Skip to content

Distributed Cache Runtime 5.7.0-pasturestack.2

Choose a tag to compare

@chen21019 chen21019 released this 06 Aug 19:15

PastureStack Distributed Cache Runtime 5.7.0-pasturestack.2

This release preserves the Hazelcast 5.7.0 API and upstream Git history while applying the reviewed PastureStack security-maintenance delta documented in SECURITY-MAINTENANCE.md.

PastureStack is an independent community project. It is not affiliated with or endorsed by Hazelcast, Inc. Upstream copyright, authorship, license files, notices, and file-level headers remain intact.

Security maintenance

  • Jackson 2 LTS 2.21.5 and Jackson 3 LTS 3.1.5
  • Netty 4.1.137.Final
  • gRPC Java 1.83.1
  • Aircompressor 2.0.3
  • Apache MINA 2.0.31
  • PostgreSQL JDBC 42.7.13
  • Tomcat Embed 11.0.24
  • Hibernate ORM 7.4.5.Final
  • LZ4 Java 1.11.2
  • Spring Boot 3.5.15 / 4.1.0 and Spring Framework 6.2.19 / 7.0.8
  • Maven Compiler Plugin 3.15.0 and Maven JAR Plugin 3.5.1 for standalone fixtures

Verification

  • Exactly one PastureStack maintenance commit follows the recorded upstream 5.7.0 boundary.
  • The clean artifact build, dependency convergence, banned-dependency checks, Checkstyle, 38 targeted tests, and three standalone fixture builds passed.
  • Final source and JAR scans reported zero Critical and zero High findings; the all-severity JAR scan reported zero findings.
  • The JAR retains the upstream LICENSE and NOTICE material.
  • The attached CycloneDX 1.7 SBOM contains 13 artifact components and no local filesystem or personal-account paths.
  • A JDK 21 runtime smoke test started and stopped a single node successfully with external discovery disabled.

Docker- and LocalStack-backed integration suites were not executed on the resource-sensitive production VM. Their sources compiled successfully; this limitation is not represented as a passed test.

Artifacts

  • hazelcast-5.7.0-pasturestack.2.jar
  • hazelcast-5.7.0-pasturestack.2.jar.sha256
  • distributed-cache-runtime-5.7.0-pasturestack.2.cdx.json
  • ghcr.io/pasturestack/distributed-cache-runtime:5.7.0-pasturestack.2

Use the version tag in operator-facing configuration. Integrity digests remain available through the registry and release evidence without being placed in UI image strings.