Skip to content

Bump nacos-client.version from 3.2.1-2026.03.30 to 3.2.4 - #4

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/nacos-client.version-3.2.4
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/nacos-client.version-3.2.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown

Bumps nacos-client.version from 3.2.1-2026.03.30 to 3.2.4.
Updates com.alibaba.nacos:nacos-client from 3.2.1-2026.03.30 to 3.2.4

Release notes

Sourced from com.alibaba.nacos:nacos-client's releases.

3.2.4 (Aug 27th, 2026)

Nacos 3.2.4 is mainly a bugfix, security-hardening, and experience-improvement release for the 3.2 series.

This release focuses on:

  • Strengthening JRaft, HTTP/gRPC authorization, embedded database, login, active health check, and MCP import security.
  • Fixing standalone Console, Prompt visibility, Config history, listener state, and MCP tool authentication issues.
  • Improving Config detail, edit, and history page usability.

For cluster and API operators, this release also:

  • Adds server-identity authentication to native JRaft gRPC traffic with rolling-upgrade-aware enforcement.
  • Disables selected deprecated v3 AI APIs by default and provides a temporary compatibility switch.
  • Adds an allowlist policy for MCP tool imports from private or local targets.

Detailed changes in this release:

Feature

  • #15687 Add server-identity authentication to native JRaft gRPC traffic with rolling-upgrade-aware enforcement.

Enhancement/Refactor

  • #14817 Add a shared, disabled-by-default compatibility gate for deprecated Pipeline and MCP import APIs.
  • #15661 Harden distributed embedded database result resolution to supported scalar types and registered row mappers.
  • #15688 Refactor controller context-path URI parsing for consistent route matching.
  • #15695 Improve Config detail, edit, and history layouts with compact metadata and a full-screen content view.
  • #15712 Harden active health checks by validating target addresses and disabling unsafe MySQL JDBC options.
  • #15749 Add configurable outbound access control for MCP tool imports, allowing public targets and allowlisted private or local targets.

BugFix

  • #15475 Fix caller identity forwarding from a standalone Console so the Server enforces caller-specific RBAC.
  • #15476 Fix Prompt visibility enforcement for list, detail, version, download, and Client read paths.
  • #15560 Fix MCP tool passthrough authentication being lost after publishing from the Console.
  • #15634 #15563 Fix authorization metadata and resource parsing across Admin, HTTP/gRPC, Prometheus, and AgentSpec APIs.
  • #15660 Fix standalone Console startup failure caused by a missing Config clone permission checker bean.
  • #15682 Prevent username enumeration by normalizing login failure responses.
  • #15701 Fix Config history next-record queries on Derby and apply gray-name filtering correctly.
  • #15724 Preserve the namespace filter when aggregating listener-by-IP state across cluster members.

Breaking Change Notice

Nacos 3.2.4 changes the default behavior of deprecated AI APIs and private MCP tool imports, and introduces an irreversible JRaft authentication enforcement transition.

Affected users:

... (truncated)

Commits

Updates com.alibaba.nacos:nacos-maintainer-client from 3.2.1-2026.03.30 to 3.2.4

Release notes

Sourced from com.alibaba.nacos:nacos-maintainer-client's releases.

3.2.4 (Aug 27th, 2026)

Nacos 3.2.4 is mainly a bugfix, security-hardening, and experience-improvement release for the 3.2 series.

This release focuses on:

  • Strengthening JRaft, HTTP/gRPC authorization, embedded database, login, active health check, and MCP import security.
  • Fixing standalone Console, Prompt visibility, Config history, listener state, and MCP tool authentication issues.
  • Improving Config detail, edit, and history page usability.

For cluster and API operators, this release also:

  • Adds server-identity authentication to native JRaft gRPC traffic with rolling-upgrade-aware enforcement.
  • Disables selected deprecated v3 AI APIs by default and provides a temporary compatibility switch.
  • Adds an allowlist policy for MCP tool imports from private or local targets.

Detailed changes in this release:

Feature

  • #15687 Add server-identity authentication to native JRaft gRPC traffic with rolling-upgrade-aware enforcement.

Enhancement/Refactor

  • #14817 Add a shared, disabled-by-default compatibility gate for deprecated Pipeline and MCP import APIs.
  • #15661 Harden distributed embedded database result resolution to supported scalar types and registered row mappers.
  • #15688 Refactor controller context-path URI parsing for consistent route matching.
  • #15695 Improve Config detail, edit, and history layouts with compact metadata and a full-screen content view.
  • #15712 Harden active health checks by validating target addresses and disabling unsafe MySQL JDBC options.
  • #15749 Add configurable outbound access control for MCP tool imports, allowing public targets and allowlisted private or local targets.

BugFix

  • #15475 Fix caller identity forwarding from a standalone Console so the Server enforces caller-specific RBAC.
  • #15476 Fix Prompt visibility enforcement for list, detail, version, download, and Client read paths.
  • #15560 Fix MCP tool passthrough authentication being lost after publishing from the Console.
  • #15634 #15563 Fix authorization metadata and resource parsing across Admin, HTTP/gRPC, Prometheus, and AgentSpec APIs.
  • #15660 Fix standalone Console startup failure caused by a missing Config clone permission checker bean.
  • #15682 Prevent username enumeration by normalizing login failure responses.
  • #15701 Fix Config history next-record queries on Derby and apply gray-name filtering correctly.
  • #15724 Preserve the namespace filter when aggregating listener-by-IP state across cluster members.

Breaking Change Notice

Nacos 3.2.4 changes the default behavior of deprecated AI APIs and private MCP tool imports, and introduces an irreversible JRaft authentication enforcement transition.

Affected users:

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `nacos-client.version` from 3.2.1-2026.03.30 to 3.2.4.

Updates `com.alibaba.nacos:nacos-client` from 3.2.1-2026.03.30 to 3.2.4
- [Release notes](https://github.com/alibaba/nacos/releases)
- [Changelog](https://github.com/alibaba/nacos/blob/develop/CHANGELOG.md)
- [Commits](alibaba/nacos@3.2.1-2026.03.30...3.2.4)

Updates `com.alibaba.nacos:nacos-maintainer-client` from 3.2.1-2026.03.30 to 3.2.4
- [Release notes](https://github.com/alibaba/nacos/releases)
- [Changelog](https://github.com/alibaba/nacos/blob/develop/CHANGELOG.md)
- [Commits](alibaba/nacos@3.2.1-2026.03.30...3.2.4)

---
updated-dependencies:
- dependency-name: com.alibaba.nacos:nacos-client
  dependency-version: 3.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: com.alibaba.nacos:nacos-maintainer-client
  dependency-version: 3.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants