2026.09.68 — 2026-09-30
Breaking
Compare PluginMessage and OutboundMessage bodies by content (714daa7b)
Two messages with the same bytes were unequal, because a record compares its byte[] component by reference. PluginMessage and OutboundMessage now implement equals and hashCode over the body's content, and toString reports the body's length instead of an array identity, so message content never reaches a log line.
Added
Sign every artifact with SLSA provenance and CycloneDX SBOMs (443f1af3)
Every release now carries keyless attestations from the release workflow: the image (stored with it on Docker Hub), the jar, and the plugin API files on Maven Central have signed SLSA provenance, and the image and jar have signed CycloneDX SBOMs. The release page adds the jar's provenance bundle and both SBOMs. Check any of them with
gh attestation verify, as described in the new "Verify a release" guide.Pull requests that change the image now fail on a critical or high vulnerability in it that has a fix.
Fixed
Do the backoff attempt subtraction in long (81648fd4)
Keep the secret hash out of a record array component (7236d009)
Compare PluginMessage and OutboundMessage bodies by content (714daa7b)
Two messages with the same bytes were unequal, because a record compares its byte[] component by reference. PluginMessage and OutboundMessage now implement equals and hashCode over the body's content, and toString reports the body's length instead of an array identity, so message content never reaches a log line.
Normalise notification timestamps to Studio's clock (fbc36333)
NotificationMapper has two constructors and neither was marked for injection, so Spring built it with the no-argument one and broker notification times were never corrected by the measured clock offset. The clock-aware constructor is now the injected one.