Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 23, 2025

Bumps github.com/nats-io/nats-server/v2 from 2.11.3 to 2.11.4.

Release notes

Sourced from github.com/nats-io/nats-server/v2's releases.

Release v2.11.4

Changelog

Refer to the 2.11 Upgrade Guide for backwards compatibility notes with 2.10.x.

Go Version

Dependencies

  • github.com/nats-io/nats.go v1.42.0 (#6868)
  • golang.org/x/crypto v0.38.0 (#6868)
  • golang.org/x/sys v0.33.0 (#6868)
  • github.com/google/go-tpm v0.9.5 (#6918)

Improved

General

  • Log lines for TLS handshake errors now include the subject and SHA-256 hash of the certificate if known (#6883)

JetStream

  • Enforcing per-subject limits on streams after a state rebuild or retention policy change is now considerably faster (#6871)
  • Reduced allocations when finding the next message matching a filter in the filestore, which also improves the performance of calculating interest state on streams with an interest/WQ retention policy (#6908)

Fixed

General

  • Reloading the gateway TLS configuration now applies to implicit remotes (#6886)

JetStream

  • Stream and consumer updates are no longer possible if all peers are offline, fixing a potential avenue for data loss (#6856)
  • The stream first sequence is now adjusted correctly when purging over interior delete gaps (#6861)
  • Consumer redeliveries are no longer incorrectly reported for consumers with a max deliver of 1 (#6877)
  • Avoid resetting the first and last sequences of a workqueue stream to zero after a crash with unflushed data (#6882)
  • Access time goroutines are now reference-counted and no longer leak (#6887)
  • Fixed a deadlock that could occur when using multi_last direct gets or when calculating the first sequence number for a consumer with a deliver-last-per-subject deliver policy (#6899)
  • A spelling error in a store error was fixed (#6895) Thanks to @​cjohansen for the contribution!
  • A rare panic in the filestore has been fixed (#6912)
  • Direct gets will no longer return messages incorrectly with up_to_time or start_time in some configurations (#6911)
  • Fixed a panic in the stree that could occur when removing subject state tracking for a short subject (#6914)

Complete Changes

nats-io/nats-server@v2.11.3...v2.11.4

... (truncated)

Commits
  • 4c2fc7f Release v2.11.4
  • 5e4e7cc Cherry-picks for 2.11.4 (#6918)
  • 5d5346a Update dependencies
  • be14545 Fix a bug that could cause a panic if subject to delete was shorter then inde...
  • 9fd1d13 Fixed spelling.
  • fb6de55 Release v2.11.4-RC.3
  • e375872 Cherry-picks for 2.11.4-RC.3 (#6913)
  • f941c3b Fix StartTime bug with memory store and only one message
  • 16645b6 Fix MultiLastFor underflow bug with UpToTime before first sequence
  • ff9445e Fix possible panic on filestore.go
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) from 2.11.3 to 2.11.4.
- [Release notes](https://github.com/nats-io/nats-server/releases)
- [Changelog](https://github.com/nats-io/nats-server/blob/main/.goreleaser.yml)
- [Commits](nats-io/nats-server@v2.11.3...v2.11.4)

---
updated-dependencies:
- dependency-name: github.com/nats-io/nats-server/v2
  dependency-version: 2.11.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels May 23, 2025
@github-actions github-actions bot added the next label May 23, 2025
@retr0h retr0h merged commit a0479da into main Jun 3, 2025
6 checks passed
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/nats-io/nats-server/v2-2.11.4 branch June 3, 2025 16:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code next

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants