)]}'
{
  "log": [
    {
      "commit": "a42b18b9a93865ed796c4494133c77108fce98b4",
      "tree": "726d6c5eb8dfe3844971d0e3bbdb7b0b82040ba7",
      "parents": [
        "c2def39207a73394420088da9b4b105571dd9036"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 12 15:59:06 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 12 15:59:06 2026 -0400"
      },
      "message": "Bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.2 (#3697)\n\n* Bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.1\n\nBumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.13.0 to 1.14.1.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e...ba38be9e461d3875417946c167d0b5f3d385a247)\n\n---\nupdated-dependencies:\n- dependency-name: pypa/gh-action-pypi-publish\n  dependency-version: 1.14.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\n\n* Bump pypa/gh-action-pypi-publish to 1.14.2\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n\n---------\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nCo-authored-by: Dmytro Shteflyuk \u003ckpumuk@kpumuk.info\u003e\nCo-authored-by: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e"
    },
    {
      "commit": "c2def39207a73394420088da9b4b105571dd9036",
      "tree": "b949c0200e0421df4ded00aa6e62642b624b004d",
      "parents": [
        "8e6393a55d1e4f21319b97017ed7348da326c5c1"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:35:06 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 12 08:48:59 2026 -0400"
      },
      "message": "THRIFT-6138: Give memory buffers private ownership\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "8e6393a55d1e4f21319b97017ed7348da326c5c1",
      "tree": "31d7a9da6a2857a39b0593aa3a09933c2b5eb037",
      "parents": [
        "30f14372c9442c6721bb53e15e6f954e12af68d9"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 05 09:17:10 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 12 06:56:50 2026 -0400"
      },
      "message": "THRIFT-6142: Enforce Ruby unframed HeaderTransport limits\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "30f14372c9442c6721bb53e15e6f954e12af68d9",
      "tree": "d5ae06a30e9f7572179133db11960395aac2aa5d",
      "parents": [
        "349c5f6afd9616c9f3484839c8328c4501df32f3"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Aug 08 16:13:00 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Aug 11 12:44:51 2026 -0400"
      },
      "message": "Update Apache Thrift DOAP metadata [skip ci]\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "349c5f6afd9616c9f3484839c8328c4501df32f3",
      "tree": "ba7eedd6690dea073e896957c45e26b4213b59da",
      "parents": [
        "9c08ae7ebaee0f4a1a810a338e012ec03a007898"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 18:02:22 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Aug 08 16:56:20 2026 -0400"
      },
      "message": "THRIFT-6139: Validate Ruby CompactProtocol integer ranges\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "9c08ae7ebaee0f4a1a810a338e012ec03a007898",
      "tree": "82d40fb02a2b00dff331c1f9e9d2bbed1451b6b9",
      "parents": [
        "d00a0a12cd8662118847c22a92ec42337a4e53ad"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 05 09:12:16 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Aug 08 09:29:04 2026 -0400"
      },
      "message": "THRIFT-6140: Reject malformed short JSON UUID values\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "d00a0a12cd8662118847c22a92ec42337a4e53ad",
      "tree": "d882a6f6dab5b8a2dcc34c67000391532e609735",
      "parents": [
        "a9663bc6661a5dd1d99d629e1f269c1907592a1a"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 05 09:14:49 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 05 16:08:25 2026 -0400"
      },
      "message": "THRIFT-6141: Adapt invalid Ruby Header ZLIB payloads\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "a9663bc6661a5dd1d99d629e1f269c1907592a1a",
      "tree": "0db7d43b76fb3b5ebe077246b814f37a7c87f190",
      "parents": [
        "e4473c9e296b79003ca04128612e7b6a846a6552"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:31:30 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Aug 05 07:31:01 2026 -0400"
      },
      "message": "THRIFT-6137: Reject incomplete Ruby HeaderTransport frames\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "e4473c9e296b79003ca04128612e7b6a846a6552",
      "tree": "1d5443314ebbd51486a707263cb18094a50976b4",
      "parents": [
        "23d88446d30fbfef7027c62685664a70b6aef37d"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:21:35 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Aug 04 20:27:51 2026 -0400"
      },
      "message": "THRIFT-6127: Close Ruby sockets after I/O timeouts\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "23d88446d30fbfef7027c62685664a70b6aef37d",
      "tree": "8c8ff33d52f26cd22fdd2c46d48c717e821803d1",
      "parents": [
        "c3fe669d27c68425431ba4fb236a1529f0cc3b3c"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Aug 03 10:04:43 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Aug 04 20:21:23 2026 -0400"
      },
      "message": "THRIFT-6136: Handle Ruby container size conversion errors\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "c3fe669d27c68425431ba4fb236a1529f0cc3b3c",
      "tree": "deb66c2f4ccf4a4cec680175c9793f6b685ce09f",
      "parents": [
        "fb564f8ce169e84978c37a4d63565e5cd9e1ed0b"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Fri Jul 31 17:37:17 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Aug 04 20:19:57 2026 -0400"
      },
      "message": "THRIFT-6045: Add Ruby recursion depth limit\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "fb564f8ce169e84978c37a4d63565e5cd9e1ed0b",
      "tree": "21f398d7961d7aa75fe8eb636448b74613dfe2ea",
      "parents": [
        "b092d0bd6b2f735ecfe79bf8bd1a1489600ddd22"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 06:03:03 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Sun Aug 02 12:41:11 2026 +0200"
      },
      "message": "Bump actions/setup-dotnet from 5.2.0 to 6.0.0\n\nBumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5.2.0 to 6.0.0.\n- [Release notes](https://github.com/actions/setup-dotnet/releases)\n- [Commits](https://github.com/actions/setup-dotnet/compare/c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7...a98b56852c35b8e3190ac28c8c2271da59106c68)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-dotnet\n  dependency-version: 6.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "b092d0bd6b2f735ecfe79bf8bd1a1489600ddd22",
      "tree": "4f5429727d2d89d0ccde60f830daefb73737b76c",
      "parents": [
        "ef695f57f43758a31b28b98d51ff0b0db5fa0ee8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 06:04:47 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Sun Aug 02 12:40:56 2026 +0200"
      },
      "message": "Bump jvm from 2.4.0 to 2.4.10 in /lib/kotlin\n\nBumps [jvm](https://github.com/JetBrains/kotlin) from 2.4.0 to 2.4.10.\n- [Release notes](https://github.com/JetBrains/kotlin/releases)\n- [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md)\n- [Commits](https://github.com/JetBrains/kotlin/compare/v2.4.0...v2.4.10)\n\n---\nupdated-dependencies:\n- dependency-name: jvm\n  dependency-version: 2.4.10\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "ef695f57f43758a31b28b98d51ff0b0db5fa0ee8",
      "tree": "74a0eb6e8a6352361c76ad51fc4c1fea4740d514",
      "parents": [
        "533f3009a50435decaec839da88468e87be7609c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 22:21:58 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Aug 01 22:21:58 2026 +0800"
      },
      "message": "Bump com.diffplug.spotless from 8.7.0 to 8.8.0 in /lib/java (#3692)\n\nBumps com.diffplug.spotless from 8.7.0 to 8.8.0.\n\n---\nupdated-dependencies:\n- dependency-name: com.diffplug.spotless\n  dependency-version: 8.8.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "533f3009a50435decaec839da88468e87be7609c",
      "tree": "74a0eb6e8a6352361c76ad51fc4c1fea4740d514",
      "parents": [
        "a131700e4dcb47cee9de06da8d191ad09ee80da3"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 22:21:08 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Aug 01 22:21:08 2026 +0800"
      },
      "message": "Bump actions/checkout from 6.0.2 to 7.0.1 (#3693)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...3d3c42e5aac5ba805825da76410c181273ba90b1)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: 7.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a131700e4dcb47cee9de06da8d191ad09ee80da3",
      "tree": "d602d47b9191d8f0d812ba286a8490437f3dcf47",
      "parents": [
        "c90cc825562e696ea9c5449587ecb72f6e739646"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 22:20:45 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Aug 01 22:20:45 2026 +0800"
      },
      "message": "Bump com.diffplug.spotless from 8.7.0 to 8.8.0 in /lib/kotlin (#3699)\n\nBumps com.diffplug.spotless from 8.7.0 to 8.8.0.\n\n---\nupdated-dependencies:\n- dependency-name: com.diffplug.spotless\n  dependency-version: 8.8.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c90cc825562e696ea9c5449587ecb72f6e739646",
      "tree": "d6ee9d1f298c0909b6283072f888f6c00495fb44",
      "parents": [
        "fd2da7b54a9e881b1acaef5d08ea4a4d23ef2a58"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 06:03:17 2026 +0000"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Aug 01 07:44:37 2026 -0400"
      },
      "message": "Bump ruby/setup-ruby from 1.314.0 to 1.321.0\n\nBumps [ruby/setup-ruby](https://github.com/ruby/setup-ruby) from 1.314.0 to 1.321.0.\n- [Release notes](https://github.com/ruby/setup-ruby/releases)\n- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)\n- [Commits](https://github.com/ruby/setup-ruby/compare/9eb537ca036ebaed86729dcb9309076e4c5c3b74...95ef2b042f9d7a56d8268cba8559e2842e2ad01b)\n\n---\nupdated-dependencies:\n- dependency-name: ruby/setup-ruby\n  dependency-version: 1.321.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "fd2da7b54a9e881b1acaef5d08ea4a4d23ef2a58",
      "tree": "19c1e68560f478d0e2d8d3185e963532d5f39b08",
      "parents": [
        "831306e501cbcd261cdbd8c2a3b8c44232704ceb"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Aug 01 06:02:55 2026 +0000"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Aug 01 07:24:22 2026 -0400"
      },
      "message": "Bump zizmorcore/zizmor-action from 0.5.6 to 0.6.1\n\nBumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.6.1.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...6fc4b006235f201fdab3722e17240ab420d580e5)\n\n---\nupdated-dependencies:\n- dependency-name: zizmorcore/zizmor-action\n  dependency-version: 0.6.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "831306e501cbcd261cdbd8c2a3b8c44232704ceb",
      "tree": "ba0da823d3ca1cf2838a0debc257ed86a48be0e4",
      "parents": [
        "eac5f4f48952cf90e7c1616ed1d407d10721e052"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 16:55:52 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 30 18:37:01 2026 -0400"
      },
      "message": "Fix Python process-pool test server lifecycle\n\nClient: py\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "eac5f4f48952cf90e7c1616ed1d407d10721e052",
      "tree": "d31a79d6cf450fa21dd994b37d1ea6e6036d47d8",
      "parents": [
        "9d63c5b6d5e02d390bb1a8361f2fc25d0318185c"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:16:53 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 30 18:35:55 2026 -0400"
      },
      "message": "THRIFT-6132: Reset Ruby Header metadata between frames\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "9d63c5b6d5e02d390bb1a8361f2fc25d0318185c",
      "tree": "d91a2a32a0a04717e1e30a0b1f82e30670e981d0",
      "parents": [
        "3b110f45634171f1717c3be2434bfd069465b892"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 09:36:53 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 30 18:35:26 2026 -0400"
      },
      "message": "THRIFT-6129: Stream Ruby HeaderTransport ZLIB output\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "3b110f45634171f1717c3be2434bfd069465b892",
      "tree": "8ba657eaee9cc6735a27a2f675aca5ba84810912",
      "parents": [
        "64601a5650e85c7f1cddb8ff34199fcc2a8492ea"
      ],
      "author": {
        "name": "Vikrant Puppala",
        "email": "vikrant.puppala@databricks.com",
        "time": "Wed Jul 29 09:43:43 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Thu Jul 30 20:50:05 2026 +0200"
      },
      "message": "THRIFT-6130: Restore CommonJS UUID compatibility\n\nClient: nodejs\n\nConstrain uuid to ^11.1.1, its maintained legacy-11 floor. This preserves the CommonJS and ESM conditional exports required by the Node.js runtime and generated code, while the caret range remains within v11 and cannot resolve ESM-only v12 or newer.\n\nAdd a behavioral regression that disables require(esm) when the runtime supports it, plus coverage for the generated-code v4 API and binary/compact UUID round trips.\n\nGenerated-by: OpenAI Codex (GPT-5)\nSigned-off-by: Vikrant Puppala \u003cvikrant.puppala@databricks.com\u003e\n"
    },
    {
      "commit": "64601a5650e85c7f1cddb8ff34199fcc2a8492ea",
      "tree": "680a9ff0875c8635fa447b1cdbc531a660559c7d",
      "parents": [
        "2ae9c11db596a90fc8daa21c3bd319821a4da42b"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 30 09:51:12 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 30 12:02:51 2026 -0400"
      },
      "message": "THRIFT-6133: Handle oversized Ruby memory-buffer reads\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "2ae9c11db596a90fc8daa21c3bd319821a4da42b",
      "tree": "a4ed9ef53a72ebb910cf34f3755f89c8843919f4",
      "parents": [
        "f69c2078b7c11c09aa4f8b8879d8b41342145461"
      ],
      "author": {
        "name": "Viacheslav Koryagin",
        "email": "viacheslavkoryagin@gmail.com",
        "time": "Thu Jul 23 15:17:49 2026 +0300"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Thu Jul 30 09:05:06 2026 +0200"
      },
      "message": "THRIFT-6108: Consolidate replace_all() into t_oop_generator\nPatch: Viacheslav Koryagin\nClient: dart,delphi\n\nThe Dart and Delphi generators each carried their own identical copy of\nthe replace_all() string helper. Move it into the shared t_oop_generator\nbase class and drop both copies. Generated output is unchanged.\n"
    },
    {
      "commit": "f69c2078b7c11c09aa4f8b8879d8b41342145461",
      "tree": "cabf84d91d948252b8110daeabfe3f9c42a653db",
      "parents": [
        "f6fee6d4e6285457069012c228202b70e3ca92a6"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:26:11 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 18:13:05 2026 -0400"
      },
      "message": "THRIFT-6125: Close Ruby client transports after uncertain sends\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "f6fee6d4e6285457069012c228202b70e3ca92a6",
      "tree": "bf3af7f5a6e7d3badc42e14e94edf78aaef94db8",
      "parents": [
        "8de8fc95bee170e527a31db395988fb67b5a2975"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 28 18:29:35 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 18:11:44 2026 -0400"
      },
      "message": "THRIFT-6128: Exclude development files from the Ruby gem\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "8de8fc95bee170e527a31db395988fb67b5a2975",
      "tree": "ad46993b0efd8b396dc8acfd8af1f03d06debcdb",
      "parents": [
        "b9b48cd0f369ccaf3c833bb8771b875ee370ccbd"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 12:51:54 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 18:05:11 2026 -0400"
      },
      "message": "THRIFT-6131: Bound Ruby HeaderTransport varint32 parsing\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "b9b48cd0f369ccaf3c833bb8771b875ee370ccbd",
      "tree": "1f42e76f49fba38fa034a65fc2df8e170c8c9a29",
      "parents": [
        "95d4e3e2311c062045a964383426f70d423993b3"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:12:35 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 09:45:28 2026 -0400"
      },
      "message": "THRIFT-6126: Handle unknown Compact and JSON types\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "95d4e3e2311c062045a964383426f70d423993b3",
      "tree": "0a18fdfff3740ed36060530ecde3d1c69bdf7e02",
      "parents": [
        "d1d7280c3b4bb9e3cb6b2a95de4c40a99e2b9fbe"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:40:48 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 09:44:06 2026 -0400"
      },
      "message": "Silence Ruby native capability queries\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "d1d7280c3b4bb9e3cb6b2a95de4c40a99e2b9fbe",
      "tree": "3d6510b77d4e6d5b12b4526215d39d0ae7e7e24e",
      "parents": [
        "4e9e407e865006a2e76a2380aa8a60d44bba230c"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:48:20 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 29 09:43:15 2026 -0400"
      },
      "message": "THRIFT-6124: Reset reused Ruby deserialization targets\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "4e9e407e865006a2e76a2380aa8a60d44bba230c",
      "tree": "ce1980f6d214e65e7fca57a20cb94efd566b87bf",
      "parents": [
        "286496115004d2643164725860109bc286613891"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:52:28 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Tue Jul 28 10:15:56 2026 +0200"
      },
      "message": "Reject a message the protocol did not name in the c_glib multiplexed processor\nClient: c_glib\n\nthrift_multiplexed_processor_process_impl handed the method name straight to\nstrtok_r once read_message_begin reported success. A protocol that reports\nsuccess without writing the name leaves that pointer NULL, and strtok_r reads\nthrough its saved state pointer, which starts out NULL as well. The name is\nalso used to build the error text and the reply header further down.\n\nReject a message the protocol did not name, the way the dispatch processor\nthis code was copied from already does.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "286496115004d2643164725860109bc286613891",
      "tree": "16bcc04cae546d5135f7f6ff4c6aac7b573f1b33",
      "parents": [
        "f9c592504df6e1f9c13fb5200691979026ecd450"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 23:41:32 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:40:42 2026 +0200"
      },
      "message": "Limit struct and container read depth in the PHP accelerator\nClient: php\n\nbinary_deserialize_spec, binary_deserialize and skip_element descend through\nnested structs, lists, sets and maps without tracking how deep they have gone,\nso a message that is nothing but nesting recursed as far as it liked. The PHP\nlibrary already bounds generated read() implementations at 64 levels; apply the\nsame limit here, for both the fields a spec declares and the ones it does not.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "f9c592504df6e1f9c13fb5200691979026ecd450",
      "tree": "1339f769ea1cd352cab76bbff52a18cb8b742daa",
      "parents": [
        "1a1bdde8eca1157d2462708a2e4d09497b95a15f"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 23:11:32 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:40:42 2026 +0200"
      },
      "message": "Take ownership of the method name in the c_glib dispatch processor\nClient: c_glib\n\nthrift_dispatch_processor_process left its method-name pointer uninitialized\nand handed it to dispatch_call whenever read_message_begin reported success,\neven for a protocol that never wrote it. The name was also only released on\nthe dispatch path, so every message that was rejected for its type, or whose\nheader read failed after the name had been allocated, left it behind.\n\nInitialize the pointer, reject a message the protocol did not name, release it\non every return path, and let the default dispatch_call answer a call it was\ngiven no name for.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "1a1bdde8eca1157d2462708a2e4d09497b95a15f",
      "tree": "3154cc1a1417f5750742aa15172fc335fd1e20e7",
      "parents": [
        "60594dc07ea69ec5e1a18db44d1815ada425e384"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 00:15:00 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:40 2026 +0200"
      },
      "message": "Limit skip recursion depth in the Smalltalk library\nClient: st\n\nTProtocol\u003e\u003eskip: descends through nested structs and containers, but did not\ntake part in the depth budget that generated read/write draws on, so the limit\nonly ever reached the fields a spec declares. Charge a level for each skip and\nrelease it on the way out with ensure:.\n\nNote: this binding has no runtime in the project\u0027s build images, so the added\ntest cases follow the existing file\u0027s manual \"file in and run the suite\"\ninstructions and have not been executed here.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "60594dc07ea69ec5e1a18db44d1815ada425e384",
      "tree": "38628c4ac90a45ca6d18f2e22ec3fa3348ee196b",
      "parents": [
        "3734de7226d8fbb748f24b18c0e166d89388832a"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 00:13:56 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:39 2026 +0200"
      },
      "message": "Limit skip recursion depth in the OCaml library\nClient: ocaml\n\nProtocol.t#skip descends through nested structs and containers, but did not take\npart in the depth budget that generated read/write draws on, so the limit only\never reached the fields a spec declares. Charge a level for each skip and\nrelease it on the way out, including when the skip itself raises.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "3734de7226d8fbb748f24b18c0e166d89388832a",
      "tree": "0c28400b2f38778e90ef7d091cacec117f3da4e0",
      "parents": [
        "5c9f82d74fd385d9fa8f45bbce195325e2b356f6"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 00:12:55 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:39 2026 +0200"
      },
      "message": "Limit skip recursion depth in the Lua library\nClient: lua\n\nTProtocolBase:skip descends through nested structs, lists, sets and maps, but\ndid not take part in the depth budget that generated read/write draws on, so the\nlimit only ever reached the fields a spec declares. Charge a level for each skip\nand release it on the way out, including when the skip itself raises.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "5c9f82d74fd385d9fa8f45bbce195325e2b356f6",
      "tree": "f06b229f4d362cb430b3f730dfb8c817a10a41dc",
      "parents": [
        "5b37f33d36ddd99a540e325ffed1029d04de57af"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 00:12:07 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:39 2026 +0200"
      },
      "message": "Limit skip recursion depth in the Perl library\nClient: perl\n\nThrift::Protocol::skip descends through nested structs, lists, sets and maps,\nbut did not take part in the depth budget that generated read()/write()\nimplementations draw on, so the limit only ever reached the fields a spec\ndeclares. Charge a level for each skip and release it on the way out, including\nwhen the skip itself dies.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "5b37f33d36ddd99a540e325ffed1029d04de57af",
      "tree": "d779a56aa0fbaa12d37c00e44ce47f565577b229",
      "parents": [
        "02e556958865211393601a2fe65837a60a004044"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 00:11:11 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:39 2026 +0200"
      },
      "message": "Limit skip recursion depth in the PHP library\nClient: php\n\nTProtocol::skip descends through nested structs, lists, sets and maps, but did\nnot take part in the depth budget that generated read() implementations draw on,\nso the limit only ever reached the fields a spec declares. Charge a level for\neach skip and release it on the way out, the way the .NET, Delphi and C++\nruntimes do.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "02e556958865211393601a2fe65837a60a004044",
      "tree": "ca8d524032cfeba58f723027215d7109bc716682",
      "parents": [
        "10340c30687d55054a2c110f1a21090e5d79f66d"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 23:29:30 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:14 2026 +0200"
      },
      "message": "Read a T_STRING field into a heap buffer in the PHP accelerator\nClient: php\n\nbinary_deserialize sized an automatic array from the length the wire declares,\n`char strbuf[size + 1]`, and copied that many bytes into it. The length is not\nbounded by anything the extension knows, and `size + 1` wraps to zero at\nUINT32_MAX.\n\nBuild the field on the heap instead, in steps, so nothing on the stack depends\non the declared length, the length takes part in no expression that can wrap,\nand a length the sender does not back with data costs only what it does send.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "10340c30687d55054a2c110f1a21090e5d79f66d",
      "tree": "f39f566057a1ff51bb5623d9c364ae53ef1aeaf6",
      "parents": [
        "1894de68d79eb148b656917ef6efd3cd21b63964"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 23:26:10 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:14 2026 +0200"
      },
      "message": "Limit skip recursion depth in the Python accelerator\nClient: py\n\nProtocolBase::skip descends through nested structs, lists, sets and maps but,\nunlike readStruct, took no recursion guard, so the depth limit reached only\nthe fields a spec declares. Guard skip the same way the C++ runtime and the\npure Python protocol do, and let the exception it raises reach the caller\ninstead of replacing it with a generic one.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "1894de68d79eb148b656917ef6efd3cd21b63964",
      "tree": "8846b59a69a606a5aac0d29bc76ad75d1ead45f9",
      "parents": [
        "988e5d120d9d5fc2c3ee9fb5b26df336192831d2"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 23:17:54 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 28 01:22:14 2026 +0200"
      },
      "message": "Handle unreadable and unroutable messages in the c_glib multiplexed processor\nClient: c_glib\n\nthrift_multiplexed_processor_process_impl ignored the result of\nread_message_begin and went on to use the message type and sequence id that a\nfailed read leaves unwritten. A method name that resolves to a registered\nservice but carries no function name reached the exception path with no error\nset, and the exception was then built from that error. Take the failure from\nthe return value, set the error when nothing else did, initialize the header\nfields, and release the method name on the remaining return paths.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "988e5d120d9d5fc2c3ee9fb5b26df336192831d2",
      "tree": "2b420d1cbe323b78e3b848e577bd32fa41f06bd7",
      "parents": [
        "18dccb9cd7fd38855ddb7cdc7aa3f9d84ee747cb"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:56:55 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 27 19:16:43 2026 -0400"
      },
      "message": "THRIFT-6123: Reset Ruby serializer after write failures\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "18dccb9cd7fd38855ddb7cdc7aa3f9d84ee747cb",
      "tree": "ca60c9ca7010e2ff0913691fcd734a3990dda7d5",
      "parents": [
        "a90cb6f15fdaabc6fa9a149433feffb2747aed93"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 23:12:46 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Tue Jul 28 01:16:24 2026 +0200"
      },
      "message": "Update the c_glib binary protocol test for non-versioned message headers\nClient: c_glib\n\nThe complex-types round trip wrote a bare int32 for the non-versioned message\ncase and expected read_message_begin to return without consuming a name, type\nand sequence id. read_message_begin reads them since commit 280d9778d, which\nleft the case failing and the rest of the stream misaligned. Send a complete\nold-style header and verify what was read back.\n\nCo-Authored-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "a90cb6f15fdaabc6fa9a149433feffb2747aed93",
      "tree": "88ced4f5da5fd005dbaa7cdcb4d2ce36886c1b17",
      "parents": [
        "ef3cf4e098f3bbb22ffbc0db9c73e14942a95385"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 18:07:51 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 27 19:15:09 2026 -0400"
      },
      "message": "THRIFT-6122: Normalize Ruby JSON Unicode handling\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "ef3cf4e098f3bbb22ffbc0db9c73e14942a95385",
      "tree": "2beb4bf67c4ac482b0a0f484767ce9d91c130372",
      "parents": [
        "c42a148f32184e645a4f97a4a14f0cf5e6e6c62d"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 16:40:33 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 27 18:47:45 2026 -0400"
      },
      "message": "Let Python test servers allocate ephemeral ports\n\nClient: py\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "c42a148f32184e645a4f97a4a14f0cf5e6e6c62d",
      "tree": "3691fa57e626a05e766d1a5face581b55bd6252f",
      "parents": [
        "c0442b9f85d12c7ab5cfbd9bf1b379136d438855"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 11:13:21 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Mon Jul 27 23:09:45 2026 +0200"
      },
      "message": "Measure JSON field size against the configured maximum\nClient: cpp\n\nreadJSONString() and readJSONNumericChars() passed their running byte count to\ncheckReadBytesAvailable(), which compares against the message size still\nremaining rather than the configured maximum. On a transport whose read() also\ndraws that budget down, the same bytes are accounted for twice: once as they are\nconsumed and once as the running count. TZlibTransport::read() does exactly\nthat, so JSON over zlib rejects a string once it passes roughly half of whatever\nwas left of the budget when the field started, and since nothing resets the\nbudget between fields the threshold keeps shrinking as the message goes on. With\na 1 KB maximum a 768-byte string is cut off at 511 bytes.\n\nMeasure the running count against the configured maximum instead, which is what\nthe Java, netstd, Delphi, Go and Python readers already do. Every transport that\nchecks the budget without drawing it down -- socket, SSL, buffered, framed,\nmemory, HTTP -- behaves exactly as before, since for those the remaining size\nnever moves off the maximum during a read.\n\nTests both directions: JSONProtoTest covers it transport-agnostically with a\nstand-in that draws the budget down as TZlibTransport does, and ZlibTest covers\nthe real composition.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "c0442b9f85d12c7ab5cfbd9bf1b379136d438855",
      "tree": "741763cf1079f44e1d4bbea398596a74a1b6beff",
      "parents": [
        "280d9778d2b715b5c9b6e7586998f3fb5881415d"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 01:57:27 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Mon Jul 27 01:57:27 2026 +0200"
      },
      "message": "Fix build for the JSON message-size test changes\nClient: cpp,java\n\nTwo follow-ups to the recent TJSONProtocol message-size work:\n\nlib/java: rewrap a javadoc comment in TestMessageSizeLimits so it matches\ngoogle-java-format; spotlessCheck rejected the previous wrapping.\n\nlib/cpp: test_tthriftjsonprotocol_read_check_exception configured a message\nsize of 2 bytes, which the JSON reader now rejects while reading the container\nelement type name (\"i32\") rather than at the container size check the test\ntargets. readListBegin() then threw earlier in the stream than before and the\nfollowing readListEnd() hit an unexpected character. Raise the configured limit\nso the container header is readable and enlarge the declared container so the\nsize check still exceeds the limit, keeping the original intent of the test.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "280d9778d2b715b5c9b6e7586998f3fb5881415d",
      "tree": "948fe71592b7d4c035e9e6c405dea1bbbbe214d8",
      "parents": [
        "845ffb605e65c3bff8ad28fa3061b94dc6514a5d"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 01:11:29 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:44:00 2026 +0200"
      },
      "message": "Handle non-versioned messages in c_glib read_message_begin\nClient: c_glib\n\nthrift_binary_protocol_read_message_begin only handled the versioned\n(sz \u003c 0) encoding and had no branch for old-style non-versioned messages,\nso for a non-negative leading int32 it returned without setting the name,\nmessage type or sequence id output parameters. Add the old-style branch\nthat reads the method name, type and sequence id, matching the Java, C++\nand Python bindings, and bound the name length by the configured string\nlimit the way read_string does. Add a testbinaryprotocol case for it.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "845ffb605e65c3bff8ad28fa3061b94dc6514a5d",
      "tree": "c8487f5c2c2b1e2fcd5bbab78d5d9ef73b17f7f6",
      "parents": [
        "8494f3c11cd67e89623af6c3b1891f939a7b3e21"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 00:26:34 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:43:59 2026 +0200"
      },
      "message": "Bound TJSONProtocol string and number reads by MaxMessageSize\nClient: java\n\nreadJSONString() and readJSONNumericChars() decode a quote-delimited string and\na character-by-character numeric literal with no declared length, so unlike the\nlength-prefixed protocols they had no size gate and could grow without bound.\nTrack the running byte count and reject a single string or numeric literal once\nit exceeds the configured MaxMessageSize, so it is bounded the way a\nlength-prefixed read already is. The count is compared against MaxMessageSize\ndirectly rather than the decrementing remaining-message-size counter, so the\nbound stays tight on the non-decrementing stream read path and does not further\ntighten transports that already decrement.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "8494f3c11cd67e89623af6c3b1891f939a7b3e21",
      "tree": "3ac7024b12d4c492321baf94db012c7ae3fbbaa7",
      "parents": [
        "2b53401b9e029a1110f750196bccd779e453698c"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Thu Jul 23 23:21:34 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:43:59 2026 +0200"
      },
      "message": "Bound TSimpleJSONProtocol delimited reads by MaxMessageSize\nClient: go\n\nThe JSON reader consumes several delimiter-terminated values that carry no\ndeclared length: ParseStringBody/ParseQuotedStringBody read a quoted string,\nParseBase64EncodedBody a base64 field, readNumeric a numeric literal, and\nParseObjectEnd/ParseListEnd the run up to a closing \u0027}\u0027/\u0027]\u0027. Unlike the\nlength-prefixed protocols none had a size gate, and bufio\u0027s ReadString/ReadBytes\nbuffer the whole run internally before returning, so an oversized value could be\nread in full before any check.\n\nRead the delimited values through a ReadSlice loop (readBinaryBounded) that\nre-checks the accumulated size against the configured MaxMessageSize after each\nbuffered chunk, and check the running length in readNumeric as characters\naccumulate, so a single value is rejected as it grows rather than buffered\nwithout bound. TJSONProtocol embeds TSimpleJSONProtocol, so both are covered.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "2b53401b9e029a1110f750196bccd779e453698c",
      "tree": "ec5c6d16f400b70f840a4520e002ae7ccddf493c",
      "parents": [
        "a57f8aa941fb0057a401f5d88ca8a16ded05a8c0"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Thu Jul 23 22:39:41 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:43:59 2026 +0200"
      },
      "message": "Bound TJSONProtocol string and number reads by string_length_limit\nClient: py\n\nreadJSONString() and readJSONNumericChars() consume quote-delimited and\ncharacter-by-character input with no declared length, so unlike the\nlength-prefixed protocols they had no size gate before growing the value.\nTJSONProtocol also hardcoded string_length_limit to None, so the per-field\nlimit that TBinaryProtocol and TCompactProtocol already honor could not be\nconfigured for JSON at all. Accept string_length_limit on the protocol and\nfactory (default None, unchanged behavior) and check the running byte count\nagainst it as the value grows -- including the inner loop that consumes a run\nof UTF-8 continuation bytes -- so a single JSON string or numeric literal is\nbounded by the configured limit the way length-prefixed reads already are.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "a57f8aa941fb0057a401f5d88ca8a16ded05a8c0",
      "tree": "54dcbaaba6785f804379624289af0049bf289697",
      "parents": [
        "4a9b2546c5554b75c7dd04c210edef2e8681c8d1"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Thu Jul 23 14:13:14 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:43:59 2026 +0200"
      },
      "message": "Enforce configured maxFrameSize in THeaderTransport receive path\nClient: cpp\n\nBind THeaderTransport::readFrame() to TConfiguration::maxFrameSize the same\nway TFramedTransport::readFrame() already does, and apply that same limit to\nthe post-transform (decompressed) payload, so the header transport honours the\noperator-configured frame-size limit consistently rather than only the\ninternal MAX_FRAME_SIZE ceiling.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "4a9b2546c5554b75c7dd04c210edef2e8681c8d1",
      "tree": "05cda858655158ebb6f960b4c99392457426a1d7",
      "parents": [
        "bbeecad4b7bfef7dc12a7afadab00beb70b58f1d"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Thu Jul 23 14:17:19 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:43:58 2026 +0200"
      },
      "message": "Bound TJSONProtocol string and number reads by MaxMessageSize\nClient: cpp\n\nreadJSONString() and readJSONNumericChars() consume quote-delimited and\ncharacter-by-character input with no declared length, so unlike the\nlength-prefixed protocols they had no size gate before growing the value.\nCheck the running byte count against the configured MaxMessageSize as the\nvalue grows, so a single JSON string or numeric literal is bounded by the\nconfigured message-size limit the way length-prefixed reads already are.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "bbeecad4b7bfef7dc12a7afadab00beb70b58f1d",
      "tree": "d340404951d050dd2c5e03b4fc9ef7a91a8067de",
      "parents": [
        "d8aea0c7022c01fa5453bca000196e71d37eebd0"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 09:10:51 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:36:22 2026 +0200"
      },
      "message": "Bound TJSONProtocol string and number reads by MaxMessageSize\nClient: netstd\n\nReadJsonStringAsync() and ReadJsonNumericCharsAsync() decode a quote-delimited\nstring and a character-by-character numeric literal with no declared length, so\nunlike the length-prefixed protocols they had no size gate and could grow without\nbound. Track the running byte count and reject a single string or numeric literal\nonce it exceeds the configured MaxMessageSize, so it is bounded the way a\nlength-prefixed read already is. The count is compared against MaxMessageSize\ndirectly rather than the decrementing remaining-message-size counter, so the bound\nstays tight on the non-decrementing stream read path and does not further tighten\ntransports that already decrement. The numeric check is placed ahead of the loop\u0027s\ntry/catch, whose TTransportException handler would otherwise swallow it.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "d8aea0c7022c01fa5453bca000196e71d37eebd0",
      "tree": "8d2a2a85fc751d2df1658d3161e63f6352cd3345",
      "parents": [
        "fb9dd3d45a80b32f302a688b4c5624df787be246"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 09:20:48 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:27:34 2026 +0200"
      },
      "message": "Bound TJSONProtocol string and number reads by MaxMessageSize\nClient: delphi\n\nReadJSONString() and ReadJSONNumericChars() decode a quote-delimited string and a\ncharacter-by-character numeric literal with no declared length, so unlike the\nlength-prefixed protocols they had no size gate and could grow without bound on the\nbuffered transport composition, which does not draw down the remaining-message-size\nbudget. Track the running byte count and reject a single string or numeric literal\nonce it exceeds the configured MaxMessageSize, so it is bounded the way a\nlength-prefixed read already is. The count is compared against MaxMessageSize\ndirectly rather than the decrementing remaining-message-size counter, so the bound is\ncorrect on the buffered path and does not double-count on the socket/framed paths that\nalready decrement.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "fb9dd3d45a80b32f302a688b4c5624df787be246",
      "tree": "b0ef1cb003c35831bffaf6b52002ca965ec1e391",
      "parents": [
        "2a659d6d37d5a9d699155e7b938b72a0ac586874"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 10:34:57 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 26 22:21:11 2026 +0200"
      },
      "message": "Route buffered transport reads through the inner transport for message-size accounting\nClient: delphi\n\nTBufferedTransportImpl refilled its input buffer directly from the inner\ntransport\u0027s raw input stream, which does not route through\nTStreamTransportImpl.Read and therefore never drew the endpoint\u0027s\nremaining-message-size counter down. As a result the configured MaxMessageSize\nwas not accounted cumulatively on the buffered composition: each individual read\nwas checked, but the running total across a message was not, so a peer could\nread an unbounded total as long as no single read exceeded the limit.\n\nWrap the inner transport in a small input-only IThriftStream so the read buffer\nrefills via ITransport.Read, mirroring how TFramedTransportImpl already reads\nthrough the inner transport. The endpoint\u0027s existing per-read accounting then\napplies on the buffered path too; the socket and framed paths, and the buffered\noutput path, are unchanged. Because the buffer reads ahead, the count reflects\nbytes pulled from the wire (bounded, as intended) and may lead the logical\nmessage position by up to one buffer near the limit.\n\nAdds a transport-level test over the buffered composition that reads past the\nlimit in small chunks and asserts the cumulative bound is applied.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "2a659d6d37d5a9d699155e7b938b72a0ac586874",
      "tree": "fdf819c25818b45ab4fab0b631dcebb8abf5f09a",
      "parents": [
        "35124deec164084215117fff9477326f5a548c2d"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 18:24:42 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 26 14:39:38 2026 -0400"
      },
      "message": "THRIFT-6121: Make Header protocol errors parseable\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "35124deec164084215117fff9477326f5a548c2d",
      "tree": "714410ae111ccebe0fcdac4f00633a735fa38b06",
      "parents": [
        "520306fa4147d373a05c9d16ed5666d996eba798"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 17:44:08 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 26 11:41:59 2026 -0400"
      },
      "message": "THRIFT-6120: Bound TLS accept handshakes\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "520306fa4147d373a05c9d16ed5666d996eba798",
      "tree": "512f979b2ffda68310cb6119899b37b402933a34",
      "parents": [
        "ceff009948d6ca92234b2dc820e2a300414d3e3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 25 20:52:40 2026 +0000"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Jul 25 19:25:03 2026 -0400"
      },
      "message": "Bump json from 2.19.2 to 2.19.9 in /test/rb\n\nBumps [json](https://github.com/ruby/json) from 2.19.2 to 2.19.9.\n- [Release notes](https://github.com/ruby/json/releases)\n- [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md)\n- [Commits](https://github.com/ruby/json/compare/v2.19.2...v2.19.9)\n\n---\nupdated-dependencies:\n- dependency-name: json\n  dependency-version: 2.19.9\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "ceff009948d6ca92234b2dc820e2a300414d3e3a",
      "tree": "a5f11b08dec15a13e93195f2e3f20ff436816a6b",
      "parents": [
        "7cfc5ec847b56647c8833d7c522feca4ca85f698"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 25 20:52:42 2026 +0000"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Jul 25 19:24:34 2026 -0400"
      },
      "message": "Bump json from 2.19.2 to 2.19.9 in /lib/rb\n\nBumps [json](https://github.com/ruby/json) from 2.19.2 to 2.19.9.\n- [Release notes](https://github.com/ruby/json/releases)\n- [Changelog](https://github.com/ruby/json/blob/master/CHANGES.md)\n- [Commits](https://github.com/ruby/json/compare/v2.19.2...v2.19.9)\n\n---\nupdated-dependencies:\n- dependency-name: json\n  dependency-version: 2.19.9\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "7cfc5ec847b56647c8833d7c522feca4ca85f698",
      "tree": "1bc12360a1dd1db3c65baf61e6cdb16448ee8e27",
      "parents": [
        "f539bb415ec529087d4c22ba612139cd06954938"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 08:56:08 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 08:56:08 2026 +0200"
      },
      "message": "Add /.ai to .gitignore\n\nThe .ai/ directory holds local agent-workflow run state and is not\npart of the source tree, mirroring the existing /.claude entry.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "f539bb415ec529087d4c22ba612139cd06954938",
      "tree": "8ae4509b79b7158b1302e3e93ea753a04c6b41e4",
      "parents": [
        "a1d73a84c51120a80c09d84067260d73f2763021"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Fri Jul 24 01:11:29 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Fri Jul 24 01:55:08 2026 +0200"
      },
      "message": "Link thrift_memory_buffer into the c_glib testbinaryprotocol test\nClient: c_glib\n\nThe recursion-depth skip tests in testbinaryprotocol.c use\nTHRIFT_TYPE_MEMORY_BUFFER, but testbinaryprotocol_LDADD did not link\nthrift_memory_buffer, so testbinaryprotocol failed to build under the\nautotools build. The cmake build links the whole library and was\nunaffected, which is why this went unnoticed.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "a1d73a84c51120a80c09d84067260d73f2763021",
      "tree": "28a7af723114852fab3a03e56cd6bd2bc8bb9179",
      "parents": [
        "d4d92514ccad7e20b13cc5aea4dc6b87d3fc5900"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 16:34:59 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 14:43:21 2026 -0400"
      },
      "message": "Fix Python socket timeout test units\n\nClient: py\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "d4d92514ccad7e20b13cc5aea4dc6b87d3fc5900",
      "tree": "b2ec0ad61f97806073f80c5eff919cce5b3f2d6e",
      "parents": [
        "9a5e4ab68d9b1af635f2527e784999630e02d90b"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:30:05 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Thu Jul 23 14:30:34 2026 -0400"
      },
      "message": "THRIFT-6119: Preserve Ruby multiplexed protocol service names\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "9a5e4ab68d9b1af635f2527e784999630e02d90b",
      "tree": "84af1a7c8d6d7bf97d4ca9888758e6ec714d5b60",
      "parents": [
        "ace596c93b5b23c9b7bc3c1f3d16e1dd2822716e"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:33:41 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Wed Jul 22 08:08:06 2026 -0400"
      },
      "message": "THRIFT-6118: Forward Ruby protocol decorator message arguments\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "ace596c93b5b23c9b7bc3c1f3d16e1dd2822716e",
      "tree": "682029c176cea74a67c8e7b2c81e908f444e4b5f",
      "parents": [
        "95ac128cf82d74d68e00611cb527642470f1a751"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Wed Jul 22 00:17:01 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Wed Jul 22 09:01:23 2026 +0200"
      },
      "message": "THRIFT-6116: Escape Python-keyword names in consts, enum-value defaults, required-field checks, and type_hints/twisted/enum modes\nClient: py\n\nA full audit of every get_name()-family call in t_py_generator.cc (105\nsites) turned up six more spots THRIFT-5927 never wired\nmaybe_escape_identifier() into. Four of the six only fire under\nnon-default generator options, which is why the existing single\n\"-gen py\" test run never caught them:\n\n- generate_const(): a keyword-named top-level const\u0027s own name.\n- render_const_value()\u0027s enum branch: an unescaped enum *value*\n  reference (e.g. \"Lambda.None\"). Reached from top-level consts and,\n  via render_field_default_value(), from every field default value --\n  struct __init__ defaults, thrift_spec entries, and type-hint\n  parameter defaults all share this one line.\n- The __setattr__ override\u0027s \"EnumType.__members__.get(\u003cfield\u003e)\" call\n  (-gen py:enum + an immutable struct), inconsistent with two escaped\n  uses of the same identifier earlier in the same statement.\n- The required-field validator\u0027s \"if self.\u003cfield\u003e is None:\" check.\n- The twisted-style \"except \u003cType\u003e as \u003cname\u003e:\" clause and its two\n  subsequent uses (-gen py:twisted): the exception type half of this\n  line was already fixed by THRIFT-6115, but the \"as\" binding itself\n  was not, inconsistent with the tornado-style and default-style\n  equivalents a few lines away, which do escape it.\n- The type-hint mode class-level field annotation (-gen py:type_hints\n  + an immutable struct).\n\nExtend test_keyword_escape.py to run the compiler under three modes\n(\"py\", \"py:type_hints,enum\", \"py:twisted\") instead of just the\ndefault, and extend Thrift5927.thrift with a keyword-named const, a\nkeyword-named enum-typed const, a required keyword-named field, and\nan immutable struct with a keyword-named enum-typed default-valued\nfield, to actually exercise all six.\n\nconst-references (e.g. \"const i32 B \u003d A;\") are resolved to their\nliteral value by the compiler at parse time, not re-emitted by name,\nso there\u0027s no separate reference-site fix needed there beyond the\ndefinition itself.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "95ac128cf82d74d68e00611cb527642470f1a751",
      "tree": "92610ee43d8094c02d303238c52c1167f36e7a07",
      "parents": [
        "a8c6db2da2857721149df55945b69c2e2a950d16"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 23:47:07 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Wed Jul 22 08:57:24 2026 +0200"
      },
      "message": "THRIFT-6115: Escape Python-keyword names in service extends and cross-module type references\nClient: py\n\ntype_name(), the shared helper rendering any struct/enum/exception/\nservice reference as a Python expression, never escaped the identifier\non any of its three return paths. This broke two more cases sharing\nThrift5927.thrift\u0027s existing keyword-named struct/service fixture data:\n\n- A service \"extends\" clause naming a keyword-named parent service\n  produced a broken \"import module.\u003ckeyword\u003e\" statement (a direct\n  call, not through type_name) and a broken base-class reference\n  \"class Client(module.\u003ckeyword\u003e.Client):\" (through type_name).\n- A struct field, deserializer, or \"except \u003cType\u003e as \u003cname\u003e:\" clause\n  referencing a keyword-named type across an \"include\" boundary\n  produced a broken \"module.ttypes.\u003ckeyword\u003e\" reference.\n\nEscape the identifier at type_name()\u0027s three return points and at the\none direct (non-type_name) extends-import call site.\n\nOne added wrinkle: True/False/None are Python keyword *literals*, not\nstatement keywords, so an unescaped \"except True as e:\" parses without\na SyntaxError -- it silently binds the wrong object and would raise a\nruntime TypeError if ever hit. py_compile-based testing alone can\u0027t\nsee that, so test_keyword_escape.py also walks the AST of each\ngenerated file and fails if any exception handler\u0027s type is a bare\nkeyword-literal Constant.\n\nTest fixtures: a same-file extends of the existing \"continue\" service,\nplus a new thrift5927include.thrift (modeled on tutorial/shared.thrift\n+ tutorial/tutorial.thrift\u0027s include pattern) providing a keyword-named\nstruct and service, included and referenced/extended from\nThrift5927.thrift the same way tutorial.thrift uses shared.thrift.\n\nThis depends on THRIFT-6114 for the service-extends-a-keyword-named-\nservice case specifically (6114 fixes the parent\u0027s own module\nfilename; this fixes the child\u0027s reference to it).\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "a8c6db2da2857721149df55945b69c2e2a950d16",
      "tree": "4c1c8255e490ee162d7589976277c9ac13a10d95",
      "parents": [
        "307f64bc8d59a75168b4f1fe351605bfa08d91b8"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 23:13:23 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Wed Jul 22 02:31:23 2026 +0200"
      },
      "message": "THRIFT-6114: Escape Python-keyword service/function names in service module and -remote script\nClient: py\n\nTHRIFT-5927 escaped reserved-keyword identifiers in structs, enums,\nfields, and the service Client/Processor bodies, but missed three\nspots exercised by the same Thrift5927.thrift fixture: the service\u0027s\nown module filename/import (built from the raw service name), its\nentry in the package\u0027s \"__all__\" list, and the generated\n\u003cservice\u003e-remote CLI script, which never escaped anything. For a\nservice or function named after a Python keyword this produced a\nmodule reachable only via importlib (not \"import x.y\" / \"from x\nimport y\", and not \"from package import *\" either, since \"__all__\"\nlisted the raw name while the file itself needed to be escaped) and a\n-remote script with actual SyntaxErrors.\n\nEscape service_name_ at its three real Python-identifier usages\n(module filename, remote script\u0027s import and client instantiation),\nthe service\u0027s own \"__all__\" entry, and the dispatched function name\nin the remote script. The CLI script\u0027s own filename and the\nhuman-readable help/usage text keep the original IDL name on purpose.\n\nExtend test_keyword_escape.py to also compile-check generated\n\"*-remote\" files, which have no .py suffix and were previously\ninvisible to the test\u0027s glob, and to statically check that every\n\"__all__\" entry is a valid, non-keyword identifier -- a mismatch\nthere compiles fine (it\u0027s just a string) and only breaks at\n\"from package import *\" time, so py_compile alone can\u0027t see it.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "307f64bc8d59a75168b4f1fe351605bfa08d91b8",
      "tree": "c8492323e192a8d6bc137dfd1e83276057555419",
      "parents": [
        "3b81e1d280890ce4b4bf48c76ae73a191b8f0b52"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 22:14:55 2026 +0000"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 20:13:33 2026 -0400"
      },
      "message": "Bump linkify-it from 5.0.1 to 5.0.2 in /lib/js\n\nBumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.\n- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/markdown-it/linkify-it/compare/5.0.1...5.0.2)\n\n---\nupdated-dependencies:\n- dependency-name: linkify-it\n  dependency-version: 5.0.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "3b81e1d280890ce4b4bf48c76ae73a191b8f0b52",
      "tree": "334fb8509b437dfe17e56c3a8d848937f1aa9949",
      "parents": [
        "41ab486cdde0766c0d4a8e1ce28ba1b819d1308d"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:32:51 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 19:49:13 2026 -0400"
      },
      "message": "THRIFT-6112: Reject duplicate Ruby socket opens\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "41ab486cdde0766c0d4a8e1ce28ba1b819d1308d",
      "tree": "bee961c54df654cb1559edb47ebdc8677c0861fe",
      "parents": [
        "8db51cf4710ae5c9976ea4776f37b4354ffe3d4e"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:37:35 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 18:57:33 2026 -0400"
      },
      "message": "THRIFT-6110: Ruby HTTP client transport should reject empty successful responses\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "8db51cf4710ae5c9976ea4776f37b4354ffe3d4e",
      "tree": "a7ba5aa9987acde27867cc7a3ff9c61e17763e02",
      "parents": [
        "af9d5556aa7eaffb2de04409f4bbdcc5b454b817"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 20:55:04 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 18:40:29 2026 -0400"
      },
      "message": "THRIFT-6098: Preserve caller-supplied Ruby SSL contexts\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "af9d5556aa7eaffb2de04409f4bbdcc5b454b817",
      "tree": "38d63a1ddcfc0e9e71b36c0cd1cb4673a28ebbca",
      "parents": [
        "8c00c6489ae9cd34bed4694f5b1b4f218430db07"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 22:50:04 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Wed Jul 22 00:19:33 2026 +0200"
      },
      "message": "THRIFT-6113: Fix test_keyword_escape.py silently skipping in CI and local builds\nClient: py\n\nThe check-local recipe invoked the test without passing THRIFT through as\nan environment variable, so find_thrift() never saw the compiler make had\njust built. Its relative-path fallback was also off by one directory\nlevel and could never resolve to compiler/cpp/thrift or\nbuild/compiler/cpp/bin/thrift. With no system-wide thrift on PATH either,\nthe test silently printed \"thrift compiler not found, skipping test\" and\nreturned success, giving no real coverage in CI since THRIFT-5927 merged.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "8c00c6489ae9cd34bed4694f5b1b4f218430db07",
      "tree": "8c26300aa857eb92e3f3b2b121300557e2379f9d",
      "parents": [
        "c65ef8f2f3551e2f87a16f278e12382e9f2b3753"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 22:59:08 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Wed Jul 22 00:13:54 2026 +0200"
      },
      "message": "updated System.ServiceModel.Primitives 10.x breaks net8/net9\n"
    },
    {
      "commit": "c65ef8f2f3551e2f87a16f278e12382e9f2b3753",
      "tree": "db20f6a22036b76a7632ce198f83fbc58158ad84",
      "parents": [
        "cd00f037fa9363f7a068d963d33729bfe9372412"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 22:59:39 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 23:02:42 2026 +0200"
      },
      "message": "FIX: AreSequenceEqual() is correct\n"
    },
    {
      "commit": "cd00f037fa9363f7a068d963d33729bfe9372412",
      "tree": "0973599c455f55208f0ec53f7c62b9c4a7d52e03",
      "parents": [
        "d8eeec5f3f1f9ee186da1cc324ec9bc09672fa4f"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 14:49:44 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Tue Jul 21 14:51:31 2026 +0200"
      },
      "message": "nuget package update\n"
    },
    {
      "commit": "d8eeec5f3f1f9ee186da1cc324ec9bc09672fa4f",
      "tree": "973da2a271276c405d89ac3b9a99d870494e8239",
      "parents": [
        "1bd5e4d5496c1896042fb495c9a56dce763929ad"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 09:44:22 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Tue Jul 21 14:43:56 2026 +0200"
      },
      "message": "Bump shell-quote from 1.8.4 to 1.10.0 in /lib/js\n\nBumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.\n- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.10.0)\n\n---\nupdated-dependencies:\n- dependency-name: shell-quote\n  dependency-version: 1.10.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "1bd5e4d5496c1896042fb495c9a56dce763929ad",
      "tree": "2a1f66984b1ccd8402867fb8cb26388c60130a14",
      "parents": [
        "5e4f1f23fc1c3f09dc8243ed5140e081b0d7cf3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 09:45:40 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Tue Jul 21 14:43:31 2026 +0200"
      },
      "message": "Bump System.Security.Cryptography.Xml from 10.0.7 to 10.0.10\n\n---\nupdated-dependencies:\n- dependency-name: System.Security.Cryptography.Xml\n  dependency-version: 10.0.10\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "5e4f1f23fc1c3f09dc8243ed5140e081b0d7cf3a",
      "tree": "90a6f8c30bf92e8937b89ad54b49542159ad2cdb",
      "parents": [
        "794ab0d4eab55c9293fbc239375cf48f4623fb0c"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:36:30 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Tue Jul 21 08:21:26 2026 -0400"
      },
      "message": "THRIFT-6111: Make Ruby struct equality symmetric\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "794ab0d4eab55c9293fbc239375cf48f4623fb0c",
      "tree": "a5950e2ed8f4985af35f792b2f4f3e4d04101ce9",
      "parents": [
        "03804e86243a2e86b35788736c825c83244e1745"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 03:40:27 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Tue Jul 21 11:34:14 2026 +0200"
      },
      "message": "Bump System.Security.Cryptography.Xml from 10.0.7 to 10.0.10\n\n---\nupdated-dependencies:\n- dependency-name: System.Security.Cryptography.Xml\n  dependency-version: 10.0.10\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "03804e86243a2e86b35788736c825c83244e1745",
      "tree": "9b71737e296f1c0b8a8069af425ecb574e2b577c",
      "parents": [
        "d2001f7444f7540e26ca553ceddad10e31392298"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 12:38:35 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 19:34:59 2026 -0400"
      },
      "message": "THRIFT-6109: Ruby HTTP client transport should provide a safe endpoint label\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.6) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "d2001f7444f7540e26ca553ceddad10e31392298",
      "tree": "86f53f86fa98b7e7ce1c34ff2386e56ce8fda12f",
      "parents": [
        "2fa08c0d36afc15fbab00df457e6bd9fe3c54824"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:42:07 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 18:00:10 2026 -0400"
      },
      "message": "THRIFT-6103: Ruby MemoryBufferTransport should return unsigned byte values\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "2fa08c0d36afc15fbab00df457e6bd9fe3c54824",
      "tree": "9a6aa07662dc31c4285431a10911f5747404f4ef",
      "parents": [
        "36f43a87c94bb2c5c62ec209bf2d79dd80a9b079"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 15:22:31 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 17:25:27 2026 -0400"
      },
      "message": "THRIFT-6105: Preserve partial MemoryBufferTransport read progress\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "36f43a87c94bb2c5c62ec209bf2d79dd80a9b079",
      "tree": "3949b92317c295b272faf22f31b368ebfefd7298",
      "parents": [
        "deb21c2cebe27d3455823346ef5eb386b2d0f464"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:40:26 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 15:31:52 2026 -0400"
      },
      "message": "THRIFT-6100: Ruby MemoryBufferTransport should respect frozen destination buffers\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "deb21c2cebe27d3455823346ef5eb386b2d0f464",
      "tree": "819d7e423255727a1775de2c9bbbde418f0ffb0d",
      "parents": [
        "35291f71024c537a024e531565dd8e5f12c4d436"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:44:28 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 15:30:59 2026 -0400"
      },
      "message": "THRIFT-6102: Ruby CompactProtocol should report malformed headers consistently\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "35291f71024c537a024e531565dd8e5f12c4d436",
      "tree": "652e9c9aee3b9f3eb78f915ec7c8a3f94f09b81f",
      "parents": [
        "9e96ff4a4500de09d4709afb9b451675315d2925"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:39:31 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 11:36:16 2026 -0400"
      },
      "message": "THRIFT-6106: Decode fixed-width values without undefined shifts\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "9e96ff4a4500de09d4709afb9b451675315d2925",
      "tree": "4da9d625edc1b60aac1013ec1628f522282c3d74",
      "parents": [
        "53276391d2ae45acba782eb5b51699e465751638"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:41:16 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 11:35:38 2026 -0400"
      },
      "message": "THRIFT-6104: Ruby native struct writing should accept Set subclasses\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "53276391d2ae45acba782eb5b51699e465751638",
      "tree": "a54f70b723425eebc9f2e6c8b932ef22c7c439e9",
      "parents": [
        "ae44493d2db21f672be7e7a93f0a74466e11a409"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:43:30 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 11:34:02 2026 -0400"
      },
      "message": "THRIFT-6101: Ruby CompactProtocol should use Ruby truthiness when writing booleans\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "ae44493d2db21f672be7e7a93f0a74466e11a409",
      "tree": "f5b8dc592e5e1db91f6b740f87065dccfac706ab",
      "parents": [
        "bc2dd8fdb5b2aeecaa66b737db7de6c019a452f2"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 13:37:24 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 11:32:48 2026 -0400"
      },
      "message": "THRIFT-6099: Ruby MemoryBufferTransport should reject invalid read lengths\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "bc2dd8fdb5b2aeecaa66b737db7de6c019a452f2",
      "tree": "ac31e219df7946f67923e3459ca5773d4c451bad",
      "parents": [
        "40d5a7ed9558adaacefc2aa4958fb6742d9b3f3f"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 19 11:47:08 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 20 11:31:50 2026 -0400"
      },
      "message": "THRIFT-6098: Verify Ruby SSL peers by default\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "40d5a7ed9558adaacefc2aa4958fb6742d9b3f3f",
      "tree": "e1cf50f6cfcb716de361b631ab68df4c48fc55e3",
      "parents": [
        "6351cd5a05ad04ce99469e33e633d9ce4b2f5654"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sat Jul 11 19:03:51 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 19 01:30:50 2026 +0200"
      },
      "message": "Link CHANGES.md 0.24.0 entries to their JIRA tickets\n\nSeveral 0.24.0 fixes were merged as direct commits rather than through\na GitHub PR, so the CHANGES.md generator (THRIFT-6077) had no PR to\nattribute them to. Adds the missing JIRA references (THRIFT-6083\nthrough THRIFT-6096) and upgrades existing bare PR-number entries to\ntheir JIRA ticket links.\n"
    },
    {
      "commit": "6351cd5a05ad04ce99469e33e633d9ce4b2f5654",
      "tree": "65702f37ebe01ca9049921a599cca2450ff3bce2",
      "parents": [
        "0187cf606bfac2064eb98475c467ae176e0c778e"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sat Jul 18 23:04:24 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 19 01:27:21 2026 +0200"
      },
      "message": "Validate the THeader transform count against the configured message size\nClient: go\n\nparseHeaders() read the wire-supplied transform count and sized two\nallocations from it before checking anything beyond count \u003e 0. Every other\nwire-supplied container count (list/set/map sizes across the binary,\ncompact, and JSON protocols) is already validated through\ncheckContainerSizeForProtocol() before use; the transform count is now\nrouted through the same check.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "0187cf606bfac2064eb98475c467ae176e0c778e",
      "tree": "8645c4d4ce1841ce5f626cc1adfc971fd307ab51",
      "parents": [
        "c6f6b484af1b0e42b12fbf99a779d96e76d6563a"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sat Jul 18 23:03:28 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sun Jul 19 01:27:14 2026 +0200"
      },
      "message": "Propagate TConfiguration through standard transport factory wrappers\nClient: cpp\n\nTFramedTransportFactory, THeaderTransportFactory, TBufferedTransportFactory,\nTPipedTransportFactory, TPipedFileReaderTransportFactory, TZlibTransportFactory,\nand THttpServerTransportFactory (base of both TWebSocketServer variants) all\nconstructed their wrapper transport without forwarding the TConfiguration\nalready attached to the transport being wrapped, so the wrapper picked up a\nfresh default TConfiguration instead of the caller\u0027s. This diverges from\ndoc/specs/thrift-tconfiguration.md, which documents that every layer of the\ntransport/protocol stack should share one TConfiguration instance by\nreference. Each factory now passes the wrapped transport\u0027s configuration\nthrough to its wrapper\u0027s constructor.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "c6f6b484af1b0e42b12fbf99a779d96e76d6563a",
      "tree": "4d60717a41870bbff284790a87c288b68e98a275",
      "parents": [
        "cdb7e5fbe8d5bd7c3dd6dae779d39974f65577f9"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Sat Jul 18 13:32:17 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 13:32:17 2026 +0200"
      },
      "message": "THRIFT-6075: Generate Equal method for Delphi Thrift structs (#3612)\n\nTHRIFT-6075: Generate Equal method for Delphi Thrift structs\nClient: delphi\nPatch: Jens Geyer\n\nCo-authored-by: Claude Code (misc models) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "cdb7e5fbe8d5bd7c3dd6dae779d39974f65577f9",
      "tree": "3cad67834668d8f3ce66661ea1a2e57d0521056a",
      "parents": [
        "09cd5f23b1e289b7a641dd0b8cf2cd890e3f4399"
      ],
      "author": {
        "name": "HTHou",
        "email": "haonan@apache.org",
        "time": "Thu Jul 16 11:36:27 2026 +0800"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Sat Jul 18 13:20:35 2026 +0200"
      },
      "message": "THRIFT-6097: Add rustls client and server support\n\nClient: rs\n\nCo-Authored-By: OpenAI Codex (GPT-5) \u003cnoreply@openai.com\u003e\n"
    },
    {
      "commit": "09cd5f23b1e289b7a641dd0b8cf2cd890e3f4399",
      "tree": "e98623ab24d3fcdfcb9c49daa16cfd7c36f5404b",
      "parents": [
        "ad471499638d63eff45e8d77e2f6dacb19aa00d2"
      ],
      "author": {
        "name": "HTHou",
        "email": "haonan@apache.org",
        "time": "Thu Jul 16 06:19:32 2026 +0800"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Thu Jul 16 00:53:47 2026 +0200"
      },
      "message": "THRIFT-5917: Remove Rust deprecation warning\n\nClient: rs\n\nGenerated-by: OpenAI Codex (GPT-5)\n"
    },
    {
      "commit": "ad471499638d63eff45e8d77e2f6dacb19aa00d2",
      "tree": "7234bb7d35de66358f73c6433ebe93006f27c3ae",
      "parents": [
        "bfa471bc2918dca8aa2c70eeb451646f7cbe5abb"
      ],
      "author": {
        "name": "Jens Geyer",
        "email": "jensg@apache.org",
        "time": "Sat Jul 11 18:14:08 2026 +0200"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Thu Jul 16 00:52:29 2026 +0200"
      },
      "message": "THRIFT-6082: Avoid reentrant Condition.notify() in TProcessPoolServer test shutdown\nClient: py\n\nThe SIGALRM-based shutdown handler in TestServer.py called\nserver.stop() from within the signal handler itself. When the\nalarm interrupts the main thread while it\u0027s blocked in\nTProcessPoolServer.serve()\u0027s Condition.wait(), the reentrant\nCondition.notify() call deadlocks: it waits for a wake\nacknowledgement that only the interrupted (and now unreachable)\nwait() call could ever send.\n\nTerminate the workers and exit the process directly instead of\ncoordinating through the Condition, since the process is being\ntorn down anyway.\n\nCo-Authored-By: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "bfa471bc2918dca8aa2c70eeb451646f7cbe5abb",
      "tree": "d3a265a2c14d4e0182ae01b654994ef97bdb280e",
      "parents": [
        "882bc8fe9100d49670a1a8f513066a599d6c6db7"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 13 23:06:34 2026 +0000"
      },
      "committer": {
        "name": "Jens Geyer",
        "email": "Jens-G@users.noreply.github.com",
        "time": "Wed Jul 15 23:24:57 2026 +0200"
      },
      "message": "Bump ws from 6.2.3 to 6.2.4 in /lib/js\n\nBumps [ws](https://github.com/websockets/ws) from 6.2.3 to 6.2.4.\n- [Release notes](https://github.com/websockets/ws/releases)\n- [Commits](https://github.com/websockets/ws/compare/6.2.3...6.2.4)\n\n---\nupdated-dependencies:\n- dependency-name: ws\n  dependency-version: 6.2.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "882bc8fe9100d49670a1a8f513066a599d6c6db7",
      "tree": "753cff3919e5bf65ca4253bfa1df7ad67dc4265a",
      "parents": [
        "4ade7f7ad807e5701721cb0e4b7275583406cdfb"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 06 18:19:00 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Mon Jul 13 19:05:33 2026 -0400"
      },
      "message": "THRIFT-6079: Add Rack HTTP server support for Ruby\n\nClient: rb\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    },
    {
      "commit": "4ade7f7ad807e5701721cb0e4b7275583406cdfb",
      "tree": "beb439f0f0905868801c51fb88cf874fc4e60463",
      "parents": [
        "b3fa3eef5756214ac4f507631f80e12d05348980"
      ],
      "author": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sat Jul 11 09:38:54 2026 -0400"
      },
      "committer": {
        "name": "Dmytro Shteflyuk",
        "email": "kpumuk@apache.org",
        "time": "Sun Jul 12 09:18:50 2026 -0400"
      },
      "message": "THRIFT-6081: Fix UUID handling in Python Header protocol\n\nClient: py\n\nCo-Authored-By: OpenAI Codex (GPT-5.4) \u003ccodex@openai.com\u003e\n"
    }
  ],
  "next": "b3fa3eef5756214ac4f507631f80e12d05348980"
}
