Skip to content

Commit 35d66d2

Browse files
committed
Add the 0.15.0 changelog entry
Correctness and supply-chain hygiene: notification ordering and the graceful-close drain, Jackson/Jetty CVE remediation, the verbatim Apache-2.0 license and packaged LICENSE/NOTICE, and the build fixes. No protocol or public API changes - verified: one main-source file changed since v0.14.0, with no public or protected signature changes.
1 parent 3bdc366 commit 35d66d2

1 file changed

Lines changed: 50 additions & 0 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,55 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [0.15.0] - 2026-08-21
9+
10+
Correctness and supply-chain hygiene. No protocol or public API changes: the ACP surface is
11+
identical to 0.14.0, so this is a drop-in upgrade.
12+
13+
### Fixed
14+
15+
- **Notification ordering.** Incoming notifications were dispatched as independent
16+
fire-and-forget subscriptions, so a handler doing any async work could observe them out of
17+
order — visible with agents that stream many rapid `session/update` chunks. They are now
18+
serialized through a sink drained by `concatMap`, preserving arrival order. Reported and
19+
fixed by @ljiro (#13, closes #11).
20+
- **Notifications lost on graceful close.** Following from the above, `closeGracefully()`
21+
completed the notification sink and disposed the drain subscription in the same synchronous
22+
block, discarding anything still queued. Because `AcpClient.SyncSpec` wraps every sync
23+
`sessionUpdateConsumer` with `subscribeOn(SYNC_HANDLER_SCHEDULER)`, sync clients always have
24+
async handlers, so a rapid burst could be lost entirely on close. `closeGracefully()` now
25+
waits for the drain to terminate before tearing the session down, bounded by the session's
26+
`requestTimeout` so a handler that never completes cannot hang shutdown. `close()` still
27+
interrupts immediately — the two methods now differ, as their names imply.
28+
- Notifications arriving after shutdown has begun are still dropped — a graceful shutdown stops
29+
accepting new work while draining what is queued, and JSON-RPC notifications carry no delivery
30+
guarantee — but the log severity now distinguishes that expected case (DEBUG) from overflow,
31+
zero-subscriber and non-serialized emission, which lose traffic on a live session (ERROR).
32+
33+
### Security
34+
35+
- Jackson 2.21.2 → **2.21.5** and Jetty 12.0.14 → **12.0.37**, clearing 17 known advisories
36+
(5 high severity) reported against the published dependency closure. Both reach consumers as
37+
compile-scope transitives of `acp-core` and `acp-websocket-jetty`.
38+
39+
### Changed
40+
41+
- **`LICENSE` is now the verbatim Apache License 2.0.** The previous file was a paraphrase: it
42+
omitted section 6 (Trademarks) entirely, renumbered the sections that follow, rewrote the
43+
section 2 copyright grant, and narrowed the `Licensor` and `Work` definitions. Automated
44+
license detection classified the repository as `NOASSERTION` while every published POM
45+
declared Apache-2.0.
46+
- `LICENSE` and a new `NOTICE` are now packaged under `META-INF` in every module artifact.
47+
- Removed a redundant `<repositories>` declaration from the published parent POM; consumers no
48+
longer inherit a repository definition with snapshots enabled.
49+
50+
### Build
51+
52+
- Integration tests now execute. Three `*IT` classes existed, but Surefire's default includes do
53+
not match `*IT` and no Failsafe plugin was configured, so `mvn verify` silently skipped them.
54+
- All GitHub Actions are pinned to commit SHAs.
55+
- `HandlerExceptionTest` no longer races the async dispatch with a fixed sleep.
56+
857
## [0.14.0] - 2026-06-11
958

1059
Protocol currency: catching up to ACP spec v0.13.6 (June 2026). Supersedes the never-published
@@ -126,3 +175,4 @@ Protocol currency: catching up to ACP spec v0.13.6 (June 2026). Supersedes the n
126175
- SLF4J 2.0.16
127176

128177
[0.9.0]: https://github.com/agentclientprotocol/java-sdk/releases/tag/v0.9.0
178+
[0.15.0]: https://github.com/agentclientprotocol/java-sdk/releases/tag/v0.15.0

0 commit comments

Comments
 (0)