Skip to content

Releases: apache/pulsar

v5.0.0

Choose a tag to compare

@lhotari lhotari released this 05 Oct 19:22
v5.0.0

2026-10-05

Milestone release notes

The 5.0.0 release also includes the changes from these milestone releases:

Approved PIPs

  • [improve][pip] PIP-441: Add Broker-Level Metrics for Skipped Non-Recoverable Data (#24716)
  • [improve][pip] PIP-494: Scalable Topics Client Specification — authoritative reference and change process (#26447)
  • [improve][pip] PIP-496: Pulsar Functions and IO support for the V5 client and scalable topics (#26698)

Library updates

  • [improve][broker] Upgrade bookkeeper to 4.18.1 (#26574)
  • [fix][sec] Upgrade Async HTTP Client to 3.0.14 and Netty Reactive Streams to 2.0.20 (#26764)
  • [fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 (#26758)
  • [fix][sec] Upgrade zstd-jni to 1.5.7-20 (#26766)
  • [fix][build] Upgrade Conscrypt to 2.6.3 (#26660)
  • [fix][build] Upgrade LightProto to 0.8.2 (#26623)
  • [improve][zk] Upgrade ZooKeeper to 3.9.6 (#26750)
  • [improve][build] Upgrade Bouncy Castle libraries (#26753)
  • [improve][build] Upgrade Caffeine to 3.3.0 (#26755)
  • [improve][build] Upgrade Gradle to 9.8.0 and update plugins (#26752)
  • [improve][build] Upgrade gRPC to 1.84.0 (#26762)
  • [improve][build] Upgrade Guava to 33.7.1-jre (#26760)
  • [improve][build] Upgrade Jackson to 2.21.7 (#26754)
  • [improve][build] Upgrade OpenTelemetry libraries to 1.66.0 level (#26756)
  • [improve][build] Upgrade Protobuf to 4.36.2 (#26757)
  • [improve][build] Upgrade SnakeYAML to 2.7 (#26761)
  • [improve][misc] Upgrade Jetty to 12.1.13 (#26738)

Broker

  • [fix][broker] Align entry filter policy checks for non-persistent topics (#26774)
  • [fix][broker] Align partitioned topic truncate checks with non-partitioned topics (#26776)
  • [fix][broker] Apply managedLedgerContinueCachingAddedEntriesAfterLastActiveCursorLeavesMillis to managed ledgers (#26785)
  • [fix][broker] Apply subscription policies to namespace and topic subscription operations (#26767)
  • [fix][broker] Apply the role logging anonymizer to topic authorization denial logs (#26642)
  • [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#26633)
  • [fix][broker] Bound classic Key_Shared dispatcher replay queue look-ahead (#26677)
  • [fix][broker] Bound the local partition metadata retry when starting a geo-replicator (#26681)
  • [fix][broker] Check the original principal of proxied HTTP requests with its own authentication data (#26748)
  • [fix][broker] Check topic permissions for binary GetSchema and GetOrCreateSchema (#26643)
  • [fix][broker] Check topic permissions for partitions and subscriptions added to a transaction (#26644)
  • [fix][broker] Decode topic name in the scalable topic migrate endpoint (#26711)
  • [fix][broker] Derive scalable topic identity from the raw local name (#26668)
  • [fix][broker] Do not enable replicated subscriptions on scalable topic segments (#26679)
  • [fix][broker] Do not start classic geo-replicators on scalable-topic segment topics (#26691)
  • [fix][broker] Fix lookup permit leak when namespace policy reads fail (#26606)
  • [fix][broker] Keep accepting Avro named type references written as objects (#26586)
  • [fix][broker] Log only non-default settings at broker startup (#26612)
  • [fix][broker] Preserve compaction state on ledger close failure (#26665)
  • [fix][broker] Preserve replicated subscription activity on activation (#26780)
  • [fix][broker] Preserve topic initialization failures (#26775)
  • [fix][broker] Prevent slow Key_Shared sockets from stalling other consumers (#26635)
  • [fix][broker] Propagate bundle split failures to the completion future (#26735)
  • [fix][broker] Read the producer name of GetOrCreateSchema before authorization completes (#26770)
  • [fix][broker] Release the compaction buffers and permits on flush failures (#26576)
  • [fix][broker] Spurious ERROR log for 307 redirect in getReplicatedSubscriptionStatus (#26706)
  • [fix][admin] Restore Pulsar 4.x compatible serialVersionUID for PackageMetadata (#26784)
  • [fix][ml] Close abandoned write ledger handle to prevent leak (#26585)
  • [fix][ml] Fail in-flight adds when a managed ledger is terminated (#26678)
  • [fix][ml] Fail queued adds when a managed ledger is terminated during a ledger rollover (#26680)
  • [fix][ml] Fix active cursor position tracking after untracking (#26629)
  • [fix][ml] Fix backlog estimation during ledger rollover with pending writes (#26647)
  • [fix][ml] Propagate cursor ledger deletion failures (#26734)
  • [fix][ml] Reset the lazily-cached position when reusing a recycled EntryImpl (#26707)
  • [fix][ml][broker] Keep source ledger data on every shadow managed ledger trim, delete and offload path (#26746)
  • [fix][meta] Close resources when ZKMetadataStore construction fails (#26673)
  • [fix][meta] Track explicitly acquired underreplicated ledger locks (#26670)
  • [improve][broker] Add configuration to enable shadow topics (#26739)
  • [improve][broker] Add metrics for message position find by timestamp (#26751)
  • [improve][broker] Allow disabling scalable topics when upgrading to 5.x (#26740)
  • [improve][broker] Allow dynamically updating topic load timeout (#26781)
  • [improve][broker] Avoid read locks in Key_Shared consumer selection (#26591)
  • [improve][broker] Avoid redundant read-completion executor handoffs for Exclusive/Failover (#26619)
  • [improve][broker] Avoid the topic-wide deduplication lock (#26763)
  • [improve][broker] Change the default number of namespace bundles to 32 and make the system namespace bundle count configurable (#26610)
  • [improve][broker] Disable subscription-thread dispatch by default (#26578)
  • [improve][broker] Make AvgShedder the default load shedding and placement strategy (#26609)
  • [improve][broker] Optimize consumer selection for shared subscriptions (#26593)
  • [improve][broker] PIP-379: Remove the classic Shared and Key_Shared dispatcher implementations (#26687)
  • [improve][broker] Raise the default dispatcherMaxReadBatchSize from 100 to 500 (#26744)
  • [improve][broker] Reduce cache retention after reads and apply retention settings at startup (#26627)
  • [improve][broker] Resume Shared dispatch when consumer channels become writable (#26630)
  • [improve][broker] Skip unused replicated subscription timestamp updates (#26655)
  • [improve][broker] Speed up auto-split Key_Shared consumer selection (#26654)
  • [improve][broker] Stor...
Read more

v4.2.5

Choose a tag to compare

@lhotari lhotari released this 05 Oct 19:23
v4.2.5

2026-08-03

Library updates

  • [improve][broker][branch-4.2] Upgrade bookkeeper to 4.17.4 (#26219)
  • [fix][sec] Bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /pulsar-function-go/examples (#26231)
  • [fix][sec] Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /pulsar-function-go (#26446)
  • [fix][sec] Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in /pulsar-function-go (#26541)
  • [fix][sec] Bump log4j2 from 2.26.0 to 2.26.1 (#26329)
  • [fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 (#26758)
  • [fix][sec] Upgrade avro to 1.12.2 (#24992)
  • [fix][sec] Upgrade grpc in pulsar-function-go to 1.82.1 to fix GHSA-hrxh-6v49-42gf (#26235)
  • [fix][sec] Upgrade Jackson to 2.18.10 (#26339)
  • [fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 (#26250)
  • [fix][sec][branch-4.2] Upgrade BouncyCastle to 1.85 and BouncyCastle FIPS to 2.0.2 to address CVEs (#26370)
  • [fix][sec][branch-4.2] Upgrade Netty to 4.1.137 to address several CVEs and bugs (#26301)
  • [fix][sec][branch-4.2] Upgrade Spring to 7.0.8 (#26270)
  • [fix][sec][branch-4.x] Upgrade async-http-client to 2.16.1 (#26436)
  • [fix][sec][branch-4.x] Upgrade lz4-java to 1.11.2 (#26439)
  • [fix][sec][branch-4.x] Upgrade Netty to 4.1.138 to address several CVEs and bugs (#26515)
  • [fix][sec][branch-4.x] Upgrade Thrift to 0.24.0 (#26438)
  • [fix][sec][branch-4.x] Upgrade vertx to 4.5.32 (#26437)
  • [fix][build] Upgrade Conscrypt to 2.6.3 (#26660)
  • [improve][zk] Upgrade ZooKeeper to 3.9.6 (#26750)
  • [improve][build] Upgrade Apache Commons libraries (#26348)
  • [improve][build] Upgrade Bouncy Castle libraries (#26753)
  • [improve][build] Upgrade Caffeine to 3.3.0 (#26755)
  • [improve][build] Upgrade Guava to 33.7.1-jre (#26760)
  • [improve][build] Upgrade Oxia Java client to 0.9.5 (#26538)
  • [improve][misc] Upgrade Conscrypt to 2.6.1 to add aarch64 native support (#26314)
  • [improve][misc] Upgrade Conscrypt to 2.6.2 to restore the native library glibc baseline (#26315)
  • [improve][misc] Upgrade Jetty to 12.1.12 (#26302)
  • [improve][misc] Upgrade Jetty to 12.1.13 (#26738)
  • [improve][misc] Upgrade log4j to 2.26.0 and slf4j to 2.0.18 (#25973)
  • [improve][misc][branch-4.x] Upgrade Jackson to 2.18.11 (#26759)
  • [fix][test][branch-4.2] Fix connector tests broken by the Avro 1.12.2 upgrade

Broker

  • [fix][broker] Add missing bundle Prometheus metrics for extensible load manager (#26192)
  • [fix][broker] Align entry filter policy checks for non-persistent topics (#26774)
  • [fix][broker] Align partitioned topic truncate checks with non-partitioned topics (#26776)
  • [fix][broker] Apply managedLedgerContinueCachingAddedEntriesAfterLastActiveCursorLeavesMillis to managed ledgers (#26785)
  • [fix][broker] Apply subscription policies to namespace and topic subscription operations (#26767)
  • [fix][broker] Apply the role logging anonymizer to topic authorization denial logs (#26642)
  • [fix][broker] Avoid load shedding and metadata writes from a former leader (#26253)
  • [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#26633)
  • [fix][broker] Bound classic Key_Shared dispatcher replay queue look-ahead (#26677)
  • [fix][broker] Bound the local partition metadata retry when starting a geo-replicator (#26681)
  • [fix][broker] Bound the topic deletion retries triggered by a replication cluster removal (#26432)
  • [fix][broker] Cancel queued transaction snapshot recovery on topic close (#26335)
  • [fix][broker] Cancel queued transaction snapshot recovery on topic close (#26335)
  • [fix][broker] Check the original principal of proxied HTTP requests with its own authentication data (#26748)
  • [fix][broker] Check topic permissions for binary GetSchema and GetOrCreateSchema (#26643)
  • [fix][broker] Check topic permissions for partitions and subscriptions added to a transaction (#26644)
  • [fix][broker] Debit un-acked messages only when the consumer is actually removed (#26422)
  • [fix][broker] Do not log an error when the tenant does not exist (#26361)
  • [fix][broker] Don't serve topic policies from a cache whose init future has not completed (#26513)
  • [fix][broker] Fix assignment and ownership cleanup races in the extensible load manager (#26520)
  • [fix][broker] Fix AvgShedder assignment cache keying with stable bundle names (#26246)
  • [fix][broker] Fix delayed-delivery bucket merge failures when delayedDeliveryMaxNumBuckets is 1-3 (#26242)
  • [fix][broker] Fix dispatcherPauseOnAckStatePersistentEnabled and schemaValidationEnforced returning wrong values when applied=true (#26472)
  • [fix][broker] Fix early completion and false timeouts in SplitManager and UnloadManager (#26363)
  • [fix][broker] Fix lookup permit leak when namespace policy reads fail (#26606)
  • [fix][broker] Fix multi-role authorization regressions and optimize nested checks (#26551)
  • [fix][broker] Fix NPE in ManagedLedgerInterceptorImpl when AppendIndexMetadataInterceptor isn't configured (#26497)
  • [fix][broker] Fix ownership-generation races in OwnershipCache removeOwnership and lock-expiry cleanup (#26197)
  • [fix][broker] Fix persistent throughput degradation caused by permit loss during frequent reconnects on Shared subscriptions (#26289)
  • [fix][broker] Keep accepting Avro named type references written as objects (#26586)
  • [fix][broker] Log exception in PulsarMetadataEventSynchronizer failure path (#26203)
  • [fix][broker] Preserve compaction state on ledger close failure (#26665)
  • [fix][broker] Preserve replicated subscription activity on activation (#26780)
  • [fix][broker] Preserve topic initialization failures (#26775)
  • [fix][broker] Prevent automatic TTL expiry from skipping reader messages (#26505)
  • [fix][broker] Prevent Key_Shared out-of-order replay starvation at the end of topic (#26268)
  • [fix][broker] Prevent NPE when the last ACK races with sticky hash reassignment (#26471)
  • [fix][broker] Propagate bundle split failures to the completion future (#26735)
  • [fix][broker] Release the compaction buffers and permits on flush failures (#26576)
  • [fix][broker] Resolve replicator remote cluster by prefix so cluster names containing a dot work (#26451)
  • [fix][broker] Send ActiveConsumerChange for non-persistent Failover subscriptions (#26482)
  • [fix][broker] Spurious ERROR log for 307 redirect in getReplicatedSubscriptionStatus (#26706)
  • [fix][broker] Stop reporting a deliberate ownership release as an expired resource lock (#26533)
  • [fix][broker]Producer with AUTO_PRODUCE schema ...
Read more

v4.0.14

Choose a tag to compare

@lhotari lhotari released this 05 Oct 19:23
v4.0.14

2026-10-05

Library updates

  • [improve][broker][branch-4.2] Upgrade bookkeeper to 4.17.4 (#26219)
  • [fix][sec] Bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /pulsar-function-go/examples (#26231)
  • [fix][sec] Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /pulsar-function-go (#26446)
  • [fix][sec] Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in /pulsar-function-go (#26541)
  • [fix][sec] Bump log4j2 from 2.26.0 to 2.26.1 (#26329)
  • [fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 (#26758)
  • [fix][sec] Upgrade grpc in pulsar-function-go to 1.82.1 to fix GHSA-hrxh-6v49-42gf (#26235)
  • [fix][sec] Upgrade Jackson to 2.18.10 (#26339)
  • [fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 (#26250)
  • [fix][sec][branch-4.2] Upgrade BouncyCastle to 1.85 and BouncyCastle FIPS to 2.0.2 to address CVEs (#26370)
  • [fix][sec][branch-4.2] Upgrade Netty to 4.1.137 to address several CVEs and bugs (#26301)
  • [fix][sec][branch-4.2] Upgrade Spring to 7.0.8 (#26270)
  • [fix][sec][branch-4.x] Upgrade async-http-client to 2.16.1 (#26436)
  • [fix][sec][branch-4.x] Upgrade lz4-java to 1.11.2 (#26439)
  • [fix][sec][branch-4.x] Upgrade Netty to 4.1.138 to address several CVEs and bugs (#26515)
  • [fix][sec][branch-4.x] Upgrade Thrift to 0.24.0 (#26438)
  • [fix][sec][branch-4.x] Upgrade vertx to 4.5.32 (#26437)
  • [fix][build] Upgrade Conscrypt to 2.6.3 (#26660)
  • [improve][zk] Upgrade ZooKeeper to 3.9.6 (#26750)
  • [improve][build] Upgrade Apache Commons libraries (#26348)
  • [improve][build] Upgrade Bouncy Castle libraries (#26753)
  • [improve][build] Upgrade Oxia Java client to 0.9.5 (#26538)
  • [improve][misc] Upgrade Conscrypt to 2.6.1 to add aarch64 native support (#26314)
  • [improve][misc] Upgrade Conscrypt to 2.6.2 to restore the native library glibc baseline (#26315)
  • [improve][misc] Upgrade Jetty to 12.1.12 (#26302)
  • [improve][misc] Upgrade Jetty to 12.1.13 (#26738)
  • [improve][misc] Upgrade log4j to 2.26.0 and slf4j to 2.0.18 (#25973)
  • [improve][misc][branch-4.x] Upgrade Jackson to 2.18.11 (#26759)

Broker

  • [fix][broker] Add missing bundle Prometheus metrics for extensible load manager (#26192)
  • [fix][broker] Align entry filter policy checks for non-persistent topics (#26774)
  • [fix][broker] Align partitioned topic truncate checks with non-partitioned topics (#26776)
  • [fix][broker] Apply subscription policies to namespace and topic subscription operations (#26767)
  • [fix][broker] Avoid load shedding and metadata writes from a former leader (#26253)
  • [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#26633)
  • [fix][broker] Bound classic Key_Shared dispatcher replay queue look-ahead (#26677)
  • [fix][broker] Bound the topic deletion retries triggered by a replication cluster removal (#26432)
  • [fix][broker] Cancel queued transaction snapshot recovery on topic close (#26335)
  • [fix][broker] Check the original principal of proxied HTTP requests with its own authentication data (#26748)
  • [fix][broker] Check topic permissions for binary GetSchema and GetOrCreateSchema (#26643)
  • [fix][broker] Check topic permissions for partitions and subscriptions added to a transaction (#26644)
  • [fix][broker] Debit un-acked messages only when the consumer is actually removed (#26422)
  • [fix][broker] Do not log an error when the tenant does not exist (#26361)
  • [fix][broker] Don't serve topic policies from a cache whose init future has not completed (#26513)
  • [fix][broker] Fix assignment and ownership cleanup races in the extensible load manager (#26520)
  • [fix][broker] Fix AvgShedder assignment cache keying with stable bundle names (#26246)
  • [fix][broker] Fix delayed-delivery bucket merge failures when delayedDeliveryMaxNumBuckets is 1-3 (#26242)
  • [fix][broker] Fix dispatcherPauseOnAckStatePersistentEnabled and schemaValidationEnforced returning wrong values when applied=true (#26472)
  • [fix][broker] Fix early completion and false timeouts in SplitManager and UnloadManager (#26363)
  • [fix][broker] Fix lookup permit leak when namespace policy reads fail (#26606)
  • [fix][broker] Fix multi-role authorization regressions and optimize nested checks (#26551)
  • [fix][broker] Fix NPE in ManagedLedgerInterceptorImpl when AppendIndexMetadataInterceptor isn't configured (#26497)
  • [fix][broker] Fix ownership-generation races in OwnershipCache removeOwnership and lock-expiry cleanup (#26197)
  • [fix][broker] Fix persistent throughput degradation caused by permit loss during frequent reconnects on Shared subscriptions (#26289)
  • [fix][broker] Log exception in PulsarMetadataEventSynchronizer failure path (#26203)
  • [fix][broker] Preserve compaction state on ledger close failure (#26665)
  • [fix][broker] Preserve replicated subscription activity on activation (#26780)
  • [fix][broker] Preserve topic initialization failures (#26775)
  • [fix][broker] Prevent automatic TTL expiry from skipping reader messages (#26505)
  • [fix][broker] Prevent Key_Shared out-of-order replay starvation at the end of topic (#26268)
  • [fix][broker] Prevent NPE when the last ACK races with sticky hash reassignment (#26471)
  • [fix][broker] Propagate bundle split failures to the completion future (#26735)
  • [fix][broker] Release the compaction buffers and permits on flush failures (#26576)
  • [fix][broker] Resolve replicator remote cluster by prefix so cluster names containing a dot work (#26451)
  • [fix][broker] Send ActiveConsumerChange for non-persistent Failover subscriptions (#26482)
  • [fix][broker] Spurious ERROR log for 307 redirect in getReplicatedSubscriptionStatus (#26706)
  • [fix][broker] Stop reporting a deliberate ownership release as an expired resource lock (#26533)
  • [fix][admin] Allow defaultNumPartitions for non-partitioned autoTopicCreation override (#25163)
  • [fix][admin] Avoid creating subscriptions when peeking messages if auto-creation is disabled (#26279)
  • [fix][admin] Reject empty cluster migration URL: fix inverted ClusterUrl.isEmpty() (#26473)
  • [fix][ml] Close abandoned write ledger handle to prevent leak (#26585)
  • [fix][ml] Fail in-flight adds when a managed ledger is terminated (#26678)
  • [fix][ml] Fail queued adds when a managed ledger is terminated during a ledger rollover (#26680)
  • [fix][ml] Fix batch ACK index loss when recovering cursor from MetadataStore (#26474)
  • [fix][ml] Preserve cursor properties when recovering from an unreadable cursor ledger (#26512)
  • [fix][ml] Preserve ledger properties w...
Read more

v5.0.0-M2

v5.0.0-M2 Pre-release
Pre-release

Choose a tag to compare

@lhotari lhotari released this 16 Sep 23:33
v5.0.0-M2

2026-09-17

Approved PIPs

  • [improve][pip] PIP-445: Add Builder Methods to Create Message-based TableView (#24842)
  • [improve][pip] PIP-486: Scalable Topic Key-Shared Consumption (#26077)
  • [improve][pip] PIP-492: Add pulsar_subscription_storage_backlog_age_seconds metric (#26362)
  • [feat][pip] PIP-478: Asynchronous v5 client auth plugin interfaces and TLS material provider plugin interface (#25890)
  • [feat][pip]PIP-487 Add event count metrics for InflightReadsLimiter acquire and release operations (#26092)

Breaking changes

  • JUL (java.util.logging) configuration is no longer effective for server-side components (#26330)

    Previously, logs from third-party libraries that use JUL (e.g., Jersey/Jetty, gRPC, Guava) were not managed by Pulsar's Log4j2 configuration, making them difficult to control and causing inconsistent log output. To solve this, third-party library logging is now bridged from JUL to Log4j2 via log4j-jul. This unifies all logging under conf/log4j2.yaml, but means the following JUL APIs and configurations no longer take effect:

    • -Djava.util.logging.config.file=logging.properties — the entire JUL configuration file is ignored
    • java.util.logging.Logger.setLevel() / addHandler() — become no-ops
    • java.util.logging.LogManager.reset() — becomes a no-op

    Migration: Move any JUL-based logging configuration to conf/log4j2.yaml. For example, to suppress gRPC logs that were previously configured as io.grpc.level=SEVERE in logging.properties, add the following to conf/log4j2.yaml:

    Loggers:
      Logger:
        - name: io.grpc
          level: error

    Revert: To restore stock JUL behavior, set:

    PULSAR_EXTRA_OPTS="-Djava.util.logging.manager=java.util.logging.LogManager"

Library updates

  • [improve][build] Switch default JDK to 25 for 5.0.0-M2 (#26070)
  • [fix][sec] Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /pulsar-function-go (#26142)
  • [fix][sec] Bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /pulsar-function-go/examples (#26231)
  • [fix][sec] Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /pulsar-function-go (#26446)
  • [fix][sec] Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in /pulsar-function-go (#26541)
  • [fix][sec] Bump log4j2 from 2.26.0 to 2.26.1 (#26329)
  • [fix][sec] Downgrade Jackson version to 2.21.5 LTS (#26166)
  • [fix][sec] Pin httpclient5 to 5.6.4 and httpcore5 to 5.4.3 (#26331)
  • [fix][sec] Upgrade avro to 1.12.2 (#24992)
  • [fix][sec] Upgrade grpc in pulsar-function-go to 1.82.1 to fix GHSA-hrxh-6v49-42gf (#26235)
  • [fix][sec] Upgrade Jackson to 2.21.6 (#26338)
  • [fix][sec] Upgrade Jackson to 2.22.0 (#26101)
  • [fix][sec] Upgrade jline to 4.2.1 and picocli to 4.7.7, drop unused jline2 (#26068)
  • [fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 (#26250)
  • [fix][sec] Upgrade Netty to 4.2.16.Final to address CVEs (#26167)
  • [fix][sec] Upgrade Netty to 4.2.17 to address several CVEs and bugs (#26300)
  • [fix][sec] Upgrade Netty to 4.2.18 to address several CVEs and bugs (#26514)
  • [fix][sec] Upgrade pulsar-client-go to v0.20.0 in pulsar-function-go, also address CVEs (#26140)
  • [fix][ci] Upgrade sandboxed-trivy-action to approved sha (#26169)
  • [improve][fn] Upgrade pulsar-client-python to 3.12.0 (#26033)
  • [improve][fn] Upgrade pulsar-client-python to 3.13.0 (#26139)
  • [improve][meta] Upgrade Oxia client to 0.9.4 (#26193)
  • [improve][monitor] Upgrade Dropwizard Metrics to 4.2.39 and HdrHistogram to 2.2.2 (#26353)
  • [improve][build] Upgrade Apache Commons libraries (#26348)
  • [improve][build] Upgrade async-http-client to 3.0.13 and netty-reactive-streams to 2.0.19 (#26366)
  • [improve][build] Upgrade BouncyCastle to 1.85 and BouncyCastle FIPS to 2.1.x (#26349)
  • [improve][build] Upgrade data structure and compression libraries (#26357)
  • [improve][build] Upgrade docker base image Alpine to 3.24 (#26225)
  • [improve][build] Upgrade Gradle plugins and move to the io.github.ben-manes.versions plugin id (#26350)
  • [improve][build] Upgrade Gradle to 9.7.0 (#26332)
  • [improve][build] Upgrade Gradle to 9.7.1 (#26440)
  • [improve][build] Upgrade gRPC to 1.83.1 and Protobuf to 4.35.1 (#26356)
  • [improve][build] Upgrade Gson to 2.14.0 and json-smart to 2.6.0 (#26355)
  • [improve][build] Upgrade Jakarta and servlet APIs within the Jakarta EE 10 level (#26354)
  • [improve][build] Upgrade Jersey to 3.1.12 (#26347)
  • [improve][build] Upgrade lightproto to 0.8.1 (#26445)
  • [improve][build] Upgrade misc tooling, annotation and utility libraries (#26359)
  • [improve][build] Upgrade networking and infrastructure client libraries (#26358)
  • [improve][build] Upgrade OkHttp to 5.5.0 and Okio to 3.18.1 (#26352)
  • [improve][build] Upgrade OpenTelemetry to 1.65.0, instrumentation to 2.30.0, semconv to 1.43.0 (#26334)
  • [improve][build] Upgrade Oxia Java client to 0.9.5 (#26538)
  • [improve][build] Upgrade Shadow plugin to 9.6.1 and merge service descriptor files in shaded jars (#26333)
  • [improve][build] Upgrade slog to 0.10.0 (#26226)
  • [improve][test] Upgrade test libraries (#26351)
  • [improve][misc] Upgrade Conscrypt to 2.6.1 to add aarch64 native support (#26314)
  • [improve][misc] Upgrade Conscrypt to 2.6.2 to restore the native library glibc baseline (#26315)
  • [improve][misc] Upgrade Jetty to 12.1.11 (#26233)
  • [improve][misc] Upgrade Jetty to 12.1.12 (#26302)

Broker

  • [fix][broker] Add missing bundle Prometheus metrics for extensible load manager (#26192)
  • [fix][broker] Avoid attaching a consumer to a migrated non-persistent topic on subscribe (#26075)
  • [fix][broker] Avoid blocking metadata read on the IO thread when redirecting migrated producers/consumers (#26051)
  • [fix][broker] Avoid blocking the bundle-throughput lookup on per-bundle metadata reads (#26054)
  • [fix][broker] Avoid blocking the dispatcher close path on delayed-delivery tracker close (#26053)
  • [fix][broker] Avoid blocking the metrics thread on the pending-ack managed ledger (#26062)
  • [fix][broker] Avoid blocking the PulsarAdmin callback thread on the post-unload load-report write (#26061)
  • [fix][broker] Avoid load shedding and metadata writes from a former leader (#26253)
  • [fix][broker] Bound the topic deletion retries triggered by a replication cluster removal (#26432)
  • [fix][broker] Cancel queued transaction snapshot recovery on topic close (#26335)
  • [fix][broker] Check deliverAt before containsMessage in bucket addMessage (#26230)
  • [fix][broker] Debit un-acked messages only when the consumer is actually removed (#26422)
  • [fix][broker] Do not log an error when the tenant does not exist (#26361)
  • [fix][broker] Don't let a closing topic-policies reader abort a concurrent cache-init reload ([#26132](https://gith...
Read more

v4.2.4

Choose a tag to compare

@lhotari lhotari released this 03 Aug 09:19
v4.2.4

2026-08-03

Library updates

  • [fix][ci] Upgrade sandboxed-trivy-action to approved sha (#26169)
  • [improve][meta] Upgrade Oxia client to 0.9.4 (#26193)
  • [improve][build] Upgrade docker base image Alpine to 3.24 (#26225)
  • [improve][build] Upgrade slog to 0.10.0 (#26226)
  • [improve][misc] Upgrade Jetty to 12.1.11 (#26233)
  • [fix][sec][branch-4.2] Upgrade Hadoop to 3.5.0 (#26194)
  • [fix][sec][branch-4.2] Upgrade Jackson version to 2.18.9 (#26186)
  • [fix][sec][branch-4.2] Upgrade Netty to 4.1.136.Final (#26168)
  • [improve][monitor][branch-4.2] Upgrade OpenTelemetry libraries (#26182)

Broker

  • [fix][broker] Check deliverAt before containsMessage in bucket addMessage (#26230)
  • [fix][broker] Fix getEstimatedSizeSinceMarkDeletePosition throw IllegalArgumentException (#26184)
  • [fix][broker] Fix bucket delayed message index metrics reset on scrape (#26171)
  • [fix][broker] Fix delayed message index data loss when trimming overlapping bucket snapshots (#26240)
  • [fix][broker] Fix incorrect listener URLs returned by ModularLoadManager lookups (#26245)
  • [fix][broker] Fix Key_Shared delivery stall when look-ahead triggers at the end of the topic (#26236)
  • [fix][broker] Fix silently dropped acknowledgement failures in PulsarMetadataEventSynchronizer (#26237)
  • [fix][broker] Fix TableViewLoadDataStoreImpl close deadlock that stalls broker shutdown (#26243)
  • [fix][broker] Prevent completing replicated snapshot before marker publish (#26119)
  • [fix][broker] Prevent partition expansion from inheriting delayed-delivery bucket state (#26179)
  • [fix][broker] Prevent stale read completions from stranding Failover subscriptions (#26174)
  • [fix][broker] Prevent stale service unit callbacks from dropping active lookup and cleanup jobs (#26146)
  • [fix][broker] Prevent stale topic unload cleanup from removing active cache entries (#26145)
  • [fix][broker] Read subscription properties directly from cursor (#26159)
  • [fix][broker] Release entry on GetLastMessageId when parseMessageMetadata throws (#26089)
  • [fix][broker] Trigger max read position callback for messages published during transaction buffer recovery (#26234)
  • [fix][broker][branch-4.2] Fix admin API HTTP 400 FAIL_ON_TRAILING_TOKENS when a broker interceptor is loaded (#26223)
  • [fix][ml] Preserve ledger entries/size when transformLedgerInfo callback completes after a concurrent close (#26228)
  • [fix][meta] Complete handleMetadataEvent future exceptionally when the initial get fails (#26199)
  • [fix][meta] Fix NPE in shouldIgnoreEvent when MetadataEvent options is null (#26200)
  • [fix][meta] Fix RocksdbMetadataStore instanceId not advancing across restarts (#26218)
  • [fix][meta] Record get op stats on the correct completion branch in AbstractMetadataStore (#26201)
  • [improve][broker] Skip system cursor when check inactive cursor. (#26149)
  • [improve][broker] Trace the asynchronous tasks in logs when loading topics (#26163)
  • [improve][offload] Support credentials from offload policies for S3 and Aliyun OSS drivers (#26232)
  • [fix][broker] Fix BucketDelayedDeliveryTracker recovery after LightProto migration (#26160)
  • [fix][broker] Prevent early replay of non-strict delayed messages (#26188)
  • [fix][ml] Preserve ledger properties when closing ledger (#26227)
  • [improve][meta] Support tuning Oxia MetadataStoreConfig through metadata-store URIs (#26150)

Client

  • [fix][client] Fix lookup permit double-release, waiting queue starvation and timeout-response races in ClientCnx (#26143)
  • [fix][client] Fix UnAckedMessageRedeliveryTracker to skip cancelled timeouts (#26043)
  • [fix][client] Fix unAckedMessageTracker cleanup on multi-topics batch ack (#26001)
  • [fix][client] Preserve null values in pulsar-admin schema output (#26196)
  • [fix][client] Sync ackSet in client with broker to stop acked messages reaching the DLQ (#26135)

Pulsar IO and Pulsar Functions

  • [fix][fn] Forward source message properties in Python runtime (#26191)
  • [fix][fn] Return inputSpecs consumerProperties in function GET info (#26217)

Others

  • [fix][metadata] Fix orphaned UR parent nodes not cleaned up with Oxia metadata backend (#26158)
  • [improve][misc][branch-4.2] Add CustomLog config for slog
  • [fix][misc][branch-4.2] Make log4j pattern compatible with slog which got pulled in by Oxia client upgrade

Tests & CI

  • [fix][test] Fix flaky test testCompactionPriority (#26198)
  • [improve][ci] Replace trivy-action with sandboxed-trivy-action (#25480)
  • [fix][test][branch-4.2] Fix ManagedCursorTest compilation (#26221)
  • [fix][ci][branch-4.2] Skip testMarkReplicatedDeletesEmptyParentNodes for Etcd
  • [fix][ci][branch-4.2] Fix OpenTelemetrySanityTest after Otel library upgrade

For the complete list, check the full changelog.

v4.0.13

Choose a tag to compare

@lhotari lhotari released this 03 Aug 09:19
v4.0.13

2026-08-03

Library updates

  • [fix][sec][branch-4.0] Upgrade Hadoop to 3.5.0 (#26195)
  • [fix][sec][branch-4.0] Upgrade Jackson version to 2.18.9 (#26187)
  • [fix][sec][branch-4.0] Upgrade Netty to 4.1.136.Final (#26170)
  • [fix][ci] Upgrade sandboxed-trivy-action to approved sha (#26169)
  • [improve][meta] Upgrade Oxia client to 0.8.0 (#25964)
  • [improve][meta] Upgrade Oxia client to 0.9.4 (#26193)
  • [improve][monitor][branch-4.0] Upgrade OpenTelemetry libraries (#26165)
  • [improve][build] Upgrade docker base image Alpine to 3.24 (#26225)
  • [improve][build] Upgrade slog to 0.10.0 (#26226)
  • [improve][misc] Upgrade Jetty to 12.1.11 (#26233)
  • [improve][misc] Upgrade to Alpine 3.23 (#25180)

Broker

  • [fix][broker] Check deliverAt before containsMessage in bucket addMessage (#26230)
  • [fix][broker] Fix getEstimatedSizeSinceMarkDeletePosition throw IllegalArgumentException (#26184)
  • [fix][broker] Fix bucket delayed message index metrics reset on scrape (#26171)
  • [fix][broker] Fix delayed message index data loss when trimming overlapping bucket snapshots (#26240)
  • [fix][broker] Fix incorrect listener URLs returned by ModularLoadManager lookups (#26245)
  • [fix][broker] Fix Key_Shared delivery stall when look-ahead triggers at the end of the topic (#26236)
  • [fix][broker] Fix silently dropped acknowledgement failures in PulsarMetadataEventSynchronizer (#26237)
  • [fix][broker] Fix TableViewLoadDataStoreImpl close deadlock that stalls broker shutdown (#26243)
  • [fix][broker] Prevent completing replicated snapshot before marker publish (#26119)
  • [fix][broker] Prevent partition expansion from inheriting delayed-delivery bucket state (#26179)
  • [fix][broker] Prevent stale read completions from stranding Failover subscriptions (#26174)
  • [fix][broker] Prevent stale service unit callbacks from dropping active lookup and cleanup jobs (#26146)
  • [fix][broker] Prevent stale topic unload cleanup from removing active cache entries (#26145)
  • [fix][broker] Read subscription properties directly from cursor (#26159)
  • [fix][broker] Release entry on GetLastMessageId when parseMessageMetadata throws (#26089)
  • [fix][broker] Trigger max read position callback for messages published during transaction buffer recovery (#26234)
  • [fix][broker][branch-4.2] Fix admin API HTTP 400 FAIL_ON_TRAILING_TOKENS when a broker interceptor is loaded (#26223)
  • [fix][ml] Preserve ledger entries/size when transformLedgerInfo callback completes after a concurrent close (#26228)
  • [fix][meta] Complete handleMetadataEvent future exceptionally when the initial get fails (#26199)
  • [fix][meta] Fix NPE in shouldIgnoreEvent when MetadataEvent options is null (#26200)
  • [fix][meta] Fix RocksdbMetadataStore instanceId not advancing across restarts (#26218)
  • [fix][meta] Record get op stats on the correct completion branch in AbstractMetadataStore (#26201)
  • [improve][broker] Skip system cursor when check inactive cursor. (#26149)
  • [improve][broker][branch-4.0] Trace the asynchronous tasks in logs when loading topics (#26163) (#26224)
  • [improve][offload] Support credentials from offload policies for S3 and Aliyun OSS drivers (#26232)

Client

  • [fix][client] Fix lookup permit double-release, waiting queue starvation and timeout-response races in ClientCnx (#26143)
  • [fix][client] Fix lookup request semaphore not release problem (#25038)
  • [fix][client] Fix UnAckedMessageRedeliveryTracker to skip cancelled timeouts (#26043)
  • [fix][client] Fix unAckedMessageTracker cleanup on multi-topics batch ack (#26001)
  • [fix][client] Preserve null values in pulsar-admin schema output (#26196)
  • [fix][client] Sync ackSet in client with broker to stop acked messages reaching the DLQ (#26135)

Pulsar IO and Pulsar Functions

  • [fix][fn] Forward source message properties in Python runtime (#26191)
  • [fix][fn] Return inputSpecs consumerProperties in function GET info (#26217)

Others

  • [improve][misc][branch-4.0] Add CustomLog config for slog
  • [fix][metadata] Fix orphaned UR parent nodes not cleaned up with Oxia metadata backend (#26158)
  • [fix][misc][branch-4.0] Make log4j pattern compatible with slog which got pulled in by Oxia client upgrade

Tests & CI

  • [fix][test] Fix flaky test testCompactionPriority (#26198)
  • [improve][ci] Replace trivy-action with sandboxed-trivy-action (#25480)
  • [fix][build][branch-4.0] Fix spotbugs failure in OffloadPoliciesImpl
  • [fix][ci][branch-4.0] Fix OpenTelemetrySanityTest after Otel library upgrade
  • [fix][ci][branch-4.0] Skip testMarkReplicatedDeletesEmptyParentNodes for Etcd

For the complete list, check the full changelog.

v4.2.3

Choose a tag to compare

@lhotari lhotari released this 06 Jul 08:46
v4.2.3

2026-07-06

Backported PIP

  • [feat][pip] PIP-469: Legacy-aware topic policies backend routing and metadata-store topic policies (#25547)

Library updates

  • [fix][sec] Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /pulsar-function-go (#26142)
  • [fix][sec] Upgrade jline to 4.2.1 and picocli to 4.7.7, drop unused jline2 (#26068)
  • [fix][sec] Upgrade pulsar-client-go to v0.20.0 in pulsar-function-go, also address CVEs (#26140)
  • [improve][fn] Upgrade pulsar-client-python to 3.12.0 (#26033)
  • [improve][fn] Upgrade pulsar-client-python to 3.13.0 (#26139)
  • [improve][misc] Upgrade Apache Commons libraries and Apache Http components (#25963)
  • [fix][sec][branch-4.2] Upgrade Jackson version to 2.18.8 (#26099)
  • [improve][meta] Upgrade Oxia client to 0.8.0 (#25964)
  • [fix][build][branch-4.2] Upgrade docker/setup-qemu-action to v4.1.0

Broker

  • [fix][broker] Avoid attaching a consumer to a migrated non-persistent topic on subscribe (#26075)
  • [fix][broker] Avoid blocking metadata read on the IO thread when redirecting migrated producers/consumers (#26051)
  • [fix][broker] Avoid blocking the bundle-throughput lookup on per-bundle metadata reads (#26054)
  • [fix][broker] Avoid blocking the dispatcher close path on delayed-delivery tracker close (#26053)
  • [fix][broker] Don't let a closing topic-policies reader abort a concurrent cache-init reload (#26132)
  • [fix][broker] Don't let a stuck or aborted topic policies cache init make a namespace's topics unloadable (#26025)
  • [fix][broker] Fail fast for load balancer misconfigurations instead of falling back to SimpleLoadManagerImpl (#26031)
  • [fix][broker] Fix compacted read could be stuck forever or message loss due to cursor mark delete (#25998)
  • [fix][broker] Fix forced topic/namespace deletion hanging or failing when compaction is in progress (#26016)
  • [fix][broker] Fix forced topic/namespace deletion still hanging when the compaction reader reconnect stalls (#26026)
  • [fix][broker] Fix geo-replication stuck after a failed publish to the remote cluster (#26002)
  • [fix][broker] Fix replication stall when a cursor rewind skips an in-flight read (#26106)
  • [fix][broker] Fix replicator getting stuck under rate limiter throttling and honor readBatchSize/maxReadSizeBytes on the default read path (#26005)
  • [fix][broker] Fix tableview divergence in ServiceUnitStateTableViewSyncer causing flaky tests (#25946)
  • [fix][broker] Forward topic policy updates after init failures (#26110)
  • [fix][broker] Guard BucketDelayedDeliveryTracker.nextDeliveryTime against empty queues (#26080)
  • [fix][broker] Prevent subscribe rate limit from stalling compaction and blocking forced deletion (#26015)
  • [fix][broker] Prevent topic policy initialization race with a buffering listener wrapper (#26044)
  • [fix][broker] Run the message expiry check off the topic policy update path (#26040)
  • [fix][broker] Run topic policy notifications on the topic-ordered executor (#26042)
  • [fix][broker]Do not trigger topic GC if replication is still active (#25915)
  • [fix][meta] Keep the leader value in the election cycle and make leader reads authoritative (#26000)
  • [fix][meta] Run ledger-underreplication notification callbacks off the metadata-store listener thread (#26065)
  • [improve][broker] Improve dispatch performance by summing entry bytes with a loop (#26055)
  • [improve][broker] Load topic policies on non-persistent topic load and gate the policy replay (#26134)
  • [improve][broker] Trim orphaned bucket snapshots when ledgers are deleted (#25984)
  • [feat][broker] Expose managed ledger properties via topic internal stats (#26079)
  • [feat][broker] PIP-469: Legacy-aware topic policies backend routing and metadata-store topic policies (#25707)
  • [fix][broker] Fix delayed messages stalling with isDelayedDeliveryDeliverAtTimeStrict=true (#26012)
  • [fix][ml] Fix eviction trigger race that cleared the in-progress marker (#25988)
  • [fix][ml] Reset messageMetadataInitialized when recycling RangeCacheEntryWrapper (#25987)

Client

  • [fix][client] Run the failover health probe off the Netty event-loop thread (#26064)
  • [fix][client] Prevent client shutdown from leaking event loop threads when DNS resolver close fails (#26045)

Pulsar IO and Pulsar Functions

  • [fix][fn] Make exclusiveLeaderProducer volatile in FunctionMetaDataManager (#26046)
  • [fix][fn] Reorder Function Worker shutdown to stop scheduler before runtime manager (#26136)

Others

  • [fix][proxy] Avoid blocking the proxy IO thread on a cold broker cache (#26052)
  • [fix] functions: Run worker leader-election off the consumer event-listener thread (#26059)

Tests & CI

  • [fix][test] Deflake TopicPoliciesTest.setupTestTopic by retrying forced namespace deletion (#25974)
  • [fix][test] Fix flaky AuditorBookieTest.testBookieClusterRestart (#26122)
  • [fix][test] Fix flaky ExtensibleLoadManagerImplTest by re-serving the channel topic in initializeState (#25976)
  • [fix][test] Fix flaky ExtensibleLoadManagerImplTest.initializeState by recovering wedged channel ownership (#25977)
  • [fix][test] Fix flaky PersistentTopicsTest setup caused by concurrent Mockito stubbing (#26083)
  • [fix][test] Fix flaky SchemaServiceTest.testSchemaRegistryMetrics (#25645)
  • [fix][test] Fix flaky testPrepareInitPoliciesCacheAsyncThrowExceptionAfterCreateReader (#26049)
  • [fix][test] Make SameAuthParamsLookupAutoClusterFailoverTest less timing-sensitive (#25675)
  • [fix][test] Run makeReadEntryProbFail's errorOrNot on a caller-provided executor (#26123)
  • [improve][test]Add test: test/testTopicPartitionCannotBeCreatedAfterTopicDeleted (#26038)
  • [fix][test][branch-4.2] Adapt ConfigurationDataUtilsTest to Jackson 2.18.8 InetSocketAddress deserialization

For the complete list, check the full changelog.

v4.0.12

Choose a tag to compare

@lhotari lhotari released this 06 Jul 08:46
v4.0.12

2026-07-06

Backported PIP

  • [feat][pip] PIP-469: Legacy-aware topic policies backend routing and metadata-store topic policies (#25547)

Library updates

  • [fix][sec] Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /pulsar-function-go (#26142)
  • [fix][sec] Upgrade jline to 4.2.1 and picocli to 4.7.7, drop unused jline2 (#26068)
  • [fix][sec] Upgrade pulsar-client-go to v0.20.0 in pulsar-function-go, also address CVEs (#26140)
  • [fix][sec][branch-4.0] Upgrade Jackson version to 2.18.8 (#26098)
  • [improve][fn] Upgrade pulsar-client-python to 3.12.0 (#26033)
  • [improve][fn] Upgrade pulsar-client-python to 3.13.0 (#26139)
  • [improve][misc] Upgrade Apache Commons libraries and Apache Http components (#25963)
  • [fix][build][branch-4.0] Upgrade docker/setup-qemu-action to v4.1.0

Broker

  • [fix][broker] Avoid attaching a consumer to a migrated non-persistent topic on subscribe (#26075)
  • [fix][broker] Avoid blocking metadata read on the IO thread when redirecting migrated producers/consumers (#26051)
  • [fix][broker] Avoid blocking the bundle-throughput lookup on per-bundle metadata reads (#26054)
  • [fix][broker] Avoid blocking the dispatcher close path on delayed-delivery tracker close (#26053)
  • [fix][broker] Don't let a closing topic-policies reader abort a concurrent cache-init reload (#26132)
  • [fix][broker] Don't let a stuck or aborted topic policies cache init make a namespace's topics unloadable (#26025)
  • [fix][broker] Fail fast for load balancer misconfigurations instead of falling back to SimpleLoadManagerImpl (#26031)
  • [fix][broker] Fix compacted read could be stuck forever or message loss due to cursor mark delete (#25998)
  • [fix][broker] Fix forced topic/namespace deletion hanging or failing when compaction is in progress (#26016)
  • [fix][broker] Fix forced topic/namespace deletion still hanging when the compaction reader reconnect stalls (#26026)
  • [fix][broker] Fix geo-replication stuck after a failed publish to the remote cluster (#26002)
  • [fix][broker] Fix replication stall when a cursor rewind skips an in-flight read (#26106)
  • [fix][broker] Fix replicator getting stuck under rate limiter throttling and honor readBatchSize/maxReadSizeBytes on the default read path (#26005)
  • [fix][broker] Fix tableview divergence in ServiceUnitStateTableViewSyncer causing flaky tests (#25946)
  • [fix][broker] Forward topic policy updates after init failures (#26110)
  • [fix][broker] Guard BucketDelayedDeliveryTracker.nextDeliveryTime against empty queues (#26080)
  • [fix][broker] Prevent subscribe rate limit from stalling compaction and blocking forced deletion (#26015)
  • [fix][broker] Prevent topic policy initialization race with a buffering listener wrapper (#26044)
  • [fix][broker] Run the message expiry check off the topic policy update path (#26040)
  • [fix][broker] Run topic policy notifications on the topic-ordered executor (#26042)
  • [fix][broker]Do not trigger topic GC if replication is still active (#25915)
  • [fix][meta] Keep the leader value in the election cycle and make leader reads authoritative (#26000)
  • [fix][meta] Run ledger-underreplication notification callbacks off the metadata-store listener thread (#26065)
  • [improve][broker] Improve dispatch performance by summing entry bytes with a loop (#26055)
  • [improve][broker] Load topic policies on non-persistent topic load and gate the policy replay (#26134)
  • [improve][broker] Trim orphaned bucket snapshots when ledgers are deleted (#25984)
  • [fix][broker][branch-4.0] Fix NOT_FOUND for topic policy operations on idle non-persistent topics
  • [feat][broker] Expose managed ledger properties via topic internal stats (#26079)
  • [feat][broker] PIP-469: Legacy-aware topic policies backend routing and metadata-store topic policies (#25707)

Client

  • [fix][client] Run the failover health probe off the Netty event-loop thread (#26064)

Pulsar IO and Pulsar Functions

  • [fix][fn] Make exclusiveLeaderProducer volatile in FunctionMetaDataManager (#26046)
  • [fix][fn] Reorder Function Worker shutdown to stop scheduler before runtime manager (#26136)

Others

  • [fix][proxy] Avoid blocking the proxy IO thread on a cold broker cache (#26052)
  • [fix] functions: Run worker leader-election off the consumer event-listener thread (#26059)

Tests & CI

  • [fix][test] Deflake TopicPoliciesTest.setupTestTopic by retrying forced namespace deletion (#25974)
  • [fix][test] Fix flaky AuditorBookieTest.testBookieClusterRestart (#26122)
  • [fix][test] Fix flaky ExtensibleLoadManagerImplTest by re-serving the channel topic in initializeState (#25976)
  • [fix][test] Fix flaky ExtensibleLoadManagerImplTest.initializeState by recovering wedged channel ownership (#25977)
  • [fix][test] Fix flaky PersistentTopicsTest setup caused by concurrent Mockito stubbing (#26083)
  • [fix][test] Fix flaky SchemaServiceTest.testSchemaRegistryMetrics (#25645)
  • [fix][test] Fix flaky testPrepareInitPoliciesCacheAsyncThrowExceptionAfterCreateReader (#26049)
  • [fix][test] Make SameAuthParamsLookupAutoClusterFailoverTest less timing-sensitive (#25675)
  • [fix][test] Run makeReadEntryProbFail's errorOrNot on a caller-provided executor (#26123)
  • [improve][test]Add test: test/testTopicPartitionCannotBeCreatedAfterTopicDeleted (#26038)
  • [fix][test][branch-4.0] Adapt ConfigurationDataUtilsTest to Jackson 2.18.8 InetSocketAddress deserialization
  • [fix][test][branch-4.0] Backport configurable read/add delays in PulsarMockBookKeeper

For the complete list, check the full changelog.

v5.0.0-M1

v5.0.0-M1 Pre-release
Pre-release

Choose a tag to compare

@lhotari lhotari released this 23 Jun 14:11
v5.0.0-M1

2026-06-23

Apache Pulsar 5.0.0-M1 is the first milestone release on the road to Apache Pulsar 5.0.0, with general availability expected later in 2026. It is a preview: an early build that puts the major new features of 5.0 in your hands so you can try them against real workloads and send feedback ahead of the GA release. It is not meant for production. Two changes stand out — Scalable Topics, a new topic type that grows and shrinks on its own, and the promotion of Oxia to Pulsar's recommended metadata store — alongside a migration of the build system to Gradle, the split of the IO connectors into a separate repository, and structured logging.

For a full walkthrough, see the announcement: Apache Pulsar 5.0.0-M1: A Preview of the Next Major Release.

Highlights

Scalable Topics (Topics v5). A new topic type that replaces fixed partitions with range-based segments, so a topic can scale up and down by transparently splitting and merging segments while preserving per-key ordering. This avoids the ordering breakage and operational drift that come from changing the partition count of a regular partitioned topic. The work spans the broker-side controller (PIP-468), metadata-driven transactions (PIP-473), regular-to-scalable topic migration (PIP-475), and automatic split/merge (PIP-483). See PIP-460.

New V5 Java client API. A clean-slate, purpose-built client API for scalable topics, shipped as a new, additive pulsar-client-v5 module — the existing pulsar-client and pulsar-client-api modules are unchanged, so current applications keep working. It replaces the classic Consumer/Reader and the four subscription types with three purpose-built consumers: QueueConsumer (parallel, individually-acknowledged work-queue consumption with dead-letter support), StreamConsumer (ordered, cumulative acks), and CheckpointConsumer (for stream processors such as Flink and Spark that track their own position). The V5 client also works against existing partitioned and non-partitioned topics, and a consumer can subscribe to an entire namespace. In M1 it ships for Java; other language SDKs will follow before GA. See PIP-466.

Oxia is now the recommended metadata store. Oxia becomes the recommended metadata store for new Pulsar clusters in 5.0 and is the backend of choice for scalable topics, whose lookups build on its streaming watch sessions. ZooKeeper remains fully supported, and PIP-454 adds a live, zero-downtime migration framework that moves an existing cluster from ZooKeeper to Oxia while the data plane keeps publishing and consuming.

Build system migrated from Maven to Gradle. Builds now use ./gradlew instead of mvn, with task-level caching and parallelism that substantially reduce local and CI build times, and a central version catalog (gradle/libs.versions.toml) for dependency management. The migration is transparent to users consuming the published Maven artifacts, Docker images, and shaded client JARs. See PIP-463.

IO connectors split into a separate repository. The built-in Pulsar IO connectors have been moved out of the core repository so they can follow their own release cadence. See PIP-465.

Structured logging. Pulsar now emits structured logs through slog across the broker, client, managed-ledger, functions, and metadata modules, with flat JSON / OpenTelemetry log output and a PULSAR_LOG_FORMAT environment variable to switch formats easily. See PIP-467.

API and platform modernization. Pulsar migrated from javax.* to jakarta.* APIs (PIP-472), made Protobuf v4 the default, migrated REST API annotations from Swagger to OpenAPI 3, and now supports building and running on Java 25. Topic policies gained a legacy-aware, metadata-store-backed routing backend (PIP-469).

Security and dependency updates. This release bundles a large set of dependency upgrades that address numerous CVEs across Netty, Jetty, log4j, BouncyCastle, Thrift, vert.x, and async-http-client, and upgrades BookKeeper to 4.18.0. See Library updates below.

Important notice

5.0.0-M1 is a major release that removes deprecated functionality and changes some APIs. Review the following before upgrading:

  • javax.* → jakarta.* migration (PIP-472). Custom broker plugins, interceptors, authentication/authorization providers, or other extensions that reference javax.* packages (for example javax.ws.rs or javax.servlet) must be updated to the corresponding jakarta.* packages and recompiled.
  • Etcd metadata store backend removed (PIP-462). Deployments using Etcd as the metadata store must migrate to ZooKeeper or Oxia before upgrading.
  • IO connectors moved to a separate repository (PIP-465). Connectors are no longer released from the core Pulsar repository; obtain them from the dedicated connectors project.
  • Build system is now Gradle (PIP-463). If you build Pulsar from source, use ./gradlew instead of mvn. Published artifacts are unchanged.
  • fastutil dependency removed (#25413).

Approved PIPs

Library updates

Read more

v4.2.2

Choose a tag to compare

@lhotari lhotari released this 08 Jun 18:16
v4.2.2

2026-06-08

Library updates

  • [fix][sec] Bump org.asynchttpclient:async-http-client from 2.14.5 to 2.15.0 (#25818)
  • [fix][sec] Upgrade commons-configuration2 to 2.15.0 to address CVE-2026-45205 (#25844)
  • [fix][sec] Upgrade Netty to 4.1.133.Final to address CVEs (#25670)
  • [improve][misc] Upgrade Netty to 4.1.134 (#25870)
  • [fix][sec] Upgrade Netty to 4.1.135.Final to address several CVEs (#25918)
  • [fix][sec] Upgrade thrift to 0.23.0 to address CVE-2026-43869 (#25744)
  • [fix][sec] Upgrade vert.x to 4.5.25 to address CVE-2026-6860 (#25737)
  • [fix][sec] Upgrade vertx to 4.5.27 to address CVE-2026-6860 (#25745)
  • [improve][misc] Upgrade vert.x to 4.5.28 (#25924)
  • [improve][build] Remove kotlin-stdlib override; upgrade okhttp3 5.3.2 and okio 3.17.0 (#25855)
  • [improve][build] Upgrade org.apache.kerby:kerb-simplekdc from 1.1.1 to 2.1.1 (#25785)
  • [improve][misc] Upgrade Jetty to 12.1.9 (#25752)
  • [improve][misc] Upgrade Jetty to 12.1.10 (#25943)
  • [improve][misc] Upgrade Caffeine to 3.2.4 (#25663)

Broker

  • [fix][broker] Clean up orphan ledger on concurrent initial schema creation in BookkeeperSchemaStorage (#25514)
  • [fix][broker] Close pending acks cleanup gap in BacklogQuotaManager (#25624)
  • [fix][broker] ConcurrentLongHashMap throw ArrayIndexOutOfBoundsException (#25644)
  • [fix][broker] Correct two race conditions in the tracker code and logic bug in InMemoryDelayedDeliveryTracker that failed with NoSuchElementException (#25681)
  • [fix][broker] Decrement unacked counter when removeAllUpTo removes pending acks (#25581)
  • [fix][broker] Fix compaction cursor reset may lose mark-delete properties (#25862)
  • [fix][broker] Fix ManagedLedgerImpl.advanceCursorsIfNecessary() method may lose non-durable cursor properties in race condition (#25796)
  • [fix][broker] Fix non-batched null-value messages not removed during topic compaction (#25817)
  • [fix][broker] Fix PersistentMessageExpiryMonitor findEntryComplete() method may lose mark-delete properties in race condition (#25803)
  • [fix][broker] Fix precision loss in DataSketchesSummaryLogger by replacing LongAdder with DoubleAdder for sum accumulation (#25594)
  • [fix][broker] Fix PulsarService.closeAsync where Condition.signalAll was called without holding a lock (#25777)
  • [fix][broker] Fix race in pending acks removal in redeliverUnacknowledgedMessages (#25589)
  • [fix][broker] Fix stuck chunks in SharedConsumerAssignor permit tracking (#25620)
  • [fix][broker] Merge broker offload extra configurations (#25736)
  • [fix][broker] Move pending acks cleanup to selected mark-delete callbacks (#25592)
  • [fix][broker] Race condition causes perpetual backlog on internal topics (#25572)
  • [fix][broker] Skip backlog-quota eviction on fenced/closing topics (#25684)
  • [fix][broker] Use effective offload policies for extra configs (#25781)
  • [fix][broker] Wait for orphan schema ledger cleanup before retry (#25579)
  • [fix][broker][fix][broker]Replication stats is empty when the cluster is the target cluster of a one-way replication (#25583)
  • [fix][broker]Replication is stuck because failed to read entries (#25625)
  • [fix][bk] Fix NPE in IsolatedBookieEnsemblePlacementPolicy when policy class does not match (#25825)
  • [fix][meta] Fix PulsarZooKeeperClient async addWatch callback retry behavior (#25913)
  • [fix][meta] Fix ZooKeeper session reconnect race condition in PulsarZooKeeperClient.clientCreator (#25910)
  • [improve][broker] optimize namespaceBundle validation to fix single-thread 100% CPU during unloading entire namespaces (#25626)
  • [improve][broker] Prevent stale replicator pending reads after termination (#25767)
  • [improve][offload] Coalesce automatic offload triggers to reduce retry loops and ledger scans (#25793)
  • [fix][broker][branch-4.2] URL-encode sub-name in Txn pending-ack topic #25727 (#25728)

Client

  • [fix][client] Apply Avro logical type conversions when decoding schema without classloader (#25759)
  • [fix][client] Clean up unacked messages when unsubscribing a topic with ack timeout backoff (#25916)
  • [fix][client] Fix failed to close consumer because of the error: param memorySize is a negative value (#25805)
  • [fix][client] Make ClientBuilder serializable (#25730) (#25739)
  • [fix][client] Match logical topic when removing unacked messages (#25921)
  • [fix][client] Preserve equals in FieldParser map values (#25907)
  • [fix][client] Prevent duplicate ServiceUrlProvider initialization (#25899)
  • [fix][client] Reset higher-index states on recovery in SameAuthParamsLookupAutoClusterFailover (#25826)
  • [fix][client] Stabilize scaleReceiverQueueHint against concurrent enqueue/take (#25578)
  • [fix][client]Broker-side producer handle leak if closes a producer which state is regitering schema (#25725)
  • [improve][client] Best-effort retry for individual/batch-index acks on send failure when ackReceiptEnabled=false (#25525)
  • [improve][client] Clean up unacked message tracker when topics are removed in multi-topic consumers (#25923)
  • [improve][client] Implement tls_client_auth for AuthenticationOAuth2 (#25538)
  • [improve][client] In cases where there is a risk of message loss, adjust the log level to error (#25854)

Pulsar IO and Pulsar Functions

  • [fix][fn] Fix functions update issue where artifact is provided as a http url (#25840)
  • [fix][fn] Fix Go function runtime to continue after user exceptions and add neg-ack tests (#25867)
  • [fix][fn] Fix orphan exclusive producer on creation timeout in WorkerUtils.createExclusiveProducerWithRetry (#25942)
  • [improve][fn] Avoid gRPC timeout when getting status of a dead process runtime (#25819)
  • [improve][fn] make built-in connector reload incremental (#25773)
  • [improve][fn] make built-in functions reload incremental (#25868)
  • [refactor][fn] Use Map instead of TreeMap for connector/function API types (#25790)
  • [improve][functions] Allow customizing Kubernetes service domain suffix in Function Worker (#25872)

Others

  • [fix][proxy] Avoid intermittent 502 when admin proxy follows a broker redirect for a request with a body (#25919)
  • [fix][proxy] Close channel on connection failure (#25770)
  • [improve][cli] Add client side looping in "pulsar-admin topics analyze-backlog" cli to avoid potential HTTP call timeout (#25126)

Tests & CI

  • [fix][test] Add timeout to initial receives in ResendRequestTest.testSharedSingleAckedPartitionedTopic (#25828)
  • [fix][test] Fix flaky ExtensibleLoadManagerImplTest.testLoadBalancerServiceUnitTableViewSyncer (#25596)
  • [fix][test] Fix flaky OneWayReplicatorDeduplicationTest.testDeduplication ([#25679]...
Read more