Repository navigation
Version 2.4.0 release notes
Grafana Pyroscope 2.4.0 adds experimental deterministic profile IDs, an optional distributor inflight bytes limit, and improvements to profile replay and asynchronous queries. It also improves compaction efficiency and includes security and stability fixes.
Notable changes are listed below. For the full diff, see the 2.4.0 changelog.
Enhancements
- distributor: Add an optional instance-level inflight bytes limit (#5546)
- experimental: Add opt-in deterministic profile ID generation (#4762)
- experimental: Support dedicated storage for asynchronous queries (#5756)
- experimental: Add queries to confirm externally detected profile anomalies (#5686)
- otlp: Detect profile language from
telemetry.sdk.language(#5606) - profilecli: Add timestamp-ordered dumps and streaming replay (#5762)
- profilecli: Add optional replay dump anonymization (#5763)
- symdb: Optimize insertion into wide stacktrace trees (#5732)
- symdb: Reduce compaction memory held by source symbols (#5734)
- query-backend: Optimize label-name queries (#5556)
- segment-writer: Measure ingestion bytes without re-serializing profiles (#5312)
- Helm: Support per-component extra labels on pod templates (#5752)
Fixes
- Revert the experimental symbol-reference tree query path (#5629)
- metastore: Reconcile Raft log writes that complete after a timeout (#5307)
- metastore: Fix a compaction queue statistics leak during restore (#5676)
- Clean up stale ring members on shutdown and through auto-forget (#5434)
- query-backend: Avoid retrying responses gRPC cannot deliver (#5590)
- query-frontend: Handle empty asynchronous results (#5677)
- query-frontend: Tolerate concurrent asynchronous-artifact cleanup (#5679)
- symdb: Handle line-less locations in Go PGO profiles (#5635, #5636)
- symdb: Preserve caller lines in Go PGO aggregation (#5637)
- Validate UTF-8 before truncating symbols at rune boundaries (#5692, #5696)
- Fix source lookup for installed Python packages (#5730)
- ui: Preserve arbitrary label matchers in profile queries (#5464)
- profilecli: Avoid closing replay datasets twice (#5591)
- profilecli: Anchor replay batch windows to due time (#5595)
- profilecli: Preserve replay retry errors and failure counts (#5785)
- Helm: Exclude headless services from the ServiceMonitor (#5758)
Security fixes
- Update the Go toolchain to 1.26.9 (#5788).
- Update
golang.org/x/netto v0.60.0, addressing CVE-2026-78659 and CVE-2026-78660 (#5791). - Update UI
source-map-jsto v1.2.2, addressing CVE-2026-93749 (#5795).
This release also includes the security updates delivered in 2.3.1 and 2.3.2.
Documentation
- Document profilecli replay (#5599)
- Document profilecli exemplar queries and drill-down commands (#5558)
- Document write-path sampling and stripped-profile limits (#5623)
- Document segment-writer object storage cost tuning (#5370)
- Expand recording rules docs and add Rust jemalloc and v2.0 upgrade guides (#5613)
- Update the Pyroscope UI documentation (#5624)
- Document the call tree view (#5625)
Changelog
- df585f3 Add QueryAnomalies RPC: confirm externally-flagged anomalies against ingested data (#5686)
- a3346b5 Add Ruby example for Puma clustered mode with preload_app! (#5714)
- e8de082 Allow dedicated object storage for asynchronous queries (#5756)
- ff50cf3 Revert symbol ref trees (#5629)
- f5a7863 Suggest min-ready-duration flag in readiness wait errors (#5741)
- 5172d19 Update golang version to 1.26.9 (#5788)
- 6576517 block: read downloaded profile tables without read-ahead (#5733)
- 8e1b035 chore(deps): jfr-praser v0.19.0 (#5642)
- 98467b4 chore(examples): update examples (#5596)
- 43c1449 chore(examples): update examples (#5618)
- f50d237 chore(examples): update examples (#5620)
- 8f2c8f8 chore(examples): update examples (#5675)
- a35e3bf chore(examples): update examples (#5742)
- b0aa472 chore(examples): update examples (#5754)
- bac7a63 chore(examples): update examples (#5784)
- a784291 chore(helm): release chart 2.3.2 (#5761)
- 4803c06 chore(helm/alloy): Update alloy to v1.19.2 (#5681)
- 292983f chore: Bump helm version (#5554)
- 325934c chore: Bump renovate base branches for release v2.3 (#5552)
- f9616ac chore: Update helm version to use v2.3.1 (#5605)
- fe84365 chore: Upgrade pyroscope/api to v1.6.0 (#5557)
- 6ab0a60 chore: include error in "query finished" log line (#5544)
- 30ac60e chore: update Go toolchain to 1.26.8 (#5589)
- 83a78c8 docs(config): document the retention_period limit (#5538)
- 3a73694 docs(segment-writer): document object storage cost tuning (#5370)
- c930304 docs: Add documentation for profilecli replay (#5599)
- 33e1140 docs: Add info about call tree view (#5625)
- 6762079 docs: Document the top-n flag in profilescli (#5562)
- 66a6dfe docs: Document write-path sampling and stripped-profile limits (#5623)
- e65bfdc docs: Expand recording rules CLI, add Rust jemalloc profiling, fix profile types, add v2.0 upgrade guide (#5613)
- 738b90e docs: Include the client flag for utf-8 label names (#5559)
- d1f78cd docs: Update release notes for v2.3.1/v2.2.2 (#5602)
- 5edb359 docs: add profilecli exemplar query and drill-down commands (#5558)
- 4558440 docs: add project-context for Docs AI skills library (#5672)
- ab1499c docs: add v2.2.3 and v2.3.2 release notes (#5760)
- fb7c0ce docs: add v2.3 release notes (#5553)
- 1c91096 docs: add v2.4 release notes (#5799) (#5800)
- 8384189 docs: document Java OTLP export limitations (#5547)
- 3220318 docs: document OTLP language detection via telemetry.sdk.language (#5700)
- 260c9b3 docs: explain what a span profile is (#5564)
- 69828f9 docs: remove duplicate self vs total screenshot (#5498)
- 4fb8363 docs: rewrite Pyroscope UI page for the single-page query UI (#5624)
- 0ddb2f6 docs: update Grafana Cloud recording rules link to new canonical URL (#5698)
- 100a6ee docs: updates the list of contributors in README (#5577)
- 71d74b5 docs: updates the list of contributors in README (#5707)
- 7fff2e9 feat(distributor): add an instance-level inflight bytes limit (#5546)
- 1be51fb feat(helm): allow per-component extraLabels on pod templates (#5752)
- b864e24 feat(otlp): detect profile language from telemetry.sdk.language resource attribute (#5606)
- 9564169 feat(profilecli): add optional replay dump anonymization (#5763)
- 2ccb6b3 feat(profilecli): stream timestamp-ordered replay dumps (#5762)
- 3a90e04 feat: Add opt-in deterministic profile ID generation (#4762)
- 5b97478 fix(block): avoid unnecessary growth of symbolsRewriter.stacktraces (#5660)
- 4a66254 fix(blocks): close profile datasets through iterators (#5594)
- d121225 fix(ci): bump update-helm-repo to fix helm-release (#5573)
- 3c0697e fix(compactionworker): synchronize worker lifecycle tests (#5597)
- 8338172 fix(deps): update golang.org/x/net to v0.60.0 [security] (#5791)
- 70528ba fix(deps): update otel log modules to v0.21.0 [security] (#5721)
- 14953b5 fix(deps): update source-map-js to 1.2.2 [security] (#5795)
- 40e2d23 fix(deps): update undici to 8.10.2 to address TLS validation bypass (#5747)
- 1562888 fix(examples): clear the remaining java rideshare CVEs (#5570)
- 396305a fix(examples): drop the build toolchain from the ruby rideshare image (#5565)
- d7e9cb5 fix(examples): update vulnerable Node.js dependencies (#5745)
- 9ef7eb5 fix(helm): exclude headless Services from the ServiceMonitor again (#5758)
- b9e5598 fix(helm): remove stray character from query URL in NOTES (#5687)
- d461a09 fix(helm): update MinIO image (#5664)
- 2c65f61 fix(metastore): prevent globalQueueStats leak on compactor Restore (#5676)
- 3581ff3 fix(metastore): reconcile abandoned raft log writes (#5307)
- 12f5b13 fix(profilecli): anchor replay batch windows to due time (#5595)
- 865d61c fix(profilecli): preserve replay retry errors and failure counts (#5785)
- 5ac0fdc fix(profilecli): stop replay dump from closing the dataset twice (#5591)
- 0aa75e2 fix(query): avoid unnecessary growth of pooled parquet buffers (#5659)
- 4f71269 fix(query-frontend): handle empty async results (#5677)
- a883cbc fix(query-frontend): tolerate concurrent async artifact cleanup (#5679)
- 1dd8a7e fix(querybackend): do not retry responses gRPC cannot deliver (#5590)
- 4c7f3c2 fix(security/high/): update module google.golang.org/grpc to v1.83.1 [security] (#5579)
- 0624440 fix(security/high/): update module google.golang.org/grpc to v1.83.2 [security] (#5607)
- 7a039f5 fix(security/high/api): update module google.golang.org/grpc to v1.83.1 [security] (#5580)
- 4ab6935 fix(security/high/api): update module google.golang.org/grpc to v1.83.2 [security] (#5608)
- 50bcb4e fix(security/high/ui): update dependency brace-expansion to v5.0.12 [security] (main) (#5704)
- 969e43a fix(security/high/ui): update dependency js-yaml to v4.3.2 [security] (main) (#5615)
- 5e0b2fc fix(security/low/): update module go.opentelemetry.io/otel/exporters/otlp/otlptrace to v1.45.0 [security] (#5644)
- c25a5ee fix(security/unknown/): update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc to v1.45.0 [security] (#5645)
- fec054f fix(security/unknown/): update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to v1.45.0 [security] (#5646)
- 4e5b714 fix(security/unknown/): update module golang.org/x/crypto to v0.56.0 [security] (main) (#5586)
- 5b8176a fix(segmentwriter): probe the bucket with Upload instead of Iter (#5560)
- 346bbfb fix(server): allow gRPC keepalive pings without active streams (#5685)
- 7b23c86 fix(symdb): handle line-less Go PGO callees (#5635)
- a1181be fix(symdb): handle line-less call site leaves (#5636)
- 26c71f6 fix(symdb): preserve caller lines in Go PGO aggregation (#5637)
- 822fb70 fix(usagestats): let the segment writer create the cluster seed on v2 storage (#5542)
- a3ae4da fix(validation): truncate symbols on rune boundaries (#5692)
- e1dd19b fix(validation): validate utf8 before truncating symbols (#5696)
- 4bcf216 fix: clean up stale ring members on shutdown and via auto-forget (#5434)
- b9de22a fix: do not treat site-packages as the Python stdlib (#5730)
- 0abc319 fix: update vulnerable Go dependencies (#5744)
- 0e36bb4 optimize label names query (#5556)
- 93dc001 perf(segmentwriter): observe ingest bytes without re-serializing the profile (#5312)
- 6e3ba0f remove logo (#5561)
- 54d062f symdb: index children of wide stack trace tree nodes (#5732)
- 6a48a93 symdb: reduce compaction memory held by source symbols (#5734)
- eabc7c3 test(compactionworker): retain job assignment during in-progress polls (#5765)
- 4d52d58 test(helm): cover headless ServiceMonitor exclusion (#5764)
- 01502da test(helm): cover per-component pod template labels (#5766)
- 7e48500 test(metastore): stabilize raft log store timeout tests (#5643)
- 653c749 ui: preserve arbitrary label matchers in profile queries (#5461) (#5464)
As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:
Docker Images
docker pull grafana/pyroscope:2.4.0