-
Notifications
You must be signed in to change notification settings - Fork 0
Release History
Authoritative sources:
CHANGELOG.md for
narrative detail, and the
GitHub releases page for the
per-release PR list.
| Version | Date | Headline |
|---|---|---|
| 2.4.0 | 2026-07-25 | Parallel consumers; request-path capacity (growth-first executor, typed timeouts, saturation meters); large dependency sweep |
| 2.3.0 – 2.3.2 | 2026-07-18 → 07-24 | Maintenance and fixes |
| 2.2.0 – 2.2.2 | 2026-07-13 → 07-18 | Spring Boot 4.1.0, Angular 22 + TypeScript 6 GUI, frontend CVE elimination, CBOR codec fuzz fix, GUI built in PR CI |
| 2.1.0 – 2.1.2 | 2026-06-06 → 07-03 | Confinement check (ConfinementScanner, strictConfinement) |
| 2.0.0 | 2026-05-30 | First GA of the v2 rewrite; evento-cli and evento-parser deleted; deploy/autoscaling surface removed |
| 2.0.0-rc1 | 2026-05-21 | First release candidate of the ground-up rewrite |
| 1.15.5 | 2025-01-01 | Last v1 line |
Patch releases between minors are largely dependency and fix work; see the releases page for the exact PR list.
Two features, both about bounded concurrency, from opposite ends of the system.
Parallel consumers (the consume path). An @EventHandler may name a bounded consumer executor
registered on EventoBundle.Builder, dispatching its events in parallel instead of one at a time.
executor = "" — the default — keeps the sequential path, so nothing changed for a bundle that does
not opt in.
- New SPI
ConsumerExecutorplus factoriesConsumerExecutors.virtual/pooled/partitioned/unbounded; register withBuilder.addConsumerExecutor(...). A name is a capacity budget shared bundle-wide. - The checkpoint advances when a task starts, not when it completes — the backpressure, and the bound on the crash-loss window.
- Guarantees relaxed: no ordering between parallel events; at-most-once for events in flight on an
abrupt kill.
ConsumerExecutors.partitionedandCheckpointMode.WATERMARKbuy each back. -
retry = -1is coerced to0under an executor. An unregistered executor name fails start-up. - Transient-failure backoff, so a downed dependency no longer causes the whole stream to be dead-lettered.
Request capacity (the request path), out of a production incident — see Throughput and Capacity:
-
BusBusinessExecutorwith aGrowthFirstQueue— grows to max before it queues. Queue default1024 → 256. -
RequestTimeoutException/TooManyPendingRequestsExceptionreplace a genericIllegalStateException; a timeout means indeterminate, not failed. -
BundleClientConfig.Builder.maxInFlightRequests(n), default 2048. - Meters
evento.server.bus.executor.{pool.size,max,active,queue.depth,saturated}; expiries movedINFO → WARNand gained abyType={...}breakdown.
Codec version tolerance. All four mappers disable FAIL_ON_UNKNOWN_PROPERTIES so a peer one
version ahead is not rejected — see Wire Protocol § 8 for the outage that prompted
it. Not a relaxation of deserialization hardening: the gadget-chain defence is MessageTypeRegistry /
the PolymorphicTypeValidator, both untouched.
Also a broad dependency sweep: Gradle 9.6.1, Netty 4.2.16.Final, Jackson 2.22.1, Flyway 13.0.0, Angular 22.0.8 family, ngx-translate v18.
Spring Boot 4.1.0, Angular 22 + TypeScript 6 for the GUI, HikariCP 7.1.0, Hibernate Validator 9.1.2. Security work: frontend npm CVEs eliminated and GUI build dependencies pinned; the GUI is now built in PR CI; a CBOR codec fuzz finding fixed.
Registration-time detection of gateway call sites invisible to static interaction-graph extraction.
ConfinementScanner sweeps every non-component class in the scanned packages with ASM and reports
each CommandGateway.send / sendAndWait / QueryGateway.query call site found there. Such gateway
leaks previously under-approximated the extracted emit set silently.
AsmInvocationScanner additionally reports gateway calls whose payload is typed as the abstract
Command / Query base, since the concrete type is statically unresolvable.
New flag EventoBundle.Builder.strictConfinement (default false): warnings by default,
IllegalStateException at registration when set. See Bundle Client § 5.
Promoted 2.0.0-rc1 to general availability. Wire-format compatibility with v1 remains
intentionally broken.
-
Self-description parity with the removed CLI — bundles publish full discovery metadata at
startup: component/handler/payload source paths and line numbers,
repositoryUrl+linePrefixfor clickable source links, and@EventoDescription. -
Removed:
evento-cli,evento-parser, and the entire deploy-by-upload / autoscaling surface (JAR uploads,/spawn+/kill,docker-spawn.py, per-bundle env/VM options,autorun/deployableflags). -
TracingAgent's default became an honest no-op. - Public documentation realigned to v2.
The full breaking-change list and the complete added surface are in the changelog; the summary is in Migrating from v1. In brief:
Deleted: v1 bundle transport (1 634 LOC), MessageBus.java (1 099 LOC), the v1 abstract
ConsumerStateStore and its Postgres/MySQL modules, the autoscale protocol.
Added: the Netty/CBOR transport layer with sealed Message records and transparent chunking; the
composable BusLifecycle server bus with its registries and exactly-once QoS; the BundleClient
façade and its state machine; the three consumer engines over five focused SPIs; the JDBC state store
for Postgres and MySQL; and both integration-test harnesses.
Four notable fixes, each a real distributed-systems bug:
| Symptom | |
|---|---|
| Fix A | Superseded-session race — handlers wiped when a bundle reconnected |
| Fix B | FK violation in BundleService orphan-payload cleanup |
| Fix C | A DEGRADED channel dropped in-flight responses |
| Fix D | TCP disconnect + reconnect lost in-flight responses |
Plus SerializedQueryResponse removed from the transport path — roughly 40% peak heap reduction
for large responses.
Semantic Versioning. The public API surface that forces a major bump is listed in Contributing and Conventions § 6. The changelog follows Keep a Changelog.
Evento Framework — Copyright 2020–2026 © Gabor Galazzo. Dual-licensed under AGPL-3.0 and a commercial licence.
This wiki documents the implementation; the repository is authoritative where the two disagree. Found something out of date? Open an issue.
Getting oriented
Internals
Operations
- Server Configuration
- Throughput and Capacity
- Observability
- Security Model
- Server REST API
- Troubleshooting
Project