diff --git a/.github/workflows/security-release-gate.yml b/.github/workflows/security-release-gate.yml
index 31dd6f085408..90f293dc2ec8 100644
--- a/.github/workflows/security-release-gate.yml
+++ b/.github/workflows/security-release-gate.yml
@@ -31,7 +31,7 @@ jobs:
- name: Check out candidate
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
- ref: ${{ inputs.release_ref || github.sha }}
+ ref: ${{ inputs.release_ref || github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false
@@ -70,7 +70,7 @@ jobs:
test -z "$(git status --porcelain)"
if [[ -n "$RELEASE_REF" ]]; then
test "$GITHUB_EVENT_NAME" = workflow_dispatch
- [[ "$RELEASE_REF" =~ ^v5\.7\.4$ ]]
+ [[ "$RELEASE_REF" =~ ^v5\.7\.5$ ]]
test "$(git cat-file -t "$RELEASE_REF")" = tag
test "$(git rev-parse HEAD)" = "$(git rev-parse "${RELEASE_REF}^{commit}")"
fi
@@ -95,7 +95,9 @@ jobs:
shell: bash
run: |
set -euo pipefail
- core_tests='com.hazelcast.aws.AwsMetadataApiTest,com.hazelcast.azure.TagTest,com.hazelcast.config.XmlSchemaSourceSecurityTest,com.hazelcast.console.ConsoleAppTest,com.hazelcast.core.server.HazelcastMemberStarterTest,com.hazelcast.dataconnection.impl.JdbcDataConnectionTest,com.hazelcast.dataconnection.impl.JdbcUrlPolicyTest,com.hazelcast.dataconnection.impl.hazelcastdataconnection.HazelcastDataConnectionConfigLoaderTest,com.hazelcast.dataconnection.impl.jdbcproperties.HikariTranslatorTest,com.hazelcast.flakeidgen.impl.FlakeIdGeneratorProxyTest,com.hazelcast.gcp.LabelTest,com.hazelcast.gcp.UtilsTest,com.hazelcast.internal.config.ConfigLoaderSecurityTest,com.hazelcast.internal.diagnostics.DiagnosticsLogFileTest,com.hazelcast.internal.serialization.impl.ByteArrayObjectDataIntegrationTest,com.hazelcast.internal.serialization.impl.ObjectDataInputStreamIntegrationTest,com.hazelcast.internal.serialization.impl.UnsafeObjectDataInputIntegrationTest,com.hazelcast.internal.util.ClockTest,com.hazelcast.internal.util.HashUtilTest,com.hazelcast.internal.util.SecureFileAccessTest,com.hazelcast.internal.util.collection.LongHashSetTest,com.hazelcast.internal.util.concurrent.BackoffIdleStrategyTest,com.hazelcast.internal.util.phonehome.PhoneHomeDifferentConfigTest,com.hazelcast.internal.util.phonehome.PhoneHomeIntegrationTest,com.hazelcast.internal.util.XmlUtilTest,com.hazelcast.jet.impl.submitjob.memberside.JobUploadStatusTest,com.hazelcast.jet.impl.submitjob.memberside.validator.JarOnClientValidatorTest,com.hazelcast.jet.retry.impl.IntervalFunctionTest,com.hazelcast.kubernetes.KubernetesApiOriginPolicyTest,com.hazelcast.kubernetes.KubernetesConfigTest,com.hazelcast.spi.discovery.multicast.MulticastDiscoveryStrategyTest,com.hazelcast.spi.utils.RestClientTest,com.hazelcast.spi.utils.RetryUtilsTest'
+ scripts/pasturestack-build-runtime preflight
+ python scripts/test-pasturestack-jackson-release.py -v
+ core_tests='com.hazelcast.aws.AwsMetadataApiTest,com.hazelcast.azure.TagTest,com.hazelcast.config.XmlSchemaSourceSecurityTest,com.hazelcast.console.ConsoleAppTest,com.hazelcast.core.server.HazelcastMemberStarterTest,com.hazelcast.dataconnection.impl.JdbcDataConnectionTest,com.hazelcast.dataconnection.impl.JdbcUrlPolicyTest,com.hazelcast.dataconnection.impl.hazelcastdataconnection.HazelcastDataConnectionConfigLoaderTest,com.hazelcast.dataconnection.impl.jdbcproperties.HikariTranslatorTest,com.hazelcast.flakeidgen.impl.FlakeIdGeneratorProxyTest,com.hazelcast.gcp.LabelTest,com.hazelcast.gcp.UtilsTest,com.hazelcast.internal.config.ConfigLoaderSecurityTest,com.hazelcast.internal.diagnostics.DiagnosticsLogFileTest,com.hazelcast.internal.serialization.impl.ByteArrayObjectDataIntegrationTest,com.hazelcast.internal.serialization.impl.ObjectDataInputStreamIntegrationTest,com.hazelcast.internal.serialization.impl.UnsafeObjectDataInputIntegrationTest,com.hazelcast.internal.util.ClockTest,com.hazelcast.internal.util.HashUtilTest,com.hazelcast.internal.util.SecureFileAccessTest,com.hazelcast.internal.util.collection.LongHashSetTest,com.hazelcast.internal.util.concurrent.BackoffIdleStrategyTest,com.hazelcast.internal.util.phonehome.PhoneHomeDifferentConfigTest,com.hazelcast.internal.util.phonehome.PhoneHomeIntegrationTest,com.hazelcast.internal.util.XmlUtilTest,com.hazelcast.jet.impl.submitjob.memberside.JobUploadStatusTest,com.hazelcast.jet.impl.submitjob.memberside.validator.JarOnClientValidatorTest,com.hazelcast.jet.impl.util.JsonUtilTest,com.hazelcast.jet.json.impl.JsonUtilImplTest,com.hazelcast.jet.retry.impl.IntervalFunctionTest,com.hazelcast.kubernetes.KubernetesApiOriginPolicyTest,com.hazelcast.kubernetes.KubernetesConfigTest,com.hazelcast.spi.discovery.multicast.MulticastDiscoveryStrategyTest,com.hazelcast.spi.utils.RestClientTest,com.hazelcast.spi.utils.RetryUtilsTest'
all_tests="$core_tests,com.hazelcast.jet.sql.impl.parse.QueryParserTest,com.hazelcast.buildutils.ExportPackageViewerTest,com.hazelcast.jet.cdc.OperationTest"
timeout --signal=TERM --kill-after=30s 30m ./mvnw -B \
-pl hazelcast,hazelcast-sql,hazelcast-build-utils,extensions/cdc-debezium,extensions/mongodb \
@@ -156,6 +158,8 @@ jobs:
com.hazelcast.jet.impl.deployment.ProcessorClassLoaderTest
com.hazelcast.jet.impl.submitjob.memberside.JobUploadStatusTest
com.hazelcast.jet.impl.submitjob.memberside.validator.JarOnClientValidatorTest
+ com.hazelcast.jet.impl.util.JsonUtilTest
+ com.hazelcast.jet.json.impl.JsonUtilImplTest
com.hazelcast.jet.retry.impl.IntervalFunctionTest
com.hazelcast.kubernetes.KubernetesApiOriginPolicyTest
com.hazelcast.kubernetes.KubernetesConfigTest
@@ -205,10 +209,10 @@ jobs:
run: |
set -euo pipefail
PASTURESTACK_OUTPUT_DIR=dist scripts/pasturestack-build-runtime
- test -s dist/hazelcast-5.7.4.jar
- sha256sum dist/hazelcast-5.7.4.jar | tee evidence/hazelcast-5.7.4.jar.sha256
- jar tf dist/hazelcast-5.7.4.jar | grep -Fxq META-INF/LICENSE
- jar tf dist/hazelcast-5.7.4.jar | grep -Fxq META-INF/NOTICE
+ test -s dist/hazelcast-5.7.5.jar
+ sha256sum dist/hazelcast-5.7.5.jar | tee evidence/hazelcast-5.7.5.jar.sha256
+ jar tf dist/hazelcast-5.7.5.jar | grep -Fxq META-INF/LICENSE
+ jar tf dist/hazelcast-5.7.5.jar | grep -Fxq META-INF/NOTICE
native_resources=(
hazelcast/src/main/resources/affinity_helper.c
hazelcast/src/main/resources/affinity_helper.h
@@ -223,7 +227,7 @@ jobs:
trap 'rm -rf "$extracted_native"' EXIT
(
cd "$extracted_native"
- jar xf "$GITHUB_WORKSPACE/dist/hazelcast-5.7.4.jar" \
+ jar xf "$GITHUB_WORKSPACE/dist/hazelcast-5.7.5.jar" \
lib/linux-x86/libicmp_helper.so \
lib/linux-x86_64/libaffinity_helper.so \
lib/linux-x86_64/libicmp_helper.so
@@ -234,7 +238,7 @@ jobs:
"$extracted_native/lib/linux-x86_64/libaffinity_helper.so"
cmp hazelcast-tpc-engine/src/main/resources/lib/linux-x86_64/libicmp_helper.so \
"$extracted_native/lib/linux-x86_64/libicmp_helper.so"
- if jar tf dist/hazelcast-5.7.4.jar | grep -Eq '(^|/)(jet_to_python[^/]*|[^/]+\.py)$'; then
+ if jar tf dist/hazelcast-5.7.5.jar | grep -Eq '(^|/)(jet_to_python[^/]*|[^/]+\.py)$'; then
echo 'The core runtime artifact unexpectedly contains Python extension resources.' >&2
exit 1
fi
@@ -312,9 +316,9 @@ jobs:
-Dfile=pom.xml -DpomFile=pom.xml
./mvnw -B org.apache.maven.plugins:maven-install-plugin:3.1.4:install-file \
-Dfile=hazelcast-parent/pom.xml -DpomFile=hazelcast-parent/pom.xml
- test -s hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.4.jar
+ test -s hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.5.jar
./mvnw -B org.apache.maven.plugins:maven-install-plugin:3.1.4:install-file \
- -Dfile=hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.4.jar \
+ -Dfile=hazelcast-tpc-engine/target/hazelcast-tpc-engine-5.7.5.jar \
-DpomFile=hazelcast-tpc-engine/pom.xml
timeout --signal=TERM --kill-after=30s 15m ./mvnw -B \
org.apache.maven.plugins:maven-help-plugin:3.5.2:effective-pom \
@@ -333,7 +337,7 @@ jobs:
-DoutputFormat=json \
-DoutputReactorProjects=false \
-DoutputDirectory="$PWD/evidence" \
- -DoutputName=hazelcast-5.7.4.cdx \
+ -DoutputName=hazelcast-5.7.5.cdx \
-DschemaVersion=1.6 \
org.cyclonedx:cyclonedx-maven-plugin:2.9.3:makeBom
printf '%s %s\n%s %s\n' \
@@ -383,18 +387,18 @@ jobs:
"$TRIVY_IMAGE" rootfs --pkg-types library \
--cache-dir /root/.cache/trivy --skip-db-update --offline-scan \
--scanners vuln --severity CRITICAL,HIGH --format json \
- --output /evidence/hazelcast-5.7.4.trivy.json /artifact/hazelcast-5.7.4.jar
+ --output /evidence/hazelcast-5.7.5.trivy.json /artifact/hazelcast-5.7.5.jar
docker run --rm --network none \
-v "$PWD/evidence:/evidence" \
-v "$trivy_cache:/root/.cache/trivy" \
"$TRIVY_IMAGE" sbom \
--cache-dir /root/.cache/trivy --skip-db-update --skip-java-db-update --offline-scan \
--scanners vuln --severity CRITICAL,HIGH --format json \
- --output /evidence/hazelcast-5.7.4.sbom.trivy.json \
- /evidence/hazelcast-5.7.4.cdx.json
+ --output /evidence/hazelcast-5.7.5.sbom.trivy.json \
+ /evidence/hazelcast-5.7.5.cdx.json
sha256sum evidence/maven-effective-pom.xml \
- evidence/maven-runtime-dependency-tree.json evidence/hazelcast-5.7.4.cdx.json \
- evidence/hazelcast-5.7.4.sbom.trivy.json evidence/hazelcast-5.7.4.trivy.json \
+ evidence/maven-runtime-dependency-tree.json evidence/hazelcast-5.7.5.cdx.json \
+ evidence/hazelcast-5.7.5.sbom.trivy.json evidence/hazelcast-5.7.5.trivy.json \
evidence/evidence-tools.sha256 \
evidence/native-resources.sha256 evidence/runtime-toolchain-boundary.txt \
> evidence/security-evidence.sha256
@@ -405,7 +409,7 @@ jobs:
set -euo pipefail
python scripts/pasturestack-verify-maven-evidence.py \
--effective-pom evidence/maven-effective-pom.xml \
- --sbom evidence/hazelcast-5.7.4.cdx.json \
+ --sbom evidence/hazelcast-5.7.5.cdx.json \
--dependency-tree evidence/maven-runtime-dependency-tree.json \
--summary evidence/maven-evidence-summary.txt
sha256sum evidence/maven-evidence-summary.txt >> evidence/security-evidence.sha256
@@ -418,9 +422,9 @@ jobs:
return json.load(stream)
source = load('evidence/source-security.json')
- artifact = load('evidence/hazelcast-5.7.4.trivy.json')
- dependency_scan = load('evidence/hazelcast-5.7.4.sbom.trivy.json')
- sbom = load('evidence/hazelcast-5.7.4.cdx.json')
+ artifact = load('evidence/hazelcast-5.7.5.trivy.json')
+ dependency_scan = load('evidence/hazelcast-5.7.5.sbom.trivy.json')
+ sbom = load('evidence/hazelcast-5.7.5.cdx.json')
maven_tree = load('evidence/maven-runtime-dependency-tree.json')
source_vulnerabilities = [
item
@@ -506,7 +510,7 @@ jobs:
or None in component_purls
or len(component_refs) != len(set(component_refs))
or len(component_purls) != len(set(component_purls))
- or maven_root != ('com.hazelcast', 'hazelcast', '5.7.4')
+ or maven_root != ('com.hazelcast', 'hazelcast', '5.7.5')
or sbom_root != maven_root
or root_ref not in dependency_refs
or dependency_refs != allowed_refs
@@ -524,7 +528,7 @@ jobs:
docker run --rm --network none \
-v "$PWD/evidence:/evidence:ro" \
cyclonedx/cyclonedx-cli:0.33.1@sha256:252c2e26f468c25fea1e63ecde1bc3198ad6e9dbb57f5ed3236bddcb2281b3a7 \
- validate --input-file /evidence/hazelcast-5.7.4.cdx.json \
+ validate --input-file /evidence/hazelcast-5.7.5.cdx.json \
--input-format json --input-version v1_6 --fail-on-errors
- name: Upload review evidence
@@ -539,12 +543,12 @@ jobs:
include-hidden-files: false
- name: Retain exact reviewed release artifact
- if: success() && inputs.release_ref != ''
+ if: success()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: distributed-cache-release-${{ steps.candidate.outputs.source_sha }}
path: |
- dist/hazelcast-5.7.4.jar
+ dist/hazelcast-5.7.5.jar
evidence/
if-no-files-found: error
retention-days: 30
diff --git a/Dockerfile.pasturestack b/Dockerfile.pasturestack
index 8a92d45873ef..8f6559c4aa50 100644
--- a/Dockerfile.pasturestack
+++ b/Dockerfile.pasturestack
@@ -19,12 +19,12 @@ FROM scratch
ARG VCS_REF
LABEL org.opencontainers.image.title="PastureStack Distributed Cache Runtime" \
- org.opencontainers.image.description="PastureStack artifact 5.7.4 with Hazelcast cluster runtime 5.7.3 and reviewed security updates" \
+ org.opencontainers.image.description="PastureStack artifact 5.7.5 with Hazelcast cluster runtime 5.7.3 and reviewed security updates" \
org.opencontainers.image.source="https://github.com/PastureStack/distributed-cache-runtime" \
org.opencontainers.image.revision="$VCS_REF" \
org.opencontainers.image.licenses="Apache-2.0 OR LicenseRef-Hazelcast-Community" \
org.opencontainers.image.vendor="PastureStack"
-COPY --from=build /src/dist/hazelcast-5.7.4.jar /opt/pasturestack/vendor/hazelcast-5.7.4.jar
-COPY --from=build /src/dist/hazelcast-5.7.4.jar.sha256 /opt/pasturestack/vendor/hazelcast-5.7.4.jar.sha256
-COPY LICENSE NOTICE ORIGIN.md SECURITY-MAINTENANCE.md /opt/pasturestack/licenses/
+COPY --from=build /src/dist/hazelcast-5.7.5.jar /opt/pasturestack/vendor/hazelcast-5.7.5.jar
+COPY --from=build /src/dist/hazelcast-5.7.5.jar.sha256 /opt/pasturestack/vendor/hazelcast-5.7.5.jar.sha256
+COPY LICENSE NOTICE ORIGIN.md SECURITY-MAINTENANCE.md RELEASE-NOTES-5.7.5.md /opt/pasturestack/licenses/
diff --git a/ORIGIN.md b/ORIGIN.md
index f5cd21089b30..2f3bea3f2d72 100644
--- a/ORIGIN.md
+++ b/ORIGIN.md
@@ -6,7 +6,7 @@ This repository is derived from the public [Hazelcast repository](https://github
- Upstream boundary commit: `60c31e3750cbad64f5720e2e02f0a9830973193c`
- PastureStack maintenance line: linear commits after that upstream boundary
- Historical maintained artifact: PastureStack Maven artifact 5.7.3-pasturestack.4 (numeric Hazelcast cluster runtime 5.7.3), based on Hazelcast 5.7.0, with reviewed source and dependency security updates
-- Current maintained artifact: pure numeric Maven artifact `5.7.4`; product identity and provenance remain in package metadata and release evidence
+- Current candidate artifact: pure numeric Maven artifact `5.7.5`, not yet built or published; product identity and provenance remain in package metadata and release evidence. Public `v5.7.4` remains immutable historical evidence.
The upstream Git history, copyright notices, author records, `LICENSE`, `NOTICE`, and file-level license headers are retained. PastureStack's maintenance commits do not replace or relicense upstream work, and PastureStack does not claim authorship of upstream contributions.
diff --git a/README.md b/README.md
index 5a8a60823678..323e4f73f4bc 100755
--- a/README.md
+++ b/README.md
@@ -5,9 +5,12 @@
Earlier public Maven artifacts remain immutable historical evidence. The
current public GitHub Release is
-[`v5.7.4`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.4),
-and the maintained artifact version produced by this source is `5.7.4`. Every
-current and future PastureStack publication uses a pure numeric version, while
+[`v5.7.4`](https://github.com/PastureStack/distributed-cache-runtime/releases/tag/v5.7.4).
+This source prepares candidate
+artifact `5.7.5`; it has not yet been built, scanned, or published. See
+[5.7.5 candidate notes](RELEASE-NOTES-5.7.5.md) for the Jackson-only update and
+pending artifact verification. Every current and future PastureStack publication
+uses a pure numeric version, while
product identity and provenance remain in metadata rather than the version.
Generated Hazelcast cluster metadata reports numeric runtime version `5.7.3`,
because the cluster protocol does not accept a Maven qualifier. See
diff --git a/RELEASE-NOTES-5.7.5.md b/RELEASE-NOTES-5.7.5.md
new file mode 100644
index 000000000000..7262e91a66e2
--- /dev/null
+++ b/RELEASE-NOTES-5.7.5.md
@@ -0,0 +1,21 @@
+# 5.7.5 candidate: Jackson security patch
+
+Status: source candidate only; not yet built, scanned, published, or validated
+in a downstream runtime. Public `v5.7.4` remains unchanged historical evidence.
+
+- Update the actual parent properties and imported BOMs from Jackson 2.22.2 to
+ 2.22.3 and from Jackson 3.2.2 to 3.2.3. FasterXML lists fixes for
+ CVE-2026-91776 (unbounded type-id cache) and CVE-2026-91777 (quadratic
+ forward-reference resolution) in both
+ [2.22.3](https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.22.3) and
+ [3.2.3](https://github.com/FasterXML/jackson/wiki/Jackson-Release-3.2.3).
+- Require those exact versions in all four embedded Jackson core/databind
+ Maven metadata entries. Update reactor coordinates, test-job fixtures,
+ carrier paths, SBOM identity, and release gates to numeric artifact `5.7.5`.
+- Preserve numeric Hazelcast cluster runtime `5.7.3`, business logic, and all
+ other dependency pins from the candidate's `origin/main` base.
+
+The existing release gate must still build the shaded JAR, run its focused
+regression suites, verify resolved Maven/SBOM and packaged metadata, and scan
+the actual artifact with current vulnerability data. Source-only checks do not
+prove that CVEs are absent from a built artifact or any downstream Engine JAR.
diff --git a/SECURITY-MAINTENANCE.md b/SECURITY-MAINTENANCE.md
index 3eef58234629..b511dd5fa0f9 100644
--- a/SECURITY-MAINTENANCE.md
+++ b/SECURITY-MAINTENANCE.md
@@ -4,14 +4,14 @@
The PastureStack maintenance delta intentionally preserves the Hazelcast 5.7.0 API while updating reviewed runtime and build-time dependencies with published security fixes:
-The resulting reviewed Maven artifact version is `5.7.4`; it is a PastureStack maintenance release based on upstream `5.7.0`, not an upstream Hazelcast release. Hazelcast's cluster protocol parser accepts numeric product versions only, so generated runtime metadata deliberately reports `5.7.3`. The artifact version must be used by Maven coordinates, filenames, the artifact carrier, SBOM, and release evidence; the numeric runtime version must be used by cluster/member compatibility code.
+The current source prepares Maven artifact candidate `5.7.5`; it is based on upstream `5.7.0`, not an upstream Hazelcast release, and is not yet built, scanned, or published. Public `v5.7.4` remains immutable historical evidence. Hazelcast's cluster protocol parser accepts numeric product versions only, so generated runtime metadata deliberately reports `5.7.3`. The artifact version must be used by Maven coordinates, filenames, the artifact carrier, SBOM, and release evidence; the numeric runtime version must be used by cluster/member compatibility code. See [5.7.5 candidate notes](RELEASE-NOTES-5.7.5.md) for the narrow Jackson update and pending verification.
| Component | Upstream 5.7.0 | PastureStack maintained version | Scope |
| --- | --- | --- | --- |
| Java release / cloud test VM | 17 / retired mixed-runtime fixtures | 25 LTS / Ubuntu 24.04 LTS | Compiler target, CI, and cloud integration runtime |
| Container build JDK | Unpinned release line | Temurin 25.0.4+7 on Ubuntu 24.04, digest pinned | Reproducible OCI build stage aligned with CI; build-only `unzip` preserves Maven ZIP checksum verification; a bounded 1.2 GiB Maven heap prevents javac OOM on the 2 GiB builder |
-| Jackson 2 core and databind | 2.21.2 | 2.22.2 | Shaded runtime |
-| Jackson 3 core, databind, and JR | 3.1.2 | 3.2.2 | Shaded runtime |
+| Jackson 2 core and databind | 2.21.2 | 2.22.3 | Shaded runtime |
+| Jackson 3 core, databind, and JR | 3.1.2 | 3.2.3 | Shaded runtime |
| Netty | 4.1.132.Final | 4.2.17.Final | Extension and Hadoop integration dependencies |
| Lettuce | 6.8.2.RELEASE | 7.7.0.RELEASE | Kafka Connect test dependency on the Netty 4.2 line |
| Apache Kafka client | 4.1.1 | 4.3.1 | Kafka connector runtime and compatibility tests |
@@ -24,7 +24,7 @@ The resulting reviewed Maven artifact version is `5.7.4`; it is a PastureStack m
| Checkstyle | 12.3.1 | 14.0.0 | Build-time source policy |
| gRPC Java / Python | 1.73.0 | 1.83.1 / 1.83.0 | gRPC and cloud extension dependencies |
| Aircompressor | 2.0.2 | 2.0.3 | Current Parquet 1.18 byte-array codec dependency; Aircompressor v3 uses a different artifact/package and MemorySegment API |
-| Hazelcast test-job dependency | 5.0.5 | 5.7.4 | Command-line integration test fixtures |
+| Hazelcast test-job dependency | 5.0.5 | 5.7.5 | Command-line integration test fixtures |
| Maven Compiler Plugin | implicit | 3.15.0 | Reproducible test-fixture builds |
| Maven JAR Plugin | 3.1.2 | 3.5.1 | Reproducible test-fixture packaging |
| Maven Install Plugin | implicit | 3.1.4 | Latest stable Maven 3-compatible install lifecycle |
@@ -66,6 +66,10 @@ Jetty 9 was eliminated instead of forcing an unrelated Jetty 12 server migration
## Validation Boundaries
+The observations below describe the prior reviewed maintenance tree. They are
+not validation evidence for the unbuilt `5.7.5` candidate or a current zero-CVE
+claim; candidate artifacts must pass the required release gates again.
+
- Temurin 25 LTS compiles the 5,863-source core module. The focused SQL, Hadoop, Avro, Protobuf, gRPC, Kafka Connect, Python, and command-line compatibility checks pass. JLine 4 selects the FFM terminal provider under WSL. The Python runtime suite passes 6/6 with Protobuf 7.36.0 and gRPC Python 1.83.0.
- Kafka 4.3.1 passes real-container read/projection and write-to-topic checks against Confluent Platform 8.3.1. Spring Boot 4.1.1 with Spring Framework 7.0.9 passes all 15 module tests. The shaded tests JAR excludes dependency-owned `junit-platform.properties`, preventing a Netty test setting from silently forcing downstream suites into unsafe parallel execution.
- CycloneDX 1.6 aggregate SBOMs contain 354 runtime components / 355 dependency nodes and 659 all-scope components / 660 dependency nodes, no random serial number, and zero Jetty components. The release runtime SBOM independently contains 15 components / 16 dependency nodes and exactly matches its Maven runtime tree. Offline Trivy 0.74.0 scans recognize 355 and 660 aggregate Java packages respectively; the working tree, release JAR, release-runtime SBOM, aggregate SBOMs, and candidate OCI image all report zero Critical, High, Medium, or Low vulnerabilities against vulnerability DB `2026-08-24T00:58:29Z` and Java DB `2026-08-24T01:07:04Z`.
@@ -100,9 +104,9 @@ All Spring Boot 3 / Spring Framework 6 compatibility profiles and the `hazelcast
A release is acceptable only when all of the following are true:
1. The upstream `v5.7.0` boundary recorded in [ORIGIN.md](ORIGIN.md) is an ancestor of the candidate, and every later commit remains on the linear PastureStack maintenance line.
-2. Every reactor POM and command-line test fixture resolves the maintained artifact at 5.7.4, while generated cluster runtime metadata resolves to numeric version 5.7.3. Maven Wrapper 3.9.16 is downloaded only from Maven Central; its ZIP and tar.gz distributions are verified against separate committed SHA-256 values before execution. The source version gate requires Java 25, Ubuntu 24.04 LTS cloud test images, Checkstyle 14.0.0, Avro 1.12.2, Jackson 2.22.2 and 3.2.2, Janino 3.1.12, Parquet 1.18.0, JLine 4.3.1 with FFM, Protobuf Java 4.36.0 and Python 7.36.0, Netty 4.2.17.Final, Lettuce 7.7.0.RELEASE, Kafka 4.3.1, Confluent Platform 8.3.1, gRPC Java 1.83.1 and Python 1.83.0, Aircompressor 2.0.3, Hadoop 3.5.0, Maven Compiler Plugin 3.15.0, Maven JAR Plugin 3.5.1, Maven Install Plugin 3.1.4, Maven Dependency Plugin 3.11.0, an in-process Kotlin Maven compiler, MINA 2.2.9, Tomcat 11.0.25, PostgreSQL JDBC 42.7.13, Hibernate ORM 7.4.5.Final, LZ4 Java 1.11.2, Apache HTTP Core 5.4.3, Apache HTTP Client 5.6.4, Elasticsearch Java API Client 9.5.1, Commons Configuration 2.15.1, OpenTelemetry 1.65.0, Log4j 2.26.1, Debezium 3.6.1.Final, Bouncy Castle bcprov 1.85.2 with bcpkix/bcutil 1.85, ZooKeeper 3.9.5, Wire 6.4.6, Micrometer 1.17.1, RabbitMQ client 5.35.0, Plexus Utils 4.1.0, Logback 1.6.3, Vert.x 5.1.6, Spring Boot 4.1.1, and Spring Framework 7.0.9. It also verifies that Jansi, all Spring Boot 3 / Spring Framework 6 compatibility profiles and artifacts, legacy Debezium configuration keys, Elasticsearch HLRC, embedded Schema Registry server, Hadoop MiniDFSCluster, Jetty, and dependency-owned JUnit platform settings are absent from their governed outputs.
+2. Every reactor POM and command-line test fixture resolves the maintained artifact at 5.7.5, while generated cluster runtime metadata resolves to numeric version 5.7.3. Maven Wrapper 3.9.16 is downloaded only from Maven Central; its ZIP and tar.gz distributions are verified against separate committed SHA-256 values before execution. The source version gate requires Java 25, Ubuntu 24.04 LTS cloud test images, Checkstyle 14.0.0, Avro 1.12.2, Jackson 2.22.3 and 3.2.3, Janino 3.1.12, Parquet 1.18.0, JLine 4.3.1 with FFM, Protobuf Java 4.36.0 and Python 7.36.0, Netty 4.2.17.Final, Lettuce 7.7.0.RELEASE, Kafka 4.3.1, Confluent Platform 8.3.1, gRPC Java 1.83.1 and Python 1.83.0, Aircompressor 2.0.3, Hadoop 3.5.0, Maven Compiler Plugin 3.15.0, Maven JAR Plugin 3.5.1, Maven Install Plugin 3.1.4, Maven Dependency Plugin 3.11.0, an in-process Kotlin Maven compiler, MINA 2.2.9, Tomcat 11.0.25, PostgreSQL JDBC 42.7.13, Hibernate ORM 7.4.5.Final, LZ4 Java 1.11.2, Apache HTTP Core 5.4.3, Apache HTTP Client 5.6.4, Elasticsearch Java API Client 9.5.1, Commons Configuration 2.15.1, OpenTelemetry 1.65.0, Log4j 2.26.1, Debezium 3.6.1.Final, Bouncy Castle bcprov 1.85.2 with bcpkix/bcutil 1.85, ZooKeeper 3.9.5, Wire 6.4.6, Micrometer 1.17.1, RabbitMQ client 5.35.0, Plexus Utils 4.1.0, Logback 1.6.3, Vert.x 5.1.6, Spring Boot 4.1.1, and Spring Framework 7.0.9. It also verifies that Jansi, all Spring Boot 3 / Spring Framework 6 compatibility profiles and artifacts, legacy Debezium configuration keys, Elasticsearch HLRC, embedded Schema Registry server, Hadoop MiniDFSCluster, Jetty, and dependency-owned JUnit platform settings are absent from their governed outputs.
3. Maven's resolved dependency graph contains those reviewed versions, no older duplicate of the same artifacts, no Elasticsearch HLRC/server/Lucene legacy graph in the Elasticsearch connector, and no `org.eclipse.jetty` graph in the Kafka, SQL, Hadoop distribution, Azure, or S3 modules.
-4. The produced file is `hazelcast-5.7.4.jar`; its embedded core Maven metadata reports 5.7.4, its generated cluster runtime metadata reports numeric version 5.7.3, and its embedded Jackson metadata reports Jackson 2.22.2 and Jackson 3.2.2. The full source commit and abbreviated revision embedded in `GeneratedBuildProperties` must match the OCI revision supplied to the build; unresolved placeholders are rejected during packaging.
+4. The produced file is `hazelcast-5.7.5.jar`; its embedded core Maven metadata reports 5.7.5, its generated cluster runtime metadata reports numeric version 5.7.3, and its embedded Jackson metadata reports Jackson 2.22.3 and Jackson 3.2.3. The full source commit and abbreviated revision embedded in `GeneratedBuildProperties` must match the OCI revision supplied to the build; unresolved placeholders are rejected during packaging.
5. Relevant core, Spring, database, and distribution integration tests pass on Java 25 LTS. The focused source-boundary suite must retain its expected suite and test counts so an accidentally undiscovered test cannot appear successful.
6. Both standalone source-boundary gates complete successfully on the release JDK.
7. `trivy fs --offline-scan --scanners vuln --severity CRITICAL,HIGH` reports zero Critical and zero High findings across the resolved source POMs.
diff --git a/distribution/pom.xml b/distribution/pom.xml
index c3c9d3c499af..5e3d9e975fd4 100644
--- a/distribution/pom.xml
+++ b/distribution/pom.xml
@@ -21,7 +21,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/extensions/avro/pom.xml b/extensions/avro/pom.xml
index 2ee89e5d4657..99d33b35031d 100644
--- a/extensions/avro/pom.xml
+++ b/extensions/avro/pom.xml
@@ -30,7 +30,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/cdc-debezium/pom.xml b/extensions/cdc-debezium/pom.xml
index 7770bbb50efc..93f37e4628ec 100644
--- a/extensions/cdc-debezium/pom.xml
+++ b/extensions/cdc-debezium/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/cdc-mysql/pom.xml b/extensions/cdc-mysql/pom.xml
index 6a083f24ab6d..bccb962be30e 100644
--- a/extensions/cdc-mysql/pom.xml
+++ b/extensions/cdc-mysql/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/cdc-postgres/pom.xml b/extensions/cdc-postgres/pom.xml
index 7bfe92645565..95ec1b3e70a1 100644
--- a/extensions/cdc-postgres/pom.xml
+++ b/extensions/cdc-postgres/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/csv/pom.xml b/extensions/csv/pom.xml
index 756e603800ea..23e51b8e5138 100644
--- a/extensions/csv/pom.xml
+++ b/extensions/csv/pom.xml
@@ -30,7 +30,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/elasticsearch/elasticsearch-7/pom.xml b/extensions/elasticsearch/elasticsearch-7/pom.xml
index 16d3c28e2139..01e871b73908 100644
--- a/extensions/elasticsearch/elasticsearch-7/pom.xml
+++ b/extensions/elasticsearch/elasticsearch-7/pom.xml
@@ -30,7 +30,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
../../pom.xml
diff --git a/extensions/grpc/pom.xml b/extensions/grpc/pom.xml
index 23697e690e65..2c0f001e6e73 100644
--- a/extensions/grpc/pom.xml
+++ b/extensions/grpc/pom.xml
@@ -27,7 +27,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/hadoop-dist/files-azure/pom.xml b/extensions/hadoop-dist/files-azure/pom.xml
index 315e2aab3d46..615d3b3c8274 100644
--- a/extensions/hadoop-dist/files-azure/pom.xml
+++ b/extensions/hadoop-dist/files-azure/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-hadoop-dist
- 5.7.4
+ 5.7.5
diff --git a/extensions/hadoop-dist/files-gcs/pom.xml b/extensions/hadoop-dist/files-gcs/pom.xml
index 8001ebda3881..7e3a6831ca1e 100644
--- a/extensions/hadoop-dist/files-gcs/pom.xml
+++ b/extensions/hadoop-dist/files-gcs/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-hadoop-dist
- 5.7.4
+ 5.7.5
diff --git a/extensions/hadoop-dist/files-s3/pom.xml b/extensions/hadoop-dist/files-s3/pom.xml
index 40a0288626cb..2cda0feac763 100644
--- a/extensions/hadoop-dist/files-s3/pom.xml
+++ b/extensions/hadoop-dist/files-s3/pom.xml
@@ -29,7 +29,7 @@
hazelcast-jet-hadoop-dist
com.hazelcast.jet
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/extensions/hadoop-dist/hadoop-all/pom.xml b/extensions/hadoop-dist/hadoop-all/pom.xml
index 3b3071c6dfc9..a4004dc0fb23 100644
--- a/extensions/hadoop-dist/hadoop-all/pom.xml
+++ b/extensions/hadoop-dist/hadoop-all/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-hadoop-dist
- 5.7.4
+ 5.7.5
diff --git a/extensions/hadoop-dist/hadoop/pom.xml b/extensions/hadoop-dist/hadoop/pom.xml
index c24525f89ef1..8207055708d1 100644
--- a/extensions/hadoop-dist/hadoop/pom.xml
+++ b/extensions/hadoop-dist/hadoop/pom.xml
@@ -27,7 +27,7 @@
com.hazelcast.jet
hazelcast-jet-hadoop-dist
- 5.7.4
+ 5.7.5
diff --git a/extensions/hadoop-dist/pom.xml b/extensions/hadoop-dist/pom.xml
index db86cf7825e6..8759f2e46082 100644
--- a/extensions/hadoop-dist/pom.xml
+++ b/extensions/hadoop-dist/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/hadoop/pom.xml b/extensions/hadoop/pom.xml
index 62cd1d505f46..acc25192fbd5 100644
--- a/extensions/hadoop/pom.xml
+++ b/extensions/hadoop/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/kafka-connect/pom.xml b/extensions/kafka-connect/pom.xml
index bed507144192..7ac4d5d1ef44 100644
--- a/extensions/kafka-connect/pom.xml
+++ b/extensions/kafka-connect/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/kafka/pom.xml b/extensions/kafka/pom.xml
index 894a8854f157..9e508bfb3858 100644
--- a/extensions/kafka/pom.xml
+++ b/extensions/kafka/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/kinesis/pom.xml b/extensions/kinesis/pom.xml
index 7bf095a2dbeb..9679101fe1e5 100644
--- a/extensions/kinesis/pom.xml
+++ b/extensions/kinesis/pom.xml
@@ -29,7 +29,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/mapstore/pom.xml b/extensions/mapstore/pom.xml
index bc0a4325f2d5..3e803950930e 100644
--- a/extensions/mapstore/pom.xml
+++ b/extensions/mapstore/pom.xml
@@ -32,7 +32,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/mongodb/pom.xml b/extensions/mongodb/pom.xml
index d4e4f5dabfda..0165d8b5b5e1 100644
--- a/extensions/mongodb/pom.xml
+++ b/extensions/mongodb/pom.xml
@@ -31,7 +31,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/pom.xml b/extensions/pom.xml
index 2929342d9c1a..5db412070311 100644
--- a/extensions/pom.xml
+++ b/extensions/pom.xml
@@ -30,7 +30,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
diff --git a/extensions/protobuf/pom.xml b/extensions/protobuf/pom.xml
index f319540cad3d..5b42c52c898b 100644
--- a/extensions/protobuf/pom.xml
+++ b/extensions/protobuf/pom.xml
@@ -30,7 +30,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/python/pom.xml b/extensions/python/pom.xml
index d6b85d23f992..d51d4c3f6782 100644
--- a/extensions/python/pom.xml
+++ b/extensions/python/pom.xml
@@ -27,7 +27,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/extensions/s3/pom.xml b/extensions/s3/pom.xml
index fefb4982ba53..2c39b3ecd6ba 100644
--- a/extensions/s3/pom.xml
+++ b/extensions/s3/pom.xml
@@ -30,7 +30,7 @@
com.hazelcast.jet
hazelcast-jet-extensions
- 5.7.4
+ 5.7.5
diff --git a/hazelcast-archunit-rules/pom.xml b/hazelcast-archunit-rules/pom.xml
index cfe87988f384..c751a33088cc 100644
--- a/hazelcast-archunit-rules/pom.xml
+++ b/hazelcast-archunit-rules/pom.xml
@@ -25,7 +25,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-build-utils/pom.xml b/hazelcast-build-utils/pom.xml
index d0f5083b8dfb..820b6399916b 100644
--- a/hazelcast-build-utils/pom.xml
+++ b/hazelcast-build-utils/pom.xml
@@ -25,7 +25,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-coverage-report/pom.xml b/hazelcast-coverage-report/pom.xml
index 6ac20c47e66c..4b8b3f894d5c 100644
--- a/hazelcast-coverage-report/pom.xml
+++ b/hazelcast-coverage-report/pom.xml
@@ -20,7 +20,7 @@
hazelcast-root
com.hazelcast
- 5.7.4
+ 5.7.5
4.0.0
pom
diff --git a/hazelcast-it/distribution-it/pom.xml b/hazelcast-it/distribution-it/pom.xml
index e54d93f205a6..574bd950efc5 100644
--- a/hazelcast-it/distribution-it/pom.xml
+++ b/hazelcast-it/distribution-it/pom.xml
@@ -6,7 +6,7 @@
com.hazelcast
hazelcast-it
- 5.7.4
+ 5.7.5
distribution-it
diff --git a/hazelcast-it/pom.xml b/hazelcast-it/pom.xml
index 0b7e045bdaee..9a8e32c0f2e8 100644
--- a/hazelcast-it/pom.xml
+++ b/hazelcast-it/pom.xml
@@ -22,7 +22,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
hazelcast-it
diff --git a/hazelcast-parent/pom.xml b/hazelcast-parent/pom.xml
index f8768f6f95ab..7d1dec6023f1 100644
--- a/hazelcast-parent/pom.xml
+++ b/hazelcast-parent/pom.xml
@@ -23,7 +23,7 @@
com.hazelcast
hazelcast-parent
pom
- 5.7.4
+ 5.7.5
Hazelcast Parent POM
Provides a base configuration for Hazelcast Platform builds
@@ -113,8 +113,8 @@
3.5.0
- 3.2.2
- 2.22.2
+ 3.2.3
+ 2.22.3
2.22
4.3.1
0.13
diff --git a/hazelcast-spring-boot-autoconfiguration/hazelcast-spring-boot4/pom.xml b/hazelcast-spring-boot-autoconfiguration/hazelcast-spring-boot4/pom.xml
index 27fa24d65b79..055c9a81242d 100644
--- a/hazelcast-spring-boot-autoconfiguration/hazelcast-spring-boot4/pom.xml
+++ b/hazelcast-spring-boot-autoconfiguration/hazelcast-spring-boot4/pom.xml
@@ -25,7 +25,7 @@
com.hazelcast
hazelcast-spring-boot-autoconfiguration
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-spring-boot-autoconfiguration/pom.xml b/hazelcast-spring-boot-autoconfiguration/pom.xml
index 9b33a6e1eb9f..e7b0bc1f3c86 100644
--- a/hazelcast-spring-boot-autoconfiguration/pom.xml
+++ b/hazelcast-spring-boot-autoconfiguration/pom.xml
@@ -25,7 +25,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-spring-tests/pom.xml b/hazelcast-spring-tests/pom.xml
index c30e6c5e2ec5..4143b2bba02c 100644
--- a/hazelcast-spring-tests/pom.xml
+++ b/hazelcast-spring-tests/pom.xml
@@ -25,7 +25,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-spring/pom.xml b/hazelcast-spring/pom.xml
index 5faec448a1b2..ab8515394c32 100644
--- a/hazelcast-spring/pom.xml
+++ b/hazelcast-spring/pom.xml
@@ -25,7 +25,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-sql/pom.xml b/hazelcast-sql/pom.xml
index 18e3a1027ef7..808e90c10a21 100644
--- a/hazelcast-sql/pom.xml
+++ b/hazelcast-sql/pom.xml
@@ -28,7 +28,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast-tpc-engine/pom.xml b/hazelcast-tpc-engine/pom.xml
index 4cac7e9b47eb..da582a399c04 100644
--- a/hazelcast-tpc-engine/pom.xml
+++ b/hazelcast-tpc-engine/pom.xml
@@ -28,7 +28,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast/pom.xml b/hazelcast/pom.xml
index a887771fc748..68aee1d508e2 100644
--- a/hazelcast/pom.xml
+++ b/hazelcast/pom.xml
@@ -26,7 +26,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml b/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml
index 3d3e565c7593..d643470d1bdd 100644
--- a/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml
+++ b/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml
@@ -16,7 +16,7 @@
com.hazelcast
hazelcast
- 5.7.4
+ 5.7.5
diff --git a/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml b/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml
index 124ec66341aa..513fc263f7e8 100644
--- a/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml
+++ b/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml
@@ -17,7 +17,7 @@
com.hazelcast
hazelcast
- 5.7.4
+ 5.7.5
diff --git a/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml b/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml
index 96882005e451..4463f693b99b 100644
--- a/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml
+++ b/hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml
@@ -16,7 +16,7 @@
com.hazelcast
hazelcast
- 5.7.4
+ 5.7.5
diff --git a/modulepath-tests/pom.xml b/modulepath-tests/pom.xml
index 10c9e6f24148..386f650c0129 100644
--- a/modulepath-tests/pom.xml
+++ b/modulepath-tests/pom.xml
@@ -27,7 +27,7 @@
com.hazelcast
hazelcast-root
- 5.7.4
+ 5.7.5
../pom.xml
diff --git a/pom.xml b/pom.xml
index 30d6daa25413..82fefc410c41 100644
--- a/pom.xml
+++ b/pom.xml
@@ -23,7 +23,7 @@
com.hazelcast
hazelcast-parent
- 5.7.4
+ 5.7.5
hazelcast-parent/pom.xml
@@ -34,7 +34,7 @@
https://github.com/mojohaus/versions/blob/a40373df037b6bcebd915901f72433891bfe691e/versions-maven-plugin/src/main/java/org/codehaus/mojo/versions/SetMojo.java#L330-L332
So instead we need to duplicate
-->
- 5.7.4
+ 5.7.5
pom
Hazelcast Root
Hazelcast In-Memory DataGrid
diff --git a/scripts/pasturestack-build-runtime b/scripts/pasturestack-build-runtime
index addfbe376aaf..48f9593e24f3 100755
--- a/scripts/pasturestack-build-runtime
+++ b/scripts/pasturestack-build-runtime
@@ -3,14 +3,14 @@ set -euo pipefail
cd "$(dirname "$0")/.."
-runtime_version=5.7.4
+runtime_version=5.7.5
output_dir=${PASTURESTACK_OUTPUT_DIR:-dist}
jar_source="hazelcast/target/hazelcast-${runtime_version}.jar"
jar_target="${output_dir}/hazelcast-${runtime_version}.jar"
# Fail before compiling if a reviewed security floor is accidentally reverted.
if find . -name pom.xml -type f -exec grep -l '5.7.0' {} + | grep -q .; then
- echo 'PASTURESTACK_PROJECT_VERSION_MISMATCH expected=5.7.4' >&2
+ echo 'PASTURESTACK_PROJECT_VERSION_MISMATCH expected=5.7.5' >&2
exit 1
fi
grep -Fq '4.1.1' hazelcast-parent/pom.xml
@@ -41,8 +41,8 @@ grep -Fq '14.0.0' hazelcast-parent/pom.
! grep -Fq '' checkstyle/checkstyle.xml
grep -Fq '1.12.2' hazelcast-parent/pom.xml
grep -Fq '3.1.12' hazelcast-parent/pom.xml
-grep -Fq '3.2.2' hazelcast-parent/pom.xml
-grep -Fq '2.22.2' hazelcast-parent/pom.xml
+grep -Fq '3.2.3' hazelcast-parent/pom.xml
+grep -Fq '2.22.3' hazelcast-parent/pom.xml
grep -Fq '1.18.0' hazelcast-parent/pom.xml
grep -Fq '4.3.1' hazelcast-parent/pom.xml
grep -Fq 'jline-terminal-ffm' distribution/pom.xml
@@ -121,9 +121,9 @@ grep -Fq '${postgresql.version}' hazelcast-parent/pom.xml
grep -Fq '${tomcat.embed.version}' pom.xml
grep -Fq 'org.hibernate.orm' hazelcast-it/distribution-it/pom.xml
grep -Fq '${hibernate.orm.version}' hazelcast-it/distribution-it/pom.xml
-grep -Fq '5.7.4' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml
-grep -Fq '5.7.4' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml
-grep -Fq '5.7.4' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml
+grep -Fq '5.7.5' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml
+grep -Fq '5.7.5' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml
+grep -Fq '5.7.5' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml
grep -Fq '3.15.0' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hazelcast-codebase/pom.xml
grep -Fq '3.15.0' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-hz-bootstrap/pom.xml
grep -Fq '3.15.0' hazelcast/src/test/resources/com/hazelcast/client/console/testjob-with-jet-bootstrap/pom.xml
@@ -208,10 +208,10 @@ jar --update \
cmp "$license_source" "$metadata_dir/META-INF/LICENSE"
test -s "$metadata_dir/META-INF/NOTICE"
test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/com.hazelcast/hazelcast/pom.properties")" = "$runtime_version"
-test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/com.fasterxml.jackson.core/jackson-core/pom.properties")" = "2.22.2"
-test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.properties")" = "2.22.2"
-test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/tools.jackson.core/jackson-core/pom.properties")" = "3.2.2"
-test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/tools.jackson.core/jackson-databind/pom.properties")" = "3.2.2"
+test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/com.fasterxml.jackson.core/jackson-core/pom.properties")" = "2.22.3"
+test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.properties")" = "2.22.3"
+test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/tools.jackson.core/jackson-core/pom.properties")" = "3.2.3"
+test "$(sed -n 's/^version=//p' "$metadata_dir/META-INF/maven/tools.jackson.core/jackson-databind/pom.properties")" = "3.2.3"
javap -classpath "$jar_target" -constants com.hazelcast.instance.GeneratedBuildProperties \
> "$metadata_dir/generated-build-properties.txt"
grep -Fq "REVISION = \"${vcs_abbrev}\";" "$metadata_dir/generated-build-properties.txt"
diff --git a/scripts/pasturestack-verify-maven-evidence.py b/scripts/pasturestack-verify-maven-evidence.py
index 868f212a3d5c..b1c6c885d890 100644
--- a/scripts/pasturestack-verify-maven-evidence.py
+++ b/scripts/pasturestack-verify-maven-evidence.py
@@ -8,7 +8,7 @@
MAVEN_NAMESPACE = {"m": "http://maven.apache.org/POM/4.0.0"}
-EXPECTED_RUNTIME = ("com.hazelcast", "hazelcast", "5.7.4")
+EXPECTED_RUNTIME = ("com.hazelcast", "hazelcast", "5.7.5")
def required_text(element, name):
diff --git a/scripts/test-pasturestack-jackson-release.py b/scripts/test-pasturestack-jackson-release.py
new file mode 100644
index 000000000000..69f8205435c8
--- /dev/null
+++ b/scripts/test-pasturestack-jackson-release.py
@@ -0,0 +1,211 @@
+#!/usr/bin/env python3
+"""Offline regression fixtures for the Jackson pins and packaged metadata gate.
+
+Exercises the build script's real gate commands, not a JAR build or a CVE scan.
+"""
+
+import importlib.util
+import os
+from pathlib import Path
+import subprocess
+import tempfile
+import unittest
+import xml.etree.ElementTree as ElementTree
+
+
+ROOT = Path(__file__).resolve().parents[1]
+NS = {"m": "http://maven.apache.org/POM/4.0.0"}
+EXPECTED = {
+ "com.fasterxml.jackson.core/jackson-core": "2.22.3",
+ "com.fasterxml.jackson.core/jackson-databind": "2.22.3",
+ "tools.jackson.core/jackson-core": "3.2.3",
+ "tools.jackson.core/jackson-databind": "3.2.3",
+}
+BUILD = (ROOT / "scripts/pasturestack-build-runtime").read_text(encoding="utf-8")
+
+
+def gate_commands(marker):
+ return "\n".join(line for line in BUILD.splitlines() if marker(line))
+
+
+class JacksonReleaseGateTest(unittest.TestCase):
+ def test_jackson_json_suites_are_selected_and_required_reports(self):
+ workflow = (ROOT / ".github/workflows/security-release-gate.yml").read_text(encoding="utf-8")
+ run = workflow.split(" - name: Run focused legitimate and malicious regression suite\n", 1)[1].split("\n - name:", 1)[0]
+ validator = workflow.split(" - name: Verify every required test suite was discovered\n", 1)[1].split("\n - name:", 1)[0]
+ selector = next(line.strip() for line in run.splitlines() if line.strip().startswith("core_tests='"))
+ selected = selector.split("'", 2)[1].split(",")
+ required = validator.split("core = '''", 1)[1].split("'''.split()", 1)[0].split()
+ for suite in (
+ "com.hazelcast.jet.impl.util.JsonUtilTest",
+ "com.hazelcast.jet.json.impl.JsonUtilImplTest",
+ ):
+ self.assertEqual(selected.count(suite), 1)
+ self.assertEqual(required.count(suite), 1)
+ self.assertIn('all_tests="$core_tests,', run)
+ self.assertIn('-Dtest="$all_tests"', run)
+ self.assertIn("(pathlib.Path('hazelcast/target/surefire-reports'), name)", validator)
+ self.assertIn("for name in core", validator)
+ self.assertIn("if total < 385 or failures or errors or skipped:", validator)
+ self.assertFalse(any("JsonMetadataCreationTest" in suite for suite in selected + required))
+
+ def test_workflow_checks_exact_pr_head_and_retains_successful_artifact(self):
+ workflow = (ROOT / ".github/workflows/security-release-gate.yml").read_text(encoding="utf-8")
+ checkout = workflow.split(" - name: Check out candidate\n", 1)[1].split("\n - name:", 1)[0]
+ retention = workflow.split(" - name: Retain exact reviewed release artifact\n", 1)[1].split("\n - name:", 1)[0]
+ self.assertEqual(
+ [line.strip() for line in checkout.splitlines() if line.strip().startswith("ref:")],
+ ["ref: ${{ inputs.release_ref || github.event.pull_request.head.sha || github.sha }}"],
+ )
+ self.assertEqual(
+ [line.strip() for line in retention.splitlines() if line.strip().startswith("if:")],
+ ["if: success()"],
+ )
+
+ def run_gate(self, commands, folder, **variables):
+ result = subprocess.run(
+ ["bash", "-euo", "pipefail", "-c", commands],
+ cwd=folder,
+ env={**os.environ, **variables},
+ capture_output=True,
+ text=True,
+ timeout=10,
+ )
+ return result.returncode
+
+ def packaged_gate(self, versions):
+ commands = gate_commands(
+ lambda line: line.startswith("test ")
+ and any("/" + coordinate + "/pom.properties" in line for coordinate in EXPECTED)
+ )
+ self.assertEqual(len(commands.splitlines()), len(EXPECTED))
+ for coordinate, version in EXPECTED.items():
+ self.assertIn('/' + coordinate + '/pom.properties")" = "' + version + '"', commands)
+ with tempfile.TemporaryDirectory() as name:
+ folder = Path(name)
+ for coordinate, version in versions.items():
+ metadata = folder / "META-INF/maven" / coordinate / "pom.properties"
+ metadata.parent.mkdir(parents=True, exist_ok=True)
+ metadata.write_text("version=" + version + "\n", encoding="utf-8")
+ return self.run_gate(commands, folder, metadata_dir=str(folder))
+
+ def test_real_parent_boms_select_patched_lines(self):
+ parent = ElementTree.parse(ROOT / "hazelcast-parent/pom.xml").getroot()
+ properties = parent.find("m:properties", NS)
+ self.assertEqual(properties.findtext("m:jackson2.version", namespaces=NS), "2.22.3")
+ self.assertEqual(properties.findtext("m:jackson3.version", namespaces=NS), "3.2.3")
+ boms = {
+ entry.findtext("m:groupId", namespaces=NS): entry.findtext("m:version", namespaces=NS)
+ for entry in parent.findall("m:dependencyManagement/m:dependencies/m:dependency", NS)
+ if entry.findtext("m:artifactId", namespaces=NS) == "jackson-bom"
+ }
+ self.assertEqual(boms, {
+ "com.fasterxml.jackson": "${jackson2.version}",
+ "tools.jackson": "${jackson3.version}",
+ })
+ core = ElementTree.parse(ROOT / "hazelcast/pom.xml").getroot()
+ jackson2 = [
+ entry for entry in core.findall("m:dependencies/m:dependency", NS)
+ if entry.findtext("m:groupId", namespaces=NS) == "com.fasterxml.jackson.core"
+ and entry.findtext("m:artifactId", namespaces=NS) in {"jackson-core", "jackson-databind"}
+ ]
+ self.assertEqual(len(jackson2), 2)
+ self.assertTrue(all(entry.findtext("m:version", namespaces=NS) == "${jackson2.version}"
+ for entry in jackson2))
+
+ def test_artifact_coordinates_preserve_cluster_protocol(self):
+ paths = set()
+ remaining = [ROOT / "pom.xml"]
+ while remaining:
+ path = remaining.pop()
+ if path in paths:
+ continue
+ paths.add(path)
+ project = ElementTree.parse(path).getroot()
+ remaining.extend(path.parent / module.text / "pom.xml"
+ for module in project.findall(".//m:modules/m:module", NS))
+ paths.update((ROOT / "hazelcast/src/test/resources/com/hazelcast/client/console")
+ .glob("testjob-*/pom.xml"))
+ self.assertTrue(paths)
+ fixtures = 0
+ for path in paths:
+ project = ElementTree.parse(path).getroot()
+ for parent in project.findall("m:parent", NS):
+ if parent.findtext("m:groupId", namespaces=NS) == "com.hazelcast":
+ self.assertEqual(parent.findtext("m:version", namespaces=NS), "5.7.5", path)
+ if project.findtext("m:groupId", namespaces=NS) == "com.hazelcast":
+ version = project.findtext("m:version", namespaces=NS)
+ if version is not None:
+ self.assertEqual(version, "5.7.5", path)
+ if "/console/testjob-" in path.as_posix():
+ fixtures += 1
+ dependency = project.find("m:dependencies/m:dependency[m:groupId='com.hazelcast']", NS)
+ self.assertIsNotNone(dependency, path)
+ self.assertEqual(dependency.findtext("m:version", namespaces=NS), "5.7.5", path)
+ self.assertEqual(fixtures, 3)
+ parent = ElementTree.parse(ROOT / "hazelcast-parent/pom.xml").getroot()
+ self.assertEqual(parent.findtext("m:properties/m:hazelcast.runtime.version", namespaces=NS), "5.7.3")
+
+ def test_source_gate_rejects_each_unpatched_parent_property(self):
+ commands = gate_commands(lambda line: line.startswith("grep -Fq ")
+ and ("jackson2.version" in line or "jackson3.version" in line))
+ self.assertEqual(len(commands.splitlines()), 2)
+ for jackson2, jackson3, expected_status in (
+ ("2.22.3", "3.2.3", 0), ("2.22.2", "3.2.3", 1), ("2.22.3", "3.2.2", 1)
+ ):
+ with self.subTest(jackson2=jackson2, jackson3=jackson3):
+ with tempfile.TemporaryDirectory() as name:
+ folder = Path(name)
+ (folder / "hazelcast-parent").mkdir()
+ (folder / "hazelcast-parent/pom.xml").write_text(
+ f"{jackson2}\n"
+ f"{jackson3}\n", encoding="utf-8"
+ )
+ self.assertEqual(self.run_gate(commands, folder), expected_status)
+
+ def test_packaged_gate_accepts_all_four_patched_properties(self):
+ self.assertEqual(self.packaged_gate(EXPECTED), 0)
+
+ def test_packaged_gate_rejects_each_unpatched_embedded_dependency(self):
+ for coordinate in EXPECTED:
+ with self.subTest(coordinate=coordinate):
+ versions = {**EXPECTED, coordinate: "2.22.2" if coordinate.startswith("com.") else "3.2.2"}
+ self.assertNotEqual(self.packaged_gate(versions), 0)
+
+ def test_packaged_gate_rejects_missing_or_ambiguous_properties(self):
+ for coordinate in EXPECTED:
+ with self.subTest(coordinate=coordinate):
+ self.assertNotEqual(self.packaged_gate({key: value for key, value in EXPECTED.items()
+ if key != coordinate}), 0)
+ self.assertNotEqual(self.packaged_gate({**EXPECTED, coordinate: ""}), 0)
+ self.assertNotEqual(self.packaged_gate({**EXPECTED, coordinate:
+ EXPECTED[coordinate] + "\nversion=" + EXPECTED[coordinate]}), 0)
+
+ def test_maven_evidence_rejects_previous_artifact_identity(self):
+ spec = importlib.util.spec_from_file_location(
+ "maven_evidence", ROOT / "scripts/pasturestack-verify-maven-evidence.py"
+ )
+ verifier = importlib.util.module_from_spec(spec)
+ spec.loader.exec_module(verifier)
+ self.assertEqual(verifier.EXPECTED_RUNTIME, ("com.hazelcast", "hazelcast", "5.7.5"))
+ with tempfile.TemporaryDirectory() as name:
+ path = Path(name) / "effective-pom.xml"
+ for version in ("5.7.5", "5.7.4"):
+ path.write_text(
+ ''
+ 'com.hazelcasthazelcast'
+ f'{version}'
+ 'jackson-databind3.2.3'
+ ''
+ 'maven-compiler-plugin3.15.0'
+ '', encoding="utf-8"
+ )
+ if version == "5.7.5":
+ self.assertEqual(verifier.validate_effective_pom(path)["effective_pom_projects"], 1)
+ else:
+ with self.assertRaisesRegex(ValueError, "expected runtime"):
+ verifier.validate_effective_pom(path)
+
+
+if __name__ == "__main__":
+ unittest.main()