)]}'
{
  "log": [
    {
      "commit": "f133c2138963fbbff22a93965567db0021e3290d",
      "tree": "4eb21525d4faf9c04e32aa0c41705a6ef9db1846",
      "parents": [
        "22fbc813d576b2d386f7baaf51a1895c96b1bece"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Fri Jul 24 15:10:09 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 15:10:09 2026 +0530"
      },
      "message": "RANGER-5690: UnixAuth service lacks rate limiting on authentication attempts (#1106)"
    },
    {
      "commit": "22fbc813d576b2d386f7baaf51a1895c96b1bece",
      "tree": "d891470a4e9bc3d411db56521888c9ce861a7f60",
      "parents": [
        "2b158c126103210df70534674d4b77b063f7af72"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Tue Jul 21 20:00:17 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 20:00:17 2026 -0700"
      },
      "message": "RANGER-5700: Support SPIFFE-based authn via HTTP headers (#1096)"
    },
    {
      "commit": "2b158c126103210df70534674d4b77b063f7af72",
      "tree": "4b23b52159676010762f8da41e47cf3b1ca032af",
      "parents": [
        "514f2a376be3ad9059d8a44ec823ed257b4e887b"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Tue Jul 21 21:01:25 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 21:01:25 2026 +0530"
      },
      "message": "RANGER-5677: make non-secure download endpoint patterns slash-insensitive (#1062)"
    },
    {
      "commit": "514f2a376be3ad9059d8a44ec823ed257b4e887b",
      "tree": "c3ad46714e53eb711ed99a5e6df488263cfe3c47",
      "parents": [
        "4f0b4e7d06626ee8d6b281a680dbf90dec92f59e"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Tue Jul 21 20:18:52 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 20:18:52 2026 +0530"
      },
      "message": "RANGER-5690: UnixAuth service lacks rate limiting on authentication attempts (#1080)"
    },
    {
      "commit": "4f0b4e7d06626ee8d6b281a680dbf90dec92f59e",
      "tree": "df9cf5e4d914057c5648ff1a1d5aadc19a70b69c",
      "parents": [
        "eaa611430a86b463f543a915270a0a9ed916452a"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Mon Jul 20 16:34:52 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 16:34:52 2026 +0530"
      },
      "message": "RANGER-5596 : Blank resource type created during new global policy creation setup. (#1093)"
    },
    {
      "commit": "eaa611430a86b463f543a915270a0a9ed916452a",
      "tree": "b62aae798f1d2c044f2e627ffb5f61da40af7f10",
      "parents": [
        "1a4784bb7267f8188ec3f084c219d7cc11ea3a56"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Mon Jul 20 15:57:09 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 15:57:09 2026 +0530"
      },
      "message": "RANGER-5570 : Ranger: New Enhanced Policy Creation Interface (#1092)"
    },
    {
      "commit": "1a4784bb7267f8188ec3f084c219d7cc11ea3a56",
      "tree": "f18d997fe13330e2cb5020037ebf9ac9fcf18b44",
      "parents": [
        "37b6e02c4d3b989790bbd669b7d5d4366f7f7644"
      ],
      "author": {
        "name": "Mugdha Varadkar",
        "email": "fimugdha@users.noreply.github.com",
        "time": "Mon Jul 20 15:31:20 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 15:31:20 2026 +0530"
      },
      "message": "RANGER-5697 : Fix redendering policy-condition in dataset access grant (#1090)"
    },
    {
      "commit": "37b6e02c4d3b989790bbd669b7d5d4366f7f7644",
      "tree": "2b57073c58786f0158f288130d1f3b9d6eb0a172",
      "parents": [
        "6723329285d1287df59e2424200e218e768e7dda"
      ],
      "author": {
        "name": "fmorg-git",
        "email": "fmorg.git@gmail.com",
        "time": "Mon Jul 20 02:25:51 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 14:55:51 2026 +0530"
      },
      "message": "RANGER-5687: Add feature flag to artifacts for RANGER-5628 (#1073)\n\n* add feature flag to artifacts for RANGER-5628\n\n* bug fixes - missing flag on patch and if flag is on and condition set on resource policy, then flag is off, ui hangs\n\n(cherry picked from commit e25cdb00df8ca54a75bb998863ede76e8d52148f)\n\n* fix checkstyle issue\n\n(cherry picked from commit d06e4049a352ee3caad45a561098a7031ada557f)\n\n* Confine Ozone action-policy gating to plugin-ozone module.\n\nMove enableOzoneActionPolicy handling out of RangerInlinePolicyEvaluator\ninto RangerOzoneAuthorizer, including legacy session-policy sanitization\nand a unit test for flag-off behavior with embedded grant actions.\n\n* RANGER-5687: read ozone action-policy flag without agents-common changes.\n\nUse ServiceDefUtil.getBooleanValue in plugin-ozone and security-admin per PR review, and revert agents-common ozone-specific additions.\n\n* Scope action-matcher option to ozone service-def only.\n\nRename enableOzoneActionPolicy to enableActionMatcherInPoliciesCondition and\nadmin config to ranger.servicedef.ozone.enableActionMatcherInPoliciesCondition.\nNon-ozone service defs always get false; ozone reads site config.\nAddresses PR review from fimugdha.\n\n* fix checkstyle issues\n\n* remove agents-common modification per mneethiraj and address fimugdha comments\n\n* Persist ozone action-matcher flag in J10065 def_options upgrade.\n\nOn upgrade, sync enableActionMatcherInPoliciesCondition from admin config into ozone def_options only, alongside existing policyConditions updates for action-matches.\n\n* Add ozone action-matcher docker flag and align J10065 def_options sync.\n\nWire RANGER_OZONE_ENABLE_ACTION_MATCHER into ranger-docker so admin setup\nreads the flag before J10065 runs, fix the def_options constant, and update\npatch unit tests after E2E validation on Mac with fresh Postgres installs.\n\n* Simplify ozone docker flag script and restore generic BUILD_OPTS.\n\nUse update_property.py from the admin tarball instead of inline Python,\nand keep BUILD_OPTS empty so ranger-docker builds remain full by default.\n\n* Fix ImportOrder checkstyle violation in J10065 patch.\n\n* Make ozone action-matcher flag follow admin config at runtime.\n\nStale def_options from an earlier J10065 run or the pre-rename enableOzoneActionPolicy\noption could override ranger.servicedef.ozone.enableActionMatcherInPoliciesCondition,\nhiding action-matches in Admin UI and ozone authorizer even when the flag was set true.\n\nAdmin config is now authoritative when serving the ozone service-def, and action-matches\nis restored from the embedded def when enabled but missing from DB.\n\n* Remove legacy enableOzoneActionPolicy handling.\n\nThe renamed enableActionMatcherInPoliciesCondition option and admin runtime\noverlay make enableOzoneActionPolicy obsolete for 3.0.\n\n* pr review comment for mneethiraj - don\u0027t automatically disable action-matches for non-Ozone service definition\n\n* pr review comments for mneethiraj - don\u0027t reference feature flag in ui\n\n* pr review comment for mneethiraj - revert updates to patch\n\n* pr review comment for mneethiraj - rename PROP_ENABLE_ACTION_MATCHER_IN_POLICIES_CONDITION to PROP_ENABLE_ACTION_MATCHER_IN_POLICIES_CONDITION_FOR_OZONE\n\n* add clarification statement for docker\n\n* Update RangerOzoneAuthorizer.java\n\n* pr review update for mneethiraj - revamp Docker handling\n\n* remove no longer valid unit test\n\n* renamed FF_ENAB_OZONE_ACTION_MATCHES_CONDITION to FF_ENABLE_OZONE_ACTION_MATCHES_CONDITION\n\n---------\n\nCo-authored-by: Fabian Morgan \u003cfmorg-git@gmail.com\u003e\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "6723329285d1287df59e2424200e218e768e7dda",
      "tree": "07f892ae20c6dc54b38f713c2ce280d7dcba6f34",
      "parents": [
        "b93fed70df3ef8bcc8002ce63352e84bce5a03d6"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Sun Jul 19 09:52:22 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 09:52:22 2026 +0530"
      },
      "message": "RANGER-5693: Stop logging full JWT bearer tokens on validation failure (#1081)\n\n* RANGER-5693: Stop logging full JWT bearer tokens on validation failure\n\nReplace jwtToken.serialize() in the validation-failure WARN path with\nsafeJwtLogContext() that logs only non-sensitive metadata and a SHA-256\nhash for log correlation. Add null-safety for missing audience claims\nand unit tests for the safe logging path.\n\n* RANGER-5693: Drop tokenHash from JWT validation failure logs.\n\nPer review feedback, remove sha256Hex/tokenHash from safeJwtLogContext;\njwtId is sufficient for log correlation when present.\n\n* Remove tokenHash assertion from JWT test\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e"
    },
    {
      "commit": "b93fed70df3ef8bcc8002ce63352e84bce5a03d6",
      "tree": "95c291fa8698bba559714c79dce964d115552e8c",
      "parents": [
        "69e31ba976cb3d1b9f3ff63ea4d7a189805f33fc"
      ],
      "author": {
        "name": "Mugdha Varadkar",
        "email": "fimugdha@users.noreply.github.com",
        "time": "Fri Jul 17 18:13:12 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 18:13:12 2026 +0530"
      },
      "message": "RANGER-5694 : Refactor policy condition rendering component to ensure layout stability (#1082)"
    },
    {
      "commit": "69e31ba976cb3d1b9f3ff63ea4d7a189805f33fc",
      "tree": "631415518244f14170769c5aa53657858cfe02a8",
      "parents": [
        "b8409fad9f0d85c20d91a2875adf8db85f646f93"
      ],
      "author": {
        "name": "Chinmay Hegde",
        "email": "hegdechinmay24@gmail.com",
        "time": "Fri Jul 17 18:07:03 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 18:07:03 2026 +0530"
      },
      "message": "RANGER-5691: Incorrect response seen when admin tries to create a key (#1077)\n\n* RANGER-5691: Propagate KMS service-not-found exception to caller in KMSKeyMgr\n\n* RANGER-5692 : Added debug logs to KMSMDCFilter dofilter method"
    },
    {
      "commit": "b8409fad9f0d85c20d91a2875adf8db85f646f93",
      "tree": "7656e1ca2b8d3bd919bf9d54d539c4df6e4782a4",
      "parents": [
        "f73cfcb4f4e31da5a8ed7cf93fe69c545506cd4f"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Fri Jul 17 17:28:09 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 17:28:09 2026 +0530"
      },
      "message": "RANGER-5468 : Policy UI to list permissions in sorted order (#1088)"
    },
    {
      "commit": "f73cfcb4f4e31da5a8ed7cf93fe69c545506cd4f",
      "tree": "1bb533d4d68db47b9fd9e182907e46feb482ed86",
      "parents": [
        "bdb7efa2c4109252e8039672adf267b3263c06e5"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Fri Jul 17 17:09:53 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 17:09:53 2026 +0530"
      },
      "message": "RANGER-5445 : Implement Confirmation Modal for Users/Groups/Roles Removal (#1087)"
    },
    {
      "commit": "bdb7efa2c4109252e8039672adf267b3263c06e5",
      "tree": "4be06ba97b57d921484f96854969fd290e2a2980",
      "parents": [
        "4953599f03656a78b55982e20ab68e91b8cf47a2"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Fri Jul 17 16:59:14 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 16:59:14 2026 +0530"
      },
      "message": "RANGER-5446 : Ensure Policy Conditions modal size and appearance are consistent (#1086)"
    },
    {
      "commit": "4953599f03656a78b55982e20ab68e91b8cf47a2",
      "tree": "48b9024d3d2b0a60a921f06ae2271236a84afa71",
      "parents": [
        "327a722ccc2df803397fd2532920891a90723606"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Fri Jul 17 16:52:03 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 16:52:03 2026 +0530"
      },
      "message": "RANGER-5444 : Policy Form Improvements – Label Corrections \u0026 Layout Updates (#1085)"
    },
    {
      "commit": "327a722ccc2df803397fd2532920891a90723606",
      "tree": "65967f711b080c3d3430584acbd06f6a060647ff",
      "parents": [
        "c631e8314b70b01cd5bb5bb2bf4ba17985da585a"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Thu Jul 16 13:10:49 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 13:10:49 2026 -0700"
      },
      "message": "RANGER-5652: Add user/group/role lookup by an authenticated user as NON-FINDING (#1075)"
    },
    {
      "commit": "c631e8314b70b01cd5bb5bb2bf4ba17985da585a",
      "tree": "14da31eb308ff29bb4a72d980f5e7a3b763a94f4",
      "parents": [
        "e2574d332ffe4fda3ec16648a3a49df8b356baa6"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Wed Jul 15 17:55:04 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 15 17:55:04 2026 +0530"
      },
      "message": "RANGER-5689: Standardize TLS hostname verification across Ranger HTTP clients using a uniform verifier (#1076)"
    },
    {
      "commit": "e2574d332ffe4fda3ec16648a3a49df8b356baa6",
      "tree": "de39b7cfa437d3bd7afd889f0e0d1b155712b826",
      "parents": [
        "f195fde0c5d730f432ce594db189a83d6aad1eb9"
      ],
      "author": {
        "name": "Bhavesh Amol Aamre",
        "email": "amrebhaveshtrade@gmail.com",
        "time": "Wed Jul 15 15:52:53 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 15 15:52:53 2026 +0530"
      },
      "message": "RANGER-5668:INSERT INTO External Hive Table Fails for Table/Database Owner When Access Is Granted Through Ranger {OWNER} Policy (#1066)"
    },
    {
      "commit": "f195fde0c5d730f432ce594db189a83d6aad1eb9",
      "tree": "99b0e09d66268b97895729751a3d408e9cca8ffd",
      "parents": [
        "e823f4cf08961fb1aab66e57fdd0fe59bd23892e"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Wed Jul 15 15:35:33 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 15 15:35:33 2026 +0530"
      },
      "message": "RANGER-5681: Align GDS secure download endpoint authorization with other secure download APIs (#1067)"
    },
    {
      "commit": "e823f4cf08961fb1aab66e57fdd0fe59bd23892e",
      "tree": "729385028ccbd4079071e114bb8b3595a3735eb7",
      "parents": [
        "d3e3a379df1f8dcf7aa2f90e2029aa011a8f0688"
      ],
      "author": {
        "name": "dhavalshah9131",
        "email": "dhavalshah9131@gmail.com",
        "time": "Mon Jul 13 11:27:22 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 13 11:27:22 2026 +0530"
      },
      "message": "RANGER-5427 : AD Groups with 1500+ Users Fail to Sync into Ranger Admin via RangerUserSync (#966)\n\nCo-authored-by: Dhaval Shah \u003cdhavalshah9131@@gmail.com\u003e"
    },
    {
      "commit": "d3e3a379df1f8dcf7aa2f90e2029aa011a8f0688",
      "tree": "bda7bc0b39f4ff7ffb2a773826e6fb1a67f1b553",
      "parents": [
        "ad447b9b95dc16cc24ca6412600525415c766f2a"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Sat Jul 11 15:16:42 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 15:16:42 2026 +0530"
      },
      "message": "RANGER-5666: update graalvm version to 25.1.3 - part 2 (#1063)\n\nBundle GraalJS 25.1.3 runtime JARs in the remaining plugin and server\nassembly tarballs so JavaScript policy conditions work on JDK 17+.\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e"
    },
    {
      "commit": "ad447b9b95dc16cc24ca6412600525415c766f2a",
      "tree": "a12065894ddd638e73dd456508d66504b50600c4",
      "parents": [
        "9bf7a9364f0f646b8d5d8e1a8244ca4cdf7a797f"
      ],
      "author": {
        "name": "Madhan Neethiraj",
        "email": "madhan@apache.org",
        "time": "Thu Jul 09 19:52:24 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 09 19:52:24 2026 -0700"
      },
      "message": "RANGER-5666: update graalvm version to 25.1.3 (#1052)\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e"
    },
    {
      "commit": "9bf7a9364f0f646b8d5d8e1a8244ca4cdf7a797f",
      "tree": "317d2819d784f9c1ebfa0421eb9d354b88e1205a",
      "parents": [
        "bfa621a251395a5a540ea992cb2b5ac5a5a9f9b2"
      ],
      "author": {
        "name": "fmorg-git",
        "email": "fmorg.git@gmail.com",
        "time": "Wed Jul 08 18:28:12 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 18:28:12 2026 -0700"
      },
      "message": "RANGER-5667: fixes in support for actions in Ozone policies (#1053)"
    },
    {
      "commit": "bfa621a251395a5a540ea992cb2b5ac5a5a9f9b2",
      "tree": "a12442ac2145f5d1390b8882eabd2cd40bc15011",
      "parents": [
        "d980f9f580289870bb5135b756131d6584f64a5c"
      ],
      "author": {
        "name": "KRISHNA CHAITANYA MUTTEVI",
        "email": "130595906+krishnamuttevi@users.noreply.github.com",
        "time": "Tue Jul 07 12:28:59 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 07 12:28:59 2026 +0530"
      },
      "message": "RANGER-5624: Fix inconsistent updatedBy masking in groupName API (#993)"
    },
    {
      "commit": "d980f9f580289870bb5135b756131d6584f64a5c",
      "tree": "0da37408968b8e6450d8427d76701cfec3cf97f8",
      "parents": [
        "0274a6a0bc9680a7640e97432f8cbd3217a1659c"
      ],
      "author": {
        "name": "KRISHNA CHAITANYA MUTTEVI",
        "email": "130595906+krishnamuttevi@users.noreply.github.com",
        "time": "Mon Jul 06 15:42:03 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 15:42:03 2026 +0530"
      },
      "message": "RANGER-5623: Updated XUserMgr.java to solve UI consistency for put groupusers endpoint (#992)\n\n* RANGER-5623: Updated XUserMgr.java to solve UI consistency in groupusers\n\n* RANGER-5623: Updated the TextXUserMgr and resolved the checkstyle error\n\n* RANGER-5623: Added the validation check for the invalid vXGroupUser input\n\n* RANGER-5623: Addressed the review comments to optimise and add proper validation"
    },
    {
      "commit": "0274a6a0bc9680a7640e97432f8cbd3217a1659c",
      "tree": "cbe667bed3cf38dfe514278624452d31da12d001",
      "parents": [
        "deaf13df3c62af8edde53e185890682fb711bec5"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Sat Jul 04 20:21:09 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 20:21:09 2026 +0530"
      },
      "message": "RANGER-5657:Limit getAllModuleNames() to sys-admin sessions in SessionMgr (#1036)\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e"
    },
    {
      "commit": "deaf13df3c62af8edde53e185890682fb711bec5",
      "tree": "9405b96ffb59b5ce96883d691495bdc093dc599e",
      "parents": [
        "6d9b1b2cf2e9a84eb4eebb2fd71c8672c333e69b"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Fri Jul 03 22:38:01 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 22:38:01 2026 +0530"
      },
      "message": "RANGER-5658: Tag Sync: remove atlas.kafka.zookeeper.connect and fix Atlas Kafka consumer for Kafka 3.9 (#1037)\n\n* RANGER-5658: Remove obsolete atlas.kafka.zookeeper.connect requirement from Tag Sync.\n\nTag Sync consumes Atlas notifications via kafka-clients (bootstrap.servers only).\nThe legacy zookeeper.connect property was never used by Atlas KafkaNotification\nbut was still required at startup and in installer templates.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5658: Remove dev-support PR template README from the patch.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* TagSync install: use rangerTagsync_password for Ranger jceks credential.\n\nsetup.py wrote tagadmin.user.password as the literal username \u0027rangertagsync\u0027\ninstead of rangerTagsync_password from install.properties, causing 401 on\nTagAdminRESTSink until updatetagadminpassword.py ran at end of setup.\n\nComplements RANGER-5658 / PR #1037 (Atlas Kafka ZK cleanup); required for\ndocker Atlas REST TagSync with Kerberos Ranger Admin.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5658: Enable Tag Sync Atlas Kafka consumer for PLAINTEXT and KRaft.\n\nEmit Kerberos JAAS in setup.py only when atlas.kafka.security.protocol is\nSASL; load atlas-application.properties via ApplicationProperties and\n-Datlas.conf; update docker sample to atlas-kafka PLAINTEXT bootstrap.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5658: Add Tag Sync Atlas Kafka operator documentation.\n\nDocument PLAINTEXT and Kerberos Kafka modes, startup commands,\n-Datlas.conf requirement, and verification steps.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5658: Align TagSync docs and docker sample with ranger-docker Kafka.\n\nUse ranger-kafka.rangernw:9092 with SASL_PLAINTEXT in docker install sample;\nrestore localhost Atlas REST endpoint; trim README change-log section.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5658: Default ranger-docker TagSync to Atlas REST source.\n\nKeep Atlas Kafka settings in install sample for optional enablement;\ndocument REST-as-default in README.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5658: Fix AtlasTagSource import order for checkstyle.\n\nOrder commons.collections imports before commons.configuration per\ndev-support/checkstyle.xml ImportOrder rules.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* Update AtlasTagSource.java\n\n* RANGER-5658: Restore ranger-docker TagSync file-source default per review.\n\ndev-support/ranger-docker has no Atlas server; default to file source\n(TAG_SOURCE_FILE_ENABLED\u003dtrue) instead of Atlas REST. Document coexist\nKafka enablement in README.\n\n* RANGER-5658: Fix AtlasTagSource trailing whitespace for checkstyle.\n\nRemove trailing spaces on blank lines reported by CI checkstyle\n(RegexpMultiline) in AtlasTagSource.java.\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "6d9b1b2cf2e9a84eb4eebb2fd71c8672c333e69b",
      "tree": "da8451e2da517d5c285f0affd6ded116575672ad",
      "parents": [
        "abe67188ff73b39cb977cf2838d6e0b1ab8b765c"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Fri Jul 03 21:21:52 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 21:21:52 2026 +0530"
      },
      "message": "RANGER-5661:Fix Kafka plugin packaging for broker-delegate classloading on Kafka 3.9+ (#1040)\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "abe67188ff73b39cb977cf2838d6e0b1ab8b765c",
      "tree": "67031f3ca240f3d383d0a2f05bd4a3ff0af4177d",
      "parents": [
        "a23c30c60418e1483f3f3ccb605a6b93e42f826e"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Fri Jul 03 21:19:10 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 21:19:10 2026 +0530"
      },
      "message": "RANGER-5660: Fix YARN plugin packaging and enable script lib path (#1039)\n\nAdd missing plugin-yarn template for assembly, install YARN plugin jars\nunder share/hadoop/yarn/lib, and include slf4j-api in ranger-yarn-plugin-impl\nto match hdfs-agent packaging.\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "a23c30c60418e1483f3f3ccb605a6b93e42f826e",
      "tree": "552c200227b0be4a23daba0417b4d667df68ba7a",
      "parents": [
        "12ea9a7916cc3a7f4987a69adb8bd4c8a283f139"
      ],
      "author": {
        "name": "Paras agnihotri",
        "email": "agnihotri.paras@gmail.com",
        "time": "Mon Jun 29 11:24:31 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 15:54:31 2026 +0530"
      },
      "message": "RANGER-4676, RANGER-5615: Add OpenSearch Dispatcher to Ranger Audit Server (#986)\n\n* RANGER-4676, RANGER-5615: Add OpenSearch audit destination via dedicated dispatcher module\n\n* Update OpenSearchAuditDestination.java\n\n* Update AuditOpenSearchDispatcher.java\n\n* Update OpenSearchDispatcherManager.java\n\n* Update OpenSearchUtilTest.java\n\n* Update OpenSearchMgrTest.java\n\n* Update OpenSearchAccessAuditsServiceTest.java\n\n* Update OpenSearchUtil.java\n\n* Update OpenSearchAccessAuditsService.java\n\n* Update TestAuditOpenSearchDispatcher.java\n\n---------\n\nCo-authored-by: Paras \u003cpagnihotri@cloudera.com\u003e\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "12ea9a7916cc3a7f4987a69adb8bd4c8a283f139",
      "tree": "708de6315393c883326f37cb9794e7ed487917ba",
      "parents": [
        "5aa6629baa3d4bb9e078285c041d3aff2cb22a68"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Sat Jun 27 23:16:14 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 27 23:16:14 2026 -0700"
      },
      "message": "RANGER-5653: Updates to apache-ranger Python client with Python 3 support only (#1034)"
    },
    {
      "commit": "5aa6629baa3d4bb9e078285c041d3aff2cb22a68",
      "tree": "beaaf2c6e626097abbc27b7aeae75b8aa1fec7a5",
      "parents": [
        "dcf5947fe96f71e311e3f8d94f0786496cf8adf4"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Sun Jun 28 07:29:18 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 28 07:29:18 2026 +0530"
      },
      "message": "RANGER-5656: TagSync Atlas REST sync fails with AbstractMethodError after RANGER-4076 Jersey 2 migration (#1035)\n\n* RANGER-5656: TagSync Atlas REST sync fails with AbstractMethodError after RANGER-4076 Jersey 2 migration\n\nReplace AtlasClientV2 with HttpURLConnection-based AtlasRESTHttpClient so TagSync\ndoes not load Jersey 1.x on the same classpath as Ranger Jersey 2.x REST sink.\nRemove atlas-client-v1/v2 from tagsync dependencies and assembly tarball.\n\n* RANGER-5656: Address review feedback on AtlasRESTHttpClient and restore resolveTag comments\n\nCollapse multi-line statements in AtlasRESTHttpClient and restore original\nresolveTag block and inline comments in AtlasRESTTagSource.\n\n* RANGER-5656: Use RangerRESTClient for Atlas REST SSL and HA URL failover\n\nReplace HttpURLConnection Atlas client with RangerRESTClient so TagSync\nreuses the same SSL and multi-URL failover as TagAdminRESTSink. Initialize\nAtlasRESTHttpClient from comma-separated endpoints and keep basic auth when\ncredentials are configured alongside Kerberos.\n\n* RANGER-5656: Fix checkstyle ImportOrder and apply review style in AtlasRESTHttpClient\n\nAdd blank line between javax and java imports for checkstyle, use single\nreturn in execute(), and keep Atlas REST client initialization on one line.\n\n* Update AtlasRESTHttpClient.java\n\n* Update AtlasRESTTagSource.java\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "dcf5947fe96f71e311e3f8d94f0786496cf8adf4",
      "tree": "de66067dc0cb9aec7298111d41218ed7cdfd5152",
      "parents": [
        "9c887928b74fb391a1ce6f9e24905d01cb8125c5"
      ],
      "author": {
        "name": "fmorg-git",
        "email": "fmorg.git@gmail.com",
        "time": "Fri Jun 26 22:01:24 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 27 10:31:24 2026 +0530"
      },
      "message": "RANGER-5628: Support for actions in Ozone Service Definition (#995)\n\n* update Ranger policy logic and Ozone authorizer\n\nGenerated-By: Cursor, Claude Code and then with additional manual updates.\n\n* add a new matcher for actions\n\nGenerated-By: Cursor, Claude Code and then with additional manual updates.\n\n* temporarily use Ozone 2.1.1 release candidate for compilation purposes\n\nGenerated-By: Cursor\n\n* Support actions in UI, populate Ozone action choices based on permissions, and ensure actions wrap around instead of scrolling horizontally indefinitely.  It also fixes latent React hook violations of having useState within a conditional (CommonComponents.jsx) and a loop (Editable.jsx).  It also ensures that the action field only shows up in the Policy Conditions section, not on the overall Resource Policy.\n\nGenerated-By: Cursor, Claude Code\n\n* update for Ozone service policy definition\n\nGenerated-By: Cursor, Claude Code\n\n* pr review comments for copilot: usePruneStaleConditions.js\n\n* pr review comments for copilot: PolicyPermissionItem.jsx\n\n* remove snapshot repository because Ozone 2.1.1 is now released\n\n* pr review updates for copilot\n\n* make junit tests package private to solve pmd violations\n\n(cherry picked from commit 91dafb06c75566da04350a2cc85a8d665aabd66f)\n\n---------\n\nCo-authored-by: Fabian Morgan \u003cfmorg-git@gmail.com\u003e"
    },
    {
      "commit": "9c887928b74fb391a1ce6f9e24905d01cb8125c5",
      "tree": "b004851ed69aacf2d7ad78d5f69278ece2ac0ba2",
      "parents": [
        "597f6506c674144cc067def0de86aaf4405142cb"
      ],
      "author": {
        "name": "Rakesh Gupta",
        "email": "rakesh.gupta.dev264@gmail.com",
        "time": "Fri Jun 26 16:46:08 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 16:46:08 2026 +0530"
      },
      "message": "RANGER-5639: Upgrade bouncycastle to 1.84 (#1022)"
    },
    {
      "commit": "597f6506c674144cc067def0de86aaf4405142cb",
      "tree": "7204fc574c2f82d9c4ebc8a1bb878e55c52c9c9e",
      "parents": [
        "7017225e604c3506b52db1d87c44325794204056"
      ],
      "author": {
        "name": "Sanket-Shelar",
        "email": "121221985+Sanket-Shelar@users.noreply.github.com",
        "time": "Fri Jun 26 11:39:42 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 11:39:42 2026 +0530"
      },
      "message": "RANGER-5648: Solr authorization fails with NPE (#1029)"
    },
    {
      "commit": "7017225e604c3506b52db1d87c44325794204056",
      "tree": "5eaab5952c4671ff8601f5f5ef9c32db9743a4af",
      "parents": [
        "33e7b3a386eb6e689d7e5411b8e00db573abc30e"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Wed Jun 24 16:25:42 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 24 16:25:42 2026 +0530"
      },
      "message": "RANGER-5654: Fix Solr audit dispatcher Kerberos TGT relogin (No key to store) via keytab-aware JAAS relogin (#1030)\n\n* RANGER-5654:Solr audit dispatcher fails to index after Kerberos TGT relogin (No key to store) with default useTicketCache\u003dtrue\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5654: Restore site XML descriptions and document relogin recovery\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5654: Drop AbstractKerberosUser change; config-only fix\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5654: Keytab-aware JAAS relogin; restore useTicketCache\u003dtrue\n\nReplace config-only useTicketCache\u003dfalse with in-place keytab relogin in\nAbstractKerberosUser (agents-audit + security-admin). KerberosAction uses\nperformRelogin() on SecurityException retry. Revert shipped and docker site\nXML to useTicketCache\u003dtrue so the Java fix alone addresses \"No key to store\"\nat TGT renewal. Add unit test for keytab relogin without logout.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5654: Wrap Kerberos javadoc and log lines for checkstyle\n\nKeep LineLength within 80 characters in AbstractKerberosUser,\nKerberosAction, and KerberosJAASConfigUser; no new checkstyle\nviolations versus the pre-change baseline in those files.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5654: Use single-line Kerberos relogin log statements\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5654: Address KerberosJAASConfigUser PR review feedback\n\nCache useKeyTab in the constructor, rename helper to getBooleanOption,\nand use a single return per method in both agents-audit and security-admin.\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "33e7b3a386eb6e689d7e5411b8e00db573abc30e",
      "tree": "1c9dbdc803112d4e22229fbd1b567db6e59a066a",
      "parents": [
        "79343e6a9b8b5411ef18c455931ca2c9314798a0"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Fri Jun 19 19:37:14 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 19:37:14 2026 +0530"
      },
      "message": "RANGER-5650: KMS plugin: package Jackson/Jersey audit client JARs in kms.xml for audit-server delivery (#1025)\n\nAdd Jackson, Jersey client, and HK2 coordinates to ranger-kms-plugin-impl\nso the isolated plugin classloader can POST audit batches to the audit-server\ningestor without LinkageError or Jersey SPI failures.\n\nhttps: //issues.apache.org/jira/browse/RANGER-5650\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "79343e6a9b8b5411ef18c455931ca2c9314798a0",
      "tree": "85ebd00d4120ad95b264ac33fc0d3f20d284f5c5",
      "parents": [
        "c804fc3518fd70e594e05d674f847847860bc53a"
      ],
      "author": {
        "name": "Vikas Kumar",
        "email": "talktovikasbit@gmail.com",
        "time": "Fri Jun 19 16:21:50 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 16:21:50 2026 +0530"
      },
      "message": "RANGER-5530: Fix for KMS API not working in docker kerberos env (#1004)\n\n* RANGER-5530: Fix for KMS API not working in docker kerberos env\n\n* RANGER-5530: Fix for KMS API not working in docker kerberos env-fixed Linkage error"
    },
    {
      "commit": "c804fc3518fd70e594e05d674f847847860bc53a",
      "tree": "65acff3e94e041fd696d919ff6e81eb9d84051eb",
      "parents": [
        "85b8eca0693208d435546d372edaf037a04b4c15"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Wed Jun 17 20:22:55 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 20:22:55 2026 +0530"
      },
      "message": "RANGER-5619: Keyadmin user unable to perform test connection for cm_kms service (#1024)"
    },
    {
      "commit": "85b8eca0693208d435546d372edaf037a04b4c15",
      "tree": "0f35e1ed076f12a75f8dbbd9098520e835f81de8",
      "parents": [
        "33ba8e8bc11a083a5962b99570440bd0e0cc2dc6"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Wed Jun 17 17:29:07 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 17:29:07 2026 +0530"
      },
      "message": "RANGER-5629: Harden GraalJS engine configuration used for policy condition (_expression) evaluation (#1002)\n\n* RANGER-5629: Harden GraalJS engine configuration used for policy condition (_expression) evaluation\n\n* RANGER-5629: changed the local variable name to address review comment"
    },
    {
      "commit": "33ba8e8bc11a083a5962b99570440bd0e0cc2dc6",
      "tree": "0c693b1c48c6f33a558123bedb96b3c200c0fab8",
      "parents": [
        "ab2b3cf00a51517c2308dff07a8e3c8e1f068a18"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Wed Jun 17 15:29:34 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 15:29:34 2026 +0530"
      },
      "message": "RANGER-5579: add validation to DefaultSchemaRegistryClient createUrlSelector method (#935)\n\n* RANGER-5579: add validation to DefaultSchemaRegistryClient createUrlSelector method\n\n* RANGER-5579: incorporated the review comments\n\n* RANGER-5579: addressed review comment"
    },
    {
      "commit": "ab2b3cf00a51517c2308dff07a8e3c8e1f068a18",
      "tree": "40e07e52b259fec6e1534e03c723b7ad2f189c64",
      "parents": [
        "6bf19137341fcbe1cbee1e7cffc2f341ac78f029"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Wed Jun 17 14:23:48 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 14:23:48 2026 +0530"
      },
      "message": "RANGER-5567: allow validateConfig API available only for users with Ranger admin role (#931)"
    },
    {
      "commit": "6bf19137341fcbe1cbee1e7cffc2f341ac78f029",
      "tree": "a4682aebee59c83188e2cedaca041723e847a5a6",
      "parents": [
        "bfaec45c18aae564439256e822f045cba330ce76"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 16 21:47:02 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 16 21:47:02 2026 +0530"
      },
      "message": "RANGER-5642: Exclude duplicate Jersey JARs from Kafka plugin packaging (#1020)\n\n* RANGER-5642: Exclude duplicate Jersey JARs from Kafka plugin packaging\n\nRevert the Kafka portion of #1015: the broker already ships Jersey on the\napplication classpath; duplicate JARs in plugin-impl cause WadlAutoDiscoverable\nClassCastException and audit ingestor POST failures.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5647: Fix remaining ISO EXPIRES_ON dates in hive tag tests.\n\nPR #1018 updated slash-format tag fixture dates to 2099/12/31 but left\n2026-06-15 ISO expiry_date values in test_policyengine_tag_hive.json.\nAfter 2026-06-15, TestPolicyEngine.testPolicyEngine_hiveForTag fails CI\nwith isAllowed expected true but was false for EXPIRES_ON SELF match.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* Revert \"RANGER-5647: Fix remaining ISO EXPIRES_ON dates in hive tag tests.\"\n\nThis reverts commit ef0dbdd2e0d0c594fa46113038aa4054e7a27348.\n\n* RANGER-5642: Exclude duplicate Jackson JARs from Kafka plugin packaging\n\nReview feedback on #1020: broker ships Jackson 2.16.x; plugin-impl must not\nalso whitelist jackson-annotations, jackson-core, jackson-databind, and\njackson-jaxrs-json-provider at Ranger 2.17.x — same principle as the Jersey\nrevert (use broker classpath for shared libraries).\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "bfaec45c18aae564439256e822f045cba330ce76",
      "tree": "f23914fd065ead067b237f18f23b58e1d76e3161",
      "parents": [
        "9272baf0832007a21982e62be6510c7a1c3e0071"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 16 10:56:46 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 16 10:56:46 2026 +0530"
      },
      "message": "RANGER-5647: Fix remaining ISO EXPIRES_ON dates in hive tag tests. (#1021)\n\nPR #1018 updated slash-format tag fixture dates to 2099/12/31 but left\n2026-06-15 ISO expiry_date values in test_policyengine_tag_hive.json.\nAfter 2026-06-15, TestPolicyEngine.testPolicyEngine_hiveForTag fails CI\nwith isAllowed expected true but was false for EXPIRES_ON SELF match.\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "9272baf0832007a21982e62be6510c7a1c3e0071",
      "tree": "afb96f85761fcac043c128a3987a9316ed228e97",
      "parents": [
        "38d21532259a9d19f9539ee358ec5b4c732f42ee"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Mon Jun 15 20:30:50 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:30:50 2026 +0530"
      },
      "message": "RANGER-5646: Exclude duplicate Hive/Hadoop JARs from hive plugin packaging. (#1019)\n\nStop whitelisting Jackson 2.17, httpclient/httpcore, hppc, and other\nlibraries HiveServer2 already provides so audit-server REST delivery no\nlonger fails with HTTP 401 from plugin classpath version skew.\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "38d21532259a9d19f9539ee358ec5b4c732f42ee",
      "tree": "60915b24ad97ddee1db4d66177f912ff909a980e",
      "parents": [
        "9ab0069321b9630b82f333e76c4a47e8b726298c"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Mon Jun 15 12:21:17 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 12:21:17 2026 +0530"
      },
      "message": "RANGER-5647: Fix date-bound tag policy engine test fixtures (#1018)\n\n* RANGER-5647: Fix date-bound tag policy engine test fixtures\n\nRESTRICTED-FINAL deny-exception uses isAccessedBefore(activation_date).\nFixture dates were 2026/06/15, so TestPolicyEngine_hiveForTag_filebased\nfailed on/after that day. Use 2099/12/31 in tag test JSON so CI stays\nstable without changing policy semantics under test.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5647: Fix thread-unsafe dynamic path wildcard matching\n\nRecursiveWildcardResourceMatcher reused a shared wildcardPathElements\nfield when expanding {USER} tokens, causing intermittent deny results\nunder concurrent policy evaluation (e.g. hdfs_resourcespec in CI).\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "9ab0069321b9630b82f333e76c4a47e8b726298c",
      "tree": "fe463dbda82abb725ed466aab56ec1989f6ec8aa",
      "parents": [
        "5be05d8d9826baddc5eb1875a9c2cc4818499db9"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Mon Jun 15 11:43:10 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 11:43:10 2026 +0530"
      },
      "message": "RANGER-5645: Add audit-ingestor service-user allowlist for Docker plugins (#1017)\n\n* RANGER-5645: Add audit-ingestor service-user allowlist for Docker plugins\n\nShip per-repo allowed.users and auth_to_local rules so plugins using the\naudit-server destination are authorized after Kerberos SPNEGO (fixes HTTP 403).\nAlign create-ranger-services.py with policy.download.auth.users for Ozone,\nAtlas, Kudu, and NiFi. Add troubleshooting README for ingestor 403 errors.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Fix auth_to_local description; drop README files from PR\n\nConsolidate auth_to_local property description (JWT note + plugin rules).\nRevert audit-server/scripts/README.md and remove troubleshooting README.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: List auth_to_local rules in Default rules provided format\n\nMatch original site XML description style with one bullet per RULE line.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Limit scope to Docker services listed in Jira\n\nRemove dev_atlas, dev_kudu, and dev_nifi from ingestor allowlist,\nauth_to_local rules, and create-ranger-services.py (not in Docker stack).\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Add dev_elasticsearch for Docker OpenSearch stack\n\nCreate Policy Manager repo for the elasticsearch service type pointing at\nranger-opensearch.rangernw:9200 with opensearch download auth users, and\nadd matching ingestor allowlist plus auth_to_local rule.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Add dev_tag service and fix auth_to_local description\n\nCreate dev_tag in create-ranger-services.py (matches Policy Manager).\nAdd dev_tag ingestor allowlist (rangertagsync) and auth_to_local rule.\nUse CDATA so description shows \u003crepo\u003e instead of XML entities.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Add atlas/kudu/nifi; remove OpenSearch elasticsearch entries\n\nMatch Policy Manager repos (dev_atlas, dev_kudu, dev_nifi). Drop\ndev_elasticsearch allowlist, auth_to_local rules, and create-service entry.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Address PR review feedback on allowlist and Docker services\n\nRemove redundant auth_to_local plugin rules covered by DEFAULT, restrict Ozone to om-only, and drop tag/atlas/kudu/nifi from create-ranger-services.py per Docker stack scope.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Fix date-bound tag policy engine tests after 2026-06-15\n\nRESTRICTED-FINAL deny-exception uses isAccessedBefore(activation_date);\nfixture dates were 2026/06/15 so TestPolicyEngine_hiveForTag_filebased\nfailed on/after that day (unrelated to ingestor allowlist changes).\nUse 2099/12/31 in tag test fixtures so CI stays stable.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Run TestPolicyEngine sub-tests sequentially for CI stability\n\nparallelStream() on a shared RangerPolicyEngine caused intermittent\nfailures (e.g. hdfs_resourcespec {USER} path policy) under CI load.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5645: Address review feedback on allowlist scope and test changes\n\n- Remove dev_tag, dev_atlas, dev_kudu, dev_nifi allowlist entries (not\n  applicable to Docker audit-ingestor scope per review)\n- Revert agents-common test fixture and TestPolicyEngine changes; tag\n  date updates belong in separate RANGER-5647 PR\n- Restore parallelStream() in TestPolicyEngine per review\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "5be05d8d9826baddc5eb1875a9c2cc4818499db9",
      "tree": "a07f5c536407e2e0c72a624d04dc708a2229c5bd",
      "parents": [
        "b283bdad2a04c79e8e0925407a48ed70edc7b039"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Mon Jun 15 07:54:37 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 07:54:37 2026 +0530"
      },
      "message": "RANGER-5635: ranger.admin.allow.unauthenticated.download.access is honored only when Kerberos is enabled (#1011)"
    },
    {
      "commit": "b283bdad2a04c79e8e0925407a48ed70edc7b039",
      "tree": "64c476c68e2a42c2e4149281f19781ec69b0362a",
      "parents": [
        "ce93068d235425379b8a09cbd5b0085a45a035e3"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Sun Jun 14 22:05:07 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 13:05:07 2026 -0700"
      },
      "message": "Add THREAT_MODEL.md + AGENTS.md/SECURITY.md discoverability chain (#994)\n\nCo-authored-by: Abhishek Kumar \u003cabhi@apache.org\u003e"
    },
    {
      "commit": "ce93068d235425379b8a09cbd5b0085a45a035e3",
      "tree": "c2f57fb4b802213a269c48622dcd59c7323f9c53",
      "parents": [
        "10bda4d11e179b034819fb948fcc861a79def217"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Sun Jun 14 20:52:19 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 08:22:19 2026 -0700"
      },
      "message": "RANGER-5643: Fix docker Kerberos for Solr audit dispatcher (#1016)\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "10bda4d11e179b034819fb948fcc861a79def217",
      "tree": "f70cc18a9167da30c3a4d7059ae32ce52905185b",
      "parents": [
        "409e8a72cacbdf7d160d6ca508d7fb4770188a5f"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Sun Jun 14 13:31:24 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 13:31:24 2026 +0530"
      },
      "message": "RANGER-5642, RANGER-5644: Package Jersey auditserver REST client JARs in Kafka and HBase plugins (#1015)\n\n* RANGER-5642, RANGER-5644: Package Jersey auditserver REST client JARs in Kafka and HBase plugins\n\nWhitelist missing Glassfish Jersey dependencies in plugin assembly descriptors so\nauditserver destination can POST JSON audits without MessageBodyWriter errors.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5644: Align HBase plugin Jersey deps with HDFS/Hive for CI stability.\n\nOmit jersey-hk2 and javax.inject from the HBase plugin tarball; they crash\nHMaster in plugins-docker-build while entity-filtering and\njersey-media-json-jackson still fix auditserver MessageBodyWriter errors.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "409e8a72cacbdf7d160d6ca508d7fb4770188a5f",
      "tree": "b712e322c41e1cbab4cd9b4d6919ae300df388ba",
      "parents": [
        "09b5315646a105216604642ec11514b6651846b9"
      ],
      "author": {
        "name": "Dayakar M",
        "email": "daya.apache@gmail.com",
        "time": "Sat Jun 13 00:58:39 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 12 12:28:39 2026 -0700"
      },
      "message": "RANGER-5634: CTAS \u0026 Temporary-Table queries from Hive bypass UDF Select authorization (#1012)"
    },
    {
      "commit": "09b5315646a105216604642ec11514b6651846b9",
      "tree": "74b1b5cfd3d009c4ec5a68bbfd629786193a0b01",
      "parents": [
        "4a061759b417e23a9ea46564681fc384166dfe35"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Fri Jun 12 01:21:43 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 12:51:43 2026 -0700"
      },
      "message": "RANGER-5640: Bump Docker Ozone to 2.1 and package audit-server JARs in ozone plugin (#1007)\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "4a061759b417e23a9ea46564681fc384166dfe35",
      "tree": "456b933609bb051ccacc114c913f33d83b2d23c9",
      "parents": [
        "137a5dd4a8bb67db9c07e2fbd117864d282da414"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Thu Jun 11 20:53:32 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 20:53:32 2026 +0530"
      },
      "message": "RANGER-5633: Wire audit-server Kafka producer and consumer tuning (#1001)\n\n* RANGER-5633: Wire audit-server Kafka producer and consumer tuning\n\nWire ingestor producer properties from site XML, apply optional topic\nconfigs at create time, default dispatchers to CooperativeStickyAssignor,\nand add unit tests for producer config and topic config wiring.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5633: Wire audit-server Kafka producer and consumer tuning\n\n* RANGER-5633: Addressing Review comments\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "137a5dd4a8bb67db9c07e2fbd117864d282da414",
      "tree": "7cdfbdf4d95244aead39eb41f1a621f7247630b0",
      "parents": [
        "31c74699af1174b46949aa6103bc5a26953cfbe3"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Wed Jun 10 23:37:38 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 23:37:38 2026 +0530"
      },
      "message": "RANGER-5637: Fix Knox and Ozone plugin docker CI smoke-test failures (#1006)\n\n* RANGER-5637: Fix Knox and Ozone plugin docker CI smoke-test failures.\n\nUse Java 17 ozone-runner (20241022-jdk17-1) and container JAVA_HOME for\nplugin enable so XmlConfigChanger and RangerOzoneAuthorizer load correctly.\nStart OM after SCM and datanode to reduce startup-order flakes.\n\nPackage Jersey/HK2 and javax.inject in the Knox plugin tarball for\nauditserver destination after RANGER-5632, and tail gateway.log when\nthe Knox gateway fails to start in CI.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Fix Knox and Ozone Java 17 docker smoke-test startup.\n\nKnox 2.0.0 needs JDK 17 module exports for SSL keystore generation; Ozone SCM\nneeds -XX:-UseContainerSupport on GitHub Actions kernels with broken cgroup metrics.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Bump Knox to 2.1.0 and fix Ozone auditserver JAX-RS packaging.\n\nKnox 2.0.0 cannot generate gateway SSL certs on JDK 17 (md5WithRSAEncryption_oid\nremoved from AlgorithmId); 2.1.0 includes KNOX-2923 JDK 17 support. Whitelist\njavax.ws.rs-api in Knox and Ozone plugin assemblies for auditserver REST client.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Skip redundant Ozone re-downloads in plugin archive CI step.\n\nReplace unconditional rm -rf downloads/ozone-* with extractOzoneIfNeeded(), which\nre-extracts only when the tree is missing, incomplete, or older than the tarball.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Stabilize Ozone extract cache with tarball stamp file.\n\nUse .ozone-extract.stamp (mtime:size) instead of directory mtime so CI skips\nre-extraction on warm cache hits. Document extractOzoneIfNeeded in script and workflow.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Add HK2 javax.inject to Ozone plugin and wait for SCM leader.\n\nPackage org.glassfish.hk2.external:javax.inject for Jersey Singleton on the\nOzone plugin classpath. Wait for SCM client port before OM plugin enable to\nreduce ServerNotLeaderException flakes.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Package javax and jakarta inject in Ozone plugin tarball.\n\nDeclare javax.inject as a runtime dependency and include jakarta.inject in\nthe assembly so OM auditserver JAX-RS clients resolve HK2 inject APIs.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Use multi-arch ozone-runner 20241108-jdk17-1.\n\n20241022-jdk17-1 is amd64-only; 20241108-jdk17-1 adds arm64 for Apple Silicon\nwithout QEMU emulation. Document the choice in .env and Dockerfile.ranger-ozone.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "31c74699af1174b46949aa6103bc5a26953cfbe3",
      "tree": "a3095423d9fb4f16875f547a31788a42c015a6ca",
      "parents": [
        "f2cec6eaf6333745917d8ed212dc1d0433b9de44"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Wed Jun 10 11:18:42 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 11:18:42 2026 +0530"
      },
      "message": "RANGER-5614 : Performance improvement for role create/update with many users, groups, and sub-roles (#980)\n\n* RANGER-5614:Role creation/updation takes more time when there are more users,groups,roles\nation/updation takes more time when there are more users,groups,roles\n\n* Fixing copilot review comments\n\n* RANGER-5614: Cache policy existence in PolicyRefUpdater\n\nResolve policyExists once via getById before principal loops to avoid\nN+1 DB lookups when building policy ref rows for large policies.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5614: Address PR #980 review feedback on RoleStore API and ref updaters.\n\nRestore backward-compatible RoleStore signatures with default cleanup overloads, use getCountById for policy existence checks, and avoid redundant principal resolution during ref-table updates.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5614 : fixing Checkstyle comments\n\n* Bundle Solr audit destination in PDP distribution tarball.\n\nInclude ranger-audit-dest-solr and its HTTP async client dependencies so\nPDP startup succeeds when Solr audit is enabled in Docker/CI.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* Fixing CI build issues\n\n* Fix sortpom order for javax.inject in pdp/pom.xml.\n\nPlace the dependency before javax.validation so sortpom:verify passes in CI.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Split plugin archive downloads to fix plugins-docker-build CI timeouts.\n\nRun Hadoop/Hive/HBase/Kafka/Knox/Ozone distro downloads in a dedicated\nplugins-download-archives job (120m, parallel with build-17) so slow\narchive.apache.org mirrors no longer consume the docker-build budget.\nAdd curl retries in download-archives.sh for transient download failures.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Tune download-archives curl retries and document flags.\n\nReduce --retry to 3 and add a brief comment explaining CI mirror\nresilience options on archive.apache.org downloads.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5637: Use auditserver destination for Docker PDP audits.\n\nRevert ranger-audit-dest-solr from the PDP distribution per RANGER-5632\nand PR #980 review feedback. Update ranger-pdp-site.xml to send audits to\nthe audit ingestor instead of Solr so services-docker-build does not require\nSolr audit destination jars at runtime.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "f2cec6eaf6333745917d8ed212dc1d0433b9de44",
      "tree": "b15fd1eacb69e7a3b83bdf7d4582b7098e62046e",
      "parents": [
        "f4edfa620f2813d8ed86228ce927cf9513c0a18c"
      ],
      "author": {
        "name": "Aurélien Pupier",
        "email": "apupier@ibm.com",
        "time": "Tue Jun 09 21:51:37 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 12:51:37 2026 -0700"
      },
      "message": "RANGER-5636: Configure GitHub workflows to use concurrency (#1003)"
    },
    {
      "commit": "f4edfa620f2813d8ed86228ce927cf9513c0a18c",
      "tree": "d9ff091358aa2ff085d1b8343db672c6e1cc918e",
      "parents": [
        "d000d3e7ee5ed4954e7d45de735f01bcc51bc8af"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 09 14:49:25 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 14:49:25 2026 +0530"
      },
      "message": "RANGER-5627: Support configuration-based super users and super groups in Ranger Admin (#1000)\n\n* RANGER-5627:https://issues.apache.org/jira/browse/RANGER-5627\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Address PR review comments\n\nRename configSuperUser to superUser, simplify role getters via OR with\nsuperUser flag, refactor hasKMSPermissions, and update config descriptions\nper PR #1000 review feedback.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Address PR review comments\n\n* RANGER-5627: Address latest PR #1000 review comments\n\nCache super-user config in RangerSuperUserConfig, use a single DAO query\nfor getGroupsForUser(), optimize group lookup in SessionMgr/UserMgr/\nRangerBizUtil, and align RoleDBStore formatting with review feedback.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Address latest PR #1000 review comments\n\n* RANGER-5627: Fix missing Collections import in TestXUserMgr.\n\nFixes CI testCompile failure in testGetGroupsForUserFromDao.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Fix flaky RangerJSONAuditWriterTest rollover test.\n\nUse doThrow on spy getLogFileStream and synchronize the exception\nassertion block to avoid races with the periodic rollover background task.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Filter blank super-user config and harden CI npm step.\n\nSkip whitespace-only entries when parsing super.users/super.groups so\nisEnabled() stays false for blank-only config. Reload the config singleton\nin testIsSuperGroupsConfigured after changing properties. Clear npm cache\nbefore Maven verify in the CI workflow.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Fix security-admin tests for super-user API changes.\n\nAlign auth filter, XUserREST, and getGroupsForUser tests with\ngetAuthenticationRolesByLoginId, DAO-based group lookup, and session\nuserRoleList used by isSingleRoleUserSession().\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Fix TestGdsREST Mockito wiring for exception tests.\n\nRemove duplicate @InjectMocks GdsDBStore that shadowed the gdsStore mock\non GdsREST, use thenThrow for createRESTException stubs, and construct\nGdsDBStore locally for validity-period filter tests.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* RANGER-5627: Fix TestServiceREST ROLE_USER session role setup.\n\nSet userRoleList on the mocked session so isSingleRoleUserSession() applies service detail masking in tests.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* Update SessionMgr.java\n\n* Update UserMgr.java\n\n* Update XUserMgr.java\n\n* Update AssetREST.java\n\n* Update RoleREST.java\n\n* RANGER-5627: Fix admin tarball swagger.json alias assembly path.\n\nUse project.parent.basedir instead of undefined ranger.root so maven-assembly-plugin resolves openapi.json for the swagger.json alias.\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\n\n* Update XUserREST.java\n\n* RANGER-5627: Address latest PR #1000 review comments\n\n* Update RangerBizUtil.java\n\n* Update RangerSuperUserConfig.java\n\n---------\n\nCo-authored-by: ramk \u003cramk@cloudera.com\u003e\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "d000d3e7ee5ed4954e7d45de735f01bcc51bc8af",
      "tree": "6d22296b2e6e013bd46581e011da4cd9c8602c3f",
      "parents": [
        "7685006a48b5d2358802bb0542b0091a84f23c8d"
      ],
      "author": {
        "name": "dhavalshah9131",
        "email": "dhavalshah9131@gmail.com",
        "time": "Tue Jun 09 12:22:38 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 12:22:38 2026 +0530"
      },
      "message": "RANGER-5611 : Support TLSv1.3 Encryption for all Communications for R… (#964)\n\nCo-authored-by: Dhaval Shah \u003cdhavalshah9131@@gmail.com\u003e"
    },
    {
      "commit": "7685006a48b5d2358802bb0542b0091a84f23c8d",
      "tree": "047bf1cc0925cd4968fb055c251bae938aa3f0fd",
      "parents": [
        "96282864f0d3c783459e9ca8a7d9330482e6ecf9"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 09 10:26:15 2026 +0530"
      },
      "committer": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 09 10:26:15 2026 +0530"
      },
      "message": "Revert: Change OZONE_RUNNER_VERSION back to 20230615-1\n\nThe Java 17 tagged version (20230615-1-java17) does not exist in the Docker registry, causing build failures.\nReverting to the working version 20230615-1."
    },
    {
      "commit": "96282864f0d3c783459e9ca8a7d9330482e6ecf9",
      "tree": "a85dc459f5f4bd1e3559023af289bbad6e067f14",
      "parents": [
        "e3babee053acc2fabe060ec75172659e1eebb315"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 09 09:07:56 2026 +0530"
      },
      "committer": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Tue Jun 09 09:07:56 2026 +0530"
      },
      "message": "Fix: Update Ozone Runner image to use Java 17 to match Ranger build\n\nThe Ranger project is built with Java 17, but the Ozone runner container was using Java 11, \ncausing UnsupportedClassVersionError when loading Ranger Ozone authorizer classes \n(compiled for class file version 61.0 requires Java 17, not 55.0 which is Java 11).\n\nUpdate OZONE_RUNNER_VERSION to use the Java 17 tagged version to ensure compatibility."
    },
    {
      "commit": "e3babee053acc2fabe060ec75172659e1eebb315",
      "tree": "fe3fd1bcfd0035b31f7d46e74c084c1a349f8cc3",
      "parents": [
        "deda4f54432fae200174734f9e6cf657d07c0732"
      ],
      "author": {
        "name": "Madhan Neethiraj",
        "email": "madhan@apache.org",
        "time": "Mon Jun 08 11:25:43 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 11:25:43 2026 -0700"
      },
      "message": "RANGER-5632: update plugins packaging to have audit-server as the only audit destination (#999)"
    },
    {
      "commit": "deda4f54432fae200174734f9e6cf657d07c0732",
      "tree": "8e8d7543cca7e18ac922603f9b02abf68efacb62",
      "parents": [
        "c32fb42dc19316264d0378ca8654e3a9c1bdacbb"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Mon Jun 08 14:33:22 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 14:33:22 2026 +0530"
      },
      "message": "RANGER-5604: Bump org.glassfish.jersey.core:jersey-client from 2.22.1 to 2.46 in /plugin-schema-registry (#955)\n\nCo-authored-by: sanket-shelar \u003csanket.shelar.dev@gmail.com\u003e"
    },
    {
      "commit": "c32fb42dc19316264d0378ca8654e3a9c1bdacbb",
      "tree": "1167113d430c9ea4682b82a03ddebddeabe5d451",
      "parents": [
        "2eca8b764c731950acbe8755a8cc1d8cac55dd95"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Sat Jun 06 00:24:42 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 06 00:24:42 2026 +0530"
      },
      "message": "RANGER-5609 : Updating library dependencies in Ranger Admin React package-lock.json (#996)"
    },
    {
      "commit": "2eca8b764c731950acbe8755a8cc1d8cac55dd95",
      "tree": "5d808505d5cde79298d13269e953941ad168d8be",
      "parents": [
        "b1db293edc8fcf005befcb25c50d689fc71df2ec"
      ],
      "author": {
        "name": "Bhaavesh Amol Amre",
        "email": "amrebhaveshtrade@gmail.com",
        "time": "Fri Jun 05 15:44:12 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 05 15:44:12 2026 +0530"
      },
      "message": "RANGER-5630:Swagger UI requests non-existent swagger.json instead of generated openapi.json (#998)"
    },
    {
      "commit": "b1db293edc8fcf005befcb25c50d689fc71df2ec",
      "tree": "a831b2c5c050a6fa85c134cd0ed520b0ee51fd22",
      "parents": [
        "5ebc3a0eaf0d7cf4f2bf0208754a2fe4ab363365"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Fri Jun 05 11:43:09 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 05 11:43:09 2026 +0530"
      },
      "message": "RANGER-5601: Bump urllib3 to 2.7.0 and requests from 2.32.5 to 2.33.0 (#954)\n\nCo-authored-by: sanket-shelar \u003csanket.shelar.dev@gmail.com\u003e"
    },
    {
      "commit": "5ebc3a0eaf0d7cf4f2bf0208754a2fe4ab363365",
      "tree": "92e7293a341b7571e050be9fa61e0b040421ac18",
      "parents": [
        "03e42b664f2ede787095412848dfcff0658ae79d"
      ],
      "author": {
        "name": "Dineshkumar Yadav",
        "email": "59435896+dineshkumar-yadav@users.noreply.github.com",
        "time": "Wed Jun 03 15:12:31 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 03 15:12:31 2026 +0530"
      },
      "message": "RANGER-5622 : Ranger: Upgrade Tomcat version to 9.0.118 (#990)"
    },
    {
      "commit": "03e42b664f2ede787095412848dfcff0658ae79d",
      "tree": "cc60947a6dde79807150164da322362962aa9501",
      "parents": [
        "ad01e93aa2e3e5e2e2eaadd35dda0e8a930908b5"
      ],
      "author": {
        "name": "KRISHNA CHAITANYA MUTTEVI",
        "email": "130595906+krishnamuttevi@users.noreply.github.com",
        "time": "Tue Jun 02 19:32:22 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 19:32:22 2026 +0530"
      },
      "message": "RANGER-5625: User Sync UI fails to render when POST /xusers/ugsync/auditinfo returns invalid \"null\" strings for syncTime and lastModified (#991)\n\n* RANGER-5625: Updated Java files for User Sync UI fix\n\n* RANGER-5625: Resolved the checkstyle error"
    },
    {
      "commit": "ad01e93aa2e3e5e2e2eaadd35dda0e8a930908b5",
      "tree": "c89426ef3e64e21a959e122a818e50b9b9c340e6",
      "parents": [
        "a372412ebb18397b15ed1393f7d23d44735e4c47"
      ],
      "author": {
        "name": "abhiishek26",
        "email": "abhisinghbest53@gmail.com",
        "time": "Tue Jun 02 19:25:51 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 19:25:51 2026 +0530"
      },
      "message": "RANGER-5607 issue in  put plugins/services/id (#984)\n\n* updated updateService in ServiceREST to aviod id mismatch issue\n\n* merge conflict resolved"
    },
    {
      "commit": "a372412ebb18397b15ed1393f7d23d44735e4c47",
      "tree": "de542d2720d925db8ffb99b24e53d2063657eeda",
      "parents": [
        "425605142d4800bc2cdfb72ff653c838b900f76f"
      ],
      "author": {
        "name": "Vyom Mani Tiwari",
        "email": "vyommani@gmail.com",
        "time": "Tue Jun 02 14:18:01 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 14:18:01 2026 +0530"
      },
      "message": "RANGER-5602: Local build failure due to unit test failure in TestPolicyACLs (#950)\n\n* RANGER-5602: Local build failure due to unit test failure in TestPolicyACLs\n\n* RANGER-5602: incorporated review comments"
    },
    {
      "commit": "425605142d4800bc2cdfb72ff653c838b900f76f",
      "tree": "f7ef6b65973e899e9a682d90ab21afc0d6cf4ace",
      "parents": [
        "faf38c21df857eb7d661346e4e50a399dcff53cd"
      ],
      "author": {
        "name": "Chinmay Hegde",
        "email": "hegdechinmay24@gmail.com",
        "time": "Mon Jun 01 20:46:07 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 20:46:07 2026 +0530"
      },
      "message": "RANGER-5588: Removed jwt cookie support from JWT files (#949)"
    },
    {
      "commit": "faf38c21df857eb7d661346e4e50a399dcff53cd",
      "tree": "6fda790e3d5a48dd1a17d658cabc99537c6e3bd4",
      "parents": [
        "12dfeb151bf2fe70ea83de92a07165262888dbd4"
      ],
      "author": {
        "name": "abhiishek26",
        "email": "abhisinghbest53@gmail.com",
        "time": "Mon Jun 01 18:29:07 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 18:29:07 2026 +0530"
      },
      "message": "RANGER-5587: modified \u0026\u0026 condition to OR to resolve the issue of definition id"
    },
    {
      "commit": "12dfeb151bf2fe70ea83de92a07165262888dbd4",
      "tree": "f044b9f7b2c611174ac249ee981b0828d84bbec0",
      "parents": [
        "58f2b149db9a621acdd2a0def26ca66a85ee69cd"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Mon Jun 01 02:28:58 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 14:58:58 2026 +0530"
      },
      "message": "RANGER-5621: Fix CI build-17 timeout due to oversized schema-registry plugin assembly (#989)"
    },
    {
      "commit": "58f2b149db9a621acdd2a0def26ca66a85ee69cd",
      "tree": "1182eed40c2e2f71a150da73d9f6319fd0b3203c",
      "parents": [
        "6172884652e02a209b01d4798506fbc45701786e"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Sun May 31 21:04:49 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 31 21:04:49 2026 -0700"
      },
      "message": "RANGER-5617: Set PDP header authn config values to null (#985)"
    },
    {
      "commit": "6172884652e02a209b01d4798506fbc45701786e",
      "tree": "f590e85821ddb3767a868023d38d3effc3006811",
      "parents": [
        "c5b55a45e7215579367bc0e97695060c62d9268b"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@apache.org",
        "time": "Thu May 28 18:27:50 2026 -0700"
      },
      "committer": {
        "name": "Ramesh Mani",
        "email": "rmani@apache.org",
        "time": "Thu May 28 18:27:50 2026 -0700"
      },
      "message": "Revert \"RANGER-5610:getResourceACLs for a principal should consider validitySchedule of principal for ACL creation (#982)\"\n\nThis reverts commit c5b55a45e7215579367bc0e97695060c62d9268b.\n"
    },
    {
      "commit": "c5b55a45e7215579367bc0e97695060c62d9268b",
      "tree": "7033930a7e47588ca38a43ecefe9f2af57cd8718",
      "parents": [
        "d319fb99b89fe1035b1a09626b7c5fe9e1ea8756"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@cloudera.com",
        "time": "Thu May 28 08:10:37 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 28 08:10:37 2026 -0700"
      },
      "message": "RANGER-5610:getResourceACLs for a principal should consider validitySchedule of principal for ACL creation (#982)\n\nCo-authored-by: Ramesh Mani \u003crmani@apache.org\u003e"
    },
    {
      "commit": "d319fb99b89fe1035b1a09626b7c5fe9e1ea8756",
      "tree": "f590e85821ddb3767a868023d38d3effc3006811",
      "parents": [
        "d2cd9ea75820df7ea219a7fefc7d3cb78a70a4e8"
      ],
      "author": {
        "name": "PradeeP AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Thu May 28 08:43:00 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 28 08:43:00 2026 +0530"
      },
      "message": "RANGER-5603: Docker setup updated to use Solr 9.4.1 (#981)\n\n* RANGER-5603: Docker setup updated to use Solr 9.4.1\n\n* RANGER-5603: Solr 9 Docker Kerberos keytabs, audit core mounts, Admin FQDN audit URL\n\n---------\n\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "d2cd9ea75820df7ea219a7fefc7d3cb78a70a4e8",
      "tree": "8e4128913c5e32746d67fe7115fa18f81edf12a5",
      "parents": [
        "e3ab2b33414c0bd021a547b34d5eb2bd3ae255f8"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@cloudera.com",
        "time": "Wed May 27 15:28:20 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 15:28:20 2026 -0700"
      },
      "message": "RANGER-5483:Add Audit Server as a destination for all the Ranger Plugins available (#969)\n\n* RANGER-5483:Add Audit Server as a destination for all the Ranger Plugins available\n\n* RANGER-5483:Add Audit Server as a destination for all the Ranger Plugins available - addressed review comments\n\n---------\n\nCo-authored-by: Ramesh Mani \u003crmani@apache.org\u003e"
    },
    {
      "commit": "e3ab2b33414c0bd021a547b34d5eb2bd3ae255f8",
      "tree": "a517c20d651034a77844084155efd99a81042519",
      "parents": [
        "1e1f91b966e2923bba04c375fd5d23759d8f03ad"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@cloudera.com",
        "time": "Wed May 27 13:53:06 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 13:53:06 2026 -0700"
      },
      "message": "RANGER-5613:DockerFile of Ranger Audit Server has issue duplicate tools sets which are already in Ranger Base image (#971)\n\n* RANGER-5613:DockerFile of Ranger Audit Server has issue duplicate tools sets which are already in Ranger Base image\n\n* RANGER-5613:DockerFile of Ranger Audit Server has issue duplicate tools sets which are already in Ranger Base image - Review Comment addressed\n\n---------\n\nCo-authored-by: Ramesh Mani \u003crmani@apache.org\u003e"
    },
    {
      "commit": "1e1f91b966e2923bba04c375fd5d23759d8f03ad",
      "tree": "5a5bbdac0d1fca7a45de00417fcbd4d350510c23",
      "parents": [
        "d1589d629d0b9b27d4e2130c17d807998a22ba97"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed May 27 17:08:37 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 17:08:37 2026 +0530"
      },
      "message": "RANGER-5600 : Bump org.apache.avro:avro in /plugin-schema-registry (#854)\n\nBumps org.apache.avro:avro from 1.11.4 to 1.11.5.\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.avro:avro\n  dependency-version: 1.11.5\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d1589d629d0b9b27d4e2130c17d807998a22ba97",
      "tree": "74bfde34fba822c47f422577dc277341093182e7",
      "parents": [
        "0289554dd1e81c4b6cb86c78282bb7bd9dd5257e"
      ],
      "author": {
        "name": "Ramachandran Krishnan",
        "email": "ramackri@gmail.com",
        "time": "Mon May 25 03:49:19 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 24 15:19:19 2026 -0700"
      },
      "message": "RANGER-3899: performance improvement in create/update of policies referencing large number of users/groups/roles (#962)\n\nCo-authored-by: Cursor \u003ccursoragent@cursor.com\u003e"
    },
    {
      "commit": "0289554dd1e81c4b6cb86c78282bb7bd9dd5257e",
      "tree": "ff48dc799bbda351632c31798cb8d941fc65a45b",
      "parents": [
        "1b74f00d9b6357e0ee4c7c64de73aa938f2c0a0b"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Sun May 24 08:00:18 2026 -0700"
      },
      "committer": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Sun May 24 08:00:18 2026 -0700"
      },
      "message": "RANGER-5499: fix checkstyle errors\n"
    },
    {
      "commit": "1b74f00d9b6357e0ee4c7c64de73aa938f2c0a0b",
      "tree": "2b73f9fce196f5f9313787cbf4e27993c78618e1",
      "parents": [
        "b8ba34cac137f2cedc5ced7b281c81f387e26c69"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Sun May 24 07:44:56 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 24 07:44:56 2026 -0700"
      },
      "message": "RANGER-5499: Set ranger-admin header authn cfg values to null (#968)"
    },
    {
      "commit": "b8ba34cac137f2cedc5ced7b281c81f387e26c69",
      "tree": "bc3210c597f07bb9e3294bc66dc6c29c92022596",
      "parents": [
        "f307c31bce77eed701964c67405bf1ba0795d207"
      ],
      "author": {
        "name": "Dhaval Rajpara",
        "email": "dhavalrajpara1304@gmail.com",
        "time": "Sat May 23 07:12:50 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 23 07:12:50 2026 +0530"
      },
      "message": "RANGER-5569 : Updating library dependencies in Ranger Admin React package-lock.json."
    },
    {
      "commit": "f307c31bce77eed701964c67405bf1ba0795d207",
      "tree": "ce5ddbddce579db44b247b1c1bc2e32e46a54294",
      "parents": [
        "13f31dbaa1efce65c9abad75638d1bd104bb9136"
      ],
      "author": {
        "name": "Dineshkumar Yadav",
        "email": "59435896+dineshkumar-yadav@users.noreply.github.com",
        "time": "Fri May 22 20:59:49 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 20:59:49 2026 +0530"
      },
      "message": "RANGER-5605 : Fix Ranger build failure when triggered through Docker (#960)"
    },
    {
      "commit": "13f31dbaa1efce65c9abad75638d1bd104bb9136",
      "tree": "893249f815df0bb40b614d47dc1057ae4592979b",
      "parents": [
        "3eb661c27c306cd612960ed82ecfdc4238001f0e"
      ],
      "author": {
        "name": "Mahesh Bandal",
        "email": "maheshbandal@apache.org",
        "time": "Fri May 22 18:36:17 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 18:36:17 2026 +0530"
      },
      "message": "RANGER-5592: [GDS] Validity Period is not working for dataset policy (#945)\n\n* RANGER-5592: [GDS] Validity Period is not working for dataset policy\n\n* RANGER-5592: [GDS] Validity Period is not working for dataset policy"
    },
    {
      "commit": "3eb661c27c306cd612960ed82ecfdc4238001f0e",
      "tree": "5d858822350d749da064c7878e8f94f1e05a1fcd",
      "parents": [
        "3fd46dbef840ba8c9490f0e85777a1fd6c272816"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@cloudera.com",
        "time": "Mon May 18 08:59:55 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 18 08:59:55 2026 -0700"
      },
      "message": "RANGER-5598:RangerHiveAuthorizer showprivileges should consider principal expiry condition in the GDS grants (#947)\n\nCo-authored-by: Ramesh Mani \u003crmani@apache.org\u003e"
    },
    {
      "commit": "3fd46dbef840ba8c9490f0e85777a1fd6c272816",
      "tree": "6ba76aa8a7d13b31c5abf2c425e0e9741cb5fa78",
      "parents": [
        "6bf21ea62902408b6d6ee0cbda2ded9ed70d48cb"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@cloudera.com",
        "time": "Sun May 10 01:07:46 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 10 01:07:46 2026 -0700"
      },
      "message": "RANGER-5520:Audit Server refactoring to segregate audit ingestion and… (#886)\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - copilot review comment fix\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - Fix review comments\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality -Fix review comments -set #2\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality -Fix review comments - set #3\n\n* addressed review suggestions\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - Fix review comments #4 - remove audit dispatcher registry\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - Fix merge conflit\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - fix dispatcher issue with handling failed audits\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - fix review comments #5\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality -fix review comments\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - Fix review comments on docker file separation for ingestor and dispatchers\n\n* RANGER-5520:Audit Server refactoring to segregate audit ingestion and dispatching functionality - Fixed review comment on docker file\n\n---------\n\nCo-authored-by: Ramesh Mani \u003crmani@apache.org\u003e\nCo-authored-by: Madhan Neethiraj \u003cmadhan@apache.org\u003e"
    },
    {
      "commit": "6bf21ea62902408b6d6ee0cbda2ded9ed70d48cb",
      "tree": "8465f0c67ead3a7d0cffe77fe9fd6f53c0fe3ecf",
      "parents": [
        "0b782da6724a004b4c2b5b441520b08845fdde65"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Fri May 08 17:20:46 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 08 17:20:46 2026 -0700"
      },
      "message": "RANGER-5582: Add PDP Service to docker build in CI setup (#937)"
    },
    {
      "commit": "0b782da6724a004b4c2b5b441520b08845fdde65",
      "tree": "02ba771c547c6251cc3e3570a5724d0b6dbc8f07",
      "parents": [
        "ba978cfa5290471cb91ca0798745b5c96a234cf1"
      ],
      "author": {
        "name": "Ramesh Mani",
        "email": "rmani@cloudera.com",
        "time": "Fri May 08 16:49:16 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 08 16:49:16 2026 -0700"
      },
      "message": "RANGER-5577:API to support bulk delete of resources in DataShare (#936)\n\n* RANGER-5577:API to support bulk delete of resources in DataShare\n\n* RANGER-5577:API to support bulk delete of resources in DataShare - Fixed review comments\n\n---------\n\nCo-authored-by: Ramesh Mani \u003crmani@apache.org\u003e"
    },
    {
      "commit": "ba978cfa5290471cb91ca0798745b5c96a234cf1",
      "tree": "e125670ae8046251788fc7e22047fd4dbf7da709",
      "parents": [
        "21520b7ae55ef12b2adb21c4ec74f9317d89d59f"
      ],
      "author": {
        "name": "Abhishek Kumar",
        "email": "abhi@apache.org",
        "time": "Thu May 07 18:41:20 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 07 18:41:20 2026 -0700"
      },
      "message": "RANGER-5583: Fix Ranger PDP installation in docker (#934)"
    },
    {
      "commit": "21520b7ae55ef12b2adb21c4ec74f9317d89d59f",
      "tree": "5fdba0ab059ac62f62e8d079aaf293a82ab5846c",
      "parents": [
        "1116eff053c14ef0508e81023149aa32a404f28a"
      ],
      "author": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Mon Apr 27 13:00:47 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Mon May 04 08:43:30 2026 +0530"
      },
      "message": "RANGER-4076: PMD issue fix\n"
    },
    {
      "commit": "1116eff053c14ef0508e81023149aa32a404f28a",
      "tree": "a2145ab964ca7ef4d09f606d3d3ec44557bcbcab",
      "parents": [
        "b9ca02c893807001d773d50229820e9830625bbf"
      ],
      "author": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Thu Apr 23 14:33:48 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Mon May 04 08:43:07 2026 +0530"
      },
      "message": "RANGER-4076: Addressed review comment of Vyom\n"
    },
    {
      "commit": "b9ca02c893807001d773d50229820e9830625bbf",
      "tree": "458014915ff54521c464f94a1fd41e2f17961d21",
      "parents": [
        "f1d05eaad8d61a7d64f58c2b267d4c732de37fe6"
      ],
      "author": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Wed Apr 22 11:00:01 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 13:08:20 2026 +0530"
      },
      "message": "RANGER-4076: Addressed review comment of copilot\n"
    },
    {
      "commit": "f1d05eaad8d61a7d64f58c2b267d4c732de37fe6",
      "tree": "fe3d0b4cd2f6ba3026af14a57161a6a391df422d",
      "parents": [
        "f40a3b003c5f89eab17ee16dbc7f83474b48dc1b"
      ],
      "author": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sat Apr 18 16:38:33 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 13:08:20 2026 +0530"
      },
      "message": "RANGER-5560: mockito upgrade to 5\n"
    },
    {
      "commit": "f40a3b003c5f89eab17ee16dbc7f83474b48dc1b",
      "tree": "8c1cfe5c7083b14c23b2756a257a066bb1551bb3",
      "parents": [
        "4b3d483a2ecb65b1afcad9ce24d0b66aa2648352"
      ],
      "author": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Mon Jan 05 10:23:19 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 13:08:14 2026 +0530"
      },
      "message": "RANGER-4076: Migrate from com.sun.jersey 1.x to glassfish jersey 2.x\n"
    },
    {
      "commit": "4b3d483a2ecb65b1afcad9ce24d0b66aa2648352",
      "tree": "5855cd5c8fd01bbb4fd068cf27a2a568e6ccbd4c",
      "parents": [
        "f0cc2a99fb64f1485c6bc441a3dea522c7af8ca8"
      ],
      "author": {
        "name": "Rakesh Gupta",
        "email": "rakesh.gupta.dev264@gmail.com",
        "time": "Thu Mar 26 15:16:33 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 12:54:00 2026 +0530"
      },
      "message": "RANGER-4076: Docker changes for ranger-plugin-enforcement\n"
    },
    {
      "commit": "f0cc2a99fb64f1485c6bc441a3dea522c7af8ca8",
      "tree": "c15babbd1684e23fce7b05400a316fd1f7968d87",
      "parents": [
        "037ed6d7773963036b7f4dbed4c701f1d37cdd5a"
      ],
      "author": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Wed Apr 01 23:53:33 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 12:54:00 2026 +0530"
      },
      "message": "RANGER-4076: Remove JDK8/JDK11 support and Add JDK17 build support\n"
    },
    {
      "commit": "037ed6d7773963036b7f4dbed4c701f1d37cdd5a",
      "tree": "002ab45317a0f7ac22d5fd4eb82d71bc4e37845f",
      "parents": [
        "f5fddbe02347778006dd09817734899d86bed52e"
      ],
      "author": {
        "name": "bhaavesh1567",
        "email": "amrebhaveshtrade@gmail.com",
        "time": "Wed Mar 04 19:07:35 2026 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 12:54:00 2026 +0530"
      },
      "message": "RANGER-4076: Fix tagsync issues for the docker\n"
    },
    {
      "commit": "f5fddbe02347778006dd09817734899d86bed52e",
      "tree": "95395632ed4bf2a3b2689f1fb24b20c91beff5ab",
      "parents": [
        "1ea1bf4f0de42fe2adf0320bb9edb48a3f953d3b"
      ],
      "author": {
        "name": "Kishor Gollapalliwar",
        "email": "kishor.gollapalliwar@gmail.com",
        "time": "Mon Dec 22 20:17:09 2025 +0530"
      },
      "committer": {
        "name": "Pradeep AgrawaL",
        "email": "pradeep@apache.org",
        "time": "Sun May 03 12:54:00 2026 +0530"
      },
      "message": "RANGER-4076: Document update for required environment variable\n"
    }
  ],
  "next": "1ea1bf4f0de42fe2adf0320bb9edb48a3f953d3b"
}
