Skip to content

Bump org.apache.pulsar:pulsar-client-all from 4.2.4 to 4.2.5 - #1558

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/main/org.apache.pulsar-pulsar-client-all-4.2.5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/main/org.apache.pulsar-pulsar-client-all-4.2.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps org.apache.pulsar:pulsar-client-all from 4.2.4 to 4.2.5.

Release notes

Sourced from org.apache.pulsar:pulsar-client-all's releases.

v4.2.5

2026-08-03

Library updates

  • [improve][broker][branch-4.2] Upgrade bookkeeper to 4.17.4 (#26219)
  • [fix][sec] Bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /pulsar-function-go/examples (#26231)
  • [fix][sec] Bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /pulsar-function-go (#26446)
  • [fix][sec] Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in /pulsar-function-go (#26541)
  • [fix][sec] Bump log4j2 from 2.26.0 to 2.26.1 (#26329)
  • [fix][sec] Upgrade at.yawk.lz4:lz4-java to 1.11.4 (#26758)
  • [fix][sec] Upgrade avro to 1.12.2 (#24992)
  • [fix][sec] Upgrade grpc in pulsar-function-go to 1.82.1 to fix GHSA-hrxh-6v49-42gf (#26235)
  • [fix][sec] Upgrade Jackson to 2.18.10 (#26339)
  • [fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 (#26250)
  • [fix][sec][branch-4.2] Upgrade BouncyCastle to 1.85 and BouncyCastle FIPS to 2.0.2 to address CVEs (#26370)
  • [fix][sec][branch-4.2] Upgrade Netty to 4.1.137 to address several CVEs and bugs (#26301)
  • [fix][sec][branch-4.2] Upgrade Spring to 7.0.8 (#26270)
  • [fix][sec][branch-4.x] Upgrade async-http-client to 2.16.1 (#26436)
  • [fix][sec][branch-4.x] Upgrade lz4-java to 1.11.2 (#26439)
  • [fix][sec][branch-4.x] Upgrade Netty to 4.1.138 to address several CVEs and bugs (#26515)
  • [fix][sec][branch-4.x] Upgrade Thrift to 0.24.0 (#26438)
  • [fix][sec][branch-4.x] Upgrade vertx to 4.5.32 (#26437)
  • [fix][build] Upgrade Conscrypt to 2.6.3 (#26660)
  • [improve][zk] Upgrade ZooKeeper to 3.9.6 (#26750)
  • [improve][build] Upgrade Apache Commons libraries (#26348)
  • [improve][build] Upgrade Bouncy Castle libraries (#26753)
  • [improve][build] Upgrade Caffeine to 3.3.0 (#26755)
  • [improve][build] Upgrade Guava to 33.7.1-jre (#26760)
  • [improve][build] Upgrade Oxia Java client to 0.9.5 (#26538)
  • [improve][misc] Upgrade Conscrypt to 2.6.1 to add aarch64 native support (#26314)
  • [improve][misc] Upgrade Conscrypt to 2.6.2 to restore the native library glibc baseline (#26315)
  • [improve][misc] Upgrade Jetty to 12.1.12 (#26302)
  • [improve][misc] Upgrade Jetty to 12.1.13 (#26738)
  • [improve][misc] Upgrade log4j to 2.26.0 and slf4j to 2.0.18 (#25973)
  • [improve][misc][branch-4.x] Upgrade Jackson to 2.18.11 (#26759)
  • [fix][test][branch-4.2] Fix connector tests broken by the Avro 1.12.2 upgrade

Broker

  • [fix][broker] Add missing bundle Prometheus metrics for extensible load manager (#26192)
  • [fix][broker] Align entry filter policy checks for non-persistent topics (#26774)
  • [fix][broker] Align partitioned topic truncate checks with non-partitioned topics (#26776)
  • [fix][broker] Apply managedLedgerContinueCachingAddedEntriesAfterLastActiveCursorLeavesMillis to managed ledgers (#26785)
  • [fix][broker] Apply subscription policies to namespace and topic subscription operations (#26767)
  • [fix][broker] Apply the role logging anonymizer to topic authorization denial logs (#26642)
  • [fix][broker] Avoid load shedding and metadata writes from a former leader (#26253)
  • [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#26633)
  • [fix][broker] Bound classic Key_Shared dispatcher replay queue look-ahead (#26677)
  • [fix][broker] Bound the local partition metadata retry when starting a geo-replicator (#26681)

... (truncated)

Commits
  • a639bf5 Release 4.2.5
  • aac54fe [fix][ci][branch-4.2] Use an ASF-approved docker/setup-qemu-action version
  • b815b90 [improve][build] Upgrade Bouncy Castle libraries (#26753)
  • d8d5f8c [feat][broker] PIP-441:Add broker-level metrics for non-recoverable data skip...
  • 8b6f937 [fix][Client] permit leak in chunked message discard path (#26661)
  • 4346fdb [fix][broker] Avoid misleading ownership lock expiry logs during shutdown (#2...
  • 2028fe0 [fix][broker] Fix lookup permit leak when namespace policy reads fail (#26606)
  • fb28010 [fix][broker] Preserve replicated subscription activity on activation (#26780)
  • 0f05f89 [fix][broker] Apply managedLedgerContinueCachingAddedEntriesAfterLastActiveCu...
  • 0645956 [improve][broker] Allow dynamically updating topic load timeout (#26781)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.pulsar:pulsar-client-all](https://github.com/apache/pulsar) from 4.2.4 to 4.2.5.
- [Release notes](https://github.com/apache/pulsar/releases)
- [Commits](apache/pulsar@v4.2.4...v4.2.5)

---
updated-dependencies:
- dependency-name: org.apache.pulsar:pulsar-client-all
  dependency-version: 4.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the type: dependency-upgrade A dependency upgrade2 label Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: dependency-upgrade A dependency upgrade2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants