NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central · #719 by repository stars
gRPC: Netty Shaded
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 3 weeks
Rarely documented
notes for 12 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
168 releases · first in 2018
core: Gracefully handle GOAWAY frames with unrecognized error codes ( #13043 ). Treats unrecognized HTTP/2 GOAWAY error codes as INTERNAL_ERROR instea
…, it missed Netty's built-in CVE-2026-47244 patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALU…
In this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following Google Play Service’s now requiring a minimum of API level 24 (Android 7.0 Nougat).
XdsServerBuilder with SocketAddresses (#12925) (ac02c6f)shutdownNow() becoming a no-op after shutdown() (#12982) (3cb7007)DefaultHttp2Connection initialization. Because NettyServerHandler instantiates DefaultHttp2Connection directly rather than using Netty's AbstractHttp2ConnectionHandlerBuilder, it missed Netty's built-in CVE-2026-47244 patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.AsyncServletOutputStreamWriter detect and handle write when not ready (#12732) (46f3080) In highly concurrent scenarios, cached servlet container ready to write state can become stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.@Zhengcy05
@carl-mastrangelo
@themechbro
@JasonLunn
@martinbaillie
@eado
@TimurRakhmatullin86
One column per quarter.
netty: Fix client-initiated stream limit bypass in NettyServerHandler ( #12942 ). Enforces the limit proactively at startup without waiting for SETTIN
api: Turn on RFC 3986 parsing by default and update javadoc.
tian__mi__mi@
codingkiddo@
Zhengcy05@
netty: Fix client-initiated stream limit bypass in NettyServerHandler ( #12941 ). Enforces the limit proactively at startup without waiting for SETTIN
The fixes that were supposed to go in this release were not included in the patch by mistake. Use 1.82.4 instead.
The fixes that were supposed to go in this release were not included in the patch by mistake. Use 1.82.4 instead.
Revert "xds: reuse connections to the control plane across channels" added in 1.81.0 ( #12886 ). If using xds heavily with many targets, then MAX_CONC
protoc-gen-grpc-java: Fix missing osx-x86_64 binary ( #12878 ). This fixes a regression in v1.82.0
This release drops support for Bazel 7. It may still run, but we are no longer testing it. We are testing Bazel 8 and 9.
This release drops support for Bazel 7. It may still run, but we are no longer testing it. We are testing Bazel 8 and 9.
We are anticipating requiring Netty 4.2 in the next release. Please file an issue if you still need Netty 4.1 support.
UNIMPLEMENTED, which tears down the stream and EDS data never arrives. This fix makes it skip DiscoveryRequests for resource types we don't actually subscribe to on a given server.@ThreadSafe annotation and replace with JavaDoc (#12762). Removes JSR-305 annotations but instead of replacing it with ErrorProne's ThreadSafe, sticks to adding a JavaDoc comment. This is done only in public non-final classes and interfaces. This allows Java applications that have moved away from javax to compile and avoids a bug in Immutables and Lombok (and possibly other annotation processors) from failing when JSR-305 is not present.streamClosed() happens before serverCallStarted().GRPC_EXPERIMENTAL_ENABLE_NEW_PICK_FIRST=true when accepting resolved addresses and in CONNECTING state (#12814). It makes sure that whenever PickFirstLeafLoadBalancer transitions into CONNECTING the current address in the addressIndex has a corresponding subchannel. This prevents an NPE in acceptResolvedAddresses in some situations.?force-xds query parameter in the google-c2p resolver (#12760) (86fa860). This disables environment checks and uses xDS unconditionally. Please note that this feature has not yet seen comprehensive testing.@becomeStar
@bengtsson1-flir
@jnowjack-lucidchart
@Kainsin
@kenkangxgwe
@mfperminov
@paulmurhy123
@schiemon
@therepanic
Revert "xds: reuse connections to the control plane across channels" added in 1.81.0 ( #12887 ). If using xds heavily with many targets, then MAX_CONC
api: Deprecate LoadBalancer.handleResolvedAddresses(). Developers maintaining custom LoadBalancer implementations should transition to using LoadBalan…
In this release we drop support for Android API level 22 or lower (Lollipop or earlier), following Google Play Service’s discontinued updates for Lollipop (API levels 21 & 22) and now requires a minimum of API level 23 (Android 6.0 Marshmallow).
API Changes
Behavior Changes
android.context.Context. For reference, it seems Chrome caches for 1 minuteBug Fixes
ManagedChannelOrphanWrapper could incorrectly log a "not shutdown properly" warning during garbage collection when using directExecutor(). (#12705) (d459338)typeUrl. (#12740) (eac9fe9)backend_service. This ensures xDS load balancing metrics are reported accurately. (#12735)New Features
grpc.client.call.custom label as defined by gRFC A108. See also the gRPC OpenTelemetry Metrics guide (update in-progress)AdvancedTlsX509KeyManager so that developers can now preserve and use key aliases when dynamically reloading TLS certificates. (#12686)Documentation
Dependencies
Thanks to
core: Added PickResult.copyWithSubchannel() and PickResult.copyWithStreamTracerFactory() to simplify updating PickResult while preserving metadata. Lo
API Changes
Bug Fixes
Improvements
New Features
Thanks to
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →