NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1064 most downloaded on PyPI
Avro is a serialization and RPC framework.
Last release 1 months ago
17 Aug 2026
Ships fairly regularly
a new release about every 7 months
Some releases are documented
notes for 12 of 36 stable releases
Nothing withdrawn
no release was ever pulled
16 years old
36 releases · first in 2010
AVRO-4196 : Package 'Microsoft.Build.Utilities.Core' 17.8.3 has a known high severity vulnerability
The Apache Avro community is pleased to announce the release of Avro 1.12.2!
All signed release artifacts, signatures and verification instructions can be found here
This release includes a broad round of hardening against malformed and adversarial input across the Java and Python SDKs (bounding allocations and enforcing decompression limits before trusting size fields read from the input), plus a handful of other fixes with security impact in C#, C++ and JavaScript:
The Avro 1.12.2 Java SDK now restricts arbitrary Java classes from being instantiated, either from the SpecificDatumReader or java-class attributes in a schema.
If you are not setting the org.apache.avro.SERIALIZABLE_CLASSES or org.apache.avro.SERIALIZABLE_PACKAGES system properties, you may experience the following java.lang.SecurityException:
java.lang.SecurityException: Forbidden com.example.MyCustomClass!
This class is not trusted to be included in Avro schemas.
at org.apache.avro.util.ClassSecurityValidator.validate(ClassSecurityValidator.java:60)
at org.apache.avro.util.ClassUtils.forName(ClassUtils.java:99)
...
See AVRO-4189 for more details.
The recommended action is to list the classes and packages that Avro is allowed to instantiate in the org.apache.avro.SERIALIZABLE_CLASSES or org.apache.avro.SERIALIZABLE_PACKAGES system properties.
If you are running Avro in an environment with trusted schemas and trusted data, you can restore the old behaviour by setting org.apache.avro.SERIALIZABLE_PACKAGES to *
(or calling ClassSecurityValidator.setGlobal(...) to trust your own classes).
These SDKs also picked up dependency and build-tooling updates with no other user-facing change: C#, C++, Java, JavaScript, Python.
Thanks to everyone for contributing!
One column per quarter.
Nothing published for this version
[AVRO-3656]: Vulnerabilities from dependencies - jackson-databind & commons-text
Requires: sectionis_human_readable configurable./build.sh clean to remove the generated Python documentscolor-backtrace with better-panic for the testsNothing published for this version
The Apache Avro community is pleased to announce the release of Avro 1.11.3!
The Apache Avro community is pleased to announce the release of Avro 1.11.3!
This release addresses 39 Avro JIRA.
All signed release artifacts, signatures and verification instructions can be found here: https://avro.apache.org/releases.html
This is a minor release, specifically addressing known issues with the 1.11.2 release, but also contains version bumps and doc fixes[1].
In addition, language-specific release artifacts are available:
Thanks to everyone for contributing!
The Apache Avro community is pleased to announce the release of Avro 1.11.2!
The Apache Avro community is pleased to announce the release of Avro 1.11.2!
This release addresses 89 Avro JIRA.
Thanks to everyone for contributing!
The Apache Avro community is pleased to announce the release of Avro 1.11.1!
The Apache Avro community is pleased to announce the release of Avro 1.11.1!
This release includes 256 Jira issues, including some interesting features:
Avro specification
C++
C#
Java
Javascript
Perl
Python
Ruby
Rust
Website
This is the first release that provides the apache-avro crate at crates.io!
A list of all JIRA tickets fixed in 1.11.1 could be found here
In addition, language-specific release artifacts are available:
Thanks to everyone for contributing!
The Apache Avro community is pleased to announce the release of Avro 1.11.0!
The Apache Avro community is pleased to announce the release of Avro 1.11.0!
All signed release artifacts, signatures and verification instructions can be found here: https://avro.apache.org/releases.html
This release includes 120 Jira issues, including some interesting features:
Specification: AVRO-3212 Support documentation tags for FIXED types C#: AVRO-2961 Support dotnet framework 5.0 C#: AVRO-3225 Prevent memory errors when deserializing untrusted data C++: AVRO-2923 Logical type corrections Java: AVRO-2863 Support Avro core on android Javascript: AVRO-3131 Drop support for node.js 10 Perl: AVRO-3190 Fix error when reading from EOF Python: AVRO-2906 Improved performance validating deep record data Python: AVRO-2914 Drop Python 2 support Python: AVRO-3004 Drop Python 3.5 support Ruby: AVRO-3108 Drop Ruby 2.5 support
For the first time, the 1.11.0 release includes experimental support for Rust. Work is continuing on this donated SDK, but we have not versioned and published official artifacts for this release.
Python: The avro package fully supports Python 3. We will no longer publish a separate avro-python3 package
And of course upgraded dependencies to latest versions, CVE fixes and more: https://issues.apache.org/jira/issues/?jql=project%3DAVRO%20AND%20fixVersion%3D1.11.0
The link to all fixed JIRA issues and a brief summary can be found at: https://github.com/apache/avro/releases/tag/release-1.11.0
In addition, language-specific release artifacts are available:
Thanks to everyone for contributing!
Migration notes: Python: AVRO-2656 The standard avro package supports Python 3, and the avro-python3 package is in the process of being deprecated.
The Apache Avro community is pleased to announce the release of Avro 1.10.2!
All signed release artifacts, signatures and verification instructions can be found here: https://avro.apache.org/releases.html
This release includes 31 Jira issues, including some interesting features:
C#: AVRO-3005 Support for large strings C++: AVRO-3031 Fix for reserved keywords in generated code Java: AVRO-2471 Fix for timestamp-micros in generated code Java: AVRO-3060 Support ZSTD level and bufferpool options Ruby: AVRO-2998 Records with symbol keys validation Ruby: AVRO-3023 Validate with Ruby 3
Migration notes: Python: AVRO-2656 The standard avro package supports Python 3, and the avro-python3 package is in the process of being deprecated.
And of course upgraded dependencies to latest versions, CVE fixes and more: https://issues.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.10.2
The link to all fixed JIRA issues and a brief summary can be found at: https://github.com/apache/avro/releases/tag/release-1.10.2
In addition, language-specific release artifacts are available:
Thanks to everyone for contributing!
…library and avro-python3 is prepared to be deprecated
The Apache Avro community is pleased to announce the release of Avro 1.10.1!
All signed release artifacts, signatures and verification instructions can be found here: https://avro.apache.org/releases.html
This release includes 33 Jira issues, including some interesting features:
C#: AVRO-2750 Support for enum defaults C++: AVRO-2891 Expose last sync offset written on DataFileWriter Java: AVRO-2924 SpecificCompiler add 'LocalDateTime' logical type Java: AVRO-2937 Expose some missing flags in SpecificCompilerTool PHP: AVRO-2096 Fixes to missing functions Ruby: AVRO-2907 Ruby schema.single_object_schema_fingerprint is reversed
Migration notes: Java: AVRO-2817 Turn off validateDefaults when reading legacy Avro files Python: AVRO-2656 avro-python package is now the preferred python3 library and avro-python3 is prepared to be deprecated
And of course upgraded dependencies to latest versions, CVE fixes and more: https://issues.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.10.1
…library and avro-python3 is prepared to be deprecated
This release includes 189 Jira issues, including some interesting features:
C#: AVRO-2389 Add Avro serialization for POCO (Reflection) Java: AVRO-2723 Automatically find defaults on POJO when using reflection Java: AVRO-2438 Better support for URI and URL types Perl: AVRO-1461 Distribute Perl module in CPAN PHP: AVRO-2527 Update to PHP 7.x Python: AVRO-2387 Type checking added to python Ruby: AVRO-1740 Support fingerprinting Ruby: AVRO-2535 Support enum defaults Ruby: AVRO-2545 Support aliases
Migration notes: Java: AVRO-2278 Throw an exception when getting a non-existent field from a record Java: AVRO-2581 Maven plugin generates specific records with private fields Java: AVRO-2335 Remove Joda Time library Python: AVRO-2656 avro-python package is now the preferred python3 library and avro-python3 is prepared to be deprecated
And of course upgraded dependencies to latest versions, CVE fixes and more https://issues.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.10.0
This release includes 71 Jira issues: https://jira.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.9.2
This release includes 71 Jira issues: https://jira.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.9.2
This release includes 31 Jira issues: https://jira.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.9.1
This release includes 31 Jira issues: https://jira.apache.org/jira/issues/?jql=project%20%3D%20AVRO%20AND%20fixVersion%20%3D%201.9.1
Deprecate Joda-Time in favor of Java8 JSR310 and setting it as default
This release includes 272 Jira issues: https://issues.apache.org/jira/projects/AVRO/versions/12333394
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →