Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 28, 2025

Bumps github.com/nats-io/nats-server/v2 from 2.11.1 to 2.11.2.

Release notes

Sourced from github.com/nats-io/nats-server/v2's releases.

Release v2.11.2

Changelog

Refer to the 2.11 Upgrade Guide for backwards compatibility notes with 2.10.x.

Go Version

  • 1.24.2

Dependencies

  • github.com/nats-io/nats.go v1.41.2 (#6805)
  • github.com/nats-io/nkeys v0.4.11 (#6805)
  • github.com/nats-io/jwt/v2 v2.7.4 (#6813)

Added

General

  • Support for a default sentinel JWT, which is used in operator mode when none is specified, has been added making it possible to have default users (#6577)
  • New trace_headers option to ensure that trace logging only emits headers and not message payloads (#6638)

JetStream

  • Subject delete markers are now placed for messages that have aged out due to their TTL and not just because of the MaxAge policy (#6741)

Improved

General

  • The publish permissions cache should now remain under the max allowed size more aggressively with improved pruning (#6674)
  • It is now possible with service imports to import the same subject from multiple different accounts (#6704)
  • Updating an account claim with a reduced max connection count no longer causes internal clients to be closed, fixing cases where JetStream assets could become unavailable (#6785)
  • GOMAXPROCS and GOMEMLIMIT are now reported in both statsz and varz (#6791)
  • Improved tls_timeout configuration parsing consistency between authorization and timeout (#6731)
  • Allow servers with different pool sizes when using multiple routes, simplifying configuration changes and rolling updates (#6676)
  • Auth tokens are now redacted in trace-level logs for enhanced security (#6808)
  • Trapped signals are now logged at notice level instead of debug (#6800)

JetStream

  • Improved purge performance, particularly for KV PurgeDeletes calls, with optimised code paths for finding last sequences and reducing allocations (#6801, #6825)
  • Improved replicated asset creation performance by campaigning for group leadership more quickly (#6697)
  • Improved the debug log message when resetting a group WAL after failing to truncate (#6705)
  • Improved checking for streams that overlap with JS API or system subjects, so that badly-configured streams should not be able to break the API (#6786)
  • Allow setting per-message TTLs to values lower than the configured SubjectDeleteMarkerTTL when the stream has a max messages per subject limit of 1 (#6818)
  • Servers that have been peer-remove'd can now be re-admitted automatically after 5 minutes without a server restart (#6815)

Fixed

... (truncated)

Commits
  • 55efd1d Release v2.11.2
  • 91a53d0 Release v2.11.2-RC.3
  • bc93b27 [FIXED] TTL-ed message not removed after graceful restart (#6828)
  • 12c2281 Fix subject tree intersection to match literals when followed by additional w...
  • 9a0cf55 [FIXED] Direct get subject delete marker (#6826)
  • d6d4ddc [FIXED] TTL-ed message not removed after graceful restart
  • 87dfae2 [FIXED] Async tombstones on PurgeEx (#6825)
  • dc16bbf Test extended full wildcard
  • b714a2a [FIXED] Server peer re-add after peer-remove (#6815)
  • 82cb3ed Fix subject tree intersection to match literals when followed by additional w...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) from 2.11.1 to 2.11.2.
- [Release notes](https://github.com/nats-io/nats-server/releases)
- [Changelog](https://github.com/nats-io/nats-server/blob/main/.goreleaser.yml)
- [Commits](nats-io/nats-server@v2.11.1...v2.11.2)

---
updated-dependencies:
- dependency-name: github.com/nats-io/nats-server/v2
  dependency-version: 2.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 28, 2025
@github-actions github-actions bot added the next label Apr 28, 2025
@retr0h retr0h merged commit d5500b5 into main Apr 29, 2025
6 checks passed
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/nats-io/nats-server/v2-2.11.2 branch April 29, 2025 00:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code next

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants