Distributed Cache Runtime 5.7.0-pasturestack.2
PastureStack Distributed Cache Runtime 5.7.0-pasturestack.2
This release preserves the Hazelcast 5.7.0 API and upstream Git history while applying the reviewed PastureStack security-maintenance delta documented in SECURITY-MAINTENANCE.md.
PastureStack is an independent community project. It is not affiliated with or endorsed by Hazelcast, Inc. Upstream copyright, authorship, license files, notices, and file-level headers remain intact.
Security maintenance
- Jackson 2 LTS 2.21.5 and Jackson 3 LTS 3.1.5
- Netty 4.1.137.Final
- gRPC Java 1.83.1
- Aircompressor 2.0.3
- Apache MINA 2.0.31
- PostgreSQL JDBC 42.7.13
- Tomcat Embed 11.0.24
- Hibernate ORM 7.4.5.Final
- LZ4 Java 1.11.2
- Spring Boot 3.5.15 / 4.1.0 and Spring Framework 6.2.19 / 7.0.8
- Maven Compiler Plugin 3.15.0 and Maven JAR Plugin 3.5.1 for standalone fixtures
Verification
- Exactly one PastureStack maintenance commit follows the recorded upstream 5.7.0 boundary.
- The clean artifact build, dependency convergence, banned-dependency checks, Checkstyle, 38 targeted tests, and three standalone fixture builds passed.
- Final source and JAR scans reported zero Critical and zero High findings; the all-severity JAR scan reported zero findings.
- The JAR retains the upstream LICENSE and NOTICE material.
- The attached CycloneDX 1.7 SBOM contains 13 artifact components and no local filesystem or personal-account paths.
- A JDK 21 runtime smoke test started and stopped a single node successfully with external discovery disabled.
Docker- and LocalStack-backed integration suites were not executed on the resource-sensitive production VM. Their sources compiled successfully; this limitation is not represented as a passed test.
Artifacts
hazelcast-5.7.0-pasturestack.2.jarhazelcast-5.7.0-pasturestack.2.jar.sha256distributed-cache-runtime-5.7.0-pasturestack.2.cdx.jsonghcr.io/pasturestack/distributed-cache-runtime:5.7.0-pasturestack.2
Use the version tag in operator-facing configuration. Integrity digests remain available through the registry and release evidence without being placed in UI image strings.