)]}'
{
  "log": [
    {
      "commit": "b4f40a96040764a79011d0bc4a73356f3c89407d",
      "tree": "3b57f40ae0fb9dd4f289f9529a84b24974a31f3c",
      "parents": [
        "6b8eaf7e0e5ecf9a22b9bb70503063c9470bf889"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Sep 03 16:47:08 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 03 16:47:08 2026 +0800"
      },
      "message": "build(deps-dev): bump browserslist from 4.25.1 to 4.28.8 in /admin/web (#1028)\n\nBumps [browserslist](https://github.com/browserslist/browserslist) from 4.25.1 to 4.28.8.\n- [Release notes](https://github.com/browserslist/browserslist/releases)\n- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/browserslist/browserslist/compare/4.25.1...4.28.8)\n\n---\nupdated-dependencies:\n- dependency-name: browserslist\n  dependency-version: 4.28.8\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6b8eaf7e0e5ecf9a22b9bb70503063c9470bf889",
      "tree": "b45b1b927d6a5564b55ab50fb1b4eb246d936068",
      "parents": [
        "05ff17f8c10dc291817c330035dec783fe7d3ea8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Sep 03 16:46:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 03 16:46:52 2026 +0800"
      },
      "message": "build(deps-dev): bump fast-uri from 3.1.5 to 3.1.7 in /admin/web (#1029)\n\nBumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n  dependency-version: 3.1.7\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "05ff17f8c10dc291817c330035dec783fe7d3ea8",
      "tree": "4365b47ad6c4f6a02e3d03b6ff572d5a08a20fb2",
      "parents": [
        "6a498838d50d88fe978748e302c25d8d67e9f98a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Sep 02 12:55:06 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 12:55:06 2026 +0800"
      },
      "message": "build(deps-dev): bump postcss-selector-parser in /admin/web (#1025)\n\nBumps [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) from 6.1.2 to 6.1.4.\n- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)\n- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss-selector-parser/compare/v6.1.2...6.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: postcss-selector-parser\n  dependency-version: 6.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6a498838d50d88fe978748e302c25d8d67e9f98a",
      "tree": "fc734b2a2b1b3044f0cce1bdbb57cbce7ff032d6",
      "parents": [
        "5e6931d3b808df065c5c0e057df2b18afa499f88"
      ],
      "author": {
        "name": "Tsukikage",
        "email": "65526564+Tsukikage7@users.noreply.github.com",
        "time": "Wed Aug 26 21:20:31 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 27 12:20:31 2026 +0800"
      },
      "message": "perf: cut gRPC/Triple/Dubbo proxy latency via connection reuse and descriptor caching (fix #820) (#1017)\n\n* perf: reduce gRPC, Triple, and Dubbo proxy latency"
    },
    {
      "commit": "5e6931d3b808df065c5c0e057df2b18afa499f88",
      "tree": "a694884fa11f87a9db31388be39fe165d96298dc",
      "parents": [
        "84e7bf5fbfe488a1ee070fbc7daf8ab68074b32b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Aug 25 11:47:31 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 11:47:31 2026 +0800"
      },
      "message": "build(deps): bump github.com/gorilla/websocket in /tools/benchmark (#1022)\n\nBumps [github.com/gorilla/websocket](https://github.com/gorilla/websocket) from 1.4.2 to 1.5.3.\n- [Release notes](https://github.com/gorilla/websocket/releases)\n- [Commits](https://github.com/gorilla/websocket/compare/v1.4.2...v1.5.3)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/gorilla/websocket\n  dependency-version: 1.5.3\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "84e7bf5fbfe488a1ee070fbc7daf8ab68074b32b",
      "tree": "074efde334b2ac458554cd99a8eaecea92e420f1",
      "parents": [
        "a84c5bb8bc738a3b16ebd87818f0b62433c6f309"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Aug 25 11:47:00 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 11:47:00 2026 +0800"
      },
      "message": "build(deps): bump github.com/gorilla/websocket from 1.4.2 to 1.5.3 (#1021)\n\nBumps [github.com/gorilla/websocket](https://github.com/gorilla/websocket) from 1.4.2 to 1.5.3.\n- [Release notes](https://github.com/gorilla/websocket/releases)\n- [Commits](https://github.com/gorilla/websocket/compare/v1.4.2...v1.5.3)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/gorilla/websocket\n  dependency-version: 1.5.3\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a84c5bb8bc738a3b16ebd87818f0b62433c6f309",
      "tree": "b5f994195dc2ef66cb365e061c4ff73b0a651d41",
      "parents": [
        "153c1fe0fcc03aeeae19094285ad1b4112c026c4"
      ],
      "author": {
        "name": "dubbo-go-bot",
        "email": "dubbo-go@outlook.com",
        "time": "Mon Aug 24 12:53:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 12:53:07 2026 +0800"
      },
      "message": "fix(accesslog): avoid max latency after decode short-circuit (#116) (#1020)\n\n* fix(accesslog): avoid max latency after decode short-circuit\n\n* test(accesslog): bound wait for log entry\n\nCo-authored-by: EmptyCity-111 \u003c3047874865@qq.com\u003e"
    },
    {
      "commit": "153c1fe0fcc03aeeae19094285ad1b4112c026c4",
      "tree": "df4fc38d59f6efd885452a9dd9683b661ef26854",
      "parents": [
        "4fd217b799d0608140c8f12f931c7a85e723f72b"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Mon Aug 24 10:46:10 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 10:46:10 2026 +0800"
      },
      "message": "fix(dubboproxy): replace panic with error returns in filter construction (#996)\n\n* fix(dubboproxy): replace panic with error returns in filter construction\n\nFixes #989 Issue 3: network filter/plugin construction path uses panic\nfor type assertion failures where normal error propagation would be safer.\n\nChanges in plugin.go:\n- CreateFilter: Replace panic with error return when config type assertion fails\n  - Already had error return in signature but was panicking instead\n  - Now returns proper error: \"expected *model.DubboProxyConnectionManagerConfig, got %T\"\n\nChanges in manager.go:\n- OnData: Replace panic with error return when data type assertion fails\n  - Already had error return in signature but was panicking instead\n  - Now returns proper error: \"expected *invocation.RPCInvocation, got %T\"\n\nClassification:\n- Both panics were type assertion failures during request/startup handling\n- Neither was a true invariant violation (programming errors should be caught)\n- Both methods already had error returns - just not using them\n- Returning errors allows graceful handling without crashing the server\n\nNote: The recover() in handleRpcInvocation (line 182-187) is kept as is -\nthat\u0027s a proper defensive pattern that catches panics from filter chain.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix(dubboproxy): improve error message clarity\n\n- Change verbose error message in CreateFilter to concise type-mismatch format\n- Change verbose error message in OnData to concise type-mismatch format\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix(dubboproxy): fix import formatting for CI\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix(dubboproxy): replace panics with error returns in OnTripleData\n\n- Check metadata value array length before accessing first element\n- Use safe type assertion for interface key extraction\n- Return descriptive errors instead of panicking\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* test(dubboproxy): add unit tests for panic-to-error fixes\n\nAdd comprehensive tests for dubboproxy network filter:\n\nplugin_test.go:\n- Test CreateFilter with valid config (success)\n- Test CreateFilter with invalid config type (error, not panic)\n\nmanager_test.go:\n- Test OnData with invalid type returns error (not panic)\n- Test OnData with valid RPCInvocation passes type check\n- Test OnTripleData with empty metadata value returns error\n- Test OnTripleData with missing interface key returns error\n- Test OnTripleData with valid metadata passes type check\n- Test OnEncode with invalid type returns error\n\nCoverage improvements:\n- CreateFilter: 100%\n- OnData: 63.2%\n- OnTripleData: 56.0%\n\nThese tests verify the fixes in PR #996 that replace panics\nwith proper error returns for type assertion failures.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix: add missing newline at end of test files\n\nCI gofmt check requires newline at end of files.\n\n* fix: format imports in test files for CI\n\nimports-formatter requires specific grouping of imports:\n- Standard library\n- Third-party packages\n- Project packages\n\n* style: replace interface{} with any in test files\n\ngolangci-lint v2.4.0 requires interface{} to be replaced with any\n\n---------\n\nCo-authored-by: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "4fd217b799d0608140c8f12f931c7a85e723f72b",
      "tree": "a92e2243dd40fdd0f07717fa01d1a46456830220",
      "parents": [
        "6ebc858b8d4857ed2281d7909537bb58918aaef9"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Aug 24 10:45:30 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 10:45:30 2026 +0800"
      },
      "message": "build(deps-dev): bump shell-quote from 1.8.4 to 1.10.0 in /admin/web (#1007)\n\nBumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.\n- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.10.0)\n\n---\nupdated-dependencies:\n- dependency-name: shell-quote\n  dependency-version: 1.10.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6ebc858b8d4857ed2281d7909537bb58918aaef9",
      "tree": "d8d843eff6bff38f2cf0b68076ac8d8bdd979e9a",
      "parents": [
        "106afed39e3447d64b5f63f6c537e6dbbd4cabc6"
      ],
      "author": {
        "name": "Yuqi Qiao",
        "email": "19606363088@163.com",
        "time": "Thu Aug 20 14:38:06 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 20 14:38:06 2026 +0800"
      },
      "message": "feat(cluster): decouple config from runtime — private Config, RuntimeState, and RoundRobin cursor migration (#973)\n\n* feat(model): add ConfigID identity and CloneClusterConfig for config-runtime decoupling\n\n- Add ConfigID field to ClusterConfig for stable config-runtime identity\n  (replaces fragile pointer comparison after deep copy)\n- Add CloneClusterConfig deep-copy helper with independent Endpoints,\n  HealthChecks, and ConsistentHash (hash set to nil for runtime rebuild)\n- Update ClusterConfig godoc: document immutability after publication,\n  runtime state ownership, and PrePickEndpointIndex legacy status\n\n* feat(cluster): decouple config from runtime with private Config and RuntimeState\n\n- Make Cluster.Config private (config) with Config() getter\n- Add RuntimeState struct with RoundRobinCursor; add accessors\n- Add RoundRobinCursor to PickContext; update snapshot RoundRobin\n  to use runtime-owned cursor instead of ClusterConfig.PrePickEndpointIndex\n- Add ConfigID for stable config-runtime identity; replace pointer\n  comparison with ConfigIsIdenticalTo\n- Wire CloneClusterConfig into replaceClusterRuntimeWithSnapshot\n- Remove dead getCluster method\n- Adapt tests and benchmarks to new API\n\n* fix(cluster): reconcile legacy RR cursor delta back to RoundRobinCursor when present\n\nWhen the legacy pickEndpoint fallback path reads cursorBefore from\nRoundRobinCursor, the Handler advances config.PrePickEndpointIndex (a local\nshallow copy). The delta was unconditionally written back to\ncontext.Config.PrePickEndpointIndex, which left the runtime-owned\nRoundRobinCursor stale. Apply the delta to RoundRobinCursor when it is\nthe source of cursorBefore.\n\n* fix(cluster): add nil guard in NewClusterWithEndpointSnapshot for config dereferences\n\nGuard clusterConfig.ConfigID and HealthChecks access against nil config,\npreserving the prior behaviour where a nil config built an empty snapshot\nwithout panicking.\n\n* fix(cluster): sync config endpoints to runtime before RefreshEndpoints\n\nWhen SetEndpoint or replaceEndpointAt appends/modifies endpoints on the\nstore\u0027s ClusterConfig, the runtime holds an independent deep copy from\nreplaceClusterRuntimeWithSnapshot. RefreshEndpoints reads from the\nruntime\u0027s config, missing the store-side mutations.\n\nAdd SyncConfigEndpoints to sync the store\u0027s authoritative endpoint slice\nback to the runtime config before RefreshEndpoints.\n\n* fix: gofmt indentation in cluster_manager.go\n\n* fix(cluster): preserve custom hash across runtime config clone"
    },
    {
      "commit": "106afed39e3447d64b5f63f6c537e6dbbd4cabc6",
      "tree": "50568784ed395ba6efb1a98a0ae421d37a4c185d",
      "parents": [
        "55d841c94d2af8e9ae55a02430cf5b29ec056189"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sat Aug 15 14:27:01 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Aug 15 14:27:01 2026 +0800"
      },
      "message": "refactor(loadbalancer): gate snapshot fast paths behind an internal opt-in token (#971)\n\n* refactor(loadbalancer): gate snapshot fast paths behind an internal opt-in token\n\nThe zero-copy and healthy-only snapshot fast paths were opt-in via two\nexported marker interfaces, ZeroCopySnapshotLoadBalancer and\nHealthyOnlySnapshotLoadBalancer. Because Go interface satisfaction is\nstructural, any external load-balancer plugin could implement those method\nnames and silently opt into contracts that require never mutating or\nretaining snapshot-owned endpoints — risking request-path mutation, stale\npointer retention, or data races on the shared snapshot.\n\nReplace the two markers with a single internal opt-in: balancers expose\nSnapshotOptIn() returning snapshotopt.Token, a struct in a new\ninternal/snapshotopt package. Only balancers rooted at\npkg/cluster/loadbalancer can import that package and name the return type,\nso only trusted in-tree balancers can opt in. External plugins cannot\nconstruct a Token, cannot satisfy the opt-in interface, and therefore\nalways fall through to the safe default: full snapshot, defensively copied.\n\nThe public extension surface (SnapshotLoadBalancer, PickContext) is\nunchanged; bundled balancers (RoundRobin, Rand, WeightRandom, Maglev,\nRingHash) keep their fast path via the new token. Behavior is otherwise\nidentical.\n\nA new test (TestExternalLikeBalancerCannotOptIntoFastPaths) reproduces an\nout-of-tree plugin carrying the old method names and asserts it is treated\nas untrusted: full snapshot, defensive copy, mutation does not escape.\n\nCloses #941\n\n* fix(loadbalancer): keep deprecated snapshot markers compatible\n\n* fix(loadbalancer): close embedding bypass and drop unreleased markers\n\nThe internal-token opt-in stops out-of-tree code from declaring\nSnapshotOptIn, but an external plugin could still embed an in-tree\nbalancer and gain the method through promotion, silently re-entering the\nzero-copy / healthy-only fast paths. snapshotOptIn now also verifies the\nbalancer\u0027s concrete type lives under pkg/cluster/loadbalancer, so a\npromoted method from an embedded balancer no longer grants trust.\n\nRemove the HealthyOnlySnapshotLoadBalancer and ZeroCopySnapshotLoadBalancer\nmarker interfaces along with the Use* methods and var _ assertions on the\nbundled balancers. The markers were introduced in #932 and never shipped\nin a release, so there is no external caller to stay compatible with;\nkeeping them contradicted the PR goal and coupled the balancers to\ndeprecated, runtime-ignored APIs.\n\nAdd an external-package regression (load_balancer_external_test.go) that\nembeds an in-tree balancer and asserts it still receives the full\nsnapshot and a defensive copy."
    },
    {
      "commit": "55d841c94d2af8e9ae55a02430cf5b29ec056189",
      "tree": "4b81decddbe24ce31d966754e3bfc92b916e52a5",
      "parents": [
        "92aa484e9b0990c6d1719e40d30bb965121ab88c"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sat Aug 15 14:08:30 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Aug 15 14:08:30 2026 +0800"
      },
      "message": "perf(llm): make cooldown store eviction O(1) with container/list LRU (#966)\n\n* perf(llm): make cooldown store eviction O(1) with container/list LRU\n\nThe bounded cooldown store evicted its oldest entry by scanning the\nwhole map to find the minimum lastFailure, so eviction on the failure\npath was O(N) in the number of tracked endpoints.\n\nBack the store with a container/list ordered oldest-at-front,\nnewest-at-back, and key the map to *list.Element. markFailure now moves\na refreshed entry to the back and inserts new entries at the back;\neviction pops the front in O(1). Each cooldownEntry carries its own key\nso a front pop can delete the matching map entry without a reverse\nlookup. A shared removeLocked helper keeps the map and list in sync on\nevery delete, sweep, and eviction, so no stale list element survives.\n\nCaller-visible cooldown behavior (key, TTL, idempotent replay, lazy\nsweep) is unchanged. No new dependency, no background goroutine.\n\nNew tests cover the LRU-specific invariants: refresh updates recency,\nthe TTL sweep clears both map and list state, and deleting an expired\ncooldown leaves no stale list element.\n\nCloses #943\n\n* refactor(llm): drop dead eviction guard in cooldown store\n\nevictOldestIfFullLocked is only called for brand-new keys, so the\noldestKey \u003d\u003d current guard can never fire. Worse, if it ever did it\nwould skip eviction and let markFailure push the store past capacity.\nRemove the guard and the now-unused current parameter.\n\n* perf(llm): inject nowFn into cooldownStore to fix timestamp/list ordering under concurrency\n\nmarkFailure previously sampled time.Now() before acquiring the mutex, so\nconcurrent callers could record a newer timestamp but insert earlier in the\nrecency list, causing eviction to drop a still-active cooldown entry.\n\nFix: add nowFn func() time.Time to cooldownStore (default time.Now), called\ninside the mutex so timestamp and PushBack order are always consistent.\nmarkFailure signature drops the lastFailure parameter; callers no longer\nsupply a timestamp. Tests inject a controlled clock via store.nowFn."
    },
    {
      "commit": "92aa484e9b0990c6d1719e40d30bb965121ab88c",
      "tree": "0902edf8f95858cdd9aba99387aa12966ce51802",
      "parents": [
        "57781a8831d69f030af14b11e8c88f6aae3186e0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 12 13:42:31 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 12 13:42:31 2026 +0800"
      },
      "message": "build(deps): bump nanoid from 3.3.11 to 3.3.18 in /admin/web (#1018)\n\nBumps [nanoid](https://github.com/ai/nanoid) from 3.3.11 to 3.3.18.\n- [Release notes](https://github.com/ai/nanoid/releases)\n- [Changelog](https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md)\n- [Commits](https://github.com/ai/nanoid/compare/3.3.11...3.3.18)\n\n---\nupdated-dependencies:\n- dependency-name: nanoid\n  dependency-version: 3.3.18\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "57781a8831d69f030af14b11e8c88f6aae3186e0",
      "tree": "1f73207dca04f56892153f32a3c4c056ef538730",
      "parents": [
        "60fcbf17dda3fb159d103a5a0e61ec81a2e9b055"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Aug 06 13:45:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 06 13:45:32 2026 +0800"
      },
      "message": "build(deps-dev): bump fast-uri from 3.1.4 to 3.1.5 in /admin/web (#1016)\n\nBumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n  dependency-version: 3.1.5\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "60fcbf17dda3fb159d103a5a0e61ec81a2e9b055",
      "tree": "5335699b8368d1128eaebb358d46d1270e77e83b",
      "parents": [
        "ac1ee2a84770d56245cf818bd44deb16a098d17a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 28 10:18:20 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 28 10:18:20 2026 +0800"
      },
      "message": "build(deps): bump github.com/quic-go/quic-go in /tools/benchmark (#1014)\n\nBumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.57.0 to 0.59.1.\n- [Release notes](https://github.com/quic-go/quic-go/releases)\n- [Commits](https://github.com/quic-go/quic-go/compare/v0.57.0...v0.59.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/quic-go/quic-go\n  dependency-version: 0.59.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "ac1ee2a84770d56245cf818bd44deb16a098d17a",
      "tree": "9523e0256d8dadd30653de3a3fdd348f01f70087",
      "parents": [
        "f49ac46a7fcfa09bf5d87ef147f9225d7116a80d"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sun Jul 26 13:38:04 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 13:38:04 2026 +0800"
      },
      "message": "refactor(cluster): consolidate duplicated endpoint ID suffix algorithm (#969) (#972)\n\nnextStableEndpointID (pkg/server) and uniqueSnapshotEndpointID (pkg/cluster)\nwere byte-for-byte identical implementations of the -2/-3 collision-suffix\nalgorithm, kept in sync only by convention. Since the endpoint ID is the\nruntime health/cooldown key, a future edit to one and not the other would\nsilently assign different IDs to the same endpoint, splitting its health\nstate across a snapshot rebuild.\n\nLift the algorithm into model.StableUniqueEndpointID next to GenerateEndpointID\n(which both already call) and route all three call sites through it. No behavior\nchange. Add a test asserting config assembly and snapshot rebuild produce\nidentical IDs for a duplicate-ID cluster, locking the two paths together."
    },
    {
      "commit": "f49ac46a7fcfa09bf5d87ef147f9225d7116a80d",
      "tree": "e348d5162612ef9be2d4ee3306e2f58e4dab3830",
      "parents": [
        "e43f7fa1e17c6b0bb2f6dcd3049217cb6f086dce"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sun Jul 26 13:36:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 13:36:13 2026 +0800"
      },
      "message": "perf(loadbalancer): O(1) snapshot pick recheck via healthy-by-ID index (#970)\n\n* perf(loadbalancer): O(1) snapshot pick recheck via healthy-by-ID index\n\nhealthyEndpointFromSnapshot validated a balancer\u0027s pick by scanning the\nhealthy slice twice: a pointer-equality pass, then a sameEndpointIdentity\npass (with a per-element SocketAddress.Equal). Zero-copy balancers hit the\npointer pass early, but non-zero-copy snapshot balancers return an element\nof the cloned HealthyEndpoints slice, whose pointer never matches the\ncontext slice — so every pick fell through to the full O(N) identity scan.\n\nExpose the snapshot\u0027s existing healthyEndpointByID index as an O(1),\nallocation-free accessor (HealthyEndpointByIDForPick) and thread it into\nPickContext via a small HealthyEndpointByIDLookup interface (declared in\nloadbalancer so it keeps no dependency on pkg/cluster). The recheck now\nresolves the single candidate by ID and applies the unchanged\nsameEndpointIdentity rules to it; it falls back to the original scan when\nno index is present (hand-built contexts) or the pick has no ID (the\nempty-ID / placeholder-address path), preserving every existing rule\nincluding the blank-domain wildcard and the reject-on-not-found defense.\n\nBenchmarkHealthyEndpointFromSnapshot, 1024 healthy endpoints, non-zero-copy\nreturn (ID at the far end):\n  identity-scan-without-index  1368 ns/op\n  identity-recheck-with-index    36 ns/op\nThe result clone (1 alloc) is unchanged; the win is the removed O(N) walk,\nwhich matters for large clusters under high QPS.\n\nCloses #955\n\n* fix(loadbalancer): clear HealthyByID in defensive snapshot context\n\ndefensiveSnapshotPickContext clones the endpoint slices to isolate\nnon-zero-copy balancers from live snapshot pointers, but it did not clear\nthe newly-added HealthyByID field. This allowed untrusted balancers to call\nHealthyByIDForPick and obtain un-cloned snapshot-owned endpoints, breaking\nthe memory-isolation guarantee that the defensive copy exists to enforce.\n\nThe recheck (healthyEndpointFromSnapshot) still works correctly because both\ncall sites pass the original context, whose HealthyByID remains intact. Only\nthe balancer-facing defensive copy is affected.\n\nCurrent impact: zero (all in-tree balancers are zero-copy and none read\nHealthyByID). This change closes a latent trust-boundary leak before external\nplugins can exploit it.\n\n* perf(loadbalancer): keep by-id zero-copy pointer fast path\n\n* chore(loadbalancer): address sonar maintainability issues"
    },
    {
      "commit": "e43f7fa1e17c6b0bb2f6dcd3049217cb6f086dce",
      "tree": "c4a00507f027baa36aac97835c9dcc3b8c91fdbd",
      "parents": [
        "192414aa7849ed60cd217ce7674a9696349917ca"
      ],
      "author": {
        "name": "twotwotwo",
        "email": "yjt20061029@gmail.com",
        "time": "Sun Jul 26 13:33:28 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 13:33:28 2026 +0800"
      },
      "message": "add: Write unit tests (#947)\n\n* Refactor RouteSnapshot and MethodAllowed function\n\n* Enhance router logic for method-specific matching\n\nRefactor routing logic to improve method-specific trie matching and error handling.\n\n* Update router.go\n\n* 修正笔误\n\n* fix a typo\n\n* Add files via upload\n\n* Add files via upload\n\n* Add files via upload\n\n* Add files via upload\n\n* Add files via upload\n\n* Add files via upload\n\n* Add OPA end-to-end test runner script\n\nThis script is a convenience wrapper for running end-to-end tests using Go. It sets up the necessary environment and executes the test suite for OPA.\n\n* Add files via upload\n\n* Refactor README.md for clarity and conciseness\n\nUpdated README.md to remove redundant explanations and clarify the purpose of the directory. Adjusted formatting and improved section headings.\n\n* Add files via upload\n\n* Update README to include language options\n\nAdd language options to the README file.\n\n* Refactor comments in e2e_opa_test.go\n\nUpdated comments for clarity and consistency in e2e_opa_test.go.\n\n* fix ci fail\n\n* fix ci fail\n\n* 优化结构\n\n* fix opa tests after review\n\n* stabilize initialize opa mock transport\n\n* Make OPA run script executable\n\n* Fix OPA E2E docs table row"
    },
    {
      "commit": "192414aa7849ed60cd217ce7674a9696349917ca",
      "tree": "f4d9106a9922dec8084b716789f4f13169639c49",
      "parents": [
        "3687feded23a26c388733f46107c64c9af0f6289"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sun Jul 26 13:20:06 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 13:20:06 2026 +0800"
      },
      "message": "ci(lint): enable staticcheck SA1019 for new deprecated-symbol usage (#964)\n\n* ci(lint): enable staticcheck SA1019 for new deprecated-symbol usage\n\nRemove the global SA1019 exclusion from .golangci.yaml so golangci-lint\nflags new uses of deprecated symbols. With the existing issues.new: true\ngate, only newly changed code is checked, leaving pre-existing third-party\ndeprecations untouched.\n\nAnnotate the intentional deprecated AutoResolve read with a narrow\n//nolint:staticcheck. Add a `make lint` target so the check is runnable\nlocally.\n\nCloses #945\n\n* fix(lint): improve Makefile lint target with proper syntax and error handling\n\n- Add .PHONY declarations for lint and check-lint targets\n- Fix dependency syntax: \u0027lint: check-lint\u0027 instead of \u0027lint:check-lint\u0027\n- Add exit 1 to check-lint so make fails early with clear message when golangci-lint is missing\n- Improve error message formatting\n\nAddresses Copilot review feedback on PR #964.\n\n* ci(lint): fetch parent for new issue filtering\n\n* fix(ci): fix SA1019 new-issue detection for multi-commit push\n\n- Remove issues.new from .golangci.yaml; move diff-base logic to workflow\n- Add \u0027Resolve lint base\u0027 step: use pull_request.base.sha for PRs,\n  github.event.before for pushes, fetch that commit to fix shallow-clone\n  \u0027fatal: bad revision\u0027 error\n- Pass --new-from-rev explicitly so golangci-lint always diffs against\n  the correct base regardless of push batch size\n\n* fix(ci): restore issues.new for local lint; workflow uses --new-from-rev"
    },
    {
      "commit": "3687feded23a26c388733f46107c64c9af0f6289",
      "tree": "218c1bbecc877835b7b3654f148fefaa610c0bbe",
      "parents": [
        "51523e6a0e98b2979258d47ee0dbfef2e005aed9"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sun Jul 26 13:19:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 13:19:22 2026 +0800"
      },
      "message": "perf(cluster): defer Config consistent-hash rebuild to legacy pick path (#967)\n\n* perf(cluster): defer Config consistent-hash rebuild to legacy pick path\n\nprepareClusterConfig rebuilt Config.ConsistentHash.Hash eagerly on every\nAddCluster/UpdateCluster/SetEndpoint/DeleteEndpoint. After the snapshot\nwork in #932, that field is only read by the legacy (non-snapshot) pick\npath; all bundled balancers are snapshot-aware and use the snapshot\u0027s own\nhealthy hash. So the eager rebuild is dead work on the common path, and\nfor a large Maglev table it is milliseconds of wasted CPU on every\nendpoint churn in flapping service-discovery environments.\n\nInvalidate the Config-level hash (set to nil) in prepareClusterConfig and\nbuild it lazily via ClusterConfig.EnsureConsistentHash, called from the\nlegacy branch of pickEndpoint under the existing legacyPickMu. The\nin-Handler nil fallback in Maglev/RingHash stays as a safety net.\n\nEnsureConsistentHash uses a nil-check rather than a sync.Once field: a\nvalue Once on ClusterConfig trips go vet copylocks at the legacy path\u0027s\n`config :\u003d *context.Config` shallow copy, and the legacy path is already\nserialized by legacyPickMu so no extra synchronization is needed. A fresh\nClusterConfig from CloneStore (whose Hash interface does not survive the\nyaml round-trip) rebuilds independently on its first legacy pick.\n\nBenchmarkSetEndpoint, 64-endpoint Maglev cluster, MaglevTableSize\u003d65537:\n  before  1087 ns/op  1721 B/op\n  after    413 ns/op   481 B/op\n\nCloses #957\n\n* test(cluster): fix BenchmarkSetEndpoint to actually exercise the rebuild path\n\nThe benchmark reused a single update set, so after the first 64-iteration\ncycle every SetEndpoint hit the content-equal idempotent short-circuit and\nreturned before prepareClusterConfig. Both the eager and deferred builds\ntherefore measured the same ~410 ns fast path, not the table rebuild the\nbenchmark claimed to compare.\n\nAlternate between two metadata generations so every SetEndpoint is a genuine\nin-place replace that runs prepareClusterConfig on each call. Corrected\nbenchstat (-count\u003d8, 64-endpoint Maglev, MaglevTableSize\u003d65537):\n\n  before (eager)     10505 us/op   18016 KiB/op   864 allocs/op\n  after  (deferred)  53.12 us/op   90.21 KiB/op   614 allocs/op\n                     -99.5%        -99.5%         -28.9%  (p\u003d0.000)\n\nAlso note in pickEndpoint that the legacy EnsureConsistentHash branch is\nunreached in-tree (all bundled balancers are snapshot-aware); the win comes\nfrom dropping the eager rebuild, and the lazy build is out-of-tree compat.\n\n* fix(cluster): preserve custom consistent hashes"
    },
    {
      "commit": "51523e6a0e98b2979258d47ee0dbfef2e005aed9",
      "tree": "2310ec4e7987ae0e47c8079d4b4a8683698dc16e",
      "parents": [
        "e7691370f89fc2f394546dfdc9a79f1a53f573d0"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Thu Jul 23 21:02:28 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 21:02:28 2026 +0800"
      },
      "message": "feat(llm): inject cooldown store via plugin and remove shared global (#963)\n\n* feat(llm): inject cooldown store via plugin and remove shared global\n\nThe LLM proxy cooldown store was a package-level sharedCooldownStore\ndiscovered through multi-level fallback in the filter factory and request\nexecutor. This made ownership fuzzy and test isolation harder.\n\nMake ownership explicit: the proxy Plugin, a process-level singleton in the\nfilter registry, lazily owns one cooldown store and injects it into every\nFilterFactory it creates. The request executor always receives a non-nil\nstore from construction, so the production request path no longer needs a\nfallback resolver.\n\nClusterManager cannot own the store without an import cycle (server does not\nimport the proxy package), so the Plugin is the clearly-owned process-level\nruntime object the store lives on.\n\nCloses #939\n\n* refactor(llm): construct plugin cooldown store eagerly\n\nThe proxy Plugin is built once at init, so guarding cooldown store creation\nbehind sync.Once added no value over building it up front. Replace the\nlazy cooldownStore() accessor with a newPlugin() constructor that creates\nthe store at construction time, dropping the cooldownOnce field. This also\nremoves the only concurrent-initialization path, so no synchronization\nreasoning is needed. Tests build plugins through the constructor.\n\n* refactor(llm): implement lazy cooldown store init with sync.Once\n\nAddress Copilot review comments:\n- Add sync.Once to Plugin for lazy cooldown store initialization\n- Implement Plugin.cooldownStore() accessor that safely initializes on first call\n- Update init() to use zero-value Plugin registration\n- Update tests to use zero-value Plugin construction\n\nThis ensures the PR description\u0027s claim of \u0027lazily owns (sync.Once)\u0027 matches\nthe implementation, and defends against zero-value Plugin construction where\np.cooldowns would otherwise be nil."
    },
    {
      "commit": "e7691370f89fc2f394546dfdc9a79f1a53f573d0",
      "tree": "3d81860c2adc1c6e9e8c54507c721004aa3e463c",
      "parents": [
        "0679e25ead96dbfc4211012e741c79729d74da67"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Thu Jul 23 21:02:08 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 21:02:08 2026 +0800"
      },
      "message": "feat(cluster): add metrics for endpoint snapshot publication (#962)\n\n* feat(cluster): add metrics for endpoint snapshot publication\n\nAdd observability for endpoint snapshot publication so operators can\ndiagnose registry churn, unexpected cluster size, or excessive health\nupdate publication.\n\nEmit three OpenTelemetry instruments, labeled only by cluster name, on\neach successful snapshot CompareAndSwap:\n\n- pixiu_cluster_snapshot_publish_total (counter)\n- pixiu_cluster_snapshot_endpoint_count (gauge)\n- pixiu_cluster_snapshot_healthy_endpoint_count (gauge)\n\nInstruments bind lazily to the global MeterProvider, so they stay no-op\nwhen metrics are disabled and do not alter snapshot publication behavior.\n\nCloses #944\n\n* fix(cluster): ensure snapshot metrics recorded at static cluster startup\n\nMove registerOtelMetricMeter before cluster construction so static clusters\u0027\ninitial snapshot publish lands on the real meter provider rather than the\nno-op default. Without this fix, static clusters with no health transitions\nshow empty counter/gauges in steady state — defeating the PR\u0027s goal of\ndiagnosing unexpected cluster sizes.\n\nChanges:\n- Move registerOtelMetricMeter call from (*Server).Start() to Start(bs),\n  positioned before server.initialize(bs) which constructs clusters\n- Add TestStaticClusterSnapshotMetricsRecordedAtStartup in pkg/server to\n  guard against ordering regression (models production: provider → clusters)\n- Expand installSnapshotMetricsReader doc to note all cluster construction\n  triggers global instrument init (t.Parallel constraint)\n\nIssue: #944\n\n* docs(cluster): fix installClusterSnapshotMetricsReader comment accuracy\n\nUpdate the helper\u0027s documentation to accurately reflect its behavior: it\ninstalls a ManualReader provider and restores the previous provider on\ncleanup, but does not reset pkg/cluster\u0027s instrument variables (which are\nin a different package and not accessible from pkg/server tests).\n\nThe comment previously claimed it \"resets the global instrument state\" and\nmentioned \"pkg/cluster instrument variables,\" but the implementation only\nswaps otel.MeterProvider without touching snapshotPublishTotal,\nsnapshotEndpointCount, or snapshotHealthyCount.\n\nAddresses review feedback on PR #962."
    },
    {
      "commit": "0679e25ead96dbfc4211012e741c79729d74da67",
      "tree": "a6841ad8179c2bd7dc44b68d6769e2418670fe66",
      "parents": [
        "e3031c478cc1ee6fdf57c2c337259fb5f3e0f0e8"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Wed Jul 22 17:48:46 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 17:48:46 2026 +0800"
      },
      "message": "feat(mcp): add deterministic tool governance for MCP server (#953)\n\n* feat(mcp): intelligent tool routing for MCP server filter (#937)\n\n* refactor(mcp): harden router admin endpoint and prune dead code\n\nSecurity/refinement (admin debug endpoint, selection context):\n- restrict the router plan-inspection endpoint to loopback peers, trusting\n  only RemoteAddr (never X-Forwarded-For) so it is not reachable from real\n  clients even when payload_logging is enabled\n- drop header sanitization/snapshotting from SelectionContext; the router\n  consumes only validated JWT claims, so request headers never enter plan\n  state or decision logs\n- extract fallback/sample-rate validation into helpers; fail fast at Build\n\nDead-code removal:\n- remove the offline SchemaMatcher and eval harness (schema.go, eval/).\n  MCP tools/list carries no prompt, so prompt-based ranking has no live\n  input; the experimental ranker and its CLI evaluator were unreachable\n  from the request path\n- drop the StageSchema label and the now-orphaned SelectionContext.UserPrompt\n- remove PassthroughSelector: a disabled router is represented by a nil\n  selector, making the no-op selector redundant\n\nQuality cleanup:\n- writeClaimsFingerprint takes io.Writer instead of an inline interface\n- replace hand-rolled containsMediaType/containsSubstring with strings.Contains\n- document that the tools/call denial message is intentionally generic and\n  decoupled from the internal error\n- document the ExpandAfterCalls default (\u003c\u003d0 -\u003e 1)\n- sync MCP docs to drop references to the removed evaluator\n\n* docs(mcp): clarify policy AND semantics and admin endpoint security\n\n- Add warning about policy rule combination (logical AND)\n- Add security warning for admin endpoint in proxy/sidecar deployments\n- Add logging for configHash marshal failures\n\nAddresses review feedback from owner review.\n\n* fix(mcp): address sonar router findings\n\n* fix(mcp): use secure sampling for router logs\n\n* test(mcp): deduplicate tools list hookpoint setup\n\n* style: run gofmt for mcp router\n\n* style: format mcp imports\n\n* style: fix mcp router comment spelling\n\n* fix mcp router session safety\n\n* fix: address mcp sonar issues\n\n* fix(mcp): separate router session lifecycle\n\n* test(mcp): cover router session reconnect\n\n* docs(mcp): align router session behavior\n\n* test(mcp): cover router session compatibility\n\n* test(mcp): reduce router benchmark complexity\n\n* fix(mcp): harden router selection state\n\n* fix(mcp): harden always-on tool governance\n\n* fix(mcp): enable tool governance when router is configured\n\n* fix(mcp): address sonar issues\n\n* test(mcp): deduplicate SSE filter helpers\n\n* fix(mcp): harden router lifecycle governance\n\n* fix(mcp): reduce tools list complexity\n\n* fix(mcp): address governance review issues\n\n* fix(mcp): address sonar parameter grouping issues in endpoint reconciler\n\n* test(mcp): deduplicate router and auth test fixtures\n\nExtract shared RouterConfig fixture in composite_test.go and the HS256\nauth-chain setup in filter_test.go into helpers to remove the duplicated\nblocks flagged by Sonar on new code.\n\n* refactor mcp router shared governance helpers\n\n* fix(mcp): harden dynamic registry publication\n\n* test(mcp): harden deterministic governance publication"
    },
    {
      "commit": "e3031c478cc1ee6fdf57c2c337259fb5f3e0f0e8",
      "tree": "d7ee4f8bb6f4bbb0b84e38252d975844bf93d17d",
      "parents": [
        "a0d523f63b87b9659663b67a544261fad6c69a45"
      ],
      "author": {
        "name": "wm_03",
        "email": "3134058368@qq.com",
        "time": "Wed Jul 22 16:33:12 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 16:33:12 2026 +0800"
      },
      "message": "Fix: improve skills for pixiu (#933)\n\n* feat: add Pixiu skills\n\n* fix: harden Pixiu skill validators and docs\n\n* fix: harden Pixiu skill scripts\n\n* fix: add MCP validator dependency preflight\n\n* harden Pixiu validators against helper failures\n\n* fix: write validator failure summaries to stderr\n\n* fix: add license headers to Pixiu skill scripts\n\n* fix: remove check scripts and reference docs\n\n* fix: update Pixiu skills for new Dubbo config style\n\n* fix: improve pixiu skills\n\n* fix: Rename pixiu-mcp-integration to pixiu-mcp-gateway\n\n* fix: add \u003cHARD-GATE\u003e\n\n* fix skills review feedback\n\n* Move Pixiu skills under agents directory\n\n* feat: introduce Pixiu agent plugin\n\n* docs(skills): tighten Pixiu filter and MCP gateway validation"
    },
    {
      "commit": "a0d523f63b87b9659663b67a544261fad6c69a45",
      "tree": "4731ae4bbcbffa4367f5c640bbee3cc447fdfae1",
      "parents": [
        "aa7ff6215b7ce530f5e06500b26a2a8ab1491e65"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 13:51:48 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 13:51:48 2026 +0800"
      },
      "message": "build(deps): bump google.golang.org/grpc in /controllers (#1009)\n\nBumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.75.1 to 1.82.1.\n- [Release notes](https://github.com/grpc/grpc-go/releases)\n- [Commits](https://github.com/grpc/grpc-go/compare/v1.75.1...v1.82.1)\n\n---\nupdated-dependencies:\n- dependency-name: google.golang.org/grpc\n  dependency-version: 1.82.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "aa7ff6215b7ce530f5e06500b26a2a8ab1491e65",
      "tree": "0eb0f48a582f0522b882d8eb8ee8e26796910db0",
      "parents": [
        "db4fbbd639503916077498f99cb4e80b3d6edfa0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 13:51:39 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 13:51:39 2026 +0800"
      },
      "message": "build(deps-dev): bump fast-uri from 3.1.2 to 3.1.4 in /admin/web (#1010)\n\nBumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.4.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n  dependency-version: 3.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "db4fbbd639503916077498f99cb4e80b3d6edfa0",
      "tree": "2b742b22e84c5cb3f1ce4673533ab76bf929f3c9",
      "parents": [
        "6b32f623309f8d40d6369e927c8e6316ee4335f9"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 13:51:31 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 13:51:31 2026 +0800"
      },
      "message": "build(deps): bump immutable from 5.0.3 to 5.1.9 in /admin/web (#1011)\n\nBumps [immutable](https://github.com/immutable-js/immutable-js) from 5.0.3 to 5.1.9.\n- [Release notes](https://github.com/immutable-js/immutable-js/releases)\n- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/immutable-js/immutable-js/compare/v5.0.3...v5.1.9)\n\n---\nupdated-dependencies:\n- dependency-name: immutable\n  dependency-version: 5.1.9\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6b32f623309f8d40d6369e927c8e6316ee4335f9",
      "tree": "cced575b6a54d111dcd8194c233e07400c02541c",
      "parents": [
        "760c9a7c3b6a3fb2ef23a732ac36f5bd3e288ecd"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 13:51:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 13:51:22 2026 +0800"
      },
      "message": "build(deps-dev): bump svgo from 2.8.0 to 2.8.3 in /admin/web (#1012)\n\nBumps [svgo](https://github.com/svg/svgo) from 2.8.0 to 2.8.3.\n- [Release notes](https://github.com/svg/svgo/releases)\n- [Commits](https://github.com/svg/svgo/compare/v2.8.0...v2.8.3)\n\n---\nupdated-dependencies:\n- dependency-name: svgo\n  dependency-version: 2.8.3\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "760c9a7c3b6a3fb2ef23a732ac36f5bd3e288ecd",
      "tree": "c02190ca5b0473133af02859ee51e6c5b4d0ad31",
      "parents": [
        "58ce97f596bd1a7d150a41ae84c4687b25dadd4d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 09:39:42 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 09:39:42 2026 +0800"
      },
      "message": "build(deps): bump body-parser from 1.20.5 to 1.20.6 in /admin/web (#1008)\n\nBumps [body-parser](https://github.com/expressjs/body-parser) from 1.20.5 to 1.20.6.\n- [Release notes](https://github.com/expressjs/body-parser/releases)\n- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)\n- [Commits](https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6)\n\n---\nupdated-dependencies:\n- dependency-name: body-parser\n  dependency-version: 1.20.6\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "58ce97f596bd1a7d150a41ae84c4687b25dadd4d",
      "tree": "aaad2aeb867bce1b4b09687cb13abed532082359",
      "parents": [
        "7edad2d89f11f92515c2e3f77e36817c01f107a1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 13:46:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 13:46:32 2026 +0800"
      },
      "message": "build(deps): bump axios from 1.15.2 to 1.18.0 in /admin/web (#1006)\n\nBumps [axios](https://github.com/axios/axios) from 1.15.2 to 1.18.0.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.15.2...v1.18.0)\n\n---\nupdated-dependencies:\n- dependency-name: axios\n  dependency-version: 1.18.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7edad2d89f11f92515c2e3f77e36817c01f107a1",
      "tree": "5c330cfa9697477becd3b27c2fa6581c435e17e9",
      "parents": [
        "3928efaa874659694c6f3d2b19b700d2311350ae"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Sat Jul 18 22:35:18 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 13:35:18 2026 +0800"
      },
      "message": "fix(cmd): replace panic with error returns in gateway startup (#997)\n\n* fix(cmd): replace panic with error returns in gateway startup\n\nFixes #989 Issue 3: gateway startup path uses panic for initialization\nand startup errors where normal error propagation would be safer.\n\nChanges:\n- PreRun → PreRunE: Use cobra\u0027s error handling instead of panic\n  - initialize() failure now returns wrapped error to cobra\n- Run → RunE: Use cobra\u0027s error handling instead of panic\n  - start() failure now returns wrapped error to cobra\n- stop() method: Return error instead of panic\n  - Changed from panic(\"implement me\") to errors.New(\"stop not implemented\")\n\nClassification:\n- PreRun panic: configuration/startup error → return error to cobra\n- Run panic: startup error → return error to cobra (currently unreachable)\n- stop panic: placeholder → return error\n\nBenefits:\n- Cobra handles errors gracefully, printing clean error messages\n- Stack traces are no longer shown for configuration errors\n- Users get clearer feedback on what went wrong\n- Future changes to server.Start() can return errors properly\n\nNote: server.Start() currently blocks and never returns errors. The RunE\nhandler is prepared for future improvements where server.Start might return\nan error instead of blocking indefinitely.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix(cli): handle Execute() errors to ensure non-zero exit codes on failure\n\n- Update cmd/pixiu/pixiu.go to call os.Exit(1) when Execute() returns an error\n- Update cmd/admin/admin.go with same fix for consistency\n- Change deploy variable to interface type for better testability\n- Add comprehensive tests for PreRunE and RunE error handling in pkg/cmd/gateway_test.go\n\nThis addresses the regression where startup failures could exit with status 0\nwhen PreRunE or RunE returned errors, breaking scripts/health checks that rely\non exit codes.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix(fmt): apply gofmt formatting\n\n- Fix import ordering in cmd/pixiu/pixiu.go\n- Fix struct field alignment in pkg/cmd/gateway_test.go\n- Add newline at end of gateway_test.go\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* fix(fmt): add blank line between import groups in gateway_test.go\n\nFollow project\u0027s imports-formatter convention for import grouping.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n---------\n\nCo-authored-by: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "3928efaa874659694c6f3d2b19b700d2311350ae",
      "tree": "5ee6c6cc3174ec4c74c9f5613726b85e0be3afde",
      "parents": [
        "c6e36c2f4c84b8ab5d1e80c0edbf817a379abd2d"
      ],
      "author": {
        "name": "Xuetao Li",
        "email": "m134679102365478@163.com",
        "time": "Fri Jul 17 12:30:51 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 20:30:51 2026 +0800"
      },
      "message": "chore(CI): add riscv build ci for pixiu (#1005)\n\n* add\n\n* add\n\n* Add wasm build tags to exclude Windows"
    },
    {
      "commit": "c6e36c2f4c84b8ab5d1e80c0edbf817a379abd2d",
      "tree": "9f225beb9b319807b71fb58bf6588bf10d31f92c",
      "parents": [
        "08c072042220cf33f6b9af2d74a5f8c49a430971"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 17:58:41 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 17:58:41 2026 +0800"
      },
      "message": "build(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /admin/web (#1004)\n\nBumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.\n- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/faye/websocket-driver-node/compare/0.7.4...0.7.5)\n\n---\nupdated-dependencies:\n- dependency-name: websocket-driver\n  dependency-version: 0.7.5\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "08c072042220cf33f6b9af2d74a5f8c49a430971",
      "tree": "6497b1e4a68af8b47a469124cb685c09bf20f154",
      "parents": [
        "0765f2579c88c52be8e3fa203b23491966c9dc10"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Sun Jul 12 18:28:40 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 13 09:28:40 2026 +0800"
      },
      "message": "build(deps): upgrade cobra v1.5.0 → v1.10.2 and viper v1.8.1 → v1.21.0 (#985)\n\nUpgrade spf13/cobra from v1.5.0 to v1.10.2 and spf13/viper from v1.8.1\nto v1.21.0. These were significantly outdated (2021-2022 versions).\n\nNotable transitive dependency changes:\n- spf13/pflag v1.0.5 → v1.0.10\n- spf13/afero v1.10.0 → v1.15.0\n- spf13/cast v1.7.1 → v1.10.0\n- fsnotify/fsnotify v1.6.0 → v1.9.0\n- inconshreveable/mousetrap v1.0.0 → v1.1.0\n- pelletier/go-toml/v2 v2.2.2 → v2.2.4\n- subosito/gotenv v1.2.0 → v1.6.0\n- Added: go-viper/mapstructure/v2 v2.4.0\n- Added: sagikazarmark/locafero v0.11.0\n- Added: sourcegraph/conc v0.3.1\n\nAll tests pass. Build verified.\n\nCo-authored-by: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "0765f2579c88c52be8e3fa203b23491966c9dc10",
      "tree": "4f9050d01290c39441ff9d4568562c943c070b7e",
      "parents": [
        "a67ef9c49bb444c35cff810a484161fe7d98e976"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Sat Jul 11 16:40:47 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 16:40:47 2026 +0800"
      },
      "message": "refactor(admin): remove personal fork dependency v.marlon.life/toolkit (#984)\n\n* refactor(admin): remove personal fork dependency v.marlon.life/toolkit\n\nReplace util.WaitGroupWrapper with standard sync.WaitGroup.\nThe dependency was used only for WaitGroupWrapper which is a thin\nwrapper around sync.WaitGroup. Using the standard library directly\neliminates a personal-domain dependency with no stability guarantees\nand addresses Apache project compliance concerns.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n* style(admin): fix import grouping for sync package\n\nMove \u0027sync\u0027 into the standard library import block to satisfy\nthe imports-formatter CI check.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n\n---------\n\nCo-authored-by: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "a67ef9c49bb444c35cff810a484161fe7d98e976",
      "tree": "07a7af2661413f1ed4b569e06e95d5d293fc433a",
      "parents": [
        "fabfc6b737b095a30971f4cb64371519a75dd12f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 11 14:09:36 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 14:09:36 2026 +0800"
      },
      "message": "build(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#1002)\n\nBumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.51.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.51.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n  dependency-version: 0.52.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "fabfc6b737b095a30971f4cb64371519a75dd12f",
      "tree": "7605670c224bb143c403289276eddd749a5912b9",
      "parents": [
        "59ee0cbc4b2bd4ca7b80acd9dc507774d8b603f5"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 11 14:09:26 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 14:09:26 2026 +0800"
      },
      "message": "build(deps): bump golang.org/x/crypto in /tools/benchmark (#1003)\n\nBumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.51.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.51.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n  dependency-version: 0.52.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "59ee0cbc4b2bd4ca7b80acd9dc507774d8b603f5",
      "tree": "3768c9895a3bdaac0cee3afeacc84b16ee9a527d",
      "parents": [
        "9c0cd206aa7774208978276e4daff52e99a5500d"
      ],
      "author": {
        "name": "wm_03",
        "email": "3134058368@qq.com",
        "time": "Mon Jul 06 20:17:16 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 20:17:16 2026 +0800"
      },
      "message": "Feat/reuse snapshot consistent hash (#960)\n\n* fix(cluster): Reuse consistent hash only for unchanged snapshots\n\n* fix: remove redundant reuseHealthyConsistentHashFrom call in withEndpointHealthForIDs"
    },
    {
      "commit": "9c0cd206aa7774208978276e4daff52e99a5500d",
      "tree": "6984347caf70390ee504a8152fef3b5172e76ed1",
      "parents": [
        "a387d8f0be2df7ff98bbdb5d57267782b7394ee7"
      ],
      "author": {
        "name": "wm_03",
        "email": "3134058368@qq.com",
        "time": "Mon Jul 06 20:16:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 20:16:52 2026 +0800"
      },
      "message": "Feat(cluster): reduce endpoint cloning (#961)\n\n* test(cluster): adds endpoint membership churn benchmark.\n\n* feat(cluster): Avoid recloning store-owned endpoints\n\n* feat(cluster): drop redundant nil guards\n\n* feat(cluster): use slices.Delete for endpoint removal"
    },
    {
      "commit": "a387d8f0be2df7ff98bbdb5d57267782b7394ee7",
      "tree": "2910897ee06c7819012359a89995f1f4b25f9102",
      "parents": [
        "665260d4ee3adb0926a49d03f56f46893972d975"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 06 09:20:57 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 09:20:57 2026 +0800"
      },
      "message": "build(deps): bump golang.org/x/net in /tools/benchmark (#1001)\n\nBumps [golang.org/x/net](https://github.com/golang/net) from 0.52.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.52.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n  dependency-version: 0.55.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "665260d4ee3adb0926a49d03f56f46893972d975",
      "tree": "1e723dd7a34070958b8927dd4626ee1b334a70c5",
      "parents": [
        "a777e99df40abd8c197b92fa266052073be17d99"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 05 15:48:56 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 05 15:48:56 2026 +0800"
      },
      "message": "build(deps): bump golang.org/x/net from 0.43.0 to 0.55.0 in /controllers (#999)\n\nBumps [golang.org/x/net](https://github.com/golang/net) from 0.43.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.43.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n  dependency-version: 0.55.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a777e99df40abd8c197b92fa266052073be17d99",
      "tree": "ef60d516b79b5e43e9ecd24f9088004d59e26d65",
      "parents": [
        "daaeb6e1f1953403e737155807e50a558034369c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 05 15:48:37 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 05 15:48:37 2026 +0800"
      },
      "message": "build(deps): bump golang.org/x/net from 0.52.0 to 0.55.0 (#1000)\n\nBumps [golang.org/x/net](https://github.com/golang/net) from 0.52.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.52.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n  dependency-version: 0.55.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "daaeb6e1f1953403e737155807e50a558034369c",
      "tree": "f910eb206e2e8431e0ea45f92e98c166144e728e",
      "parents": [
        "c3df76a0fc1652a1dc9da9e910bf83ec91369ed5"
      ],
      "author": {
        "name": "Skylm808",
        "email": "lmtian808@gmail.com",
        "time": "Mon Jun 29 09:37:24 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 09:37:24 2026 +0800"
      },
      "message": "Feature/openapi sdk validator (#948)\n\n* Add OpenAPI request validation filter\n\n\n---------\n\nCo-authored-by: Tianlm \u003cskylm@TianlmdeMacBook-Air.local\u003e"
    },
    {
      "commit": "c3df76a0fc1652a1dc9da9e910bf83ec91369ed5",
      "tree": "5032e2fa1b0a0d17e80933bc12c41bfc6c29d452",
      "parents": [
        "93f6f7097ea7f1a596d832af4c44536cd46c4053"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 22 09:25:06 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 22 09:25:06 2026 +0800"
      },
      "message": "build(deps): bump form-data in /admin/web (#988)\n\nBumps  and [form-data](https://github.com/form-data/form-data). These dependencies needed to be updated together.\n\nUpdates `form-data` from 4.0.5 to 4.0.6\n- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6)\n\nUpdates `form-data` from 3.0.4 to 3.0.5\n- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6)\n\n---\nupdated-dependencies:\n- dependency-name: form-data\n  dependency-version: 4.0.6\n  dependency-type: indirect\n- dependency-name: form-data\n  dependency-version: 3.0.5\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "93f6f7097ea7f1a596d832af4c44536cd46c4053",
      "tree": "f3f09ed3eb103f0133de674b222c469b90b3463b",
      "parents": [
        "a742e8ffdb4f1ee7915bb6f0785ed3f2e22bbbc4"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 22 09:20:42 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 22 09:20:42 2026 +0800"
      },
      "message": "build(deps): bump ws from 6.2.3 to 6.2.4 in /admin/web (#987)\n\nBumps [ws](https://github.com/websockets/ws) from 6.2.3 to 6.2.4.\n- [Release notes](https://github.com/websockets/ws/releases)\n- [Commits](https://github.com/websockets/ws/compare/6.2.3...6.2.4)\n\n---\nupdated-dependencies:\n- dependency-name: ws\n  dependency-version: 6.2.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a742e8ffdb4f1ee7915bb6f0785ed3f2e22bbbc4",
      "tree": "5f0fdb8811b8c56a7eab15ec7b70645a6ab1f5a9",
      "parents": [
        "331735d3cfd1dd2170ad53f5c11f845fc34035e6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 22 09:20:28 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 22 09:20:28 2026 +0800"
      },
      "message": "build(deps): bump launch-editor from 2.9.1 to 2.14.1 in /admin/web (#986)\n\nBumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.9.1 to 2.14.1.\n- [Commits](https://github.com/vitejs/launch-editor/compare/v2.9.1...v2.14.1)\n\n---\nupdated-dependencies:\n- dependency-name: launch-editor\n  dependency-version: 2.14.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "331735d3cfd1dd2170ad53f5c11f845fc34035e6",
      "tree": "f3c390784c00693a1d87c087fb641ce4fa70b82d",
      "parents": [
        "c53ffa53e707857504184b7bb83af889232ca8fe"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sun Jun 14 13:53:40 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 13:53:40 2026 +0800"
      },
      "message": "perf(llm): drop per-request hex alloc in cooldown credential hash (#965)\n\n* perf(llm): drop per-request hex alloc in cooldown credential hash\n\nEvery LLM request resolves a cooldownKey at least once (more on the\nretry/fallback path) via endpointCredentialHash, which ran\nfmt.Sprintf(\"%x\", sum) and allocated a fresh 64-byte hex string that\nescaped to the heap. The hex string is pure overhead: credentialHash is\nonly ever used as a comparable component of the cooldownKey map key.\n\nUse the raw [32]byte sha256 output directly as the key component. A\n[32]byte array is comparable and valid in a struct map key, so the hex\nencoding and its heap allocation are removed while the cooldown identity\nsemantics stay byte-for-byte identical. sha256 itself stays per-call\n(nanoseconds for short keys); the allocation was the dominant cost.\n\nBenchmarkCooldown_EndpointInCooldown (100 endpoints):\n  before  300.0 ns/op  168 B/op  6 allocs/op\n  after   163.2 ns/op   40 B/op  3 allocs/op\n\nCloses #956\n\n* test(llm): pin cooldown benchmark TTL to keep hot path stable\n\nThe benchmark relied on the endpoint\u0027s 60s HealthCheckInterval as the\ncooldown TTL. A long -benchtime (or a slow machine) could let entries\nexpire mid-run, shifting measurement from the intended in-cooldown path\nonto the delete+log path and destabilizing results.\n\nSet HealthCheckInterval to 24h so every iteration stays on the hot path\nregardless of -benchtime."
    },
    {
      "commit": "c53ffa53e707857504184b7bb83af889232ca8fe",
      "tree": "d5b9d149281e8469f7316dad2eff25876249a42c",
      "parents": [
        "4d6cc6733385e3792a500d05317e17a71a35715e"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Fri Jun 12 09:43:53 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 12 09:43:53 2026 +0800"
      },
      "message": "fix(hotreload): bound reload request body size (#977)\n\n* Bound hot reload request bodies\n\nThe reload endpoint accepted authenticated request bodies of arbitrary size and read them fully into memory. Limit the body before parsing YAML and reject oversized requests with 413 while keeping the existing empty-body file reload behavior.\n\nConstraint: Preserve existing authenticated reload behavior for normal and empty request bodies\n\nRejected: Streaming YAML decode directly | larger behavior change than needed for this endpoint\n\nConfidence: high\n\nScope-risk: narrow\n\nDirective: Keep reload body limits explicit when adding new reload input modes\n\nTested: go test ./pkg/hotreload\n\n* Address hot reload review comments\n\nUse http.MaxBytesReader for reload body limits and add tests for exact-size bodies and empty-body fallback behavior. This keeps the existing file reload fallback while locking the request body boundary semantics.\n\nConstraint: Preserve repository imports-formatter grouping that CI enforces\n\nRejected: Keep io.LimitReader | MaxBytesReader is the standard net/http request limit mechanism\n\nConfidence: high\n\nScope-risk: narrow\n\nTested: go test ./pkg/hotreload"
    },
    {
      "commit": "4d6cc6733385e3792a500d05317e17a71a35715e",
      "tree": "7fc69589e26a075047472aee4926e8f8703ce833",
      "parents": [
        "d7b8f3b120825e8b4c5a24e8956b630d58436afb"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jun 10 09:23:05 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 09:23:05 2026 +0800"
      },
      "message": "build(deps): bump shell-quote from 1.8.1 to 1.8.4 in /admin/web (#974)\n\nBumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.1 to 1.8.4.\n- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.1...v1.8.4)\n\n---\nupdated-dependencies:\n- dependency-name: shell-quote\n  dependency-version: 1.8.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d7b8f3b120825e8b4c5a24e8956b630d58436afb",
      "tree": "21d01b5c7701af8708ae4e2bb9bac58812efde00",
      "parents": [
        "d2e421d99ee5770798ad82f3f1efe3fcf496035f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jun 09 18:03:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 18:03:13 2026 +0800"
      },
      "message": "build(deps): bump github.com/quic-go/quic-go from 0.57.0 to 0.59.1 (#959)\n\nBumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.57.0 to 0.59.1.\n- [Release notes](https://github.com/quic-go/quic-go/releases)\n- [Commits](https://github.com/quic-go/quic-go/compare/v0.57.0...v0.59.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/quic-go/quic-go\n  dependency-version: 0.59.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d2e421d99ee5770798ad82f3f1efe3fcf496035f",
      "tree": "a3c373a9683187b4677d79ccf8783d45ab7cf4c7",
      "parents": [
        "fafcaf0c2f86e144c4226f4037a8d6c73e5cd74e"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Tue Jun 02 18:14:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 18:14:22 2026 +0800"
      },
      "message": "feat(cluster):introduce healthy endpoint snapshot (issue #905 step 5) (#932)"
    },
    {
      "commit": "fafcaf0c2f86e144c4226f4037a8d6c73e5cd74e",
      "tree": "7bd5a454ac8f3a92fbe37c6c5184a7a9efacc5ed",
      "parents": [
        "4e7eb45e442561ef369bd13e063fe83dbf7e65a0"
      ],
      "author": {
        "name": "Yuqi Qiao",
        "email": "19606363088@163.com",
        "time": "Tue Jun 02 10:41:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 10:41:32 2026 +0800"
      },
      "message": "style: fix import ordering in filter_sse_test.go to pass gofmt (#954)"
    },
    {
      "commit": "4e7eb45e442561ef369bd13e063fe83dbf7e65a0",
      "tree": "14d2761cdd965df474b7e521a9cb9852b2f265cb",
      "parents": [
        "798fcc752b920f0640ccb21f062e6baf4c9f866c"
      ],
      "author": {
        "name": "Yuqi Qiao",
        "email": "19606363088@163.com",
        "time": "Fri May 29 14:41:42 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 29 14:41:42 2026 +0800"
      },
      "message": "fix(mcp): clear Content-Length header  (#931)\n\n* fix(mcp): clear Content-Length header before returning tool call response\n\nWhen the MCP filter wraps a backend response into MCP JSON-RPC format,\nthe new body is larger than the original. However, the old Content-Length\nheader from the backend was still present, causing Go\u0027s net/http to report\n\u0027wrote more than the declared Content-Length\u0027 and forcibly close the connection.\n\nClear the stale header so net/http auto-calculates the correct\nContent-Length from the actual response body.\n\n* fix(mcp): add a regression test that explicitly asserts Content-Length is cleared after sendMCPResponse\n\n* fix:add missing client import to resolve typecheck error in filter_sse_test"
    },
    {
      "commit": "798fcc752b920f0640ccb21f062e6baf4c9f866c",
      "tree": "349960b411b9f192e90828882538618acb3da5eb",
      "parents": [
        "e54dc30420e58c46544740d1eb6777a9a14c1c0c"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Tue May 26 19:26:30 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 26 19:26:30 2026 +0800"
      },
      "message": "fix(loadbalancer/maglev): satisfy benchmark lint (#946)"
    },
    {
      "commit": "e54dc30420e58c46544740d1eb6777a9a14c1c0c",
      "tree": "c91c815127834b38f3fea897b3ca610fbf9073ad",
      "parents": [
        "91688317f74306b5117c2120fc8146def0bc4eea"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Mon May 25 09:47:02 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 25 09:47:02 2026 +0800"
      },
      "message": "fix(loadbalancer/maglev): use fast deterministic request hash (#928)\n\n* fix(loadbalancer/maglev): use deterministic _hash1 for lookup table\n\nLookUpTable.Hash called maphash.MakeSeed() on every invocation, so the\nsame key produced a different hash each call. Get(key) and GetHash both\nflow through Hash, which meant Maglev silently degraded to pseudo-random\nselection — session affinity and cache locality guarantees never held.\n\nRoute Hash through the package-internal deterministic _hash1, the same\nhash already used by permutation generation.\n\n* test(loadbalancer/maglev): lock Hash determinism for the same key\n\nRegression coverage for the previous random-seed bug. Calls Hash on the\nsame key 20 times and asserts stability.\n\n* fix(loadbalancer/maglev): use fast deterministic request hash\n\n* chore(loadbalancer/maglev): satisfy request hash naming rule\n\n* chore(loadbalancer/maglev): fix import grouping"
    },
    {
      "commit": "91688317f74306b5117c2120fc8146def0bc4eea",
      "tree": "e2e2ed4a7102145965cbfe9283b4040a4576647f",
      "parents": [
        "09e446a04c8c2f7f75f8488a7b5f92dd0ad9da2a"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Sun May 24 14:33:43 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 24 14:33:43 2026 +0800"
      },
      "message": "fix(endpoint): stabilize endpoint.ID across restarts (nacos + static-config paths) (#930)\n\n* model: add GeneratedEndpointID helper for deterministic endpoint identity\n\nReturns a stable \"generated-\u003csha8\u003e\" identifier derived from cluster name,\nendpoint address, and (when present) LLM provider + API key. Endpoints\nthat differ only by credential do not collide, and the same endpoint\nacross restarts hashes to the same ID.\n\nUsed by the Nacos LLM registry to drop random UUID fallback identifiers.\n\n* fix(adapter/nacos): deterministic endpoint identity and address baseline\n\ngenerateEndpoint previously generated a fresh UUID for every Nacos\ninstance that did not carry an explicit metadata[\"id\"]. Process restarts\nand re-subscriptions therefore broke any external mapping keyed on\nendpoint.ID (metrics labels, log correlation, runtime health tracking).\n\nReplace the UUID fallback with a three-step lookup:\n  1. metadata[\"id\"] (trimmed)\n  2. instance.InstanceId (trimmed)\n  3. model.GeneratedEndpointID(cluster, endpoint) — stable hash of\n     cluster, address, and LLM credential material\n\nTwo related fixes ride along because they share the same function:\n  - Address now seeds from instance.Ip / instance.Port before metadata\n    overrides, so instances without metadata.ip/port still get a usable\n    upstream address.\n  - When metadata[\"port\"] fails to parse, the previous code overwrote\n    Address.Port with 0; now the parsed value only applies on success.\n\nEndpoint.ID becomes upgrade-visible: existing deployments will see new\nIDs after upgrade. Operators relying on endpoint.ID for dashboards or\nlog correlation should rebuild their indexes.\n\n* test(adapter/nacos): cover stable ID, rename, InstanceId fallback paths\n\n- Invalid port now expects fallback to instance.Port instead of zero,\n  matching the parse-failure fix.\n- generateEndpoint prefers instance.InstanceId when metadata id is absent.\n- generateEndpoint hashes deterministically when both metadata id and\n  instance id are absent; rotating an API key changes the generated ID,\n  the raw key never appears in it.\n- subscribeCallback emits stable IDs across renames and re-subscriptions.\n- subscribeCallback keeps endpoints with identical credentials but\n  different Nacos InstanceIds distinct.\n\n* model: rename GeneratedEndpointID -\u003e GenerateEndpointID and expand docs\n\nRename uses the standard Go verb form. The godoc now states three\nnon-obvious design choices so future readers don\u0027t have to re-derive\nthem:\n\n- The 64-bit (8-byte) truncation rationale and the per-cluster scale\n  at which it is safe.\n- That clusterName is part of the hash material so endpoints from\n  different clusters never alias, and how Nacos callers supply it.\n- That the LLM API key is included on purpose, with the SHA-256\n  one-way guarantee that prevents the raw key from leaking into IDs.\n\nAdds two helper test cases that nail the contract:\n- Different cluster names produce different IDs for the same endpoint.\n- Different addresses (host or port) produce different IDs.\n\n* server: replace random-UUID endpoint identity with GenerateEndpointID\n\nassembleClusterEndpoints used to assign a random UUID to any endpoint\nwith an empty ID, mirroring the now-removed Nacos UUID fallback and\nbreaking the same downstream contracts (metrics keyed on endpoint.ID,\nPickNextEndpoint cursors, DeleteEndpoint lookups). Switch to the\ndeterministic helper so endpoint identity is stable across process\nrestarts regardless of registry source.\n\nTwo static endpoints sharing (cluster_name, address, provider, api_key)\nnow collapse to a single identifier. They were already indistinguishable\nto the picker, so the previous random IDs offered no real separation;\noperators who need distinct entries must set an explicit \"id:\".\n\nhashicorp/go-uuid is no longer imported anywhere in pkg/, so it drops\nfrom the direct dependency list (still transitively pulled in).\n\n* server: warn on duplicate generated endpoint IDs and harden contract\n\nTwo follow-ups to the random-UUID -\u003e deterministic-ID migration:\n\nassembleClusterEndpoints now logs a warning when two endpoints inside\nthe same cluster collapse to the same generated ID. Previously this was\nsilent: operators would discover the missing entry only via dashboards\ncounting fewer endpoints than the config declares. The warning names\nboth slice positions and the shared ID so the fix (set explicit `id:`)\nis mechanical.\n\nendpointIDMaterial gets a contract comment stating that it MUST NOT\ndepend on endpoint.Name. Two call sites rely on this implicitly:\nClusterStore.assembleClusterEndpoints derives the ID before assigning\na default Name, and TestGenerateEndpointIDIgnoresEndpointName asserts\nrename invariance. Documenting the contract makes the constraint\nvisible to anyone tempted to extend the hash material.\n\nThe godoc paragraph on truncation now reads as a neutral statement\nrather than first-person (\"we\"), since this is library code in an OSS\nproject.\n\nAdds TestClusterManager_AssembleEndpointsCollapseDuplicateGenerated to\nlock the documented collapse behavior.\n\n* adapter/nacos: unify nacosEndpointID lookup style\n\nThe three-tier lookup previously mixed two idioms — an ok-check plus\nTrimSpace for metadata[\"id\"], and a single-step assignment for\nInstanceId — which left the metadata branch calling TrimSpace twice.\nSwitch metadata[\"id\"] to the same single-step form. Go returns the\nzero value for a missing map key, so the ok-check is redundant.\n\nBehavior is unchanged; this is a readability cleanup surfaced by the\nsecond-round review.\n\n* docs(kvcache): document endpoint.id derivation and upgrade behavior\n\nThe \"Routing Contract\" section already states that LMCache instance_id\nmust equal pixiu endpoint.id, but did not say how endpoint.id is\nderived or what happens when pixiu\u0027s identity scheme changes. Operators\nrunning kvcache against the new deterministic identity could not tell\nfrom the doc whether the contract was still meant to hold long-term.\n\nAdds two sub-sections under \"Routing Contract\":\n\n- Lists the three-tier derivation order (metadata id -\u003e InstanceId -\u003e\n  generated-\u003csha8\u003e) and states that all three forms are stable across\n  restarts, so the LMCache \u003c-\u003e pixiu contract holds long-term.\n- Calls out the one-time ID-shape transition during the upgrade from\n  the previous random-UUID behavior, so LMCache operators know to\n  expect a relearn window per endpoint and that it self-recovers.\n\nMirrors the same update in the Chinese doc.\n\n* fix(nacos): fall back to cluster name for endpoint id\n\n* Refine contract definition for LMCache and pixiu\n\nClarify the definition of the contract between LMCache instance_id and pixiu endpoint.id.\n\n* fix(model): clarify generated endpoint id encoding\n\n* ci: avoid persisted checkout credentials in integration test"
    },
    {
      "commit": "09e446a04c8c2f7f75f8488a7b5f92dd0ad9da2a",
      "tree": "75159372c4177ac9a7aab12d390c6d2dd9e6f906",
      "parents": [
        "1df11291c3a7c1954080574ee425c2308ed3dd8b"
      ],
      "author": {
        "name": "Xuetao Li",
        "email": "m134679102365478@163.com",
        "time": "Sat May 23 16:56:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 23 16:56:07 2026 +0800"
      },
      "message": "Add protection for master and develop branches (#936)"
    },
    {
      "commit": "1df11291c3a7c1954080574ee425c2308ed3dd8b",
      "tree": "3e7c36f3dcca142b82e282d87fa3a7770f3f6e99",
      "parents": [
        "f0ba052d26d3322b6d4de833de2b58f7385c3c47"
      ],
      "author": {
        "name": "The Apache Software Foundation",
        "email": "root-asf-gitbox-commits@apache.org",
        "time": "Sat May 23 03:37:49 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 23 16:37:49 2026 +0800"
      },
      "message": "Set up default protection ruleset for default and release branches (#929)"
    },
    {
      "commit": "f0ba052d26d3322b6d4de833de2b58f7385c3c47",
      "tree": "1cdfdd932fe4ceca48ceabe6f7bcd0d1342c57f0",
      "parents": [
        "16dd5011756db257438100ef13a90949297b7f79"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat May 23 12:29:43 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 23 12:29:43 2026 +0800"
      },
      "message": "build(deps): bump qs and express in /admin/web (#935)\n\nBumps [qs](https://github.com/ljharb/qs) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.\n\nUpdates `qs` from 6.14.2 to 6.15.2\n- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/ljharb/qs/compare/v6.14.2...v6.15.2)\n\nUpdates `express` from 4.22.1 to 4.22.2\n- [Release notes](https://github.com/expressjs/express/releases)\n- [Changelog](https://github.com/expressjs/express/blob/v4.22.2/History.md)\n- [Commits](https://github.com/expressjs/express/compare/v4.22.1...v4.22.2)\n\n---\nupdated-dependencies:\n- dependency-name: qs\n  dependency-version: 6.15.2\n  dependency-type: indirect\n- dependency-name: express\n  dependency-version: 4.22.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "16dd5011756db257438100ef13a90949297b7f79",
      "tree": "fdee431d3d8264c6ac6ead65aff8a1d1b110e853",
      "parents": [
        "54c4ecaf8dcc98a645ef5c0362bd92443ded2746"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri May 22 13:42:03 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 13:42:03 2026 +0800"
      },
      "message": "build(deps): bump js-cookie from 2.2.0 to 3.0.7 in /admin/web (#934)\n\nBumps [js-cookie](https://github.com/js-cookie/js-cookie) from 2.2.0 to 3.0.7.\n- [Release notes](https://github.com/js-cookie/js-cookie/releases)\n- [Commits](https://github.com/js-cookie/js-cookie/compare/v2.2.0...v3.0.7)\n\n---\nupdated-dependencies:\n- dependency-name: js-cookie\n  dependency-version: 3.0.7\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "54c4ecaf8dcc98a645ef5c0362bd92443ded2746",
      "tree": "752d2902f79b9aaf98dbc9ed7f236a3936c5ae91",
      "parents": [
        "dd62a985a0706c1ff4aa0a2adb632fd256f328ba"
      ],
      "author": {
        "name": "twotwotwo",
        "email": "yjt20061029@gmail.com",
        "time": "Thu May 21 13:55:33 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 13:55:33 2026 +0800"
      },
      "message": "fix: Router method wildcard no longer matches non-HTTP route methods after snapshot refactor (#922)\n\n* Refactor RouteSnapshot and MethodAllowed function\n\n* Enhance router logic for method-specific matching\n\nRefactor routing logic to improve method-specific trie matching and error handling.\n\n* Update router.go\n\n* 修正笔误\n\n* fix a typo\n\n* Add files via upload"
    },
    {
      "commit": "dd62a985a0706c1ff4aa0a2adb632fd256f328ba",
      "tree": "6b9990e8a5d86f24292ca8acce6410fe0d560a8f",
      "parents": [
        "773de1077ac57104f71ea920dca11c19d85f91aa"
      ],
      "author": {
        "name": "wm_03",
        "email": "3134058368@qq.com",
        "time": "Sat May 16 17:30:11 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 16 17:30:11 2026 +0800"
      },
      "message": "feat: add Pixiu skills (#921)\n\n* feat: add Pixiu skills"
    },
    {
      "commit": "773de1077ac57104f71ea920dca11c19d85f91aa",
      "tree": "6028bbc469b3c9025dbdf76a2b37a10bb72f2ad9",
      "parents": [
        "21d6907734429fe52fd34e01af5270fef74393b6"
      ],
      "author": {
        "name": "linmao",
        "email": "lmtian808@gmail.com",
        "time": "Fri May 15 13:07:37 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 15 13:07:37 2026 +0800"
      },
      "message": "Feature/857 Add OpenAPI request validation to apiconfig (#909)\n\n* feat(apiconfig): add OpenAPI request validation\n\n* docs(openapi): add usage guide and sample spec\n\n* fix(apiconfig): align OpenAPI validation with V1 docs\n\n* Prevent duplicate OpenAPI route registration\n\nMerge OpenAPI validation metadata into existing api_config routes so duplicate path+method entries do not fail startup.\n\nTested: go test ./pkg/filter/http/apiconfig/...; go test ./...\n\n---------\n\nCo-authored-by: Tianlm \u003cskylm@TianlmdeMacBook-Air.local\u003e"
    },
    {
      "commit": "21d6907734429fe52fd34e01af5270fef74393b6",
      "tree": "5b543ac72057d858d9647c6b3e578bd9258be92d",
      "parents": [
        "4d627d4df47e7ef93f2946e92b701f63de4635c7"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed May 13 10:22:05 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 13 10:22:05 2026 +0800"
      },
      "message": "build(deps-dev): bump @babel/plugin-transform-modules-systemjs (#927)\n\nBumps [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) from 7.27.1 to 7.29.4.\n- [Release notes](https://github.com/babel/babel/releases)\n- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/babel/babel/commits/v7.29.4/packages/babel-plugin-transform-modules-systemjs)\n\n---\nupdated-dependencies:\n- dependency-name: \"@babel/plugin-transform-modules-systemjs\"\n  dependency-version: 7.29.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "4d627d4df47e7ef93f2946e92b701f63de4635c7",
      "tree": "6ff9b05afbd990db4872d107323f249c23f0cb0f",
      "parents": [
        "4ceeb323455626d76a8593ba1f19c898bdacdc95"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat May 09 11:51:33 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 09 11:51:33 2026 +0800"
      },
      "message": "build(deps-dev): bump fast-uri from 3.0.6 to 3.1.2 in /admin/web (#926)\n\nBumps [fast-uri](https://github.com/fastify/fast-uri) from 3.0.6 to 3.1.2.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.0.6...v3.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n  dependency-version: 3.1.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "4ceeb323455626d76a8593ba1f19c898bdacdc95",
      "tree": "bbb92379f71ee5873fba2aff75f69d61dc6f01f6",
      "parents": [
        "9791a83bc02df51d15ce9433e15cb88a6fe0f3b1"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Wed May 06 18:28:01 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 18:28:01 2026 +0800"
      },
      "message": "fix(cluster): switch cluster lookup to runtime map (#923)"
    },
    {
      "commit": "9791a83bc02df51d15ce9433e15cb88a6fe0f3b1",
      "tree": "8c7f4cc5515a13551c90fb97224618920895600c",
      "parents": [
        "dd8b0409c8d16b36ee3d925b028c6ce78d72cc5c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed May 06 14:06:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 14:06:52 2026 +0800"
      },
      "message": "build(deps): bump axios from 1.13.5 to 1.15.2 in /admin/web (#924)\n\nBumps [axios](https://github.com/axios/axios) from 1.13.5 to 1.15.2.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.13.5...v1.15.2)\n\n---\nupdated-dependencies:\n- dependency-name: axios\n  dependency-version: 1.15.2\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "dd8b0409c8d16b36ee3d925b028c6ce78d72cc5c",
      "tree": "1118d7ddfd8799d6d1fe6e454bac3fced664a9d0",
      "parents": [
        "55c62109a5f73633ce4755cbd0a8c92f4980c5fd"
      ],
      "author": {
        "name": "Zerui Yang",
        "email": "zeruiyoung@gmail.com",
        "time": "Wed May 06 13:38:16 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 13:38:16 2026 +0800"
      },
      "message": "Feat: add some dubbo config and use new config style (#862)\n\n* feat(config): add cluster, protocol, and check options to DubboProxyConfig\n\n* feat(config): enhance DubboProxyConfig with new fields for filter, serialization, sticky connections, and custom parameters\n\n* feat(dubbo): manually initialize ReferenceOptions for generic invocation support\n\n* fix: downgrade dubbo-go dependency version to maintain compatibility\n\n* fix: reorganize import statements in config.go for clarity\n\n* refactor(dubbo): resolve refer spec in unified client\n\n* refactor(remote): route triple through dubbo client\n\n* test(triple): cover forwarded tri headers\n\n* chore: ignore local worktrees\n\n* refactor(dubbo): clean up configuration structure and remove unused fields\n\n* refactor(dubbo): simplify invoke payload and context preparation\n\n* refactor(tests): organize imports in call_test.go and refer_test.go\n\n* feat(dubbo): enhance direct generic invocation with parameter types and serialization\n\n* feat(dubbo): add outbound request contract\n\n* test(dubbo): isolate legacy refer tests for outbound transition\n\n* refactor(dubbo): extract type and protocol helpers\n\n* refactor(dubbo): wire extracted helpers into existing paths\n\n* refactor(dubbo): normalize opt values types through shared helpers\n\n* refactor(dubbo): complete inferred java type mapping\n\n* feat(remote): add DubboHandler for outbound mapping\n\n* test(remote): align DubboHandler helpers with plan contract\n\n* refactor(remote): preserve opt values inline type coercion\n\n* refactor(dubbo): implement outbound client call\n\n* fix(dubbo): include consumer defaults in cache key\n\n* refactor(remote): route dubbo calls through outbound handler\n\n* docs(dubbo): remove opt application from samples\n\n* docs(dubbo): align zh universality option example\n\n* refactor(dubbo): remove legacy mapping path\n\n* fix(remote): enforce direct outbound contract\n\n* feat(dubbo): update Dubbo client and outbound request types\n\n* refactor(dubbo): replace hardcoded Java class names with constants\n\n* refactor(client): update Client interface and remove unused Dubbo resolver\n\n* fix: fix some review comments\n\n* docs(dubbo): add comments to clarify functionality in call and handler methods\n\n* fix(dubbo): enhance direct address handling and validation in DubboHandler\n\n* feat(dubbo): add serialization key to registry and update dependencies\n\n* chore(tests): reorganize import statements in registry_test.go\n\n* chore: trigger ci\n\n* feat: refactor Dubbo client context handling and update dependencies"
    },
    {
      "commit": "55c62109a5f73633ce4755cbd0a8c92f4980c5fd",
      "tree": "8f74bf1d9ee6bf3d0e1320c7231e9b6fa13a0269",
      "parents": [
        "91445beda8e0e9545faedd0b627d1fcf0d0aea9c"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Wed May 06 11:06:09 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 11:06:09 2026 +0800"
      },
      "message": "fix(cluster): tighten runtime consistency (#919)\n\n* fix(cluster): tighten runtime consistency\n\n* fix(cluster): address runtime consistency review comments"
    },
    {
      "commit": "91445beda8e0e9545faedd0b627d1fcf0d0aea9c",
      "tree": "7a4cbee8d489f2c2787726a2b2184f642a9d707e",
      "parents": [
        "ad9b844e2d1dfe9528d9efbbc9f60d89c04da553"
      ],
      "author": {
        "name": "承潜",
        "email": "2972013548@qq.com",
        "time": "Tue Apr 28 11:43:20 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 28 11:43:20 2026 +0800"
      },
      "message": "fix(cluster): complete Issue #905 step 2 correctness for Rand and Rou… (#915)\n\n* fix(cluster): complete Issue #905 step 2 correctness for Rand and RoundRobin\n\n* fix(cluster): address review feedback for issue 905\n\n* fix(test): address sonar warnings for blank imports\n\n* fix(cluster): preserve round-robin cursor across store refresh\n\n* fix(cluster): use atomic cursor carry-over"
    },
    {
      "commit": "ad9b844e2d1dfe9528d9efbbc9f60d89c04da553",
      "tree": "001e4920b877f1168377a33a5eeafeaf90e59585",
      "parents": [
        "e6be67833cd679e0ef879e557ba4a46328c092a1"
      ],
      "author": {
        "name": "Joe Zhong",
        "email": "11638005@qq.com",
        "time": "Mon Apr 27 11:24:58 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 11:24:58 2026 +0800"
      },
      "message": "use hot reload update gateway (#892)\n\n* use hot reload update gateway\n\nfix gofmt\n\nfix imports-formatter\n\nfix golangci-lint\n\nfix typo\n\nfix typo\n\nfix gofmt\n\nfix imports-formatter\n\nchore: trigger CI to recheck linter\n\nfix: rewrite http_handler to fix gofmt issue\n\nfix: split variable declaration to fix gofmt issue\n\nfix: inline map to avoid gofmt issue\n\nfix: apply gofmt formatting to http_handler.go\n\nfix: replace interface{} with string map and handle Body.Close error\n\nfix: guard against nil server in GetRouterManager to prevent panic in tests\n\n* Potential fix for pull request finding\n\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e\n\n* build(deps): bump minimatch from 3.1.2 to 3.1.5 in /admin/web (#883)\n\nBumps [minimatch](https://github.com/isaacs/minimatch) from 3.1.2 to 3.1.5.\n- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)\n- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5)\n\n---\nupdated-dependencies:\n- dependency-name: minimatch\n  dependency-version: 3.1.5\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\n\n* Admin opa backend (#877)\n\n* add the OPA on the admin without readme\n\n* fmt\n\n* add the description of change in readme\n\n* remove the log\n\n* fix the issue\n\n* fix the issue\n\n* delete the log and improve the yml of docker\n\n* remove the redundent -\n\n* add the newLine\n\n* fix(admin): honor OPA request timeout with context and add 30s fallback\n\n* build(deps): bump go.opentelemetry.io/otel/sdk in /controllers (#887)\n\nBumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.37.0 to 1.40.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.37.0...v1.40.0)\n\n---\nupdated-dependencies:\n- dependency-name: go.opentelemetry.io/otel/sdk\n  dependency-version: 1.40.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\n\n* feat: Add KVCache offload funtion in PIXIU gateway (#878)\n\n* feat: KV Cache\n\n* fix: fix some problems\n\n* feat: add KVCache feats\n\n* feat: v2\n\n* feat: v2\n\n* chore: ignore .worktrees\n\n* fix: fix some bugs\n\n* feat: v3\n\n* feat: v4\n\n* feat: fix some problems\n\n* fix: delete some unuesd gomod\n\n* fix: fix some problems\n\n* fix: fix some problems\n\n* add apache lisences\n\n* fix: fix some problems\n\n* fix: add unit test and fix some problems\n\n* fix: delete some unused code\n\n* fix: add docs\n\n* feat: add some new features\n\n* build(deps): bump go.opentelemetry.io/otel/sdk from 1.21.0 to 1.40.0 (#890)\n\nBumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.21.0 to 1.40.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.21.0...v1.40.0)\n\n---\nupdated-dependencies:\n- dependency-name: go.opentelemetry.io/otel/sdk\n  dependency-version: 1.40.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\n\n* feat(auth/saml): add SAML authentication filter (#893)\n\n* feat(auth/saml): add initial SAML auth filter scaffold\n\n* feat(auth/saml): implement core SAML authentication logic\n\n* test(auth/saml): add unit tests for SAML filter\n\n* fix(auth/saml): address code review findings\n\n  - Distinguish ErrNoSession from other session errors in Decode()\n  - DeepCopy config in PrepareFilterChain to avoid pointer sharing\n  - Strip client-supplied SAML-controlled headers to prevent spoofing\n  - Set CookieSameSite for cross-site ACS POST compatibility\n  - Fix gofmt formatting in config_test.go\n\n* docs(auth/saml): add SAML filter user documentation\n\n* chore: revert .gitignore to upstream state\n\n* style: format plugin registry\n\n* refactor(auth/saml): reduce Apply complexity\n\n* style(auth/saml): format imports with imports-formatter\n\n* docs(auth/saml): add Chinese user guide\n\n* build(deps): bump github.com/buger/jsonparser in /tools/benchmark (#898)\n\nBumps [github.com/buger/jsonparser](https://github.com/buger/jsonparser) from 1.1.1 to 1.1.2.\n- [Release notes](https://github.com/buger/jsonparser/releases)\n- [Commits](https://github.com/buger/jsonparser/compare/v1.1.1...v1.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/buger/jsonparser\n  dependency-version: 1.1.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\n\n* build(deps-dev): bump picomatch from 2.3.1 to 2.3.2 in /admin/web (#899)\n\nBumps [picomatch](https://github.com/micromatch/picomatch) from 2.3.1 to 2.3.2.\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/picomatch/compare/2.3.1...2.3.2)\n\n---\nupdated-dependencies:\n- dependency-name: picomatch\n  dependency-version: 2.3.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\n\n* fix 1\n\n* fix 2\n\n* fix 3\n\n* fix 4\n\n* fix 5\n\n* fix 6\n\n* fix 7\n\n* fix 8\n\n* fix check\n\n* fix lint\n\n* fix 9\n\n* fix 10\n\n* fix 11\n\n* fix 12\n\n* fix check\n\n---------\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nCo-authored-by: nanjiek \u003c127271430+nanjiek@users.noreply.github.com\u003e\nCo-authored-by: 陈乐樂 \u003c1239498998@qq.com\u003e\nCo-authored-by: linmao \u003clmtian808@gmail.com\u003e"
    },
    {
      "commit": "e6be67833cd679e0ef879e557ba4a46328c092a1",
      "tree": "d2e738250414c3287d844a3acda086db08d68041",
      "parents": [
        "8166e242866ec6778ef4b64b3f6b06fc957119f8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Apr 16 08:32:59 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 16 08:32:59 2026 +0800"
      },
      "message": "build(deps): bump follow-redirects from 1.15.11 to 1.16.0 in /admin/web (#914)\n\nBumps [follow-redirects](https://github.com/follow-redirects/follow-redirects) from 1.15.11 to 1.16.0.\n- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)\n- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.15.11...v1.16.0)\n\n---\nupdated-dependencies:\n- dependency-name: follow-redirects\n  dependency-version: 1.16.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8166e242866ec6778ef4b64b3f6b06fc957119f8",
      "tree": "4f0e24d2abb9fa589da089102385704f37474984",
      "parents": [
        "67fb157dcd4f66c69a7f2fac489afbd6a9f38394"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Apr 12 19:33:04 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 12 19:33:04 2026 +0800"
      },
      "message": "build(deps): bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 (#908)\n\nBumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.40.0 to 1.43.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.40.0...v1.43.0)\n\n---\nupdated-dependencies:\n- dependency-name: go.opentelemetry.io/otel/sdk\n  dependency-version: 1.43.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "67fb157dcd4f66c69a7f2fac489afbd6a9f38394",
      "tree": "2ac66a6d3c3f54e2f221c32c97ee0cd4bf5cb43f",
      "parents": [
        "d12a6bb768e38fbbf45362e98b62427e6cba46c4"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Apr 03 19:07:48 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 03 19:07:48 2026 +0800"
      },
      "message": "build(deps): bump path-to-regexp and express in /admin/web (#903)\n\nBumps [path-to-regexp](https://github.com/pillarjs/path-to-regexp) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.\n\nUpdates `path-to-regexp` from 0.1.12 to 0.1.13\n- [Release notes](https://github.com/pillarjs/path-to-regexp/releases)\n- [Changelog](https://github.com/pillarjs/path-to-regexp/blob/v.0.1.13/History.md)\n- [Commits](https://github.com/pillarjs/path-to-regexp/compare/v0.1.12...v.0.1.13)\n\nUpdates `express` from 4.21.2 to 4.22.1\n- [Release notes](https://github.com/expressjs/express/releases)\n- [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md)\n- [Commits](https://github.com/expressjs/express/compare/4.21.2...v4.22.1)\n\n---\nupdated-dependencies:\n- dependency-name: path-to-regexp\n  dependency-version: 0.1.13\n  dependency-type: indirect\n- dependency-name: express\n  dependency-version: 4.22.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d12a6bb768e38fbbf45362e98b62427e6cba46c4",
      "tree": "7f1b87e0ea0dc4c6ea088f1a7a763bee8413d0e9",
      "parents": [
        "4eea345eed0fcd4ef69ce9811305164f138fc457"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Apr 03 11:03:31 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 03 11:03:31 2026 +0800"
      },
      "message": "build(deps): bump lodash from 4.17.21 to 4.18.1 in /admin/web (#904)\n\nBumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.18.1.\n- [Release notes](https://github.com/lodash/lodash/releases)\n- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.18.1)\n\n---\nupdated-dependencies:\n- dependency-name: lodash\n  dependency-version: 4.18.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "4eea345eed0fcd4ef69ce9811305164f138fc457",
      "tree": "e3be1924319965d256fcade232e577cf670318a5",
      "parents": [
        "45d231332095cabcf7ced41362c49924300e3438"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Mar 26 13:16:20 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 26 13:16:20 2026 +0800"
      },
      "message": "build(deps-dev): bump picomatch from 2.3.1 to 2.3.2 in /admin/web (#899)\n\nBumps [picomatch](https://github.com/micromatch/picomatch) from 2.3.1 to 2.3.2.\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/picomatch/compare/2.3.1...2.3.2)\n\n---\nupdated-dependencies:\n- dependency-name: picomatch\n  dependency-version: 2.3.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "45d231332095cabcf7ced41362c49924300e3438",
      "tree": "1f5b5939a25c0dd743f7efcf3fcf9c6eaa8f1711",
      "parents": [
        "1b96e77db2b940661e8a3c4547792eab68c48c62"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Mar 26 03:00:47 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 26 03:00:47 2026 +0800"
      },
      "message": "build(deps): bump github.com/buger/jsonparser in /tools/benchmark (#898)\n\nBumps [github.com/buger/jsonparser](https://github.com/buger/jsonparser) from 1.1.1 to 1.1.2.\n- [Release notes](https://github.com/buger/jsonparser/releases)\n- [Commits](https://github.com/buger/jsonparser/compare/v1.1.1...v1.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/buger/jsonparser\n  dependency-version: 1.1.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1b96e77db2b940661e8a3c4547792eab68c48c62",
      "tree": "7789a3fb9c623cc347eea9c8dfd8c124286889c1",
      "parents": [
        "5257003f130a6188d82952677238f9816d480a7a"
      ],
      "author": {
        "name": "linmao",
        "email": "lmtian808@gmail.com",
        "time": "Wed Mar 25 20:03:41 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 25 20:03:41 2026 +0800"
      },
      "message": "feat(auth/saml): add SAML authentication filter (#893)\n\n* feat(auth/saml): add initial SAML auth filter scaffold\n\n* feat(auth/saml): implement core SAML authentication logic\n\n* test(auth/saml): add unit tests for SAML filter\n\n* fix(auth/saml): address code review findings\n\n  - Distinguish ErrNoSession from other session errors in Decode()\n  - DeepCopy config in PrepareFilterChain to avoid pointer sharing\n  - Strip client-supplied SAML-controlled headers to prevent spoofing\n  - Set CookieSameSite for cross-site ACS POST compatibility\n  - Fix gofmt formatting in config_test.go\n\n* docs(auth/saml): add SAML filter user documentation\n\n* chore: revert .gitignore to upstream state\n\n* style: format plugin registry\n\n* refactor(auth/saml): reduce Apply complexity\n\n* style(auth/saml): format imports with imports-formatter\n\n* docs(auth/saml): add Chinese user guide"
    },
    {
      "commit": "5257003f130a6188d82952677238f9816d480a7a",
      "tree": "daa13e0dc5cea036cfd5a793fc1d9bdab99aafff",
      "parents": [
        "ea927c124c2fc2e274a76aaa40790655937fb101"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Mar 09 13:39:33 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 09 13:39:33 2026 +0800"
      },
      "message": "build(deps): bump go.opentelemetry.io/otel/sdk from 1.21.0 to 1.40.0 (#890)\n\nBumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.21.0 to 1.40.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.21.0...v1.40.0)\n\n---\nupdated-dependencies:\n- dependency-name: go.opentelemetry.io/otel/sdk\n  dependency-version: 1.40.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "ea927c124c2fc2e274a76aaa40790655937fb101",
      "tree": "b655f7954f255c6255fe3b83ded945e536467a21",
      "parents": [
        "9bf04fa09ac3bda2aae215aa170ebe04276114c3"
      ],
      "author": {
        "name": "陈乐樂",
        "email": "1239498998@qq.com",
        "time": "Mon Mar 09 11:20:14 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 09 11:20:14 2026 +0800"
      },
      "message": "feat: Add KVCache offload funtion in PIXIU gateway (#878)\n\n* feat: KV Cache\n\n* fix: fix some problems\n\n* feat: add KVCache feats\n\n* feat: v2\n\n* feat: v2\n\n* chore: ignore .worktrees\n\n* fix: fix some bugs\n\n* feat: v3\n\n* feat: v4\n\n* feat: fix some problems\n\n* fix: delete some unuesd gomod\n\n* fix: fix some problems\n\n* fix: fix some problems\n\n* add apache lisences\n\n* fix: fix some problems\n\n* fix: add unit test and fix some problems\n\n* fix: delete some unused code\n\n* fix: add docs\n\n* feat: add some new features"
    },
    {
      "commit": "9bf04fa09ac3bda2aae215aa170ebe04276114c3",
      "tree": "9e66de3796cb47ea140f357965d8894b1e40fb3f",
      "parents": [
        "8fe7b26841f01db0941b9d7976cc7b05cf80ed70"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 06 04:16:37 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 06 04:16:37 2026 +0800"
      },
      "message": "build(deps): bump go.opentelemetry.io/otel/sdk in /controllers (#887)\n\nBumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.37.0 to 1.40.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.37.0...v1.40.0)\n\n---\nupdated-dependencies:\n- dependency-name: go.opentelemetry.io/otel/sdk\n  dependency-version: 1.40.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8fe7b26841f01db0941b9d7976cc7b05cf80ed70",
      "tree": "e81d694070d13488ff848f66ad8b60cb578dc0dc",
      "parents": [
        "7e88d1dbcc83cdb500de2ceb1e303daad8795d3e"
      ],
      "author": {
        "name": "nanjiek",
        "email": "127271430+nanjiek@users.noreply.github.com",
        "time": "Mon Mar 02 11:19:50 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 02 11:19:50 2026 +0800"
      },
      "message": "Admin opa backend (#877)\n\n* add the OPA on the admin without readme\n\n* fmt\n\n* add the description of change in readme\n\n* remove the log\n\n* fix the issue\n\n* fix the issue\n\n* delete the log and improve the yml of docker\n\n* remove the redundent -\n\n* add the newLine\n\n* fix(admin): honor OPA request timeout with context and add 30s fallback"
    },
    {
      "commit": "7e88d1dbcc83cdb500de2ceb1e303daad8795d3e",
      "tree": "427c885c6310cde36fb41eb9781c10bcf9cf575f",
      "parents": [
        "ddd85e019ff332ce2abb6f45f4def8008cacc0de"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Mar 01 00:44:25 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 01 00:44:25 2026 +0800"
      },
      "message": "build(deps): bump minimatch from 3.1.2 to 3.1.5 in /admin/web (#883)\n\nBumps [minimatch](https://github.com/isaacs/minimatch) from 3.1.2 to 3.1.5.\n- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)\n- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5)\n\n---\nupdated-dependencies:\n- dependency-name: minimatch\n  dependency-version: 3.1.5\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "ddd85e019ff332ce2abb6f45f4def8008cacc0de",
      "tree": "07b36ce6f162391cf8d0885e09dfe7c99b8b888f",
      "parents": [
        "1f93d8c9bf4515732421b23dbb33afb4a736e4a8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Feb 20 15:09:14 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 20 15:09:14 2026 +0800"
      },
      "message": "build(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (#882)\n\nBumps [filippo.io/edwards25519](https://github.com/FiloSottile/edwards25519) from 1.1.0 to 1.1.1.\n- [Commits](https://github.com/FiloSottile/edwards25519/compare/v1.1.0...v1.1.1)\n\n---\nupdated-dependencies:\n- dependency-name: filippo.io/edwards25519\n  dependency-version: 1.1.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1f93d8c9bf4515732421b23dbb33afb4a736e4a8",
      "tree": "7f8cc4f3657d200330026c8762c3232b810a1377",
      "parents": [
        "0dc820ed3c344450140e6b241454b1a8e60bd32b"
      ],
      "author": {
        "name": "LEI-LEI",
        "email": "59425000+LEILEI0628@users.noreply.github.com",
        "time": "Fri Feb 13 10:23:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Feb 13 10:23:07 2026 +0800"
      },
      "message": "Fixes issue #869 where circuit breaker never opens despite backend errors. (#876)\n\n* fix: implement feedback loop for circuit breaker state transitions (#869)\n\nFixes issue #869 where circuit breaker never opens despite backend errors.\n\nRoot Cause:\n- entry.Exit() was called in Decode phase before backend response\n- Missing error reporting to Sentinel state machine\n\nSolution:\n- Store Sentinel entry in HttpContext instead of immediate Exit()\n- Implement Encode phase to check response status and report errors\n- Entry-Exit now brackets complete request lifecycle for accurate stats\n\nChanges:\n- Modified Decode to store entry in ctx.Params\n- Added Encode to call entry.SetError() for 5xx responses\n- Ensures proper latency and error tracking\n\nTesting:\n- Added comprehensive test suite with 7 test cases\n- All tests pass including error ratio and slow request scenarios\n\nFixes #869\n\nCo-Authored-By: LEI-LEI \u003cLEILEI20010628@gmail.com\u003e\n\n* fix: implement feedback loop for circuit breaker state transitions (#869)\n\nFixes issue #869 where circuit breaker never opens despite backend errors.\n\nChanges:\n- Formatted imports following Go conventions\n\nTesting:\n- Added comprehensive test suite with 7 test cases\n- All tests pass including error ratio and slow request scenarios\n\nFixes #869\n\nCo-Authored-By: LEI-LEI \u003cLEILEI20010628@gmail.com\u003e\n\n* Formatted imports\n\n* fix: enhance circuit breaker error messages and add test coverage (#869)\n- Add detailed error context (HTTP status code, method, URL)\n- Add tests for circuit breaker triggered and invalid entry scenarios\n- Align logging style with project conventions\n\n* refactor: move ContextKeySentinelEntry to common constant package (#869)\n\n---------\n\nCo-authored-by: yaolei_cao \u003cyaolei_cao@intsig.net\u003e\nCo-authored-by: LEI-LEI \u003cLEILEI20010628@gmail.com\u003e"
    },
    {
      "commit": "0dc820ed3c344450140e6b241454b1a8e60bd32b",
      "tree": "b34fe6797895b82a728800998eebd4dde31dfd74",
      "parents": [
        "1af727755ede2e8e8546fd1474534341e13a887b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Feb 12 09:27:53 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Feb 12 09:27:53 2026 +0800"
      },
      "message": "build(deps): bump axios from 1.12.0 to 1.13.5 in /admin/web (#880)\n\nBumps [axios](https://github.com/axios/axios) from 1.12.0 to 1.13.5.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.12.0...v1.13.5)\n\n---\nupdated-dependencies:\n- dependency-name: axios\n  dependency-version: 1.13.5\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1af727755ede2e8e8546fd1474534341e13a887b",
      "tree": "6c7c9fe982f8399f36eb823613fa5b16bfa40613",
      "parents": [
        "7d702130f97bed1480e3cb086d933877cc7d009a"
      ],
      "author": {
        "name": "mfordjody",
        "email": "11638005@qq.com",
        "time": "Mon Feb 09 21:33:23 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Feb 09 21:33:23 2026 +0800"
      },
      "message": "Update pixiu docker image (#879)\n\n* Update pixiu docker image\n\n* fix ci\n\n* fix ci"
    },
    {
      "commit": "7d702130f97bed1480e3cb086d933877cc7d009a",
      "tree": "7c9ebe68d6980c0c23745c4ab5e08d35ef294d90",
      "parents": [
        "b5901aee02e4db209fbdeaf51bb955f30690edc5"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jan 28 09:59:05 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jan 28 09:59:05 2026 +0800"
      },
      "message": "build(deps): bump github.com/quic-go/quic-go in /tools/benchmark (#875)\n\nBumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.52.0 to 0.57.0.\n- [Release notes](https://github.com/quic-go/quic-go/releases)\n- [Commits](https://github.com/quic-go/quic-go/compare/v0.52.0...v0.57.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/quic-go/quic-go\n  dependency-version: 0.57.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b5901aee02e4db209fbdeaf51bb955f30690edc5",
      "tree": "b03fd9cb37ed7ae2b2d03d85e9a75825e44abc19",
      "parents": [
        "2c9ad41c2672e68ce3ebdb2c5a27d6ab02fafab0"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Tue Jan 27 16:15:57 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jan 27 16:15:57 2026 +0800"
      },
      "message": "Chore: upgrade dependencies jwt (#874)\n\n* chore: upgrade deprecated jwt-go to golang-jwt/jwt/v4\n\n* chore: update port mappings in docker-compose.yml\n\nSigned-off-by: liuhy \u003cliuhongyu@apache.org\u003e\n\n* chore: reorder jwt import statements in multiple files\n\n---------\n\nSigned-off-by: liuhy \u003cliuhongyu@apache.org\u003e"
    },
    {
      "commit": "2c9ad41c2672e68ce3ebdb2c5a27d6ab02fafab0",
      "tree": "e97bd2fd43be6e5190cf2caf868aecc18ba25adc",
      "parents": [
        "37642626fddb4d55f501af25ff77b35b6048da75"
      ],
      "author": {
        "name": "Tsukikage",
        "email": "65526564+Tsukikage7@users.noreply.github.com",
        "time": "Tue Jan 27 12:21:25 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jan 27 12:21:25 2026 +0800"
      },
      "message": "feat(benchmark): unify IDL definitions and modernize to dubbo-go v3 API (#856)\n\n- Consolidate scattered proto definitions into unified api/ directory\n- Create shared benchmark.proto with User service definitions\n- Add separate grpcstub/ for gRPC-specific generated code\n- Migrate triple server/client to dubbo-go v3 programmatic API\n- Remove legacy dubbogo.yml configuration files\n- Update README with markdown tables and performance comparison\n- Upgrade Go version to 1.25.0\n- Add GetUsers and GetUserByName tests for triple protocol\n- Fix import formatting across test files"
    },
    {
      "commit": "37642626fddb4d55f501af25ff77b35b6048da75",
      "tree": "078b77901168946dcd6a6a4a116bf38923bf1509",
      "parents": [
        "f5050e6a6bcb9147d9f0e0117bfd38ec8502b41d"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Tue Jan 27 10:57:04 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jan 27 10:57:04 2026 +0800"
      },
      "message": "fix: Fixed ARM64 Build Support (#872)\n\n* Fixed ARM64 Build Support:\n    - Modified Dockerfile to remove the hardcoded GOARCH\u003damd64 setting.\n    - This allows the build process to respect the host\u0027s native architecture (ARM64 on Apple Silicon), resolving the unrecognized command-line option \u0027-m64\u0027 error\n\nSigned-off-by: liuhy \u003cliuhongyu@apache.org\u003e\n\n* fix: update goversion to use a simple version string\n\n---------\n\nSigned-off-by: liuhy \u003cliuhongyu@apache.org\u003e"
    },
    {
      "commit": "f5050e6a6bcb9147d9f0e0117bfd38ec8502b41d",
      "tree": "0fe66045267b76f55c442457e6f8be7f32e85311",
      "parents": [
        "9206cb2c488e044c0580aa395819f7333a09e190"
      ],
      "author": {
        "name": "mfordjody",
        "email": "11638005@qq.com",
        "time": "Sat Jan 24 22:38:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jan 24 22:38:32 2026 +0800"
      },
      "message": "Remove samples and migrate to the target repository (#870)\n\n"
    },
    {
      "commit": "9206cb2c488e044c0580aa395819f7333a09e190",
      "tree": "64355d25fa216d1b2b5fd2afd10c54ca7615e21a",
      "parents": [
        "eefe6c6bf5218b62888b9eb81ab20542e2a24730"
      ],
      "author": {
        "name": "aias00",
        "email": "liuhongyu@apache.org",
        "time": "Fri Jan 23 19:02:44 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 23 19:02:44 2026 +0800"
      },
      "message": "feat: arm64 support (#867)\n\n* chore: ignore .worktrees directory\n\n* refactor: replace supermonkey with gomonkey in test files\n\nSigned-off-by: liuhy \u003cliuhongyu@apache.org\u003e\n\n---------\n\nSigned-off-by: liuhy \u003cliuhongyu@apache.org\u003e"
    },
    {
      "commit": "eefe6c6bf5218b62888b9eb81ab20542e2a24730",
      "tree": "919a460dc1a6aabd2b6abdd403ea1a668331ec83",
      "parents": [
        "5ac916297109daabdad749c0f53530788e64bbef"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jan 17 22:17:19 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jan 17 22:17:19 2026 +0800"
      },
      "message": "build(deps): bump tar and fsevents in /admin/web (#865)\n\nRemoves [tar](https://github.com/isaacs/node-tar). It\u0027s no longer used after updating ancestor dependency [fsevents](https://github.com/fsevents/fsevents). These dependencies need to be updated together.\n\n\nRemoves `tar`\n\nUpdates `fsevents` from 1.2.7 to 1.2.13\n- [Release notes](https://github.com/fsevents/fsevents/releases)\n- [Commits](https://github.com/fsevents/fsevents/compare/v1.2.7...v1.2.13)\n\n---\nupdated-dependencies:\n- dependency-name: tar\n  dependency-version: \n  dependency-type: indirect\n- dependency-name: fsevents\n  dependency-version: 1.2.13\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5ac916297109daabdad749c0f53530788e64bbef",
      "tree": "6b7e39c24fcf6aa3de3f8706c1ef1236d9f4a50b",
      "parents": [
        "4d9a42295d4133e6c551aadaaceec8a88a4c51c9"
      ],
      "author": {
        "name": "Tsukikage",
        "email": "65526564+Tsukikage7@users.noreply.github.com",
        "time": "Fri Jan 09 21:56:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 09 21:56:13 2026 +0800"
      },
      "message": "feat(grpc-proxy): add gRPC Server Reflection support (#821) (#849)\n\nAdd gRPC reflection mode to enable content-aware proxying:\n- Support three modes: passthrough, reflection, hybrid\n- Add descriptor caching with TTL and LRU eviction\n- Add dynamic codec for message inspection\n- Fix unary call deadlock by detecting stream type"
    },
    {
      "commit": "4d9a42295d4133e6c551aadaaceec8a88a4c51c9",
      "tree": "182420073146430949135fda6eea90d4fc0e6670",
      "parents": [
        "d62fdff5634e9b700800465eaeefbd5dc8470c3f"
      ],
      "author": {
        "name": "Tsukikage",
        "email": "65526564+Tsukikage7@users.noreply.github.com",
        "time": "Sun Dec 28 22:34:06 2025 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Dec 28 22:34:06 2025 +0800"
      },
      "message": "feat(controllers): improve gateway controller configuration and code quality (#848)\n\n- Make Image and ImagePullPolicy configurable instead of hardcoded\n    - Add GatewayConfig struct with default values\n    - Default image: mfordjody/pixiugateway:debug\n    - Default pull policy: Always\n\n  - Add warning log for unsupported filter types in mergeFilterConfig\n\n  - Refactor duplicate policy loading loops into shared loadClusterPolicyByName\n\n  - Add unit tests for config and utils_policy packages\n\n  Resolves PR #827 and #839 review comments"
    },
    {
      "commit": "d62fdff5634e9b700800465eaeefbd5dc8470c3f",
      "tree": "58d2974f28b77f1af66698af535552962a39540d",
      "parents": [
        "b4e19e31f1e78bd62e9974e3d69db83d8776c265"
      ],
      "author": {
        "name": "陈乐樂",
        "email": "1239498998@qq.com",
        "time": "Sun Dec 28 22:33:28 2025 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Dec 28 22:33:28 2025 +0800"
      },
      "message": "feat: Upgrade dubbo go to v3.3.1 (#853)\n\n* feat:update dubbo-go to latest version #828\n\n* chore: tidy go.sum after upgrade\n\n* feat:update dubbo-go to latest version #828\n\n* fix\n\n* fix: format imports per formatter\n\n* test: re-enable metric push and SDK duplicate name cases\n\n* fix import format\n\n* chore: normalize imports\n\n* style: split imports into std/third-party/local groups\n\n* fix: format imports according to project style\n\n* fix: format imports according to project style\n\n* fix CI problem in nacos registry\n\n* fix\n\n* increase the waiting time in nacos registry\n\n* fix : delete nacos files changes\n\n* feat: upgrade dubbo-go to latest\n\n* feat: upgrade dubbo-go version to v3.3.1"
    },
    {
      "commit": "b4e19e31f1e78bd62e9974e3d69db83d8776c265",
      "tree": "f57295b938ea9312cb150f3991902d9a83006afb",
      "parents": [
        "e9a3d17179a278084f2344ca900262eb4d297f5b"
      ],
      "author": {
        "name": "Xuetao Li",
        "email": "m134679102365478@163.com",
        "time": "Tue Dec 23 10:03:08 2025 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Dec 23 10:03:08 2025 +0800"
      },
      "message": "release: prepare v1.1.0 — update CHANGELOG (#850)\n\n* CHANGELOG_and_UPDATE_VERSION"
    },
    {
      "commit": "e9a3d17179a278084f2344ca900262eb4d297f5b",
      "tree": "91b6104e19818f81472fea2c350fe96733b4633e",
      "parents": [
        "03a9c5a4bcf7844e65d2dfa94e66e9b0fa70501c"
      ],
      "author": {
        "name": "EVERFID",
        "email": "166227111+everfid-ever@users.noreply.github.com",
        "time": "Tue Dec 23 09:41:57 2025 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Dec 23 09:41:57 2025 +0800"
      },
      "message": "feat: migrate dubbo-go-pixiu/pixiu-api to this repo (#841)\n\n* feat: migrate dubbo-go-pixiu/pixiu-api to this repo"
    },
    {
      "commit": "03a9c5a4bcf7844e65d2dfa94e66e9b0fa70501c",
      "tree": "7c94c39ec1406033556154406d68283655c16570",
      "parents": [
        "e4b944f2344b4e5c78129bc20034bf29c6780ad1"
      ],
      "author": {
        "name": "Xuetao Li",
        "email": "m134679102365478@163.com",
        "time": "Mon Dec 22 07:50:15 2025 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Dec 22 07:50:15 2025 +0800"
      },
      "message": "release: prepare v1.1.0 — update CHANGELOG \u0026 version bump (#837)\n\n* CHANGELOG_and_UPDATE_VERSION\n"
    }
  ],
  "next": "e4b944f2344b4e5c78129bc20034bf29c6780ad1"
}
