Releases: tinystruct/tinystruct
Release list
v1.7.35
v1.7.35
This release focuses on dependency maintenance, security hardening, documentation clarity, and a few robustness fixes around threading and action transport behavior.
Highlights
- Updated the framework version to 1.7.35 across the project, scripts, and docs.
- Clarified
@Actionbehavior for transport-neutral vs transport-specific actions in the skill documentation. - Improved concurrency robustness in scheduling and message queue code.
- Bumped several key dependencies and patched transitive CVEs.
- Added GitHub funding metadata and a CI build workflow.
- Cleaned up project hygiene and docs version references.
Key changes
- Improved guidance for
@Actionmodes:- transport-neutral actions are dual-mode by default
- HTTP- and CLI-specific actions are intentionally bound to the matching transport
- Fixed interrupt handling in
AlarmClockto restore the thread interrupt state correctly. - Refactored
DistributedMessageQueue.testing()to use cleaner producer/consumer methods with proper interruption-safe loops. - Updated the framework and distribution metadata for version 1.7.35.
- Added GitHub support links via
.github/FUNDING.yml. - Added CI workflow for Maven verification on push and pull request.
- Ignored
*.logfiles in.gitignore.
Dependency and security updates
- Netty BOM upgraded to 4.2.18.Final
- Lettuce upgraded to 7.8.0.RELEASE
- H2 upgraded to 2.5.252
- Mockito upgraded to 5.24.0
- Kafka transitive vulnerability patches:
- zstd-jni 1.5.7-20
- lz4-java 1.12.0
- snappy-java 1.1.10.8
- Reactor Core patched to 3.6.18
- Central publishing plugin upgraded to 0.11.0
Documentation updates
- Updated installation examples and version references from 1.7.34 to 1.7.35 in:
README.mdDEVELOPER_GUIDE.md- localized docs
- Removed stray BOM/encoding noise in docs and normalized header formatting.
Notes
- No major breaking API changes appear in this release.
- This is primarily a maintenance and hardening release with improved guidance and dependency hygiene.
If you want, I can also turn this into a shorter GitHub Release markdown version or a more “changelog-style” version.
v1.7.34
v1.7.34 Release Notes
This release improves CLI startup reliability and makes action argument metadata more robust, especially for enum-based collection parameters and generated dispatcher launchers.
Highlights
-
Improved dispatcher script generation and project setup guidance
- Clearer instructions for generating and maintaining
bin/dispatcherandbin/dispatcher.cmd - Better handling for Windows/Git Bash differences and classpath issues
- Documentation updates around launcher creation,
--importusage, and project layout expectations
- Clearer instructions for generating and maintaining
-
Better
@Actionargument metadata- Preserved declaration order, optional flags, and parameter types for command arguments
- Generic parameter types are now tracked for collection-based arguments such as
Set<Role>andList<Role>
-
Enum collection conversion support
- Comma-separated strings like
ADMIN,USERcan now convert directly intoSet<Role>orList<Role> - Invalid enum names fail clearly instead of being silently ignored
- Comma-separated strings like
-
Version updates
- Updated framework version references across documentation, scripts, and build metadata to
1.7.34
- Updated framework version references across documentation, scripts, and build metadata to
Details
Dispatcher and CLI improvements
The launcher scripts are now better documented and easier to maintain across environments. The framework encourages generating the project launcher rather than hand-writing it, ensuring the correct script is created for the active OS and consistent version metadata is preserved.
Action metadata and generic type support
@Action argument metadata now retains the Java parameter type, including generic information. This improves compatibility when actions accept typed collections, especially when arguments are bound from CLI strings or command metadata.
Enum conversion
Collection parameters that use enum elements can now accept comma-separated input values and convert them into strongly typed Java collections. This reduces boilerplate and makes CLI-driven action arguments more natural to use.
Upgrade notes
No breaking changes are required for typical applications. If you rely on generated dispatcher scripts, regenerate or refresh them from the project root after upgrading.
v1.7.33
v1.7.33 Release Notes
This release makes the default distribution smaller and improves database mapping flexibility.
Highlights
-
Smaller default JAR
- The dependency-bundled “fat JAR” is no longer built by default.
- Build the standalone CLI JAR when needed:
./mvnw package -Pstandalone # Windows mvnw.cmd package -Pstandalone - The standalone artifact is approximately 50 MB and is not included in the regular release.
-
Annotation-based database mapping
- Generate POJOs using
@Table,@Id, and@Columnannotations:bin/dispatcher generate --tables users --mapping annotation
- XML mapping remains the default and continues to be supported.
- Annotation mappings take precedence when both annotations and XML mappings exist.
- Mapping metadata is cached per class.
- Generate POJOs using
-
Automatic table creation
- Missing tables can be created automatically from class mappings:
database.autocreate=true - Disabled by default.
- Supports annotation and XML mappings across supported databases.
- Existing tables are never altered or migrated.
- Missing tables can be created automatically from class mappings:
-
CLI and documentation updates
- Updated the dispatcher scripts and application version to
1.7.33. - Updated installation instructions and localized documentation.
- Corrected Mockito dependency scope to
test. - Updated copyright notices to 2026.
- Updated the dispatcher scripts and application version to
Upgrade notes
The default Maven build now produces the regular library JAR only. If you depend on the bundled executable JAR, explicitly enable the standalone profile:
./mvnw package -Pstandalonev1.7.32
v1.7.32 Release Notes
This is a maintenance release focused on bug fixes, performance improvements, and stability enhancements.
Bug Fixes & Improvements
- Various stability and performance enhancements
- Ongoing improvements to the core framework
Version Information
- Previous version: v1.7.31
- Framework version: 1.7.32
Full Changelog: v1.7.31...v1.7.32
v1.7.31
v1.7.31 Release Notes
Major Features & Enhancements
PostgreSQL Schema & SSL Support
- Schema-Qualified Table Mappings: Full support for schema-qualified table mappings across all database types
- PostgreSQL Schema-Aware Code Generation: Enhanced code generator with schema support for PostgreSQL
- JDBC SSL Support: Resolved JDBC SSL certificate and key files from classpath for secure database connections
- SQL Script Parsing Improvements: Enhanced parsing for semicolons inside quoted strings, preventing false split points
Performance Optimization
- XML Mapping Caching: Added caching for XML mapping templates to reduce parsing overhead
- Class Path Caching: Implemented class path resolution caching for improved initialization speed
- SQL Injection Verdict Caching: Cached SQL injection analysis results for better query execution performance
- Database Result Parsing: Optimized repository result parsing and bulk row population for faster data operations
Distributed Lock & Queue Enhancements
- Watcher Polling Timeouts: Introduced polling timeouts for file lock acquisition to prevent indefinite blocking
- DistributedMessageQueue Reliability: Fixed lock acquisition, polling sleep, and state verification logic
- Improved Locking Mechanisms: Better handling of distributed locks with improved timeout and polling strategies
Code Quality & Maintenance
- Field & FieldInfo Optimization: Refactored with HashMap-based optimizations and improved code comments
- MCP Tool Schema Generation: Improved schema generation and request dispatching for MCP tools
- PostgreSQL Dispatcher Support: Added PostgreSQL generator support to the command dispatcher
- Unit Tests Enhancement: Updated JUnit tests for comprehensive coverage
Database & Repository Improvements
Repository Method Unification
- Consolidated Parameter Binding: Unified
setParameters()methods inAbstractDataRepositoryfor all repository types - Generic Whitelist-Based Updates: Implemented generic parameter-driven update methods in
AbstractDataRepositoryandRedisServer - Type Support: Fixed
longtype handling in parameter-binding loops across MySQL, SQLite, and SQL Server implementations
Bug Fixes
- Missing Long Type Support: Resolved missing
longtype support in MySQL, SQLite, and SQL Server parameter binding - Prepared Statement Binding: Improved SQL Server prepared statement binding with proper parameter order
Version Updates
- Core framework version bumped from 1.7.30 to 1.7.31
- Updated in pom.xml and related configuration files
Technical Details
Key Commits:
- Schema-qualified table mappings and SSL resource resolution
- Performance improvements across data, locking, and MCP modules
- Caching layers for XML templates, class paths, and SQL injection verdicts
- Field and FieldInfo optimization with HashMap refactoring
This release focuses on PostgreSQL enhancements, performance optimization through strategic caching, improved distributed locking mechanisms, and better code quality across the framework.
v1.7.30
v1.7.30 Release Notes
Major Features
PostgreSQL Database Support
- Added full support for PostgreSQL database operations
- Introduced
PostgreSQLServerrepository implementation with complete CRUD operations - Added
PostgreSQLGeneratorfor automatic code generation from PostgreSQL tables - PostgreSQL is now available as a
Type.PostgreSQLoption in the repository type enum - Enhanced connection manager with intelligent default port detection (3306 for MySQL, 5432 for PostgreSQL, 1433 for SQL Server)
Database & ORM Improvements
Repository Interface Enhancements
- Added new
update(Field ready_fields, String table, Set<String> onlyFields)method to the Repository interface for selective field updates - Allows developers to update specific fields while keeping others unchanged, preventing accidental overwrites
- All repository implementations now support selective field updating
Parameter Type Handling
- Enhanced
setParameters()methods inAbstractDataRepositoryto properly handlelongtype fields - Improved database type mapping and parameter binding across all database implementations
SQLite & SQLServer Updates
- Added support for
longdata type in SQLite operations - Updated SQLServer update logic to use prepared statements with proper parameter binding
- Improved error handling and type conversion in all repository implementations
Security Enhancements
Deserialization Protection
- Added
ObjectInputFiltertoDistributedHashMapto prevent gadget-chain deserialization attacks (CWE-502) - Implemented allow-list of safe queue classes that can be deserialized
- Protects against unsafe autoType features by restricting class instantiation during object deserialization
JSON Processing & Parsing
Nested Structure Protection
- Added
ParseContextclass to track nesting depth for JSON parsing - Implements maximum nesting depth limit (default: 1000) to guard against StackOverflowError
- Prevents both maliciously deep and accidentally malformed JSON input
- Enhanced
BuilderandBuildersclasses to share a singleParseContextacross mutually-recursive parsing operations
Code Generation
- New PostgreSQL-specific code generator for automatic entity class generation
- Generates proper mapping files for PostgreSQL-specific data types
- Supports PostgreSQL-specific type conversions (timestamp, character varying, bytea, etc.)
Dependencies Updates
- SQLite JDBC: upgraded from 3.53.2.1 to 3.53.4.0
- PostgreSQL JDBC: added version 42.7.13
- Maven Surefire Plugin: added version 3.2.5 for improved test execution
Testing
- Added comprehensive unit tests for PostgreSQL functionality
- Added tests for MySQL, SQL Server, and SQLite operations
- New tests for PostgreSQL code generator functionality
- Enhanced Builder and Builders tests for Unicode character handling
Documentation Updates
- Updated all README files (English and multilingual) with PostgreSQL support documentation
- Updated developer guide with PostgreSQL dependency information
- Updated SKILL.md with PostgreSQL MCP server support starting from v1.7.30
- Updated all configuration examples to reflect PostgreSQL as an available database option
Bug Fixes & Quality Improvements
- Fixed line ending issues (CRLF/LF normalization) across multiple repository files
- Improved Unicode character handling in JSON serialization
- Enhanced field type mapping across different database systems
- Better handling of NULL values in result set processing
Version Updates
- Core framework version bumped from 1.7.29 to 1.7.30
- Updated in multiple configuration locations: pom.xml, dispatcher scripts, and ApplicationManager
v1.7.29
Release Notes for v1.7.29
Security & Authentication
- Enhanced JWT Configuration: Separated the symmetric secret and asymmetric public key configurations. You can now cleanly use
jwt.secretfor HMAC secrets (with a configurablejwt.secret.format) andjwt.key.publicfor RSA public keys.
Server & Network Enhancements
- Domain Logic Decoupling: Removed hard-coded or specific domain logic from
HttpServerto allow for more agnostic host processing. - Flexible Cookies: Removed strict domain limitations for cookie setting, providing greater flexibility when deploying across varying environments.
- Path Processing Optimization: Simplified the processing logic for raw request paths, making routing more robust.
Examples & Documentation
- Sample Update: Minor updates to the
SampleMCPServerApplication.javareference implementation.
v1.7.28: fix(security): prevent path traversal and refine HTTP server controls
- Enhance path normalization in `Dispatcher` and `HttpServer` to properly validate base directory boundaries and prevent directory traversal attacks. - Update `sanitizeUri` in `HttpServer` to return a normalized `Path` and support longer URIs (up to 2048 chars). - Hide sensitive exception details in HTTP 500 responses unless the environment is set to 'development'. - Mark session cookies as `Secure` when requests are served over HTTPS. - Update `maven-assembly-plugin` to version 3.7.1. - Bump project version to 1.7.28.