. (#9151)- xds: Add support for
contains_matchin route header matchers. (#9223)Bug Fixes
- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (#9197)
- grpc: Fix compilation on Plan 9 targets (
GOOS=plan9), broken since v1.81.0. (#9255)
- Special Thanks:
@YusufihsangorgelRelease 1.82.2
Security
- server: Reject requests missing both
:authorityandHostheaders with HTTP 400 and statusInternal. (grpc/grpc-go#9365)
... (truncated)
Commits1550d9e Change version to 1.83.1 (#9336)ebba6f3 Cherry-pick #9258 and #9332 into v1.83.x (#9335)8cfeca0 Cherry-pick #9331 to v1.83.x (#9333)dec6951 Change version to 1.83.1-dev (#9229)4c226da Change version to 1.83.0 (#9228)c198988 Cherrypick 9223 into v1.83.x (#9279)8ce3ebf Cherrypick PR 9255 into v1.83.x (#9263)e393849 Cherry-pick recent changes from master (#9240)2a112a8 authz: add onPolicyUpdate callback to authz file watcher (#9142)1a80fca vet: adds a check to disallow usage of regex.Compile in xDS code (#9216)Sourced from mysql2's releases.
v3.22.0
3.22.0 (2026-04-10)
Features
- disable mysql_clear_password plugin by default (#4236) (884bec5), closes #1617
- implement COM_RESET_CONNECTION with pool integration (#4148) (49a64cc)
Performance Improvements
v3.21.1
3.21.1 (2026-04-09)
Bug Fixes
- limit client flags to server capabilities (#4227) (e1930b8)
- use Number.isSafeInteger for supportBigNumbers boundary check (#4225) (295264b)
v3.21.0
3.21.0 (2026-04-09)
Features
- add support for query attributes (#4223) (d732f78)
- types: export ExecuteValues and QueryValues from entry point (9fafd6f)
v3.20.0
3.20.0 (2026-03-15)
Features
Bug Fixes
- explicitly specify in auth plugins (#4175) (#4187) (5ac5563)
- prevent double release from corrupting the connection pool (#4186) (7e57db6)
- restore
PoolConnectionas subclass ofConnection(#4183) (97855a6)v3.19.1
3.19.1 (2026-03-09)
... (truncated)
ChangelogSourced from mysql2's changelog.
3.22.0 (2026-04-10)
Features
- disable mysql_clear_password plugin by default (#4236) (884bec5), closes #1617
- implement COM_RESET_CONNECTION with pool integration (#4148) (49a64cc)
Performance Improvements
3.21.1 (2026-04-09)
Bug Fixes
- limit client flags to server capabilities (#4227) (e1930b8)
- use Number.isSafeInteger for supportBigNumbers boundary check (#4225) (295264b)
3.21.0 (2026-04-09)
Features
- add support for query attributes (#4223) (d732f78)
- types: export ExecuteValues and QueryValues from entry point (9fafd6f)
3.20.0 (2026-03-15)
Features
Bug Fixes
- explicitly specify in auth plugins (#4175) (#4187) (5ac5563)
- prevent double release from corrupting the connection pool (#4186) (7e57db6)
- restore
PoolConnectionas subclass ofConnection(#4183) (97855a6)3.19.1 (2026-03-09)
Bug Fixes
... (truncated)
Commits71bcbff chore(master): release 3.22.0 (#4237)ab131de perf: defer Error object creation to error handlers in promise wrappers (#4257)bb0100b build(deps-dev): bump the website-dev-dependencies group across 1 directory w...5f63557 build(deps-dev): bump the dev-dependencies group across 1 directory with 4 up...0b750e0 build(deps): bump the docusaurus group in /website with 2 updates (#4249)9566475 ci(dependabot): group dependency updates to reduce PR noise (#4248)e4f3b42 build(deps): bump the react group in /website with 2 updates (#4247)53f9c9e ci(dependabot): group react and react-dom updates together (#4246)49a64cc feat: implement COM_RESET_CONNECTION with pool integration (#4148)884bec5 feat: disable mysql_clear_password plugin by default (#4236)ErrInvalidAddressLen.varintPrefixLen to assert buffer length before reading varints, preventing out-of-bounds slice panics on truncated multi-byte headers.ErrNullAdaptiveValue, ErrInlineAdaptiveValue, ErrTruncatedVarint, and ErrInvalidAddressLen for callers and tests..dolt/sql-server.info files left by crashed servers and recover locally, while connection failures provide troubleshooting steps.
creds.go: Add ProcessExists.server.go: Writing .dolt/sql-server.info is deferred until after InitSQLServer binds the listener.queryist_utils.go: PingContext checks connectivity early and closes conn on dial failure.Sourced from org.mariadb:r2dbc-mariadb's releases.
MariaDB Connector/R2DBC 1.4.1
1.4.1 (Jun 2026)
Notable Changes:
- R2DBC-116 Add GraalVM native-image configuration and CI coverage
- Update dependencies (Project Reactor 2025.0.6, Netty 4.2.15.Final)
Bugs Fixed:
- R2DBC-115 Clear-text authentication plugins (PAM, mysql_clear_password) must require a secure connection (report by fg0x0)
- R2DBC-117 Cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- R2DBC-119 Fail closed when a
classpath:SSL certificate is missing- R2DBC-120 Stored-procedure CALL detection wrongly matched any query containing "call" (thanks to yunhobb)
- R2DBC-121
caching_sha2_password/sha256_passwordlogin fails with passwords of 20 characters or more (report by 4UjwXc)- R2DBC-124 Ensure a non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- R2DBC-122 Fix SQL parser to correctly handle '--' in expressions
- R2DBC-123 Pin Locale.ROOT on locale-sensitive wire-format codec sites (thanks to jmestwa-coder)
MariaDB Connector/R2DBC 1.4.0
1.4.0 (Feb 2026)
Notable Changes:
- R2DBC-109 Add fallbackToSystemTrustStore and fallbackToSystemKeyStore options
- R2DBC-110 Support java.time.Instant parameters
- R2DBC-114 Implement Wrapped interface to expose EventLoop scheduler for r2dbc-pool optimization
Bugs Fixed:
- R2DBC-108 Handle authentication plugin multi-exchange prefix (0x01) introduced in MDEV-37554
- R2DBC-111 Potential hang when upstream subscription is cancelled before demand
- R2DBC-112 Failed authentication when using
caching_sha2_passwordwith passwords longer than 18 characters- R2DBC-113 Add support for RSA public key content in cachingRsaPublicKey and rsaPublicKey options
MariaDB Connector/R2DBC 1.3.1
1.3.1 (Jun 2026)
Maintenance release for the 1.3 line, back-porting the corrections, CI and security fixes made after 1.3.0.
java.time.Instantparameter support is intentionally not included.Notable Changes:
- R2DBC-108 Handle authentication plugin multi-exchange prefix (0x01) introduced in MDEV-37554
- R2DBC-109 Add
fallbackToSystemTrustStoreandfallbackToSystemKeyStoreoptions- R2DBC-113 Support inline RSA public key for
sha256_passwordandcaching_sha2_password- R2DBC-114 Implement
Wrappedinterface to expose the EventLoop scheduler for r2dbc-pool- R2DBC-116 Add GraalVM native-image configuration and CI testing
Bugs Fixed:
- R2DBC-111 Potential hang when upstream subscription is cancelled before demand
- R2DBC-112 Failed authentication using
caching_sha2_passwordwith passwords longer than 18 characters
... (truncated)
ChangelogSourced from org.mariadb:r2dbc-mariadb's changelog.
Commits1.4.1 (Jun 2026)
Notable Changes:
- R2DBC-116 Add GraalVM native-image configuration and CI coverage
- Update dependencies (Project Reactor 2025.0.6, Netty 4.2.15.Final)
Bugs Fixed:
- R2DBC-115 Clear-text authentication plugins (PAM, mysql_clear_password) must require a secure connection (report by fg0x0)
- R2DBC-117 Cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- R2DBC-119 Fail closed when a
classpath:SSL certificate is missing- R2DBC-120 Stored-procedure CALL detection wrongly matched any query containing "call" (thanks to yunhobb)
- R2DBC-121
caching_sha2_password/sha256_passwordlogin fails with passwords of 20 characters or more (report by 4UjwXc)- R2DBC-124 Ensure a non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- R2DBC-122 Fix SQL parser to correctly handle '--' in expressions
- R2DBC-123 Pin Locale.ROOT on locale-sensitive wire-format codec sites (thanks to jmestwa-coder)
1.4.0 (Feb 2026)
Notable Changes:
- R2DBC-109 Add fallbackToSystemTrustStore and fallbackToSystemKeyStore options
- R2DBC-110 Support java.time.Instant parameters
- R2DBC-114 Implement Wrapped interface to expose EventLoop scheduler for r2dbc-pool optimization
Bugs Fixed:
- R2DBC-108 Handle authentication plugin multi-exchange prefix (0x01) introduced in MDEV-37554
- R2DBC-111 Potential hang when upstream subscription is cancelled before demand
- R2DBC-112 Failed authentication when using
caching_sha2_passwordwith passwords longer than 18 characters- R2DBC-113 Add support for RSA public key content in cachingRsaPublicKey and rsaPublicKey options
1.3.0 (Oct 2024)
Notable Changes:
- R2DBC-106 Implement parsec authentication. see https://mariadb.com/kb/en/authentication-plugin-parsec/
a82d265 bump 1.4.144602cb [misc] fix flaky PrepareResultSetTest.cacheReuse under load68d9f81 [misc] test correction about pamOtherPwd sanitization4656951 [misc] bump dependenciescd9b6f9 [misc] code style correction76181aa [R2DBC-121] caching_sha2_password/sha256_password login fails with passwords ...ccf4326 [R2DBC-120] Stored-procedure CALL detection wrongly matched any query contain...84dc70c Merge PR #92 (yunhobb): fix incorrect stored procedure CALL detection in crea...11d92c0 [misc] mask pamOtherPwd in MariadbConnectionConfiguration.toString()1ec789e [misc] reject malformed auth-switch seed and column-definition packets cleanlySourced from org.mariadb.jdbc:mariadb-java-client's releases.
MariaDB Connector/Java 3.5.9
3.5.9 (Jun 2026)
Key Enhancements
- CONJ-1223 - cache TLS trust/key managers across connections to reduce SSL connection cost
- CONJ-1314 - add SPI for interactive dialog (PAM) authentication callback
- CONJ-1311 - add dedicated option
useIpForKillQueryfor query cancellation- CONJ-1310 - Add full native image support and CI coverage
Issues Resolved
- CONJ-1320 - PAM (dialog) authentication must require a secure connection (report by fg0x0)
- CONJ-1319 - Use constant-time comparison when validating the server certificate fingerprint (report by jmestwa-coder)
- CONJ-1318 - enforce
allowLocalInfile=falseon the server's local-infile request, so a malicious server cannot read a client file despite the option being disabled- CONJ-1322 - match local infile filename case-sensitively (thanks to jmestwa-coder)
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1315 - cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- CONJ-1317 - ensure non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- CONJ-1304 - CallableStatement parameter metadata read from mysql.proc, with MySQL info_schema fallback
- CONJ-1299 - keep VALUES literals after the last placeholder when rewriting batches
- CONJ-1313 - race condition in HaMode#getAvailableHostInOrder can cause NPE
- CONJ-1311 - Connection.cancelCurrentQuery fails with SslMode.VERIFY_FULL when client socket IP is set
- CONJ-1264 - handle LocalDateTime as a zoneless wall-clock value
- CONJ-1316 - pin Locale.ROOT on locale-sensitive call sites and date/time/Duration text formatting (fixes locale-dependent parsing/formatting, e.g. under tr_TR) (thanks to jmestwa-coder)
- CONJ-1324 - fix SQL parser to correctly handle '--' in expressions and reset lastChar after block comments
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
MariaDB Connector/Java 3.5.8
3.5.8 (Apr 2026)
Issues Resolved
- CONJ-1305 - XAResource.isSameRM() incorrectly returns true when rewriteBatchedStatements differs between connections
- CONJ-1303 - Statement.cancel() fails to kill running query during result streaming
Other
- CONJ-1298 - Performance improvement: avoid decoding extended format
MariaDB Connector/Java 3.5.7
3.5.7 (Dec 2025)
Key Enhancements
... (truncated)
ChangelogSourced from org.mariadb.jdbc:mariadb-java-client's changelog.
3.5.9 (Jun 2026)
Key Enhancements
- CONJ-1223 - cache TLS trust/key managers across connections to reduce SSL connection cost
- CONJ-1314 - add SPI for interactive dialog (PAM) authentication callback
- CONJ-1311 - add dedicated option
useIpForKillQueryfor query cancellation- CONJ-1310 - Add full native image support and CI coverage
Issues Resolved
- CONJ-1320 - PAM (dialog) authentication must require a secure connection (report by fg0x0)
- CONJ-1319 - Use constant-time comparison when validating the server certificate fingerprint (report by jmestwa-coder)
- CONJ-1318 - enforce
allowLocalInfile=falseon the server's local-infile request, so a malicious server cannot read a client file despite the option being disabled- CONJ-1322 - match local infile filename case-sensitively (thanks to jmestwa-coder)
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1315 - cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if MitM (report by tonghuaroot)
- CONJ-1317 - ensure non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- CONJ-1304 - CallableStatement parameter metadata read from mysql.proc, with MySQL info_schema fallback
- CONJ-1299 - keep VALUES literals after the last placeholder when rewriting batches
- CONJ-1313 - race condition in HaMode#getAvailableHostInOrder can cause NPE
- CONJ-1311 - Connection.cancelCurrentQuery fails with SslMode.VERIFY_FULL when client socket IP is set
- CONJ-1264 - handle LocalDateTime as a zoneless wall-clock value
- CONJ-1316 - pin Locale.ROOT on locale-sensitive call sites and date/time/Duration text formatting (fixes locale-dependent parsing/formatting, e.g. under tr_TR) (thanks to jmestwa-coder)
- CONJ-1324 - fix SQL parser to correctly handle '--' in expressions and reset lastChar after block comments
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1318 - allowLocalInfile=false does not block LOAD DATA LOCAL INFILE against a malicious server (thanks to tharavel)
3.4.3 (Jun 2026)
Bugs Fixed
- CONJ-1315 - cap BigDecimal/BigInteger string parsing length to prevent CPU exhaustion if Mitm (report by tonghuaroot)
- CONJ-1316 - pin Locale.ROOT on locale-sensitive call sites and date/time/Duration text formatting (fixes locale-dependent parsing/formatting, e.g. under tr_TR) (thanks to jmestwa-coder)
- CONJ-1259 - DatabaseMetaData read-only detection: handle MariaDB 12.0
@@read_onlyreturningON/OFFinstead of1/0- CONJ-1317 - ensure non-UTF8 charset cannot be used for protocol exchanges (report by fg0x0)
- CONJ-1320 - PAM (dialog) authentication now requires a secure connection (TLS or unix socket), like mysql_clear_password (report by fg0x0)
- CONJ-1319 - use constant-time comparison when validating the server certificate fingerprint (thanks to jmestwa-coder)
- CONJ-1322 - match local infile filename case-sensitively (thanks to jmestwa-coder)
- CONJ-1323 - LOAD LOCAL INFILE validation rejects statements preceded by line comments (thanks to sebdomdev)
- CONJ-1318 - allowLocalInfile=false does not block LOAD DATA LOCAL INFILE against a malicious server (thanks to tharavel)
3.3.5 (Jun 2026)
... (truncated)
Commitsdf4ebe2 [misc] enhance TcpProxy and TcpProxySocket for improved thread safety and con...687c840 [misc] update environment variable for Maxscale version4466ad6 [misc] test stability improvement : update proxy close method in PooledConnec...1e29819 [misc] update README versionda297f1 Merge branch 'develop'83d3da9 [misc] Update CHANGELOGe39e8b9 match local infile filename case-sensitivelyd90b987 [misc] Implement secure authentication checks and add regression tests for cr...f4a727c [CONJ-1320] PAM (dialog) authentication must require a secure connectiona87c711 [misc] update CHANGELOGdolt log --not "", dolt diff --include-cols "") no longer panics.Sourced from mariadb's releases.
MariaDB Connector/Node.js 3.5.3
3.5.3 (Jun1 2026)
Notable changes
- Minimum supported Node.js version is now 20 (was 18; Node 18 went EOL in April 2025)
- CONJS-346: Add
RowsWithMeta<T>andWithMeta<T>helper types for typingquery()/execute()result shapes —RowsWithMeta<T>for the default rows-array-with-metashape,WithMeta<T>for themetaAsArray: truetuple form (types-only, no runtime change)Issues Fixed
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel)- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-344: Restore dual ESM/CJS support after the 3.5 ESM migration (#346):
- TypeScript types now compile under
moduleResolution: "Node16" / "NodeNext" / "Bundler"— fixes TS2846 / TS2834 reported in 3.5.1 and 3.5.2- Ship paired
.d.ctsdeclarations for therequirecondition- Ship a real CJS bundle in
dist/sorequire('mariadb')works on Node 20+ without--experimental-require-moduleorExperimentalWarning- Restore the default ESM export, so
import mariadb from 'mariadb'works again (matches 3.4.x behavior)MariaDB Connector/Node.js 3.5.2
3.5.2 (Mar 2026)
Issues Fixed
- CONJS-342 Resolved TypeScript compilation errors introduced in mariadb-connector-nodejs v3.5.1
- CONJS-343 Fixed an issue where batch operations would hang when provided with empty array parameter values
MariaDB Connector/Node.js 3.5.1
3.5.1 (Feb 2026)
Notable changes
- CONJS-338 Add asyncDispose support for Connection, PoolConnection and Pool #250
- CONJS-339 Add default type parameter to Prepare interface and fix executeStream generic #334
- CONJS-339 Add wildcard for values params on Prepare
Issues Fixed
- CONJS-331 Plugin authentication change correction
- CONJS-335 Deno compatibility: send COM_QUIT synchronously to prevent socket cleanup race condition
- CONJS-336 Connection attribute _server_host send host, but IP resulting of name resolution
- CONJS-340 Fix pool connection event to emit wrapped connections and prevent user errors from breaking pool #342
- CONJS-341 Support charset + collation combination in connection options #337
MariaDB Connector/Node.js 3.5.0 RC
3.5.0-rc.0 (Oct 2025)
Notable changes
- CONJS-326 migrate from commonJS to ESM
- CONJS-325 deno compatibility
... (truncated)
ChangelogSourced from mariadb's changelog.
3.5.3 (Jun1 2026)
Notable changes
- Minimum supported Node.js version is now 20 (was 18; Node 18 went EOL in April 2025)
- CONJS-346: Add
RowsWithMeta<T>andWithMeta<T>helper types for typingquery()/execute()result shapes —RowsWithMeta<T>for the default rows-array-with-metashape,WithMeta<T>for themetaAsArray: truetuple form (types-only, no runtime change)Issues Fixed
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel)- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-344: Restore dual ESM/CJS support after the 3.5 ESM migration (#346):
- TypeScript types now compile under
moduleResolution: "Node16" / "NodeNext" / "Bundler"— fixes TS2846 / TS2834 reported in 3.5.1 and 3.5.2- Ship paired
.d.ctsdeclarations for therequirecondition- Ship a real CJS bundle in
dist/sorequire('mariadb')works on Node 20+ without--experimental-require-moduleorExperimentalWarning- Restore the default ESM export, so
import mariadb from 'mariadb'works again (matches 3.4.x behavior)3.4.6 (Jun 2026)
Issues Fixed
- CONJS-331: Corrected parsec authentication plugin handling
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-349: Fixed cleartext password disclosure to a man-in-the-middle when relying on certificate fingerprint validation (self-signed trust mode)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel)- Refuse sending the password in clear (
mysql_clear_password) over an unencrypted connection3.3.3 (Jun 2026)
Issues Fixed
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-349: Fixed cleartext password disclosure to a man-in-the-middle when relying on certificate fingerprint validation (self-signed trust mode)
- CONJS-351: Use constant-time comparison when validating the server certificate fingerprint token, preventing a timing side-channel that could leak the token to a man-in-the-middle
- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
- CONJS-354: Reject a server-initiated LOAD DATA LOCAL INFILE request when
permitLocalInfileis disabled (report by tharavel)- Refuse sending the password in clear (
mysql_clear_password) over an unencrypted connection3.2.4 (Jun 2026)
Issues Fixed
- CONJS-350: Fixed possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charset (report by fg0x0)
- CONJS-353: PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text (report by fg0x0)
... (truncated)
Commits14e0f16 [misc] Update CHANGELOG.md to include recent security fixes for PAM authentic...cd00457 Merge branch 'develop'f34b785 [misc] test stability: poll debug log until flushed instead of fixed wait2df7c26 [CONJS-354] Reject server-initiated LOAD DATA LOCAL INFILE when permitLocalIn...7d6e44a [misc] Cap the length of server-sent numeric strings before BigInt parsing, p...53b3042 [CONJS-353] PAM (dialog) authentication now requires a secure connection (TLS...41eec7f [CONJS-351] Implement constant-time comparison in validateFingerPrint to prev...aa50c50 Update CHANGELOG.md for version 3.4.6, 3.3.3 and 3.2.4, adding fixed issues a...6c10db5 [misc] test stability correction5d5293a [misc] Refuse mysql_clear_password over an insecure connectionRowIter and enforce subquery authdolt_query_diff. With this change, permissions on tables, views, and databases referenced are verified during planning. Table rows are only fetched when the query is executed, fixing edge cases with EXPLAIN.
WithCatalog now calls engine.AnalyzeQuery to parse and validate permissions without instantiating rows.WithCatalog.deferred field so log consumers can classify it without parsing prose.dolt_rebase data-conflict enginetest to assert the abort that the error message promises actually happened: original branch restored, the dolt_rebase_<branch> working branch and the dolt_rebase plan table both gone, and dolt_conflicts empty.Statistic.Created on newly generated table-scan and index statistics so dolt_statistics.created_at reports the collection time instead of Go’s zero value, while cached statistics keep their existing timestamps.Sourced from github.com/apache/thrift's releases.
ChangelogVersion 0.24.0
Please head over to the official release download source: http://thrift.apache.org/download
The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.
Sourced from github.com/apache/thrift's changelog.
0.24.0
Build Process
- THRIFT-5000 - Thrift docker image publish on releases
- THRIFT-5855 - Improve fuzzing support
- THRIFT-5952 - Optimize MSVC Docker image to reduce size and speed up CI
- THRIFT-5965 - Add zizmor for GitHub Actions workflows security analysis
- THRIFT-5967 - Refactor SCA GitHub workflow for better extensibility
- THRIFT-5973 - Automated CHANGELOG creation
- THRIFT-6002 - Add netstd codegen test script and GitHub Actions CI matrix job (.NET 8/9/10)
- THRIFT-6003 - Add Haxe codegen test script and GitHub Actions CI job
- THRIFT-6077 - improve CHANGES.md generator section assignment
- #3613 - Bump rubygems/release-gem from 1.2.0 to 1.4.0
- #3616 - Bump ruby/setup-ruby from 1.310.0 to 1.314.0
- #3617 - Bump rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5
- #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
- #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin
- #3615 - Bump actions/setup-go from 6.4.0 to 6.5.0
- THRIFT-6092 - fix off-by-ten header bounds check in readHeaderFormat
- #3593 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/js
- #3591 - Bump shell-quote from 1.7.3 to 1.8.4 in /lib/ts
- #3589 - Update MSVC CI to windows-2025-vs2026 runner and start Docker service explicitly
- #3581 - Run the Haxe library unit tests (neko) in CI
- #3576 - Bump ruby/setup-ruby from 1.306.0 to 1.310.0
- #3575 - Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6
- #3577 - Bump actions/setup-dotnet from 4.3.1 to 5.2.0
- #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin
- #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin
- #3578 - Harden the MSVC build workflow against transient Docker daemon unavailability
- #3564 - Enable Copilot reviews
- #3565 - Allow CI to fail on ruby-head
- #3517 - Bump uuid and nyc
- #3513 - Remove Ruby known failures from cross-test list
- #3501 - Fix netstd CI .NET SDK setup
- #3496 - Add generator paths to mergeable labels
- #3430 - Updated projects settings in .asf.yaml (features, merge buttons, Jira autolinking)
- #3487 - Update to setup-php 2.37.1
- #3471 - Update build.yml
- #3461 - Migration *.sln to *.slnx (except c++ libs)
- #3454 - Fixing bundler on ruby-head build
- #3440 - Removed deprecated 'publish' workflow
- #3439 - Pin all actions to a specific SHA consistently
- #3437 - Validate GitHub workflows against the ASF allowlist
- #3433 - Pin actions/upload-artifact to a specific SHA consistently
- #3433 - Bump actions/upload-artifact from 7.0.0 to 7.0.1
- #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
- #3423 - Bump uuid from 13.0.0 to 14.0.0
- #3424 - Bump json from 2.18.1 to 2.19.2 in /lib/rb
- #3404 - Cleanup Adobe Flex SDK installation following AS3 library removal
... (truncated)
Commits6d2ec95 Tune make dist: drop generated/build artifacts, add missing sources4f303a2 Strip node_modules from dist to fix make dist symlink recursion270b81e Fix stale EXTRA_DIST references that broke make distc1df044 Fix Go and Rust version detection for multi-digit version numbers342a803 updated CHANGES.md0d66913 bump doap & debian changelogf961cdb fix info-header string bound check in THeaderTransport::readString0ab16e3 enforce max_string_size on non-strict binary message name817e0f1 Bump rubygems/release-gem from 1.2.0 to 1.4.06dfb0b2 THRIFT-6073: Allow injecting external SSL_CTX into C++ SSLContextNote truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →