15 hours ago
telegraf

v1.40.1

v1.40.1 [2026-09-21]

Bugfixes

  • #18780 aggregators Prevent duplicate push on early timer fire
  • #19686 common.socket Parse vsock CID and port from URL host
  • #19673 inputs.dns_query Use correct defaults
  • #19509 inputs.kinesis_consumer Resume expired iterators after the last read record
  • #19663 inputs.opcua Respect the server's MaxNodesPerRegisterNodes limit
  • #19671 inputs.opentelemetry Check profile index boundaries
  • #19733 inputs.vault Decode float values of gauges and counters
  • #19734 outputs.amqp Recreate client configuration to successfully reconnect
  • #19670 outputs.kafka Set timeout defaults
  • #19560 outputs.parquet Let a field take precedence over a tag
  • #19559 outputs.parquet Rotate on the age of the open file
  • #19704 processors.reverse_dns Cache answers containing invalid PTR names

Dependency Updates

  • #19642 deps Bump cloud.google.com/go/bigquery from 1.82.0 to 1.83.0
  • #19645 deps Bump cloud.google.com/go/storage from 1.66.0 to 1.67.0
  • #19709 deps Bump cloud.google.com/go/storage from 1.67.0 to 1.67.1
  • #19641 deps Bump github.com/SAP/go-hdb from 1.18.2 to 1.18.3
  • #19710 deps Bump github.com/SAP/go-hdb from 1.18.3 to 1.18.4
  • #19712 deps Bump github.com/apache/arrow-go/v18 from 18.7.0 to 18.8.0
  • #19644 deps Bump github.com/elastic/go-elasticsearch/v9 from 9.5.1 to 9.5.2
  • #19635 deps Bump github.com/go-sql-driver/mysql from 1.10.0 to 1.10.1
  • #19638 deps Bump github.com/grid-x/modbus from 0.0.0-20240503115206-582f2ab60a18 to 1.5.1
  • #19716 deps Bump github.com/hashicorp/consul/api from 1.34.4 to 1.34.5
  • #19707 deps Bump github.com/jackc/pgx/v5 from 5.10.0 to 5.11.0
  • #19649 deps Bump github.com/klauspost/compress from 1.19.2 to 1.20.0
  • #19647 deps Bump github.com/moby/moby/api from 1.55.0 to 1.56.0
  • #19640 deps Bump github.com/moby/moby/client from 0.5.1 to 0.6.0
  • #19634 deps Bump github.com/pion/dtls/v3 from 3.1.6 to 3.1.8
  • #19651 deps Bump github.com/prometheus/client_model from 0.6.2 to 0.6.3
  • #19639 deps Bump github.com/prometheus/common from 0.70.1 to 0.71.0
  • #19652 deps Bump github.com/rclone/rclone from 1.75.0 to 1.75.1
  • #19713 deps Bump github.com/seancfoley/ipaddress-go from 1.8.3 to 1.8.4
  • #19648 deps Bump github.com/shirou/gopsutil/v4 from 4.26.7 to 4.26.8
  • #19636 deps Bump github.com/showwin/speedtest-go from 1.8.2 to 1.8.3
  • #19643 deps Bump github.com/yuin/goldmark from 1.8.5 to 1.8.6
  • #19711 deps Bump go.mongodb.org/mongo-driver from 1.17.9 to 1.17.10
  • #19653 deps Bump go.opentelemetry.io/collector/pdata from 1.65.0 to 1.66.0
  • #19739 deps Bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.45.0
  • #19715 deps Bump go.step.sm/crypto from 0.89.0 to 0.90.0
  • #19720 deps Bump golang.org/x/crypto from 0.56.0 to 0.57.0
  • #19722 deps Bump golang.org/x/mod from 0.40.0 to 0.41.0
  • #19708 deps Bump golang.org/x/oauth2 from 0.36.0 to 0.37.0
  • #19718 deps Bump golang.org/x/sync from 0.22.0 to 0.23.0
  • #19723 deps Bump golang.org/x/sys from 0.47.0 to 0.48.0
  • #19721 deps Bump golang.org/x/term from 0.45.0 to 0.46.0
  • #19714 deps Bump golang.org/x/text from 0.41.0 to 0.42.0
  • #19717 deps Bump golang.org/x/tools from 0.49.0 to 0.50.0
  • #19650 deps Bump google.golang.org/api from 0.295.0 to 0.297.0
  • #19646 deps Bump modernc.org/sqlite from 1.57.0 to 1.58.0
  • #19705 deps Bump srebhan/label-milestone-action from 1.1.1 to 1.2.0
  • #19706 deps Bump the aws-sdk-go-v2 group with 11 updates
  • #19633 deps Bump the aws-sdk-go-v2 group with 11 updates
  • #19745 deps Downgrade google.golang.org/grpc from 1.85.0-dev to 1.84.0

Packages

Arch Platform Package SHA256
arm64 CentOS telegraf-1.40.1-1.aarch64.rpm a67ef92e35c70e140be041e2b82e8040cfd1503a05001dd03e72d0029255f216
armel CentOS telegraf-1.40.1-1.armel.rpm caba5fd251a0ada9df2ed0f40fd77d6b1dc8e430b44c2715eabb9319974dc07e
armv6hl CentOS telegraf-1.40.1-1.armv6hl.rpm 3f21d44ae8fdaab62fdaf38ffbf6a8db73639f7ae21227e281806ac223b142ce
i386 CentOS telegraf-1.40.1-1.i386.rpm e1ca4f64eb721680b89e2d658da6845978610afc3eb5caddf034cfe163df8e80
unknown CentOS telegraf-1.40.1-1.loongarch64.rpm 2e845e19ca809643a009a4a0b3378216bb01d9836bc37a4a2d6cd5c3073bcf94
ppc64le CentOS telegraf-1.40.1-1.ppc64le.rpm 254991c1e4c5c2c1abdf4d938427ab92fdfccd114c9e3e0356beb68c9937f2d5
riscv64 CentOS telegraf-1.40.1-1.riscv64.rpm cd0c36ae3aaa08f0a21f51ff0c19dec7ab94e1e124aa92632134d594b119f538
s390x CentOS telegraf-1.40.1-1.s390x.rpm 9ce930ad004359219bdfb2ceb8396cbf3d25383aaca1af296507011aba567cf0
amd64 CentOS telegraf-1.40.1-1.x86_64.rpm 9da98a513600d5f8e08e721cec77683063c50bb1a55a3662c1ff2e1d0e25fe85
amd64 macOS telegraf-1.40.1_darwin_amd64.dmg 9dffa6a6c89c001b5cc973f933b9403035ce55382ef3d0ff51bbea6efc825dfd
amd64 macOS telegraf-1.40.1_darwin_amd64.tar.gz 19b7886b3507d99f49b6459f892955ad60d4c367035887e2aa77c05d8fd0467a
arm64 macOS telegraf-1.40.1_darwin_arm64.dmg 29fa344dde60ccf843bb78e34bc43f7803169d9d438f54689d3402417ed6af71
arm64 macOS telegraf-1.40.1_darwin_arm64.tar.gz 0b7094777deb982d4f36291478035e6c146cb52436fc4b3ad200d4e71e2dc217
amd64 FreeBSD telegraf-1.40.1_freebsd_amd64.tar.gz 7abc56443b445b53b3b01f073ab06b104fc6d85001a646b7914496fba3376a35
armv7 FreeBSD telegraf-1.40.1_freebsd_armv7.tar.gz 62178ce8dc2857babb290ec09a3b1979466034a1aa41a96a4b842d6191012cc5
i386 FreeBSD telegraf-1.40.1_freebsd_i386.tar.gz 51418b244bd81ba0a39bb8a59a8691ca1894071a84a5f39a34642503ba700fae
amd64 Linux telegraf-1.40.1_linux_amd64.tar.gz 3a6cfa0ab1b08a31687d80b3813304706280dba789348b5dad539bdbe0a72d52
arm64 Linux telegraf-1.40.1_linux_arm64.tar.gz ad585998c635e065ef3c5ffed4c1974731ac280f2947a04179a70c205b3147af
armel Linux telegraf-1.40.1_linux_armel.tar.gz 1f076bf3b609f8fcae50c1e772119bbfeaa5a9de122e4ede934b3784b2ddeab3
armhf Linux telegraf-1.40.1_linux_armhf.tar.gz b197f69f42d80aabc4d5287e9b818153da72184eb040c2a96ff0c9e0f72f035a
i386 Linux telegraf-1.40.1_linux_i386.tar.gz 99858c0aed45b1de53ccf325548a90966e99759c885cddc0b96b1efd39466c27
loong64 Linux telegraf-1.40.1_linux_loong64.tar.gz 3d775f3aae936e1717ea5ec329f3a1b2de545d330942b8c529f4442455d8c788
mips Linux telegraf-1.40.1_linux_mips.tar.gz c9d7453469195b214258ace8280fe0c272632ab060d12291e4182f57c3538b61
mipsel Linux telegraf-1.40.1_linux_mipsel.tar.gz b6962d772d2bd37d78952ec5a9d33cf4e561329b229c558e15acc94e37f1e945
ppc64le Linux telegraf-1.40.1_linux_ppc64le.tar.gz af8b0cc3e4ca9cf49f2b9f5c0d8391ecd2710bb5637b2a0b8be224e63f5d1a4e
riscv64 Linux telegraf-1.40.1_linux_riscv64.tar.gz a08d00bdc42d08d0ac0976b3f9e33c7e632440d45b7e0b7202a648ce02b79049
s390x Linux telegraf-1.40.1_linux_s390x.tar.gz 63ef9315009fa820ff1ee806c0c9bc9ebcf6037d858e8c8604c750e82d99e6b1
amd64 Windows telegraf-1.40.1_windows_amd64.zip cabe07907628afc17ce8c58a1c27b3a55a838b1fb9418b2c05e9342e6e8af8d9
arm64 Windows telegraf-1.40.1_windows_arm64.zip 5a27cfdcb42388bed362eddbb69147d5ff59754781fb422c5b681dca2e0e7df6
i386 Windows telegraf-1.40.1_windows_i386.zip 6b192a1b0c058b7da6581d444130d3cd588ff53ae1a7079b706df797be93e1c4
amd64 Debian telegraf_1.40.1-1_amd64.deb 6d7f22abf3e463a209d82004fc4ecbabd5e332312d94992f0050c7bceb0d5c2a
arm64 Debian telegraf_1.40.1-1_arm64.deb 07fd200434928f8387cdf7c49ac65aee2b2db225f26895322cd52166f67af256
armel Debian telegraf_1.40.1-1_armel.deb c16aa1b144d8cc09c456531258f1a0133d1820f0dbd79c9ade1fce40c912fbb4
armhf Debian telegraf_1.40.1-1_armhf.deb e785baf38cd3647b3f65666d0dc1c237816c729dc30667d7ab6e7fa0d7e975e3
i386 Debian telegraf_1.40.1-1_i386.deb f67e0c2f952c92976e6d8bac2fc9a4eb9ed47d8817bd8389cff1e535c91a4704
loong64 Debian telegraf_1.40.1-1_loong64.deb 9434919de731ef41a742dbf8b93d28f2fa77fab65d5f2bbd1e0c1b0c95d9720c
mips Debian telegraf_1.40.1-1_mips.deb a6a7fe76affb46dfeb5f28b414d75b24c45767cfbb98db62c075a3981b9f14a9
mipsel Debian telegraf_1.40.1-1_mipsel.deb d7f84e11654826aa68bd54bf1bf6a95e39fea458f12beb3e71096d7d118d3935
ppc64el Debian telegraf_1.40.1-1_ppc64el.deb 4c2f57a9e9436b06ae89a61a8f5e2fdc9b6c3905a813a34f71e28fd9e26b6a16
riscv64 Debian telegraf_1.40.1-1_riscv64.deb 4fda7701381bc4817dcd2a29076d2bcf047dfdb79772d09ad5d0f1575da7da63
s390x Debian telegraf_1.40.1-1_s390x.deb a5ce476fbc20724fb21c6afe592565c0a0675847ab3fda41a9e959fbd83d9ad7
19 hours ago
ClickHouse
20 hours ago
rustfs

RustFS 1.0.1-preview.9 (preview)

What's Changed

New Contributors

Full Changelog: https://github.com/rustfs/rustfs/compare/1.0.0...1.0.1-preview.9

1 days ago
nacos

3.3.0-RC

Nacos 3.3.0-RC is a release candidate for the Nacos 3.3 feature iteration. It builds on 3.3.0-BETA with expanded AI Registry capabilities, DNS service discovery, and further security and compatibility improvements.

This release focuses on:

  • Protocol-neutral Agent management and RAD discovery, including transport negotiation and Watch/Push.
  • Shared AI resource search and unified MCP lifecycle management.
  • DNS-based service discovery and Config SDK improvements.
  • Authentication enabled by default, migration safeguards, and runtime stability.

The main feature updates include:

  • Agent registration, endpoint publication, discovery, Java SDKs, and Console management, with a migration path for historical A2A data.
  • Search and discovery across Agent, AgentSpec, Skill, Prompt, and MCP resources, including shared indexes and artifact retrieval.
  • MCP draft, review, publish, online/offline, and visibility management while retaining existing serving contracts.
  • Optional DNS A-record queries over UDP and TCP.

The release also retains BETA's dynamic plugin management, distributed locks, Jackson 2/3 support, and Spring Boot 4 compatibility. It includes further fixes across Config, Naming, Console, clients, AI storage, and authorization.

These notes are cumulative for 3.3.0 and include the changes documented in 3.3.0-BETA.


Detailed changes in this release:

Feature

  • #50 Add optional DNS service discovery with A-record queries over UDP and TCP.
  • #14466 Add a neutral JSON adapter with Jackson 2 and Jackson 3 runtime support.
  • #14804 Add protocol-neutral Agent lifecycle management, Console workflows, RAD discovery, runtime endpoints, transport negotiation, Watch/Push, and Java SDKs.
  • #15279 Add distributed reentrant and non-reentrant locks with watchdog renewal, FIFO waiting, gRPC notifications, Raft consistency, and a Java Lock SDK.
  • #15471 Support SkillSpector as an AI publish pipeline.
  • #15475 Add unified dynamic plugin configuration, lifecycle management, runtime updates, deterministic discovery, and Console configuration workflows.
  • #15476#15604 Add plugin-owned visibility grant and revoke APIs and Console management for Skill and AgentSpec resources.
  • #15541 Add Agentic Resource Discovery with search, exploration, artifact retrieval, visibility filtering, persistent indexes, and hybrid keyword and vector retrieval.
  • #15640 Support Nacos server deployments on Linux RISC-V with RocksDB.
  • #15761 Add shared MCP lifecycle management with drafts, review, publish, online/offline operations, visibility, Java SDKs, and historical reconciliation while preserving existing Config/Naming serving data.

Enhancement/Refactor

  • #8354 Replace the mandatory Prometheus client dependency with a pluggable client metrics SPI and a no-op default.
  • #12064 Support configuring the gRPC port offset through individual client properties.
  • #12734 Add request/result-based Config SDK methods, encrypted Config CAS publishing, and conditional queries with local cache reuse.
  • #13690 Log the resolved client logging configuration and include namespace IDs in subscription logs.
  • #14804 Improve Agent detail, draft creation, version history, and legacy A2A Console workflows.
  • #14817 Disable selected deprecated Pipeline and MCP import APIs by default and provide a shared temporary compatibility switch.
  • #14932 Reduce read-path contention and improve index consistency in the legacy MCP cache.
  • #14980 Support deregistering persistent Naming instances from Console v3.
  • #15315#15561 Improve Skill upload precheck, conflict handling, and server-side ZIP validation.
  • #15322 Remove obsolete Config migration compatibility code and retain only the current Config storage model.
  • #15346 Manage the reserved latest label for AI resources on the server.
  • #15357 Enable Client API authentication by default and validate standard integration scenarios with authentication enabled.
  • #15432#15440#15441 Remove reviewed unused Java code while preserving required compatibility contracts.
  • #15448 Improve English translations in Console UI Next.
  • #15486 Include the Skill owner in upload permission-denied messages.
  • #15606 Return a stable per-item result for every Skill batch upload candidate.
  • #15661 Restrict distributed embedded database query results to supported scalar types and registered row mappers.
  • #15678 Decouple the visibility plugin SPI from server runtime modules.
  • #15686#15692 Align authorization method resolution with Spring MVC routing and expand controller-level authorization regression coverage.
  • #15687 Authenticate native JRaft gRPC requests with server identity and a rolling-upgrade enforcement transition.
  • #15695 Improve Config detail, edit, and history page layouts with larger content areas and full-screen reading.
  • #15720 Automatically publish the first uploaded Skill version.
  • #15746 Add operator-controlled outbound access policies for MCP tool imports.
  • #15838 Clarify that rolling back the first inserted Config history record deletes the configuration.
  • #15854 Remove untagged legacy Raft request parsing and preserve explicit errors for malformed log entries.

BugFix

  • #11122 Accept healthCheckEnabled as a health-check switch entry while retaining the legacy check alias.
  • #11890 Avoid removing metadata for instances that still exist after restart.
  • #12557 Retry Config dump write-lock acquisition to prevent stale MD5 cache data.
  • #14008 Fix native-image metadata required to establish gRPC client connections.
  • #14804 Keep AI search available with partial results while indexes are being backfilled.
  • #14981#15468 Fix concurrent Config publish duplicate-key handling through the datasource dialect SPI, including PostgreSQL unique_violation.
  • #15410 Fix trailing separators when joining collections containing null elements.
  • #15415 Prevent malformed config-plugin property names from discarding valid plugin configuration.
  • #15420 Fix Skill ZIP uploads with invalid or unavailable version candidates.
  • #15425 Prevent out-of-range batch indexes from causing IndexOutOfBoundsException.
  • #15446 Fix page count calculation for empty and exactly divisible result sets.
  • #15447 Prevent NamingUtils.getServiceName from failing on a trailing service separator.
  • #15466 Correct @Since annotations for Skill upload APIs.
  • #15470 Prevent Naming connection cleanup from waiting for unrelated distributed-lock Raft writes.
  • #15475 Fix standalone Console auth plugin initialization and forward the caller identity to downstream Server requests.
  • #15476 Enforce Prompt visibility on list, detail, version, download, and Client read APIs.
  • #15477 Wait for persistent service metadata before starting health checks.
  • #15490 Fix Chinese text corruption in Skill Scanner pipeline reports on Windows.
  • #15494 Restore complete MCP tool advanced-template support in Console UI Next.
  • #15510 Reject explicitly supplied invalid Bearer tokens instead of falling back to anonymous access.
  • #15534 Generate deterministic, ASCII-safe physical Config keys for AI resources.
  • #15543 Restore case-sensitive collation for newly initialized MySQL Config schemas.
  • #15557 Fix startup failures when plugin state snapshots are restored before unified plugin discovery.
  • #15560 Preserve MCP tool passthrough authentication when editing and publishing runtime templates.
  • #15603 Fix visibility query conversion when explicitly authorized resources are present.
  • #15618 Try lower-priority explicit Skill upload versions before generating a version.
  • #15620 Allow AI resource versions to be resubmitted after completed or stale review results.
  • #15625 Fix gray Config cache null access and cross-thread visibility in Config disk services and client connections.
  • #15634 Fix API authorization metadata, custom resource parser precedence, AgentSpec authorization, and Prometheus security path matching.
  • #15642 Make AI resource deletion cleanup-first and retryable across all stored versions.
  • #15658 Keep AI resource reads, updates, and deletion bound to the persisted storage provider.
  • #15660 Fix standalone Console startup when the Config clone source-permission checker is unavailable.
  • #15663 Preserve case-sensitive AI resource identities in MySQL search and task tables.
  • #15675 Preserve nullable MCP tool output schemas during editing, display, and OpenAPI import.
  • #15682 Prevent login responses from disclosing whether a username exists.
  • #15689 Preserve string serialization of Config storage IDs with Jackson 3 to avoid numeric precision loss.
  • #15701 Fix Config history next-record queries on Derby and preserve gray-version filtering.
  • #15703 Migrate the legacy skills.sh importer state key without overriding canonical configuration.
  • #15705 Clean removed Skill and AgentSpec draft files while retaining retry metadata after storage failures.
  • #15710 Declare the required SQL LIKE escape clause for Derby, Oracle, and other affected dialects.
  • #15712#15827 Reject unsafe instance addresses, HTTP targets, headers, and MySQL connection options in active health checks.
  • #15714 Handle encoded context paths consistently in the legacy controller-method resolver.
  • #15718 Escape all LIKE predicates when searching embedded roles with username filters.
  • #15724 Forward the namespace when querying Config listeners by IP across cluster members.
  • #15744 Align bootstrap and distribution configuration defaults.
  • #15763 Reject invalid IPv6 mixed addresses with too many explicit address blocks.
  • #15803 Reject unsafe AgentSpec and Skill ZIP layouts and enforce entry-count and decompression limits.
  • #15804 Reject unsafe filesystem paths before Config, archive, and local rule-storage operations.
  • #15821 Increase the embedded Derby connection timeout to prevent initialization failures on slow storage.
  • #15844 Use the correct default gRPC protocol negotiator type.
  • #15847 Restore public defaults for newly created Agent and MCP resources and preserve existing visibility scopes.
  • #15850#15851 Select the default JDBC driver from the datasource dialect and clarify non-MySQL configuration examples.
  • #15853 Return schema metadata in current, historical, and previous-version Config details.
  • #15864 Resolve HEAD requests through their GET mapping in the legacy controller-method cache.
  • #15866 Remove server-list event subscriptions on client shutdown and prevent callbacks from accessing a closed server-list provider.

Dependencies

  • #14944 Upgrade Spring Boot from 3.5.14 to 4.0.6.
  • #15470 Upgrade SOFA JRaft to 1.4.1 while preserving callback cache behavior and JRaft authentication.
  • #15584 Upgrade Maven Compiler Plugin from 3.5.1 to 3.15.0 for JDK 25 build compatibility.
  • #15645#15834 Upgrade compatible legacy and next Console dependencies, patch the sanitizer bundled with Monaco, and refresh packaged frontend assets.
  • #15707 Upgrade Log4j API from 2.25.4 to 2.25.5.
  • #15767 Upgrade gRPC to 1.81.0 to address CVE-2026-33871.

Breaking Change Notice

Nacos 3.3.0-RC changes authentication defaults, disables selected deprecated APIs, and introduces migration and compatibility boundaries that require attention before upgrading.

Affected users:

  • Applications that connect without credentials and rely on the previous Client API authentication default.
  • Integrations using deprecated Pipeline or Console MCP import endpoints.
  • Deployments with legacy Config data, unsafe historical AI Config keys, or untagged Raft logs.
  • Clusters migrating historical A2A or MCP resources, or planning a downgrade after migration or JRaft authentication enforcement.
  • Applications relying on built-in Prometheus client metrics, private-network MCP tool imports, or implicit Agent/MCP visibility defaults.

Recommended upgrade path:

  • Prepare Client API credentials. An absent nacos.core.auth.enabled now means true. Existing explicit false settings remain effective. If credentials are not ready, explicitly retain false during migration, provision identities and permissions, verify client access, and then enable authentication consistently on every member. Admin and Console authentication defaults are unchanged.
  • Migrate deprecated AI API calls. The deprecated Pipeline base-path list and path-variable detail endpoints, and the old Console MCP import endpoints, return HTTP 410 with API_DEPRECATED by default. Use Pipeline /list and /detail endpoints and the unified /v3/console/ai/import/validate and /execute endpoints. nacos.core.api.compatibility.enabled=true temporarily reopens the selected endpoints; the old nacos.ai.resource.import.legacy-mcp-api-enabled property is no longer recognized.
  • Complete legacy Config migrations. Upgrade pre-3.0 deployments through an earlier Nacos 3.x version. Migrate default-namespace data from the empty tenant to public, and legacy beta/tag data from config_info_beta and config_info_tag to config_info_gray. For the nacos_config AI storage provider, explicitly migrate affected historical non-ASCII or overlength Config coordinates to the deterministic ASCII-safe mapping.
  • Check persisted Raft logs. Nacos 3.3 no longer replays untagged entries, including entries originally written by Nacos 2.0.x and retained across intermediate upgrades. Complete recovery and snapshot/log migration with a version that can read those entries before upgrading. Changing the running version alone does not convert persisted logs.
  • Plan historical A2A migration explicitly. The default nacos.ai.a2a.compatibility.mode=CANONICAL does not scan historical data. For historical 3.0–3.2 A2A data, follow the migration runbook and configure new members with AUTO and a consistent migration policy. Early 3.3 AUTO deployments require the runbook's separate preflight. After permanent canonical cutover, a legacy-only server must not rejoin. MCP reconciliation also has a one-way managed-lifecycle transition; preserve its migration state and existing Config/Naming serving data.
  • Keep cluster server identities consistent. Native JRaft authentication becomes enforced once all members advertise support, and enforcement persists across restarts. A rolling downgrade to members without JRaft credential support is not guaranteed to remain available.
  • Install a client metrics provider when needed. The mandatory Prometheus dependency has been removed from nacos-client. Without an implementation of NacosClientMetricsProvider, client metrics recording is a no-op, even when enableClientMetrics is enabled.
  • Review MCP import access policy. Public MCP import targets remain available by default. Private or local targets must be explicitly allowed with nacos.console.ai.mcp.import.allowed-private-addresses; HTTP redirects are not followed.
  • Set private resource scopes explicitly. The built-in visibility plugin defaults new Agent and MCP resources to PUBLIC. Existing stored scopes and Prompt/Skill defaults are unchanged. Set the intended private scope for resources that should not be discoverable by other users.
  • Back up and rehearse the upgrade. Back up the database and relevant persisted data, then verify authentication, historical resource migration, discovery, and client behavior in staging before upgrading to Nacos 3.3.0-RC.

Deployments without the affected historical data do not require the data migrations above; the new authentication defaults and applicable API changes still need review.


Java Version Requirements

Module Java Required
Nacos-Server / Nacos-Console Java 17
Nacos-Client Java 8
Nacos-Maintainer-Client Java 8

New Contributors

Full Changelog: https://github.com/alibaba/nacos/compare/3.2.2...3.3.0-RC

1 days ago
rustfs

RustFS 1.0.1-preview.8 (preview)

What's Changed

New Contributors

Full Changelog: https://github.com/rustfs/rustfs/compare/1.0.0...1.0.1-preview.8

2 days ago
loongcollector

Release v3.4.1

Release v3.4.1

LoongCollector v3.4.1 是继 v3.3.5 之后的功能与稳定性版本,覆盖约 48 个提交。本版本重点增强 LLM 可观测(AgentSight)eBPF CPU Profiling原生/Go 混合流水线自监控闭环,并修复一批文件采集、Checkpoint、Kubernetes 与安全相关问题。

完整提交与 PR 列表见:v3.3.5...v3.4.1

破坏性变更

升级前请确认运行环境满足以下要求:

  • 源码构建要求 Go 1.25.9+
  • 容器运行时必须提供 CRI v1,建议使用 containerd 1.6+不再兼容 CRI v1alpha2
  • Docker 客户端升级后,Docker Engine 最低要求为 19.03+(Docker API 1.40+)。Docker Engine 18.09 及更早版本不再兼容。

主要新特性

LLM 可观测(AgentSight)

  • 新增并持续增强 eBPF AgentSight 输入插件,用于采集 LLM / Agent 流量(会话增量、step/sequence、工具调用等)。
  • 支持 DashScope 等域名识别、不可解析流量回退为 Raw HTTP,以及 tool_call 名称保留。
  • 优化 input messages delta / 哈希口径,避免 system prompt 抖动导致增量失效。

eBPF CPU Profiling

  • 集成 coolbpf CPU Profiling,支持进程/容器发现、多配置、采集间隔与自定义应用名等能力。

自监控与混合流水线

  • 支持将自监控数据发送到 Go Pipeline,并补齐 Go↔C++ 自监控 Protobuf 推送/接收协议。
  • 新增一次性采集插件 input_internal_agent_logs_onetime,便于导出 Agent 自身日志。
  • 原生 Input 默认允许与 Go 插件组合;补齐原生 Input 事件类型注册、v2 插件 PassThroughEvents,以及 Extended Flusher 的 FlusherV2.Export

采集与平台能力

  • input_file WHOLE_FILE 覆盖写检测与按行/字符边界的分块输出。
  • service_syslog 支持自动配置 rsyslog 转发(AutoConfigRsyslog),实现开箱即用的主机 syslog 采集。
  • 新增 working_interface,用于指定主机 IP 解析网卡。
  • Prometheus 插件支持 Windows;OTel Proto JSON 反序列化忽略未知字段。
  • 构建/发布脚本识别 riscv64

重要修复

  • 安全:升级 Go 1.25.9+ 及一批存在漏洞的依赖(含 gRPC CVE-2026-84304 等),修复 OSV 扫描问题。
  • 稳定性:启动时安装 OpenSSL 线程锁回调,避免旧版 OpenSSL 多线程 SSL 场景崩溃。
  • Kubernetes / 容器:修复大规模集群剧烈变更时的 k8s-meta 内存泄漏;修复 Pod 重建后静态容器 K8s label 陈旧 的问题。
  • 文件采集 / Checkpoint:修复 dump 轮次误清 pending checkpoint、dump key 冲突导致活跃文件 checkpoint 丢失;配置目录扫描错误码与不完整 diff 处理更稳健。
  • 指标与发送:热更后 reader 指标 gauge 不再掉零;SLS Flusher 跳过空 package list;Prometheus 启动 IP 回退链与 loopback 绑定修复。
  • 其他:时间解析 timeStrCache 不再被未匹配尾缀污染;ICMP RTT 精度提升;Windows ETW session 清理与命名加固;VM relabel 空指针、神农 profile 后缀匹配等边界问题。

下载

Filename OS Arch SHA256 Checksum
loongcollector-3.4.1.linux-amd64.tar.gz Linux x86-64 loongcollector-3.4.1.linux-amd64.tar.gz.sha256
loongcollector-3.4.1.linux-arm64.tar.gz Linux arm64 loongcollector-3.4.1.linux-arm64.tar.gz.sha256
loongcollector-3.4.1.windows-amd64.zip Windows x86-64 loongcollector-3.4.1.windows-amd64.zip.sha256

Docker Image

拉取命令

docker pull sls-opensource-registry.cn-shanghai.cr.aliyuncs.com/loongcollector-community-edition/loongcollector:3.4.1
docker pull ghcr.io/alibaba/loongcollector:3.4.1
docker pull ghcr.io/alibaba/loongcollector:latest

镜像标签

  • sls-opensource-registry.cn-shanghai.cr.aliyuncs.com/loongcollector-community-edition/loongcollector:3.4.1
  • ghcr.io/alibaba/loongcollector:3.4.1
  • ghcr.io/alibaba/loongcollector:latest

New Contributors