@@ -5,6 +5,55 @@ All notable changes to this project will be documented in this file.
55The format is based on [ Keep a Changelog] ( https://keepachangelog.com/en/1.0.0/ ) ,
66and this project adheres to [ Semantic Versioning] ( https://semver.org/spec/v2.0.0.html ) .
77
8+ ## [ 0.15.0] - 2026-08-21
9+
10+ Correctness and supply-chain hygiene. No protocol or public API changes: the ACP surface is
11+ identical to 0.14.0, so this is a drop-in upgrade.
12+
13+ ### Fixed
14+
15+ - ** Notification ordering.** Incoming notifications were dispatched as independent
16+ fire-and-forget subscriptions, so a handler doing any async work could observe them out of
17+ order — visible with agents that stream many rapid ` session/update ` chunks. They are now
18+ serialized through a sink drained by ` concatMap ` , preserving arrival order. Reported and
19+ fixed by @ljiro (#13 , closes #11 ).
20+ - ** Notifications lost on graceful close.** Following from the above, ` closeGracefully() `
21+ completed the notification sink and disposed the drain subscription in the same synchronous
22+ block, discarding anything still queued. Because ` AcpClient.SyncSpec ` wraps every sync
23+ ` sessionUpdateConsumer ` with ` subscribeOn(SYNC_HANDLER_SCHEDULER) ` , sync clients always have
24+ async handlers, so a rapid burst could be lost entirely on close. ` closeGracefully() ` now
25+ waits for the drain to terminate before tearing the session down, bounded by the session's
26+ ` requestTimeout ` so a handler that never completes cannot hang shutdown. ` close() ` still
27+ interrupts immediately — the two methods now differ, as their names imply.
28+ - Notifications arriving after shutdown has begun are still dropped — a graceful shutdown stops
29+ accepting new work while draining what is queued, and JSON-RPC notifications carry no delivery
30+ guarantee — but the log severity now distinguishes that expected case (DEBUG) from overflow,
31+ zero-subscriber and non-serialized emission, which lose traffic on a live session (ERROR).
32+
33+ ### Security
34+
35+ - Jackson 2.21.2 → ** 2.21.5** and Jetty 12.0.14 → ** 12.0.37** , clearing 17 known advisories
36+ (5 high severity) reported against the published dependency closure. Both reach consumers as
37+ compile-scope transitives of ` acp-core ` and ` acp-websocket-jetty ` .
38+
39+ ### Changed
40+
41+ - ** ` LICENSE ` is now the verbatim Apache License 2.0.** The previous file was a paraphrase: it
42+ omitted section 6 (Trademarks) entirely, renumbered the sections that follow, rewrote the
43+ section 2 copyright grant, and narrowed the ` Licensor ` and ` Work ` definitions. Automated
44+ license detection classified the repository as ` NOASSERTION ` while every published POM
45+ declared Apache-2.0.
46+ - ` LICENSE ` and a new ` NOTICE ` are now packaged under ` META-INF ` in every module artifact.
47+ - Removed a redundant ` <repositories> ` declaration from the published parent POM; consumers no
48+ longer inherit a repository definition with snapshots enabled.
49+
50+ ### Build
51+
52+ - Integration tests now execute. Three ` *IT ` classes existed, but Surefire's default includes do
53+ not match ` *IT ` and no Failsafe plugin was configured, so ` mvn verify ` silently skipped them.
54+ - All GitHub Actions are pinned to commit SHAs.
55+ - ` HandlerExceptionTest ` no longer races the async dispatch with a fixed sleep.
56+
857## [ 0.14.0] - 2026-06-11
958
1059Protocol currency: catching up to ACP spec v0.13.6 (June 2026). Supersedes the never-published
@@ -126,3 +175,4 @@ Protocol currency: catching up to ACP spec v0.13.6 (June 2026). Supersedes the n
126175- SLF4J 2.0.16
127176
128177[ 0.9.0 ] : https://github.com/agentclientprotocol/java-sdk/releases/tag/v0.9.0
178+ [ 0.15.0 ] : https://github.com/agentclientprotocol/java-sdk/releases/tag/v0.15.0
0 commit comments