Skip to content

Bump org.apache.pulsar:pulsar-client-all from 4.2.2 to 4.2.4 - #1536

Merged
sobychacko merged 1 commit into
mainfrom
dependabot/gradle/main/org.apache.pulsar-pulsar-client-all-4.2.4
Aug 4, 2026
Merged

sobychacko merged 1 commit into
mainfrom
dependabot/gradle/main/org.apache.pulsar-pulsar-client-all-4.2.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps org.apache.pulsar:pulsar-client-all from 4.2.2 to 4.2.4.

Release notes

Sourced from org.apache.pulsar:pulsar-client-all's releases.

v4.2.4

2026-08-03

Library updates

  • [fix][ci] Upgrade sandboxed-trivy-action to approved sha (#26169)
  • [improve][meta] Upgrade Oxia client to 0.9.4 (#26193)
  • [improve][build] Upgrade docker base image Alpine to 3.24 (#26225)
  • [improve][build] Upgrade slog to 0.10.0 (#26226)
  • [improve][misc] Upgrade Jetty to 12.1.11 (#26233)
  • [fix][sec][branch-4.2] Upgrade Hadoop to 3.5.0 (#26194)
  • [fix][sec][branch-4.2] Upgrade Jackson version to 2.18.9 (#26186)
  • [fix][sec][branch-4.2] Upgrade Netty to 4.1.136.Final (#26168)
  • [improve][monitor][branch-4.2] Upgrade OpenTelemetry libraries (#26182)

Broker

  • [fix][broker] Check deliverAt before containsMessage in bucket addMessage (#26230)
  • [fix][broker] Fix getEstimatedSizeSinceMarkDeletePosition throw IllegalArgumentException (#26184)
  • [fix][broker] Fix bucket delayed message index metrics reset on scrape (#26171)
  • [fix][broker] Fix delayed message index data loss when trimming overlapping bucket snapshots (#26240)
  • [fix][broker] Fix incorrect listener URLs returned by ModularLoadManager lookups (#26245)
  • [fix][broker] Fix Key_Shared delivery stall when look-ahead triggers at the end of the topic (#26236)
  • [fix][broker] Fix silently dropped acknowledgement failures in PulsarMetadataEventSynchronizer (#26237)
  • [fix][broker] Fix TableViewLoadDataStoreImpl close deadlock that stalls broker shutdown (#26243)
  • [fix][broker] Prevent completing replicated snapshot before marker publish (#26119)
  • [fix][broker] Prevent partition expansion from inheriting delayed-delivery bucket state (#26179)
  • [fix][broker] Prevent stale read completions from stranding Failover subscriptions (#26174)
  • [fix][broker] Prevent stale service unit callbacks from dropping active lookup and cleanup jobs (#26146)
  • [fix][broker] Prevent stale topic unload cleanup from removing active cache entries (#26145)
  • [fix][broker] Read subscription properties directly from cursor (#26159)
  • [fix][broker] Release entry on GetLastMessageId when parseMessageMetadata throws (#26089)
  • [fix][broker] Trigger max read position callback for messages published during transaction buffer recovery (#26234)
  • [fix][broker][branch-4.2] Fix admin API HTTP 400 FAIL_ON_TRAILING_TOKENS when a broker interceptor is loaded (#26223)
  • [fix][ml] Preserve ledger entries/size when transformLedgerInfo callback completes after a concurrent close (#26228)
  • [fix][meta] Complete handleMetadataEvent future exceptionally when the initial get fails (#26199)
  • [fix][meta] Fix NPE in shouldIgnoreEvent when MetadataEvent options is null (#26200)
  • [fix][meta] Fix RocksdbMetadataStore instanceId not advancing across restarts (#26218)
  • [fix][meta] Record get op stats on the correct completion branch in AbstractMetadataStore (#26201)
  • [improve][broker] Skip system cursor when check inactive cursor. (#26149)
  • [improve][broker] Trace the asynchronous tasks in logs when loading topics (#26163)
  • [improve][offload] Support credentials from offload policies for S3 and Aliyun OSS drivers (#26232)
  • [fix][broker] Fix BucketDelayedDeliveryTracker recovery after LightProto migration (#26160)
  • [fix][broker] Prevent early replay of non-strict delayed messages (#26188)
  • [fix][ml] Preserve ledger properties when closing ledger (#26227)
  • [improve][meta] Support tuning Oxia MetadataStoreConfig through metadata-store URIs (#26150)

Client

  • [fix][client] Fix lookup permit double-release, waiting queue starvation and timeout-response races in ClientCnx (#26143)

... (truncated)

Commits
  • 534a635 Release 4.2.4
  • 3ad321c [fix][broker] Release entry on GetLastMessageId when parseMessageMetadata thr...
  • 338b922 [fix][broker] Prevent stale service unit callbacks from dropping active looku...
  • bc69930 [fix][broker] Fix TableViewLoadDataStoreImpl close deadlock that stalls broke...
  • 5d030f8 [fix][client] Fix unAckedMessageTracker cleanup on multi-topics batch ack (#2...
  • 58a059f [fix][fn] Forward source message properties in Python runtime (#26191)
  • 5d83ace [fix][broker] Fix silently dropped acknowledgement failures in PulsarMetadata...
  • 98f8b8c [fix][broker] Fix delayed message index data loss when trimming overlapping b...
  • 5993b6f [fix][broker] Fix incorrect listener URLs returned by ModularLoadManager look...
  • 14afc4d [fix][broker] Prevent completing replicated snapshot before marker publish (#...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.pulsar:pulsar-client-all](https://github.com/apache/pulsar) from 4.2.2 to 4.2.4.
- [Release notes](https://github.com/apache/pulsar/releases)
- [Commits](apache/pulsar@v4.2.2...v4.2.4)

---
updated-dependencies:
- dependency-name: org.apache.pulsar:pulsar-client-all
  dependency-version: 4.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the type: dependency-upgrade A dependency upgrade2 label Aug 3, 2026
@sobychacko
sobychacko merged commit 5167463 into main Aug 4, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/gradle/main/org.apache.pulsar-pulsar-client-all-4.2.4 branch August 4, 2026 15:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: dependency-upgrade A dependency upgrade2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant