This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/thrift-website.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new 769d6f0  Automatic Site Publish by Buildbot
769d6f0 is described below

commit 769d6f0961f06874a1a9751d6eb65cbf6654a355
Author: buildbot <[email protected]>
AuthorDate: Thu Jul 30 21:17:47 2026 +0000

    Automatic Site Publish by Buildbot
---
 output/changelog.html                          | 596 +++++++++++++++++++------
 output/docs/committers/HowToThriftWebsite.html |   4 +-
 output/docs/idl.html                           |   2 +-
 output/download.html                           |  20 +-
 output/index.html                              |  14 +-
 output/lib/rb.html                             |  76 +++-
 output/test/index.html                         |  15 +-
 7 files changed, 573 insertions(+), 154 deletions(-)

diff --git a/output/changelog.html b/output/changelog.html
index 5f5993b..f49cefe 100644
--- a/output/changelog.html
+++ b/output/changelog.html
@@ -54,10 +54,451 @@
       
 <h1 id="apache-thrift-changelog">Apache Thrift Changelog</h1>
 
-<h2 id="0230">0.23.0</h2>
+<h2 id="0240">0.24.0</h2>
 
 <h3 id="build-process">Build Process</h3>
 
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5000";>THRIFT-5000</a> - 
Thrift docker image publish on releases</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5855";>THRIFT-5855</a> - 
Improve fuzzing support</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5952";>THRIFT-5952</a> - 
Optimize MSVC Docker image to reduce size and speed up CI</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5965";>THRIFT-5965</a> - Add 
zizmor for GitHub Actions workflows security analysis</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5967";>THRIFT-5967</a> - 
Refactor SCA GitHub workflow for better extensibility</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5973";>THRIFT-5973</a> - 
Automated CHANGELOG creation</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6002";>THRIFT-6002</a> - Add 
netstd codegen test script and GitHub Actions CI matrix job (.NET 8/9/10)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6003";>THRIFT-6003</a> - Add 
Haxe codegen test script and GitHub Actions CI job</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6077";>THRIFT-6077</a> - 
improve CHANGES.md generator section assignment</li>
+  <li><a href="https://github.com/apache/thrift/pull/3613";>#3613</a> - Bump 
rubygems/release-gem from 1.2.0 to 1.4.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3616";>#3616</a> - Bump 
ruby/setup-ruby from 1.310.0 to 1.314.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3617";>#3617</a> - Bump 
rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5</li>
+  <li><a href="https://github.com/apache/thrift/pull/3618";>#3618</a> - Bump 
jvm from 2.3.21 to 2.4.0 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3619";>#3619</a> - Bump 
com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3615";>#3615</a> - Bump 
actions/setup-go from 6.4.0 to 6.5.0</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6092";>THRIFT-6092</a> - fix 
off-by-ten header bounds check in readHeaderFormat</li>
+  <li><a href="https://github.com/apache/thrift/pull/3593";>#3593</a> - Bump 
shell-quote from 1.7.3 to 1.8.4 in /lib/js</li>
+  <li><a href="https://github.com/apache/thrift/pull/3591";>#3591</a> - Bump 
shell-quote from 1.7.3 to 1.8.4 in /lib/ts</li>
+  <li><a href="https://github.com/apache/thrift/pull/3589";>#3589</a> - Update 
MSVC CI to windows-2025-vs2026 runner and start Docker service explicitly</li>
+  <li><a href="https://github.com/apache/thrift/pull/3581";>#3581</a> - Run the 
Haxe library unit tests (neko) in CI</li>
+  <li><a href="https://github.com/apache/thrift/pull/3576";>#3576</a> - Bump 
ruby/setup-ruby from 1.306.0 to 1.310.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3575";>#3575</a> - Bump 
zizmorcore/zizmor-action from 0.5.3 to 0.5.6</li>
+  <li><a href="https://github.com/apache/thrift/pull/3577";>#3577</a> - Bump 
actions/setup-dotnet from 4.3.1 to 5.2.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3574";>#3574</a> - Bump 
com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3572";>#3572</a> - Bump 
org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3578";>#3578</a> - Harden 
the MSVC build workflow against transient Docker daemon unavailability</li>
+  <li><a href="https://github.com/apache/thrift/pull/3564";>#3564</a> - Enable 
Copilot reviews</li>
+  <li><a href="https://github.com/apache/thrift/pull/3565";>#3565</a> - Allow 
CI to fail on ruby-head</li>
+  <li><a href="https://github.com/apache/thrift/pull/3517";>#3517</a> - Bump 
uuid and nyc</li>
+  <li><a href="https://github.com/apache/thrift/pull/3513";>#3513</a> - Remove 
Ruby known failures from cross-test list</li>
+  <li><a href="https://github.com/apache/thrift/pull/3501";>#3501</a> - Fix 
netstd CI .NET SDK setup</li>
+  <li><a href="https://github.com/apache/thrift/pull/3496";>#3496</a> - Add 
generator paths to mergeable labels</li>
+  <li><a href="https://github.com/apache/thrift/pull/3430";>#3430</a> - Updated 
projects settings in .asf.yaml (features, merge buttons, Jira autolinking)</li>
+  <li><a href="https://github.com/apache/thrift/pull/3487";>#3487</a> - Update 
to setup-php 2.37.1</li>
+  <li><a href="https://github.com/apache/thrift/pull/3471";>#3471</a> - Update 
build.yml</li>
+  <li><a href="https://github.com/apache/thrift/pull/3461";>#3461</a> - 
Migration *.sln to *.slnx (except c++ libs)</li>
+  <li><a href="https://github.com/apache/thrift/pull/3454";>#3454</a> - Fixing 
bundler on ruby-head build</li>
+  <li><a href="https://github.com/apache/thrift/pull/3440";>#3440</a> - Removed 
deprecated ‘publish’ workflow</li>
+  <li><a href="https://github.com/apache/thrift/pull/3439";>#3439</a> - Pin all 
actions to a specific SHA consistently</li>
+  <li><a href="https://github.com/apache/thrift/pull/3437";>#3437</a> - 
Validate GitHub workflows against the ASF allowlist</li>
+  <li><a href="https://github.com/apache/thrift/pull/3433";>#3433</a> - Pin 
actions/upload-artifact to a specific SHA consistently</li>
+  <li><a href="https://github.com/apache/thrift/pull/3433";>#3433</a> - Bump 
actions/upload-artifact from 7.0.0 to 7.0.1</li>
+  <li><a href="https://github.com/apache/thrift/pull/3434";>#3434</a> - Bump 
jvm from 2.3.20 to 2.3.21 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3423";>#3423</a> - Bump 
uuid from 13.0.0 to 14.0.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3424";>#3424</a> - Bump 
json from 2.18.1 to 2.19.2 in /lib/rb</li>
+  <li><a href="https://github.com/apache/thrift/pull/3404";>#3404</a> - Cleanup 
Adobe Flex SDK installation following AS3 library removal</li>
+  <li><a href="https://github.com/apache/thrift/pull/3400";>#3400</a> - Bump 
json from 2.18.1 to 2.19.2 in /test/rb</li>
+  <li><a href="https://github.com/apache/thrift/pull/3397";>#3397</a> - Address 
vulnerabilities in Rack</li>
+  <li><a href="https://github.com/apache/thrift/pull/3386";>#3386</a> - Bump 
lodash from 4.17.23 to 4.18.1</li>
+  <li><a href="https://github.com/apache/thrift/pull/2957";>#2957</a> - Fix PHP 
cross-test server IPv4 binding</li>
+  <li><a href="https://github.com/apache/thrift/pull/3384";>#3384</a> - Fix 
ubuntu-noble Docker build: modernize NodeSource GPG setup</li>
+  <li><a href="https://github.com/apache/thrift/pull/3384";>#3384</a> - Fix 
ubuntu-focal Docker build: update NodeSource setup and ENV format</li>
+  <li><a href="https://github.com/apache/thrift/pull/3384";>#3384</a> - Fix 
ubuntu-jammy Docker build: update NodeSource and ENV format</li>
+  <li><a href="https://github.com/apache/thrift/pull/3380";>#3380</a> - Fix 
docker warnings on ENV format</li>
+  <li><a href="https://github.com/apache/thrift/pull/3380";>#3380</a> - 
Override enforcement of PEP 668</li>
+</ul>
+
+<h3 id="c-glib">C glib</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5930";>THRIFT-5930</a> - 
thrift_server_socket() copies Unix socket paths into sockaddr_un.sun_path 
without bounds checking</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6088";>THRIFT-6088</a> - Add 
consumed byte tracking to ThriftZlibTransport read</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
Widen container size precheck to 64-bit in c_glib protocols</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6094";>THRIFT-6094</a> - Copy 
buffered data not the GByteArray struct in c_glib read_slow</li>
+  <li><a href="https://github.com/apache/thrift/pull/3585";>#3585</a> - limit 
recursion depth in c_glib thrift_protocol_skip</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6086";>THRIFT-6086</a> - Add 
peer hostname validation to c_glib TLS client</li>
+  <li><a href="https://github.com/apache/thrift/pull/3393";>#3393</a> - Fix 
parent class resolution in c_glib generated dispatch_call</li>
+</ul>
+
+<h3 id="c">C++</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-3165";>THRIFT-3165</a> - 
Disable unsafe TLSv1.0 and TLSv1.1 by default</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6021";>THRIFT-6021</a> - When 
C++ client with HTTP transport calls a oneway RPC method, it must not expect a 
response</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6060";>THRIFT-6060</a> - C++ 
THttpClient does not reopen socket after server sends Connection: close</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6073";>THRIFT-6073</a> - 
Allow injecting external SSL_CTX into C++ SSLContext</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6088";>THRIFT-6088</a> - Add 
decompressed byte tracking to C++ TZlibTransport</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
Widen container size precheck to 64-bit in C++ protocols</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6093";>THRIFT-6093</a> - Read 
the zlib transform result directly in THeaderTransport untransform</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6096";>THRIFT-6096</a> - Fix 
info-header string bound check in THeaderTransport::readString</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6092";>THRIFT-6092</a> - link 
UnitTests against libthriftz to resolve THeaderTransport vtable</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6092";>THRIFT-6092</a> - fix 
off-by-ten header bounds check in readHeaderFormat</li>
+  <li><a href="https://github.com/apache/thrift/pull/3569";>#3569</a> - Add the 
cpp.ref (&amp;) annotation to the recursive exception in Recursive.thrift</li>
+  <li><a href="https://github.com/apache/thrift/pull/3519";>#3519</a> - 
Preserve private_optional field order</li>
+  <li><a href="https://github.com/apache/thrift/pull/3498";>#3498</a> - change 
sprintf to snprintf to eliminate security warnings on OSX</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6087";>THRIFT-6087</a> - 
Enforce RFC 6125 wildcard placement in TSSLSocket hostname matching</li>
+  <li><a href="https://github.com/apache/thrift/pull/3508";>#3508</a> - Replace 
memory-safety asserts with unconditional throws in TBufferTransports</li>
+  <li><a href="https://github.com/apache/thrift/pull/3431";>#3431</a> - Remove 
another boost header from the public API</li>
+</ul>
+
+<h3 id="compiler-general">Compiler (General)</h3>
+
+<ul>
+  <li><a href="https://github.com/apache/thrift/pull/3529";>#3529</a> - 
nodejs+compiler: Add opt-in BigInt support for int64 via js:bigint flag</li>
+  <li><a href="https://github.com/apache/thrift/pull/3461";>#3461</a> - 
Migration *.sln to *.slnx (except c++ libs)</li>
+  <li><a href="https://github.com/apache/thrift/pull/2957";>#2957</a> - Fix PHP 
cross-test server IPv4 binding</li>
+  <li><a href="https://github.com/apache/thrift/pull/3372";>#3372</a> - Fix 
JavaScript exception construction implementation (ES6)</li>
+</ul>
+
+<h3 id="d">D</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6053";>THRIFT-6053</a> - 
Limit struct read/write recursion depth in D library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6088";>THRIFT-6088</a> - Add 
decompressed data size limit to D TZlibTransport</li>
+</ul>
+
+<h3 id="dart">Dart</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6034";>THRIFT-6034</a> - 
Harden Dart protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6056";>THRIFT-6056</a> - 
Limit struct read/write recursion depth in Dart library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+</ul>
+
+<h3 id="delphi">Delphi</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-2462";>THRIFT-2462</a> - 
prevent possible stack overflow due to recursive syntax support</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6007";>THRIFT-6007</a> - 
Implement MESSAGE_SIZE_LIMIT exception type for Delphi library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
Compute container size precheck in 64-bit in Delphi protocols</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+</ul>
+
+<h3 id="documentation">Documentation</h3>
+
+<ul>
+  <li><a href="https://github.com/apache/thrift/pull/3520";>#3520</a> - added 
thrift-threat-model.md, SECURITY.md and security section to AGENTS.md</li>
+</ul>
+
+<h3 id="erlang">Erlang</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6030";>THRIFT-6030</a> - 
Harden Erlang protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+</ul>
+
+<h3 id="go">Go</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5214";>THRIFT-5214</a> - go: 
Implement connection check in TSocket</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5969";>THRIFT-5969</a> - 
Introduce gofmt for Go library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5996";>THRIFT-5996</a> - go: 
connection check should work for TLS sockets</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6011";>THRIFT-6011</a> - Make 
compiled Go code formatting compatible with gofmt</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6012";>THRIFT-6012</a> - Fix 
inverted regexp.MatchString arguments and precompile patterns in Go 
validator</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6044";>THRIFT-6044</a> - 
Limit struct read/write recursion depth in Go library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6071";>THRIFT-6071</a> - 
Validate container size fits int32 range before narrowing conversion in 
TSimpleJSONProtocol</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6088";>THRIFT-6088</a> - Add 
decompressed data size limit to TZlibTransport</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
Bound the container element count before the 64-bit size precheck in the Go 
JSON protocol</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
widen container size precheck to 64-bit in go protocols</li>
+  <li><a href="https://github.com/apache/thrift/pull/3599";>#3599</a> - check 
wire-supplied size in simple json ReadMapBegin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3497";>#3497</a> - Bump 
golang.org/x/sys to 0.0.0-20220412211240-33da011f77ad</li>
+  <li><a href="https://github.com/apache/thrift/pull/3458";>#3458</a> - Prevent 
concurrent calls to socketConn.Close() in Go</li>
+  <li><a href="https://github.com/apache/thrift/pull/3428";>#3428</a> - Fix 
range check on 32-bit architectures</li>
+  <li><a href="https://github.com/apache/thrift/pull/3379";>#3379</a> - Replace 
addr with factory in TServerSocket</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+  <li><a href="https://github.com/apache/thrift/pull/3381";>#3381</a> - added 
int range checks</li>
+</ul>
+
+<h3 id="haxe">Haxe</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5992";>THRIFT-5992</a> - Haxe 
generator: keyword escaping, stdlib-type renaming, typedef import and FIELD_ID 
fixes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5993";>THRIFT-5993</a> - Haxe 
generator: cross-package import shadowing and Haxe base-type name 
collisions</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5994";>THRIFT-5994</a> - Haxe 
generator: map&lt;bool,V&gt;, map&lt;double,V&gt;, map&lt;binary,V&gt; and set 
equivalents generate invalid ObjectMap/ObjectSet</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6003";>THRIFT-6003</a> - Add 
Haxe codegen test script and GitHub Actions CI job</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6006";>THRIFT-6006</a> - 
Implement MESSAGE_SIZE_LIMIT exception type for Haxe library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6065";>THRIFT-6065</a> - Haxe 
TMemoryStream cannot be written to (fixed-size buffer, uninitialized 
Position)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
Compute container size precheck in 64-bit in Haxe protocols</li>
+  <li><a href="https://github.com/apache/thrift/pull/3571";>#3571</a> - Add 
recursion-depth round-trip test for the Haxe library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+</ul>
+
+<h3 id="java">Java</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6088";>THRIFT-6088</a> - Add 
decompressed byte tracking to Java TZlibTransport</li>
+  <li><a href="https://github.com/apache/thrift/pull/3618";>#3618</a> - Bump 
jvm from 2.3.21 to 2.4.0 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3619";>#3619</a> - Bump 
com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3605";>#3605</a> - enforce 
stringLengthLimit in TCompactProtocol.readBinary</li>
+  <li><a href="https://github.com/apache/thrift/pull/3574";>#3574</a> - Bump 
com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3572";>#3572</a> - Bump 
org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6085";>THRIFT-6085</a> - Add 
message byte tracking to consumeBuffer() in Java transports</li>
+  <li><a href="https://github.com/apache/thrift/pull/3434";>#3434</a> - Bump 
jvm from 2.3.20 to 2.3.21 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3420";>#3420</a> - Fix 
Java Spotless formatting</li>
+  <li><a href="https://github.com/apache/thrift/pull/3415";>#3415</a> - Connect 
skip() to TConfiguration recursion limit</li>
+  <li><a href="https://github.com/apache/thrift/pull/3412";>#3412</a> - Use 
bounded default for maxSkipDepth in TProtocolUtil</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+  <li><a href="https://github.com/apache/thrift/pull/3396";>#3396</a> - Enable 
TLS hostname verification in TNonblockingSSLSocket</li>
+  <li><a href="https://github.com/apache/thrift/pull/3390";>#3390</a> - Enable 
TLS hostname verification in TSSLTransportFactory</li>
+</ul>
+
+<h3 id="javame">JavaME</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6036";>THRIFT-6036</a> - 
Harden JavaME protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6055";>THRIFT-6055</a> - 
Limit struct read/write recursion depth in javame library</li>
+</ul>
+
+<h3 id="javascript">JavaScript</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6014";>THRIFT-6014</a> - Add 
recursion depth limit to skip() in JavaScript library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6017";>THRIFT-6017</a> - 
Upgrade jsdoc from 3.6 to 4.x in lib/js and lib/ts</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6020";>THRIFT-6020</a> - 
Address remaining npm transitive dependency vulnerabilities via audit fix 
(minimatch, elliptic, lodash)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6037";>THRIFT-6037</a> - 
Harden JavaScript (browser) protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6046";>THRIFT-6046</a> - 
Limit struct read/write recursion depth in js library</li>
+  <li><a href="https://github.com/apache/thrift/pull/3593";>#3593</a> - Bump 
shell-quote from 1.7.3 to 1.8.4 in /lib/js</li>
+  <li><a href="https://github.com/apache/thrift/pull/3591";>#3591</a> - Bump 
shell-quote from 1.7.3 to 1.8.4 in /lib/ts</li>
+  <li><a href="https://github.com/apache/thrift/pull/3517";>#3517</a> - Bump 
uuid and nyc</li>
+  <li><a href="https://github.com/apache/thrift/pull/3423";>#3423</a> - Bump 
uuid from 13.0.0 to 14.0.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3385";>#3385</a> - Add 
test for ES6 generated exception constructor</li>
+  <li><a href="https://github.com/apache/thrift/pull/3386";>#3386</a> - Bump 
lodash from 4.17.23 to 4.18.1</li>
+  <li><a href="https://github.com/apache/thrift/pull/3372";>#3372</a> - Fix 
JavaScript exception construction implementation (ES6)</li>
+</ul>
+
+<h3 id="kotlin">Kotlin</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6054";>THRIFT-6054</a> - 
Limit struct read/write recursion depth in Kotlin library</li>
+  <li><a href="https://github.com/apache/thrift/pull/3618";>#3618</a> - Bump 
jvm from 2.3.21 to 2.4.0 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3572";>#3572</a> - Bump 
org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in /lib/kotlin</li>
+  <li><a href="https://github.com/apache/thrift/pull/3434";>#3434</a> - Bump 
jvm from 2.3.20 to 2.3.21 in /lib/kotlin</li>
+</ul>
+
+<h3 id="lua">Lua</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6031";>THRIFT-6031</a> - 
Harden Lua protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6049";>THRIFT-6049</a> - 
Limit struct read/write recursion depth in Lua library</li>
+  <li><a href="https://github.com/apache/thrift/pull/3448";>#3448</a> - final 
change to make header parsing case insensitive</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+</ul>
+
+<h3 id="markdown">Markdown</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6027";>THRIFT-6027</a> - Fix 
UB/assertion in t_markdown_generator::str_to_id (debug build crash)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6038";>THRIFT-6038</a> - 
Markdown generator: use .md extension by default and render @param/@return tags 
as table</li>
+</ul>
+
+<h3 id="mermaid">Mermaid</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6026";>THRIFT-6026</a> - Add 
Mermaid diagram generator (–gen mmd)</li>
+</ul>
+
+<h3 id="netstd">netstd</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-2462";>THRIFT-2462</a> - 
prevent possible stack overflow due to recursive syntax support</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-4534";>THRIFT-4534</a> - 
netcore package should not depend on Microsft.AspNetCore and 
Microsoft.Extensions.*</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5997";>THRIFT-5997</a> - 
netstd generator: binary and uuid constants emitted as C# const instead of 
static readonly</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5998";>THRIFT-5998</a> - 
netstd generator: duplicate DeepCopy/Equals/GetHashCode extension methods when 
IDL includes other IDL files</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6002";>THRIFT-6002</a> - Add 
netstd codegen test script and GitHub Actions CI matrix job (.NET 8/9/10)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6091";>THRIFT-6091</a> - 
Compute container size precheck in 64-bit in netstd protocols</li>
+  <li><a href="https://github.com/apache/thrift/pull/3461";>#3461</a> - 
Migration *.sln to *.slnx (except c++ libs)</li>
+  <li><a href="https://github.com/apache/thrift/pull/3416";>#3416</a> - netcore 
package upgrades</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+  <li><a href="https://github.com/apache/thrift/pull/3407";>#3407</a> - Build 
netstd fuzzers during make check (without instrumentation)</li>
+</ul>
+
+<h3 id="nodejs">nodejs</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5802";>THRIFT-5802</a> -  
Inconsistent Validation for transmitted values</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6019";>THRIFT-6019</a> - 
Replace html-validator-cli with a maintained alternative in root Node.js 
package</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6020";>THRIFT-6020</a> - 
Address remaining npm transitive dependency vulnerabilities via audit fix 
(minimatch, elliptic, lodash)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6040";>THRIFT-6040</a> - 
Switch JS/Node generator and runtime from Q to native Promise</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6090";>THRIFT-6090</a> - 
Bound receive size and amortize buffer growth in Node.js transports</li>
+  <li><a href="https://github.com/apache/thrift/pull/3529";>#3529</a> - 
nodejs+compiler: Add opt-in BigInt support for int64 via js:bigint flag</li>
+  <li><a href="https://github.com/apache/thrift/pull/3526";>#3526</a> - Fix 
WebSocket subprotocol for ws v8</li>
+  <li><a href="https://github.com/apache/thrift/pull/3526";>#3526</a> - Upgrade 
ws from 5.2.x to 8.21.0</li>
+  <li><a href="https://github.com/apache/thrift/pull/3517";>#3517</a> - Bump 
uuid and nyc</li>
+  <li><a href="https://github.com/apache/thrift/pull/3389";>#3389</a> - Add 
recursion depth limit to Node.js protocol skip()</li>
+  <li><a href="https://github.com/apache/thrift/pull/3385";>#3385</a> - Fix 
prettier formatting in generated-exceptions test</li>
+</ul>
+
+<h3 id="nodets">nodets</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6016";>THRIFT-6016</a> - 
lib/ts: jsdoc incorrectly listed under dependencies instead of 
devDependencies</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6017";>THRIFT-6017</a> - 
Upgrade jsdoc from 3.6 to 4.x in lib/js and lib/ts</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6018";>THRIFT-6018</a> - 
Remove phantom and phantomjs-prebuilt from lib/ts devDependencies</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6020";>THRIFT-6020</a> - 
Address remaining npm transitive dependency vulnerabilities via audit fix 
(minimatch, elliptic, lodash)</li>
+  <li><a href="https://github.com/apache/thrift/pull/3591";>#3591</a> - Bump 
shell-quote from 1.7.3 to 1.8.4 in /lib/ts</li>
+  <li><a href="https://github.com/apache/thrift/pull/3517";>#3517</a> - Bump 
uuid and nyc</li>
+</ul>
+
+<h3 id="ocaml">OCaml</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6032";>THRIFT-6032</a> - 
Harden OCaml protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6051";>THRIFT-6051</a> - 
Limit struct read/write recursion depth in OCaml library</li>
+</ul>
+
+<h3 id="perl">Perl</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5064";>THRIFT-5064</a> - 
Introduce Perl::Critic into the SCA</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6028";>THRIFT-6028</a> - 
Harden Perl protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6048";>THRIFT-6048</a> - 
Limit struct read/write recursion depth in Perl library</li>
+</ul>
+
+<h3 id="php">PHP</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-4171";>THRIFT-4171</a> - PHP 
TSocket sendTimeout is being used as connectTimeout</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5757";>THRIFT-5757</a> - Unit 
tests for php lib</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5759";>THRIFT-5759</a> - PHP 
mbstring.func_overload is deprecated</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5929";>THRIFT-5929</a> - Fix 
build failure on PHP 8.5 due to removed zend_exception_get_default</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5951";>THRIFT-5951</a> - PHP 
Unit test update</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5956";>THRIFT-5956</a> - Bump 
minimum PHP version to 8.1</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5957";>THRIFT-5957</a> - Add 
phpstan static analysis with CI guardrail for the PHP runtime library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5959";>THRIFT-5959</a> - 
Adopt PSR-12 across the PHP library and align C++ generator emission style</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5960";>THRIFT-5960</a> - 
Adopt strict_types and native parameter / return / property types in 
lib/php/lib/</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5961";>THRIFT-5961</a> - 
Migrate PHPUnit tests to attribute syntax</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5962";>THRIFT-5962</a> - 
Upgrade PHPUnit to 10 / 11</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5975";>THRIFT-5975</a> - 
Remove dead pre-namespace lib/php/src/{Thrift,autoload}.php</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5976";>THRIFT-5976</a> - Add 
native types to PHP library properties (PHPDoc @var → declared types)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5977";>THRIFT-5977</a> - 
Apply constructor property promotion in PHP runtime library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5978";>THRIFT-5978</a> - 
Apply declare(strict_types=1) in PHP runtime library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5979";>THRIFT-5979</a> - Add 
native method types to PHP Server and Factory classes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5980";>THRIFT-5980</a> - Add 
native method types to PHP Transport hierarchy</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5981";>THRIFT-5981</a> - Add 
native method types to PHP Protocol hierarchy</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5983";>THRIFT-5983</a> - 
Replace switch with match expression in PHP TProtocol::skip and skipBinary</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5984";>THRIFT-5984</a> - 
Cache function_exists() capability checks in PHP runtime hot paths</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5985";>THRIFT-5985</a> - Add 
native method types to PHP Exception hierarchy</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5986";>THRIFT-5986</a> - Emit 
declare(strict_types=1) in PHP generator output</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5987";>THRIFT-5987</a> - Fix 
PHP protocol type-safety bugs in readBool and popContext</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5988";>THRIFT-5988</a> - PHP 
8.1 upgrade follow-up: float constants, README version, and TSSLServerSocket 
API compatibility</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5989";>THRIFT-5989</a> - Work 
around JWT-format GITHUB_TOKEN breaking composer install in CI</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5990";>THRIFT-5990</a> - Emit 
native return types on generated PHP struct methods</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5991";>THRIFT-5991</a> - Emit 
native types on generated PHP struct properties and constructor</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5995";>THRIFT-5995</a> - Add 
native method types to TBase and TException internal serialization helpers</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5999";>THRIFT-5999</a> - 
Raise PHPStan level from 1 to 5 on PHP library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6000";>THRIFT-6000</a> - Add 
native method types to PHP JSON protocol helpers and context classes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6001";>THRIFT-6001</a> - Type 
remaining core PHP library methods and fix TException tmethod UUID drift</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6004";>THRIFT-6004</a> - Emit 
native types on generated PHP service-level methods 
(Client/Interface/Processor/Rest)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6005";>THRIFT-6005</a> - 
Raise PHPStan level from 5 to 6 on PHP library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6008";>THRIFT-6008</a> - Add 
regression tests for recent PHP fixes (UUID exception fields, readBool 
container state, popContext underflow)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6009";>THRIFT-6009</a> - Add 
PSR-3 logger support and runtime deprecation warnings to PHP transports</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6010";>THRIFT-6010</a> - Add 
PSR-18 HTTP transport (TPsrHttpClient) for PHP library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6023";>THRIFT-6023</a> - Add 
HTTP transport support to PHP cross-tests</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6029";>THRIFT-6029</a> - 
Harden PHP protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6047";>THRIFT-6047</a> - 
Limit struct read/write recursion depth in PHP library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+  <li><a href="https://github.com/apache/thrift/pull/2957";>#2957</a> - Fix PHP 
cross-test server IPv4 binding</li>
+</ul>
+
+<h3 id="python">Python</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5915";>THRIFT-5915</a> - 
Python 3.12+ is not supported due to distutils</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5923";>THRIFT-5923</a> - UUID 
support for Python</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6024";>THRIFT-6024</a> - 
Python THeaderTransport and TZlibTransport default max frame/decompressed size 
should be DEFAULT_MAX_FRAME_SIZE (16384000), not HARD_MAX_FRAME_SIZE 
(0x3FFFFFFF)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6043";>THRIFT-6043</a> - 
Harden Python binary protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6067";>THRIFT-6067</a> - 
Python: pip install fails on setuptools &lt; 69 due to sys.exit() in setup.py 
(PEP 517 build backend)</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6069";>THRIFT-6069</a> - 
suggestion for a few python perf improvements</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6070";>THRIFT-6070</a> - 
Publish Python wheel distributions to PyPI</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6088";>THRIFT-6088</a> - Add 
decompressed size limit to Python TZlibTransport</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+  <li><a href="https://github.com/apache/thrift/pull/3413";>#3413</a> - Use 
sslcompat hostname matcher in TSSLSocket</li>
+  <li><a href="https://github.com/apache/thrift/pull/3411";>#3411</a> - Add 
default recursion depth limit to TProtocol.skip()</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6083";>THRIFT-6083</a> - Add 
decompressed payload size limit to Python THeaderTransport</li>
+  <li><a href="https://github.com/apache/thrift/pull/3377";>#3377</a> - 
Optimize Python C extension readStruct for nested structs</li>
+  <li><a href="https://github.com/apache/thrift/pull/2957";>#2957</a> - Fix PHP 
cross-test server IPv4 binding</li>
+</ul>
+
+<h3 id="ruby">Ruby</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-1916";>THRIFT-1916</a> - 
Compiled ruby code generates warning if field with name “fields” is present</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5310";>THRIFT-5310</a> - Ruby 
BinaryProtocol has invalid range checks for byte and i64</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5940";>THRIFT-5940</a> - Ruby 
generator should emit RuboCop-compliant code and SCA should lint generated 
Ruby</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5941";>THRIFT-5941</a> - Add 
Ruby ext cppcheck coverage</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5942";>THRIFT-5942</a> - 
Incorrect connection timeout handling in TSocket / TSSLSocket</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5944";>THRIFT-5944</a> - Fix 
protocol benchmarks for Ruby and add compact protocol support</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5945";>THRIFT-5945</a> - 
Incomplete cleanup in NonblockingServer leaks sockets</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5946";>THRIFT-5946</a> - Use 
trusted publishing for Ruby gem releases</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5948";>THRIFT-5948</a> - 
Reduce Ruby binary extension write-path overhead in native 
force_binary_encoding helper</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5949";>THRIFT-5949</a> - Ruby 
server sockets do not enforce write timeouts on accepted connections</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5950";>THRIFT-5950</a> - Add 
frozen_string_literal to Ruby files to reduce allocations</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6013";>THRIFT-6013</a> - Add 
recursion depth limit to skip() in Ruby library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6015";>THRIFT-6015</a> - 
Allow multiplex processors to fall back to a default service for old 
clients</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6025";>THRIFT-6025</a> - Ruby 
client must validate container sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6045";>THRIFT-6045</a> - 
Limit struct read/write recursion depth in Ruby library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6072";>THRIFT-6072</a> - Ruby 
ThreadedServer and SimpleServer crash on SSL accept errors</li>
+  <li><a href="https://github.com/apache/thrift/pull/3565";>#3565</a> - Allow 
CI to fail on ruby-head</li>
+  <li><a href="https://github.com/apache/thrift/pull/3565";>#3565</a> - Fix 
Ruby lib CI: drop pry/byebug, incompatible with Ruby 4.1+</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6089";>THRIFT-6089</a> - 
Bound decompressed size for Ruby HeaderTransport ZLIB transform</li>
+  <li><a href="https://github.com/apache/thrift/pull/3429";>#3429</a> - Updated 
lib/rb/README.md to highlight Ruby syntax</li>
+  <li><a href="https://github.com/apache/thrift/pull/3424";>#3424</a> - Bump 
json from 2.18.1 to 2.19.2 in /lib/rb</li>
+  <li><a href="https://github.com/apache/thrift/pull/3422";>#3422</a> - Adjust 
minimum Ruby version in the gemspec to match documentation, CI, and 
Changelog</li>
+  <li><a href="https://github.com/apache/thrift/pull/3419";>#3419</a> - Ruby: 
suppress -Wdefault-const-init-field-unsafe for clang 21+</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+  <li><a href="https://github.com/apache/thrift/pull/3395";>#3395</a> - Remove 
unused Ruby client reply helpers</li>
+  <li><a href="https://github.com/apache/thrift/pull/3400";>#3400</a> - Bump 
json from 2.18.1 to 2.19.2 in /test/rb</li>
+  <li><a href="https://github.com/apache/thrift/pull/3397";>#3397</a> - Address 
vulnerabilities in Rack</li>
+  <li><a href="https://github.com/apache/thrift/pull/3382";>#3382</a> - Updated 
Gemfile.lock to fix build issues</li>
+</ul>
+
+<h3 id="rust">Rust</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5953";>THRIFT-5953</a> - Rust 
codegen should support forward-compatible deserialization for union fields in 
structs</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5954";>THRIFT-5954</a> - 
Rust: Add read/write timeout support to TTcpChannel</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6057";>THRIFT-6057</a> - 
Limit struct read/write recursion depth in Rust library</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6058";>THRIFT-6058</a> - Rust 
codegen: <code class="language-plaintext 
highlighter-rouge">list&lt;UnionType&gt;</code> deserialization generates 
shadowed variable and missing Box wrapping</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6059";>THRIFT-6059</a> - add 
crate_prefix option for cross-file import path</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6064";>THRIFT-6064</a> - Rust 
generator does not box recursive union variant on read</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6068";>THRIFT-6068</a> - 
Thrift release on crates.io is very stale; consider auto-publishing</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6095";>THRIFT-6095</a> - 
enforce max_string_size on non-strict binary message name</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6084";>THRIFT-6084</a> - Add 
byte-count limit to TCompactProtocol varint reader</li>
+</ul>
+
+<h3 id="smalltalk">Smalltalk</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6035";>THRIFT-6035</a> - 
Harden Smalltalk protocol negative sizes</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6052";>THRIFT-6052</a> - 
Limit struct read/write recursion depth in Smalltalk library</li>
+</ul>
+
+<h3 id="swift---no-longer-supported">Swift - NO LONGER SUPPORTED</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5864";>THRIFT-5864</a> - Drop 
Swift support</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6033";>THRIFT-6033</a> - 
Harden Swift protocol negative sizes</li>
+</ul>
+
+<h3 id="test-suite">Test Suite</h3>
+
+<ul>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5941";>THRIFT-5941</a> - Add 
Ruby ext cppcheck coverage</li>
+  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-6023";>THRIFT-6023</a> - Add 
HTTP transport support to PHP cross-tests</li>
+</ul>
+
+<h2 id="0230">0.23.0</h2>
+
+<h3 id="build-process-1">Build Process</h3>
+
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5877";>THRIFT-5877</a> - Add 
cpp cross tests</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5866";>THRIFT-5866</a> - 
Dockerfile to support Ubuntu 24.04 LTS (Noble Numbat)</li>
@@ -65,14 +506,14 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5649";>THRIFT-5649</a> - add 
go in GitHub workflow / action</li>
 </ul>
 
-<h3 id="c-glib">C glib</h3>
+<h3 id="c-glib-1">C glib</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5931";>THRIFT-5931</a> - 
thrift_ssl_socket_get_ssl_error() can underflow its remaining-buffer counter 
and write past the stack buffer</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5871";>THRIFT-5871</a> - 
Improve MAX_MESSAGE_SIZE check and friends</li>
 </ul>
 
-<h3 id="c">C++</h3>
+<h3 id="c-1">C++</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5911";>THRIFT-5911</a> - 
Inconsistent UUID compilation for aliased types</li>
@@ -90,20 +531,20 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5920";>THRIFT-5920</a> - 
Remove threadsafe warnings in thrift-maven-plugin</li>
 </ul>
 
-<h3 id="delphi">Delphi</h3>
+<h3 id="delphi-1">Delphi</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5939";>THRIFT-5939</a> - 
Replace GUID generation with stable UUID algorithm</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5876";>THRIFT-5876</a> - Add 
Delphi WinHTTP client TLS1.3 support</li>
 </ul>
 
-<h3 id="go">Go</h3>
+<h3 id="go-1">Go</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5896";>THRIFT-5896</a> - Race 
condition in TServerSocket.Addr() method</li>
 </ul>
 
-<h3 id="java">Java</h3>
+<h3 id="java-1">Java</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5925";>THRIFT-5925</a> - UUID 
implementation in JAVA is not according to the Thrift Specification</li>
@@ -114,14 +555,14 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5879";>THRIFT-5879</a> - java 
and kotlin cross tests fail in the GitHub action</li>
 </ul>
 
-<h3 id="netstd">netstd</h3>
+<h3 id="netstd-1">netstd</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5902";>THRIFT-5902</a> - Add 
net10 support</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5874";>THRIFT-5874</a> - 
Introduce new type <code class="language-plaintext 
highlighter-rouge">MESSAGE_SIZE_LIMIT</code> in TTransportException</li>
 </ul>
 
-<h3 id="nodejs">nodejs</h3>
+<h3 id="nodejs-1">nodejs</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5937";>THRIFT-5937</a> - 
nodejs episodic generation does not handle extending services</li>
@@ -129,13 +570,13 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-4987";>THRIFT-4987</a> - 
TProtocolException: Bad version in readMessageBegin when using XHR client with 
C++ server</li>
 </ul>
 
-<h3 id="nodets">nodets</h3>
+<h3 id="nodets-1">nodets</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5924";>THRIFT-5924</a> - UUID 
support for nodejs and nodets</li>
 </ul>
 
-<h3 id="php">PHP</h3>
+<h3 id="php-1">PHP</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5935";>THRIFT-5935</a> - Fix 
deprecated non-canonical casts for PHP 8.5 compatibility</li>
@@ -143,7 +584,7 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5929";>THRIFT-5929</a> - Fix 
build failure on PHP 8.5 due to removed zend_exception_get_default</li>
 </ul>
 
-<h2 id="python">Python</h2>
+<h2 id="python-1">Python</h2>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5927";>THRIFT-5927</a> - 
Cannot use reserved language keyword “None” with target language Python</li>
@@ -158,7 +599,7 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5900";>THRIFT-5900</a> - 
Thrift Cross Test broken in Github (Python 3.14)</li>
 </ul>
 
-<h3 id="ruby">Ruby</h3>
+<h3 id="ruby-1">Ruby</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5308";>THRIFT-5308</a> - 
implement ruby seq reply </li>
@@ -174,7 +615,7 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5918";>THRIFT-5918</a> - 
Implement header protocol support for Ruby</li>
 </ul>
 
-<h3 id="rust">Rust</h3>
+<h3 id="rust-1">Rust</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5559";>THRIFT-5559</a> - 
Processor can be implemented on handler trait itself</li>
@@ -190,20 +631,20 @@
 
 <h2 id="0220">0.22.0</h2>
 
-<h3 id="build-process-1">Build Process</h3>
+<h3 id="build-process-2">Build Process</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5836";>THRIFT-5836</a> - 
0.21.0 fails to build from sources at Arch Linux: No rule to make target 
‘Thrift5272.thrift’, needed by ‘gen-cpp/Thrift5272_types.h’</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5860";>THRIFT-5860</a> - 
cmake 3.5 as a minimum version does not work with cmake 4.0.0</li>
 </ul>
 
-<h3 id="c-glib-1">C glib</h3>
+<h3 id="c-glib-2">C glib</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5817";>THRIFT-5817</a> - 
Avoid copy of TUuid</li>
 </ul>
 
-<h3 id="c-1">C++</h3>
+<h3 id="c-2">C++</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5637";>THRIFT-5637</a> - 
Thrift compiler should be able to output c++ Aggregate types</li>
@@ -217,14 +658,14 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5865";>THRIFT-5865</a> - Fix 
TBinayProtocol with <code class="language-plaintext 
highlighter-rouge">list&lt;UUID&gt;</code></li>
 </ul>
 
-<h3 id="compiler-general">Compiler (General)</h3>
+<h3 id="compiler-general-1">Compiler (General)</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5823";>THRIFT-5823</a> - Fix 
illegal uses of exceptions as normal struct type</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5835";>THRIFT-5835</a> - 
Allow exceptions to be used as regular struct datatype</li>
 </ul>
 
-<h3 id="delphi-1">Delphi</h3>
+<h3 id="delphi-2">Delphi</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5822";>THRIFT-5822</a> - 
Remove deprecated AnsiString functions from the library</li>
@@ -239,7 +680,7 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5856";>THRIFT-5856</a> - 
Client should validate HTTP status</li>
 </ul>
 
-<h3 id="go-1">Go</h3>
+<h3 id="go-2">Go</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5833";>THRIFT-5833</a> - go: 
Combine I/O and original error in compiler generated Process functions</li>
@@ -247,13 +688,13 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5859";>THRIFT-5859</a> - go: 
Generate a map for know values of an enum type</li>
 </ul>
 
-<h3 id="java-1">Java</h3>
+<h3 id="java-2">Java</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5858";>THRIFT-5858</a> - 
Introduce new type MESSAGE_SIZE_LIMIT in TTransportException</li>
 </ul>
 
-<h3 id="netstd-1">netstd</h3>
+<h3 id="netstd-2">netstd</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5832";>THRIFT-5832</a> - Drop 
net6 support and add net9 instead</li>
@@ -261,7 +702,7 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5852";>THRIFT-5852</a> - 
Promote known total stream sizes for seekable stream transports</li>
 </ul>
 
-<h3 id="nodejs-1">Node.js</h3>
+<h3 id="nodejs-2">Node.js</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5811";>THRIFT-5811</a> - Add 
ES module support to JS codegen</li>
@@ -269,14 +710,14 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5849";>THRIFT-5849</a> - 
Expose createClient in browser version of nodejs package</li>
 </ul>
 
-<h3 id="php-1">PHP</h3>
+<h3 id="php-2">PHP</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-1482";>THRIFT-1482</a> - Unix 
domain socket support under PHP</li>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5829";>THRIFT-5829</a> - PHP 
lib Use of “static” in callables is deprecated notice</li>
 </ul>
 
-<h3 id="python-1">Python</h3>
+<h3 id="python-2">Python</h3>
 
 <ul>
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5024";>THRIFT-5024</a> - 
tutorial\py.tornado\PythonServer.py failed under Tornado6</li>
@@ -291,113 +732,6 @@
   <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-4838";>THRIFT-4838</a> - add 
unix domain socket support to Swift TSocketTransport implementation</li>
 </ul>
 
-<h2 id="0210">0.21.0</h2>
-
-<h3 id="build-process-2">Build Process</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5815";>THRIFT-5815</a> - 
veralign.sh broken and incomplete</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5810";>THRIFT-5810</a> - 
Wrong installation path for static MSVC libs.</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5755";>THRIFT-5755</a> - 
Docker image build fail</li>
-</ul>
-
-<h3 id="c-2">C++</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5272";>THRIFT-5272</a> - 
printTo does not properly handle i8 datatypes</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5492";>THRIFT-5492</a> - 
Bogus END_OF_FILE exception</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5678";>THRIFT-5678</a> - 
TConnectedClient: warning due to non-virtual dtor</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5682";>THRIFT-5682</a> - UB 
in generated C++ code    stops compiling with C++20”</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5709";>THRIFT-5709</a> - 
Drastically improve <code class="language-plaintext 
highlighter-rouge">to_num()</code> performace</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5772";>THRIFT-5772</a> - Add 
UUID support for C++</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5773";>THRIFT-5773</a> - UUID 
wrapper for C++</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5816";>THRIFT-5816</a> - Fix 
UUID for boost 1.86.0 (change in data member usage)</li>
-</ul>
-
-<h3 id="compiler-general-1">Compiler (General)</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5800";>THRIFT-5800</a> - 
“Could not find include file foo.thrift” probably should be failure instead of 
warning</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5766";>THRIFT-5766</a> - 
Replace std::endl with “\n”</li>
-</ul>
-
-<h3 id="delphi-2">Delphi</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5789";>THRIFT-5789</a> - 
Refactor test suite client implementation</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5782";>THRIFT-5782</a> - 
implement full deprecation support</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5750";>THRIFT-5750</a> - 
Remove “ansistr_binary_” option</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5788";>THRIFT-5788</a> - 
Refactor and streamline hash set implementation</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5765";>THRIFT-5765</a> - 
Extra override for WriteBinary() to avoid unnecessary memory allocations when 
using COM types</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5764";>THRIFT-5764</a> - 
Extra CTOR for TThriftBytesImpl</li>
-</ul>
-
-<h3 id="go-2">Go</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5786";>THRIFT-5786</a> - Full 
deprecation support for go</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5654";>THRIFT-5654</a> - 
LNK4042 and LNK2019 in go_validator_generator.cc</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5784";>THRIFT-5784</a> - go: 
Add THeaderTransforms to TConfiguration</li>
-</ul>
-
-<h3 id="java-2">Java</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5762";>THRIFT-5762</a> - 
Expose service result objects in Java</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5530";>THRIFT-5530</a> - 
could not resolve plugin artifact 
‘com.github.johnrengelman.shadow:com.github.johnrengelman.shadow.gradle.plugin:4.0.4’</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5230";>THRIFT-5230</a> - Fix 
connection leak and CancelledKeyException when handling Epoll bug</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-4847";>THRIFT-4847</a> - 
CancelledKeyException causes TThreadedSelectorServer to fail.</li>
-</ul>
-
-<h3 id="json">JSON</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5761";>THRIFT-5761</a> - 
Lib/json tests fail</li>
-</ul>
-
-<h3 id="netstd-2">netstd</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5798";>THRIFT-5798</a> - 
Expand netstd compile tests to fully cover all current target environments</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5797";>THRIFT-5797</a> - 
HashSet() CTOR takes no argument for net &lt; 5</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5796";>THRIFT-5796</a> - 
Indicate target environment via #if check</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5795";>THRIFT-5795</a> - 
namespace not properly escaped</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5794";>THRIFT-5794</a> - 
Uncompilable C# code in 0.20.0</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5781";>THRIFT-5781</a> - 
implement full deprecation support</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5780";>THRIFT-5780</a> - 
Prevent certain warnings related to net8</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5787";>THRIFT-5787</a> - .NET 
ApacheThrift client v20.0 breaks compatibility in TBinaryProtocol.Factory 
constructor</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5783";>THRIFT-5783</a> - drop 
net7 support</li>
-</ul>
-
-<h3 id="nodejs-2">Node.js</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5769";>THRIFT-5769</a> - 
Large messages crash Node.js client when using TFramedTransport</li>
-</ul>
-
-<h3 id="php-2">PHP</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5760";>THRIFT-5760</a> - 
Update minimal version of php</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5758";>THRIFT-5758</a> - PHP 
8.2 Deprecate dynamic properties</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5756";>THRIFT-5756</a> - Run 
php tests in github actions</li>
-</ul>
-
-<h3 id="python-2">Python</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-4181";>THRIFT-4181</a> - PEP 
484 Type Hinting on generated code</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5813";>THRIFT-5813</a> - 
Clarify TSocket state after isOpen</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5777";>THRIFT-5777</a> - 
timeout exception mismatched</li>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5139";>THRIFT-5139</a> - Type 
hinting for Python library</li>
-</ul>
-
-<h3 id="rust-1">Rust</h3>
-
-<ul>
-  <li><a 
href="https://issues.apache.org/jira/browse/THRIFT-5812";>THRIFT-5812</a> - 
Capacity overflow in Rust server</li>
-</ul>
-
 <p class="snippet_footer">This page was generated by Apache Thrift's 
<strong>source tree docs</strong>:
 <a 
href="https://gitbox.apache.org/repos/asf?p=thrift.git;a=blob;hb=HEAD;f=CHANGES.md";>CHANGES.md</a>
 </p>
diff --git a/output/docs/committers/HowToThriftWebsite.html 
b/output/docs/committers/HowToThriftWebsite.html
index 9b972a4..d0ab006 100644
--- a/output/docs/committers/HowToThriftWebsite.html
+++ b/output/docs/committers/HowToThriftWebsite.html
@@ -103,8 +103,8 @@ consistent experience with the various markdown parsers 
deployed by the CMS.</p>
 file” <a 
href="https://svn.apache.org/repos/asf/thrift/cms-site/trunk/lib/path.pm";>lib/path.pm</a>.
 Update
 the following values and then following <b>Updating the Website</b> section 
below</p>
 
-<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code>current_release: "0.23.0"
-current_release_date: "2026-APR-27"
+<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code>current_release: "0.24.0"
+current_release_date: "2026-JUL-11"
 </code></pre></div></div>
 
 <h3 id="updating-the-website">Updating the website</h3>
diff --git a/output/docs/idl.html b/output/docs/idl.html
index 369d806..8302cb9 100644
--- a/output/docs/idl.html
+++ b/output/docs/idl.html
@@ -54,7 +54,7 @@
       
 <h2 id="thrift-interface-description-language">Thrift interface description 
language</h2>
 
-<p>For Thrift version 0.24.0.</p>
+<p>For Thrift version 0.25.0.</p>
 
 <p>The Thrift interface definition language (IDL) allows for the definition of 
<a href="/docs/types">Thrift Types</a>. A Thrift IDL file is processed by the 
Thrift code generator to produce code for the various target languages to 
support the defined structs and services in the IDL file.</p>
 
diff --git a/output/download.html b/output/download.html
index 56b9d1c..9778381 100644
--- a/output/download.html
+++ b/output/download.html
@@ -52,26 +52,26 @@
 
     <div class="container">
       <h2 id="release">Release</h2>
-<p>The latest stable release of Thrift is 0.23.0 (released on 2026-APR-27).</p>
+<p>The latest stable release of Thrift is 0.24.0 (released on 2026-JUL-11).</p>
 
 <p>See the <a href="/changelog">Apache Thrift changelog</a> for release notes 
and development history.</p>
 
 <ul>
-  <li><a 
href="http://www.apache.org/dyn/closer.cgi?path=/thrift/0.23.0/thrift-0.23.0.tar.gz";>thrift-0.23.0.tar.gz</a>
 [<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.asc";>PGP</a>]
-[<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.sha256";>SHA256</a>]
-[<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.sha1";>SHA1</a>]
-[<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.md5";>MD5</a>]</li>
-  <li><a 
href="http://www.apache.org/dyn/closer.cgi?path=/thrift/0.23.0/thrift-0.23.0.exe";>Thrift
 compiler for Windows (thrift-0.23.0.exe)</a> [<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.exe.asc";>PGP</a>]
-[<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.exe.sha256";>SHA256</a>]
-[<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.exe.sha1";>SHA1</a>]
-[<a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.exe.md5";>MD5</a>]</li>
+  <li><a 
href="http://www.apache.org/dyn/closer.cgi?path=/thrift/0.24.0/thrift-0.24.0.tar.gz";>thrift-0.24.0.tar.gz</a>
 [<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.asc";>PGP</a>]
+[<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.sha256";>SHA256</a>]
+[<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.sha1";>SHA1</a>]
+[<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.md5";>MD5</a>]</li>
+  <li><a 
href="http://www.apache.org/dyn/closer.cgi?path=/thrift/0.24.0/thrift-0.24.0.exe";>Thrift
 compiler for Windows (thrift-0.24.0.exe)</a> [<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.exe.asc";>PGP</a>]
+[<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.exe.sha256";>SHA256</a>]
+[<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.exe.sha1";>SHA1</a>]
+[<a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.exe.md5";>MD5</a>]</li>
 </ul>
 
 <h2 id="maven-artifact">Maven artifact</h2>
 <pre><code>&lt;dependency&gt;
   &lt;groupId&gt;org.apache.thrift&lt;/groupId&gt;
   &lt;artifactId&gt;libthrift&lt;/artifactId&gt;
-  &lt;version&gt;0.23.0&lt;/version&gt;
+  &lt;version&gt;0.24.0&lt;/version&gt;
 &lt;/dependency&gt;
 </code></pre>
 
diff --git a/output/index.html b/output/index.html
index 8990098..b7cf31a 100644
--- a/output/index.html
+++ b/output/index.html
@@ -82,27 +82,27 @@
   </div>
   <div class="span3 well center pull-right">
     <h2>Download</h2>
-    <p>Apache Thrift v0.23.0</p>
+    <p>Apache Thrift v0.24.0</p>
     <p>
-      <a class="btn btn-large" 
href="http://www.apache.org/dyn/closer.cgi?path=/thrift/0.23.0/thrift-0.23.0.tar.gz";>
-          Download <small>v0.23.0</small>
+      <a class="btn btn-large" 
href="http://www.apache.org/dyn/closer.cgi?path=/thrift/0.24.0/thrift-0.24.0.tar.gz";>
+          Download <small>v0.24.0</small>
       </a>
     </p>
     <p>
       <small>
-       <a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.sha256";>SHA256</a>
+       <a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.sha256";>SHA256</a>
       </small>
       |
       <small>
-       <a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.sha1";>SHA1</a>
+       <a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.sha1";>SHA1</a>
       </small>
       |
       <small>
-       <a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.md5";>MD5</a>
+       <a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.md5";>MD5</a>
       </small>
       |
       <small>
-       <a 
href="https://www.apache.org/dist/thrift/0.23.0/thrift-0.23.0.tar.gz.asc";>PGP</a>
+       <a 
href="https://www.apache.org/dist/thrift/0.24.0/thrift-0.24.0.tar.gz.asc";>PGP</a>
       </small>
     </p>
     <p>
diff --git a/output/lib/rb.html b/output/lib/rb.html
index bbb8364..f9e2d1f 100644
--- a/output/lib/rb.html
+++ b/output/lib/rb.html
@@ -131,6 +131,29 @@ directly from your application.</p>
 <span class="n">server</span><span class="p">.</span><span 
class="nf">serve</span>
 </code></pre></div></div>
 
+<h2 id="rack-http-endpoint">Rack HTTP Endpoint</h2>
+
+<p>Ruby HTTP transport can be mounted as a Rack application, so applications 
can
+run Thrift on an existing Rack server such as Puma or Falcon.
+The examples below use the generated <code class="language-plaintext 
highlighter-rouge">Calculator::Processor</code> and the
+<code class="language-plaintext highlighter-rouge">CalculatorHandler</code> 
from <a href="#basic-server-usage">Basic Server Usage</a>.</p>
+
+<div class="language-ruby highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="c1"># config.ru</span>
+<span class="nb">require</span> <span class="s1">'thrift'</span>
+<span class="nb">require</span> <span 
class="s1">'thrift/server/rack_application'</span>
+
+<span class="n">processor</span> <span class="o">=</span> <span 
class="no">Calculator</span><span class="o">::</span><span 
class="no">Processor</span><span class="p">.</span><span 
class="nf">new</span><span class="p">(</span><span 
class="no">CalculatorHandler</span><span class="p">.</span><span 
class="nf">new</span><span class="p">)</span>
+<span class="n">run</span> <span class="no">Thrift</span><span 
class="o">::</span><span class="no">RackApplication</span><span 
class="p">.</span><span class="nf">new</span><span class="p">(</span><span 
class="n">processor</span><span class="p">)</span>
+</code></pre></div></div>
+
+<p>For Rails or another Rack router, mount the endpoint at the route that 
should
+receive Thrift HTTP requests:</p>
+
+<div class="language-ruby highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="c1"># config/routes.rb</span>
+<span class="n">processor</span> <span class="o">=</span> <span 
class="no">Calculator</span><span class="o">::</span><span 
class="no">Processor</span><span class="p">.</span><span 
class="nf">new</span><span class="p">(</span><span 
class="no">CalculatorHandler</span><span class="p">.</span><span 
class="nf">new</span><span class="p">)</span>
+<span class="n">mount</span> <span class="no">Thrift</span><span 
class="o">::</span><span class="no">RackApplication</span><span 
class="p">.</span><span class="nf">new</span><span class="p">(</span><span 
class="n">processor</span><span class="p">)</span> <span class="o">=&gt;</span> 
<span class="s2">"/thrift"</span>
+</code></pre></div></div>
+
 <h2 id="development-and-tests">Development and Tests</h2>
 
 <ul>
@@ -155,6 +178,33 @@ optional native extension that accelerates protocols and 
buffers.</li>
 
 <h2 id="breaking-changes">Breaking Changes</h2>
 
+<h3 id="0250">0.25.0</h3>
+
+<p>Ruby HTTP servers now share one Rack endpoint. Run <code 
class="language-plaintext highlighter-rouge">Thrift::RackApplication</code>
+as a Rack app, or mount it at one path in an app such as Rails. The
+cross-language HTTP tests now cover Puma and Falcon.</p>
+
+<p><code class="language-plaintext 
highlighter-rouge">Thrift::MongrelHTTPServer</code> has been removed because 
Mongrel no longer works
+with supported Ruby versions. To migrate, mount <code 
class="language-plaintext highlighter-rouge">Thrift::RackApplication</code> in
+a supported Rack server. See <a href="#rack-http-endpoint">Rack HTTP 
Endpoint</a>.</p>
+
+<p><code class="language-plaintext 
highlighter-rouge">Thrift::ThinHTTPServer</code> is deprecated because Thin is 
no longer maintained.
+Its EventMachine dependency also does not build on new Ruby development
+versions. Creating a Thin server now prints a warning. Move to
+<code class="language-plaintext 
highlighter-rouge">Thrift::RackApplication</code> with a supported Rack server 
such as Puma or Falcon.</p>
+
+<p><code class="language-plaintext highlighter-rouge">Thrift::SSLSocket</code> 
now verifies peers by default when no SSL context is
+provided. It creates a context that uses the system certificate store. A
+supplied SSL context is not reconfigured by Thrift, so the application is
+responsible for its verification mode and trust sources. A newly constructed
+<code class="language-plaintext 
highlighter-rouge">OpenSSL::SSL::SSLContext</code> defaults to <code 
class="language-plaintext highlighter-rouge">OpenSSL::SSL::VERIFY_NONE</code>; 
configuring
+a trust source alone does not enable certificate chain verification. The server
+certificate must still match the connection hostname.</p>
+
+<p><code class="language-plaintext 
highlighter-rouge">Thrift::Socket#open</code> now raises
+<code class="language-plaintext 
highlighter-rouge">Thrift::TransportException::ALREADY_OPEN</code> when the TCP 
transport is already
+open. Close the transport before opening it again.</p>
+
 <h3 id="0240">0.24.0</h3>
 
 <p>Connect timeout handling changed for both <code class="language-plaintext 
highlighter-rouge">Thrift::Socket</code> and
@@ -263,6 +313,14 @@ use different require paths, so switch them atomically 
with regenerated code.</p
 <h2 id="migration-notes">Migration Notes</h2>
 
 <ul>
+  <li>If you upgrade to <code class="language-plaintext 
highlighter-rouge">0.25.0</code>, note that <code class="language-plaintext 
highlighter-rouge">Thrift::SSLSocket</code> now verifies peers
+by default when it creates the SSL context. Supplied contexts are used
+unchanged and must configure their own verification mode and trust sources.
+A blank supplied context defaults to <code class="language-plaintext 
highlighter-rouge">OpenSSL::SSL::VERIFY_NONE</code>. Hostname
+checking is performed for both supplied and default contexts.</li>
+  <li>If you upgrade to <code class="language-plaintext 
highlighter-rouge">0.25.0</code>, close a <code class="language-plaintext 
highlighter-rouge">Thrift::Socket</code> before calling <code 
class="language-plaintext highlighter-rouge">open</code>
+again. A duplicate open now raises
+<code class="language-plaintext 
highlighter-rouge">Thrift::TransportException::ALREADY_OPEN</code>.</li>
   <li>If you upgrade to <code class="language-plaintext 
highlighter-rouge">0.24.0</code>, treat <code class="language-plaintext 
highlighter-rouge">timeout</code> on <code class="language-plaintext 
highlighter-rouge">Thrift::Socket</code> and
 <code class="language-plaintext highlighter-rouge">Thrift::SSLSocket</code> as 
one budget for the whole open path. For
 <code class="language-plaintext highlighter-rouge">Thrift::SSLSocket</code>, 
that includes both the TCP connect and the TLS
@@ -303,8 +361,22 @@ request and reply state on a single transport stream.</li>
   <li>Client and server must agree on transport and protocol choices. If you
 switch to SSL, HTTP, header transport, compact protocol, or namespaced
 generated code, update both ends together.</li>
-  <li>HTTPS client transport verifies peers by default, and <code 
class="language-plaintext highlighter-rouge">Thrift::SSLSocket</code>
-performs a hostname check against the host you pass in.</li>
+  <li>
+    <p>HTTPS client transport and <code class="language-plaintext 
highlighter-rouge">Thrift::SSLSocket</code> verify peers by default.
+When no SSL context is provided, <code class="language-plaintext 
highlighter-rouge">Thrift::SSLSocket</code> creates one with peer
+verification and the system certificate store. Thrift passes a supplied
+context to OpenSSL without reconfiguring it. <code class="language-plaintext 
highlighter-rouge">Thrift::SSLSocket</code> always
+checks the certificate against <code class="language-plaintext 
highlighter-rouge">server_hostname</code> (or the connection host by
+default). <code class="language-plaintext 
highlighter-rouge">OpenSSL::SSL::SSLContext.new</code> defaults to
+<code class="language-plaintext 
highlighter-rouge">OpenSSL::SSL::VERIFY_NONE</code>, and setting <code 
class="language-plaintext highlighter-rouge">ca_file</code>, <code 
class="language-plaintext highlighter-rouge">ca_path</code>, or <code 
class="language-plaintext highlighter-rouge">cert_store</code>
+does not enable verification by itself. Set <code class="language-plaintext 
highlighter-rouge">verify_mode</code> explicitly when
+supplying a context. For example, to disable certificate chain 
verification:</p>
+
+    <div class="language-ruby highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code><span class="n">context</span> <span class="o">=</span> 
<span class="no">OpenSSL</span><span class="o">::</span><span 
class="no">SSL</span><span class="o">::</span><span 
class="no">SSLContext</span><span class="p">.</span><span class="nf">new</span>
+<span class="n">context</span><span class="p">.</span><span 
class="nf">verify_mode</span> <span class="o">=</span> <span 
class="no">OpenSSL</span><span class="o">::</span><span 
class="no">SSL</span><span class="o">::</span><span 
class="no">VERIFY_NONE</span>
+<span class="n">socket</span> <span class="o">=</span> <span 
class="no">Thrift</span><span class="o">::</span><span 
class="no">SSLSocket</span><span class="p">.</span><span 
class="nf">new</span><span class="p">(</span><span class="n">host</span><span 
class="p">,</span> <span class="n">port</span><span class="p">,</span> <span 
class="kp">nil</span><span class="p">,</span> <span 
class="n">context</span><span class="p">)</span>
+</code></pre></div>    </div>
+  </li>
 </ul>
 
 <p class="snippet_footer">This page was generated by Apache Thrift's 
<strong>source tree docs</strong>:
diff --git a/output/test/index.html b/output/test/index.html
index 1667f24..ee5ba31 100644
--- a/output/test/index.html
+++ b/output/test/index.html
@@ -93,6 +93,12 @@ Java TBinaryProtocol:</p>
 <div class="language-plaintext highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code>test/test.py --regex "java.*binary"
 </code></pre></div></div>
 
+<p>Use <code class="language-plaintext highlighter-rouge">--dry-run</code> to 
print the selected test names without running them. All
+other filters still apply:</p>
+
+<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre 
class="highlight"><code>test/test.py --dry-run --client rb --regex "_http-"
+</code></pre></div></div>
+
 <h2 id="test-case-definition-file">Test case definition file</h2>
 
 <p>The cross test cases are defined in <a href="tests.json">tests.json</a>.
@@ -140,8 +146,15 @@ definition root:</p>
 }
 </code></pre></div></div>
 
+<p>List values in <code class="language-plaintext 
highlighter-rouge">client</code> and <code class="language-plaintext 
highlighter-rouge">server</code> definitions are appended to matching
+root values. They do not replace them. Some targets need combinations that
+cannot share the same lists. Such targets may use more than one definition
+with the same <code class="language-plaintext highlighter-rouge">name</code>. 
The runner treats those definitions as one target. Each
+test name includes its protocol, transport, and socket, so reports and known
+failures still identify the exact case. Use <code class="language-plaintext 
highlighter-rouge">--regex</code> to select one profile.</p>
+
 <p>For the complete list of supported keys and their effect, see source code
-comment at the opt of <a 
href="crossrunner/collect.py">crossrunner/collect.py</a>.</p>
+comment at the top of <a 
href="crossrunner/collect.py">crossrunner/collect.py</a>.</p>
 
 <h2 id="list-of-known-failures">List of known failures</h2>
 

Reply via email to