dependabot[bot] opened a new pull request, #16484:
URL: https://github.com/apache/pinot/pull/16484

   Bumps [org.apache.pulsar:pulsar-bom](https://github.com/apache/pulsar) from 
4.0.5 to 4.0.6.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/pulsar/releases";>org.apache.pulsar:pulsar-bom's 
releases</a>.</em></p>
   <blockquote>
   <h2>v4.0.6</h2>
   <h4>2025-07-31</h4>
   <h3>Known issues</h3>
   <ul>
   <li>The changes from PR <a 
href="https://redirect.github.com/apache/pulsar/pull/24533";>#24533</a> included 
in this release might break proxy authorization scenarios for some custom 
implementations of AuthorizationProvider, where both the proxy's auth data 
(<code>authDataSource</code>) and the original client's auth data 
(<code>originalAuthDataSource</code>) need to be validated separately.
   <ul>
   <li>A fix will be provided in the next release with <a 
href="https://redirect.github.com/apache/pulsar/pull/24593";>#24593</a></li>
   </ul>
   </li>
   </ul>
   <h3>Library updates</h3>
   <ul>
   <li>[improve] Upgrade pulsar-client-python to 3.8.0 in Docker image (<a 
href="https://redirect.github.com/apache/pulsar/pull/24544";>#24544</a>)</li>
   <li>[improve][misc] Upgrade Netty to 4.1.122.Final and tcnative to 
2.0.72.Final (<a 
href="https://redirect.github.com/apache/pulsar/pull/24397";>#24397</a>)</li>
   <li>[fix][sec] Upgrade Kafka connector and clients version to 3.9.1 to 
address CVE-2025-27818 (<a 
href="https://redirect.github.com/apache/pulsar/pull/24564";>#24564</a>)</li>
   <li>[fix][sec] Upgrade pulsar-function-go dependencies to address 
CVE-2025-22868 (<a 
href="https://redirect.github.com/apache/pulsar/pull/24547";>#24547</a>)</li>
   <li>[improve][build] replace org.apache.commons.lang to 
org.apache.commons.lang3 (<a 
href="https://redirect.github.com/apache/pulsar/pull/24473";>#24473</a>)</li>
   <li>[improve][build] Bump org.apache.commons:commons-lang3 from 3.17.0 to 
3.18.0 (<a 
href="https://redirect.github.com/apache/pulsar/pull/24514";>#24514</a>)</li>
   <li>[improve][broker] Upgrade bookkeeper to 4.17.2/commons-configuration to 
2.x/grpc to 1.72.0 and enable ZooKeeper client to establish connection in 
read-only mode (<a 
href="https://redirect.github.com/apache/pulsar/pull/24468";>#24468</a>)</li>
   <li>[fix][sec] Remove dependency on out-dated commons-configuration 1.x (<a 
href="https://redirect.github.com/apache/pulsar/pull/24562";>#24562</a>)</li>
   <li>[improve][misc] Upgrade RE2/J to 1.8 (<a 
href="https://redirect.github.com/apache/pulsar/pull/24530";>#24530</a>)</li>
   </ul>
   <h3>Broker</h3>
   <ul>
   <li>[fix][broker] expose consumer name for partitioned topic stats (<a 
href="https://redirect.github.com/apache/pulsar/pull/24360";>#24360</a>)</li>
   <li>[fix][broker] Fix Broker OOM due to too many waiting cursors and reuse a 
recycled OpReadEntry incorrectly (<a 
href="https://redirect.github.com/apache/pulsar/pull/24551";>#24551</a>)</li>
   <li>[fix][broker] Fix deduplication replay might never complete for 
exceptions (<a 
href="https://redirect.github.com/apache/pulsar/pull/24511";>#24511</a>)</li>
   <li>[fix][broker] Fix duplicate increment of ADD_OP_COUNT_UPDATER in 
OpAddEntry (<a 
href="https://redirect.github.com/apache/pulsar/pull/24506";>#24506</a>)</li>
   <li>[fix][broker] Fix exclusive producer creation when last shared producer 
closes (<a 
href="https://redirect.github.com/apache/pulsar/pull/24516";>#24516</a>)</li>
   <li>[fix][broker] Fix issue that topic policies was deleted after a sub 
topic deleted, even if the partitioned topic still exists (<a 
href="https://redirect.github.com/apache/pulsar/pull/24350";>#24350</a>)</li>
   <li>[fix][broker] Fix ManagedCursor state management race conditions and 
lifecycle issues (<a 
href="https://redirect.github.com/apache/pulsar/pull/24569";>#24569</a>)</li>
   <li>[fix][broker] Fix matching of topicsPattern for topic names which 
contain non-ascii characters (<a 
href="https://redirect.github.com/apache/pulsar/pull/24543";>#24543</a>)</li>
   <li>[fix][broker] Fix maxTopicsPerNamespace might report a false failure (<a 
href="https://redirect.github.com/apache/pulsar/pull/24560";>#24560</a>)</li>
   <li>[fix][broker] Fix the non-persistenttopic's replicator always get error 
&quot;Producer send queue is full&quot; if set a small value of the config 
replicationProducerQueueSize (<a 
href="https://redirect.github.com/apache/pulsar/pull/24424";>#24424</a>)</li>
   <li>[fix][broker] Ignore metadata changes when broker is not in the Started 
state (<a 
href="https://redirect.github.com/apache/pulsar/pull/24352";>#24352</a>)</li>
   <li>[fix][broker] No longer allow creating subscription that contains slash 
(<a href="https://redirect.github.com/apache/pulsar/pull/23594";>#23594</a>)</li>
   <li>[fix][broker] Once the cluster is configured incorrectly, the broker 
maintains the incorrect cluster configuration even if you removed it (<a 
href="https://redirect.github.com/apache/pulsar/pull/24419";>#24419</a>)</li>
   <li>[fix][broker] replication does not work due to the mixed and repetitive 
sending of user messages and replication markers (<a 
href="https://redirect.github.com/apache/pulsar/pull/24453";>#24453</a>)</li>
   <li>[fix][broker] Resolve the issue of frequent updates in message 
expiration deletion rate (<a 
href="https://redirect.github.com/apache/pulsar/pull/24190";>#24190</a>)</li>
   <li>[fix][broker]excessive replication speed leads to error: Producer send 
queue is full (<a 
href="https://redirect.github.com/apache/pulsar/pull/24189";>#24189</a>)</li>
   <li>[fix][broker]Fix deadlock when compaction and topic deletion execute 
concurrently (<a 
href="https://redirect.github.com/apache/pulsar/pull/24366";>#24366</a>)</li>
   <li>[fix][broker]Global topic policies do not affect after unloading topic 
and persistence global topic policies never affect (<a 
href="https://redirect.github.com/apache/pulsar/pull/24279";>#24279</a>)</li>
   <li>[fix][broker]Non-global topic policies and global topic policies 
overwrite each other (<a 
href="https://redirect.github.com/apache/pulsar/pull/24286";>#24286</a>)</li>
   <li>[fix] Prevent IllegalStateException: Field 'message' is not set (<a 
href="https://redirect.github.com/apache/pulsar/pull/24472";>#24472</a>)</li>
   <li>[fix][ml] Cursor ignores the position that has an empty ack-set if 
disabled deletionAtBatchIndexLevelEnabled (<a 
href="https://redirect.github.com/apache/pulsar/pull/24406";>#24406</a>)</li>
   <li>[fix][ml] Enhance OpFindNewest to support skip non-recoverable data (<a 
href="https://redirect.github.com/apache/pulsar/pull/24441";>#24441</a>)</li>
   <li>[fix][ml] Fix asyncReadEntries might never complete if empty entries are 
read from BK (<a 
href="https://redirect.github.com/apache/pulsar/pull/24515";>#24515</a>)</li>
   <li>[fix][ml] Fix ManagedCursorImpl.individualDeletedMessages concurrent 
issue (<a 
href="https://redirect.github.com/apache/pulsar/pull/24338";>#24338</a>)</li>
   <li>[fix][ml] Fix the possibility of message loss or disorder when ML 
PayloadProcessor processing fails (<a 
href="https://redirect.github.com/apache/pulsar/pull/24522";>#24522</a>)</li>
   <li>[fix][ml]Received more than once callback when calling cursor.delete (<a 
href="https://redirect.github.com/apache/pulsar/pull/24405";>#24405</a>)</li>
   <li>[fix][ml]Revert a behavior change of releasing idle offloaded ledger 
handle: only release idle BlobStoreBackedReadHandle (<a 
href="https://redirect.github.com/apache/pulsar/pull/24384";>#24384</a>)</li>
   <li>[fix][ml]Still got BK ledger, even though it has been deleted after 
offloaded (<a 
href="https://redirect.github.com/apache/pulsar/pull/24432";>#24432</a>)</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/apache/pulsar/commit/4538ef7645c45a3c8686092128fde6c5d61c762b";><code>4538ef7</code></a>
 Release 4.0.6</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/0508c51ae6e1e17c3c5c3de3f6a21b83f8e6a192";><code>0508c51</code></a>
 Revert &quot;[fix][broker]Fix thread safety issues in 
BucketDelayedDeliveryTracker...</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/16271dc888c20d3e2233f1717b37f6f13fcb8af3";><code>16271dc</code></a>
 [fix][client][branch-4.0] Partitioned topics are unexpectedly created by 
clie...</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/e73c8f9d8cf7940f6599f115d7c2b921ef465398";><code>e73c8f9</code></a>
 [fix][test] fix flaky 
GrowableArrayBlockingQueueTest.testPollBlockingThreadsT...</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/0510a9f5647d3aac5dd68d7a7513e64dbd13881e";><code>0510a9f</code></a>
 [fix][sec] Remove dependency on out-dated commons-configuration 1.x (<a 
href="https://redirect.github.com/apache/pulsar/issues/24562";>#24562</a>)</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/ec56ca52980418984c17cda2dfa55a72aed5e1ea";><code>ec56ca5</code></a>
 [fix][broker] Fix ManagedCursor state management race conditions and 
lifecycl...</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/ba9147ad3383a0a68aec5e3ea9e02b0f165eed4c";><code>ba9147a</code></a>
 [improve][client] Terminate consumer.receive() when consumer is closed (<a 
href="https://redirect.github.com/apache/pulsar/issues/24550";>#24550</a>)</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/d1724da0a5774574ea8d96d410b727c14848ef92";><code>d1724da</code></a>
 [fix][sec] Upgrade Kafka connector and clients version to 3.9.1 to address 
CV...</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/125a33f79544f3c232243f96354f2304ce640224";><code>125a33f</code></a>
 [fix][broker] Fix maxTopicsPerNamespace might report a false failure (<a 
href="https://redirect.github.com/apache/pulsar/issues/24560";>#24560</a>)</li>
   <li><a 
href="https://github.com/apache/pulsar/commit/257e4c235d819b4f152b877d70cbdfe73be2c762";><code>257e4c2</code></a>
 [fix][test]fix flaky test 
BrokerServiceAutoTopicCreationTest.testDynamicConfi...</li>
   <li>Additional commits viewable in <a 
href="https://github.com/apache/pulsar/compare/v4.0.5...v4.0.6";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.pulsar:pulsar-bom&package-manager=maven&previous-version=4.0.5&new-version=4.0.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to