Published middleware  / field guide
Practitioner field guide · 11 October 2026

What the vendor cannot host, you will maintain

Ten years of Alibaba's published middleware, reconstructed from Maven Central upload dates, GitHub advisories, pull-request history, in-repository design proposals and one archive notice. The record shows which of a large publisher's components keep being maintained, which quietly stop, and the property that predicts the difference before you take the dependency.

36 primary artefacts 11 published components 6 advisories Evidence through October 2026 Read: 33 min
01

The territory

The question is not whether a published component is good. It is who will still be maintaining it in five years, and whether that answer depends on anything its publisher cares about.

Every system delegates part of itself to code a large company wrote, published and gave away. The adoption decision is usually made on merit: benchmarks, stars, whether the interface is pleasant. Five years later the question that actually matters is a different one. Somebody has to ship the fix for the next critical defect, follow the language and framework underneath it, and answer the issue you filed. The published artefact record tells you who that will be, and it tells you years in advance, if you read the right fields.

Alibaba is the clearest case available, because it published most of a service-governance stack in the open over a decade and every artefact carries a date. A JSON serializer from 2012. An RPC framework handed to the Apache Software Foundation. A flow-control library written for a shopping peak that lands on the same calendar day every year. A registry and configuration server. A distributed transaction coordinator whose own README traces it from an internal project in 2014 to a cloud product in 2016 to the Apache Incubator in October 2023. A Kubernetes scheduling layer that pushes resource policy into the container runtime. Read together, by upload date rather than by README, these components have not shared a fate.

Three of them stopped. The fastjson repository went read-only on 29 July 2026, nine years into an unbroken chain of deserialization advisories, the last of which, CVE-2026-16723, critical at CVSS 9.0, still records no patched version. Sentinel, the in-process flow-control library, went from twelve releases in 2019 to one in each of 2023, 2024 and 2025. The specification that was supposed to move its policy out of the process, OpenSergo, has not had a commit since 29 March 2023, and Sentinel's README still points readers to it. Meanwhile Nacos, the registry and configuration server, has shipped releases in every one of the last nine years and in 2026 is being extended into an agent and MCP registry.

The property that separates them is not popularity and it is not quality. It is whether the publisher can run the thing for you. Nacos, the broker and the transaction coordinator are servers, and a server can be sold as a managed service; Alibaba sells exactly that, and the Nacos README points at it in the quick start. A serializer and a flow-control SDK run inside your process, where nobody can operate them on your behalf. That is the asymmetry this guide is about, and the rest of the page is the evidence, the decisions it should change, and the failure modes it produces.

4 yr 2 mo
Gap between fastjson 1.2.83 and the final 1.2.84, published the day the repository was archived
12 to 1
Sentinel releases per year, 2019 against 2023, 2024 and 2025
9 years
From the first autoType advisory to the last one, which has no fix
493
Sentinel pull requests closed without being merged

Figure 1 · The same function, three distances from your code

Inside your process

Serializer

Flow-control SDK

A server, yours or rented

Registry and config

Broker, coordinator

The node's runtime

Scheduler and runtime hooks

Your platform team operates it,
upstream follows the runtime.

The publisher can host it,
so the publisher keeps shipping it.

You operate it.
Nobody can sell you the operating.

Inside your process

Serializer

Flow-control SDK

A server, yours or rented

Registry and config

Broker, coordinator

The node's runtime

Scheduler and runtime hooks

Your platform team operates it,
upstream follows the runtime.

The publisher can host it,
so the publisher keeps shipping it.

You operate it.
Nobody can sell you the operating.

What to notice: the distance from your process decides who can be paid to operate the component, and therefore who will still be maintaining it. Reconstructed from the repository and artefact record listed in the evidence wall.
Diagram source
Scope

This guide covers components a publisher released for other people to run, read through Alibaba's Java and Kubernetes middleware between 2012 and October 2026. It does not cover Alibaba's internal systems, its databases, its model stack, or the operation of Alibaba Cloud itself. It carries no production telemetry: no request rates, no utilisation, no incident impact. This session's network policy reached GitHub, Maven Central and the Apache archives and was refused by every engineering blog, documentation site, video host and preprint server, so the blog, talk and paper tiers of the evidence wall are empty on purpose. What remains is dated, primary and checkable, and it is enough for the argument this page makes.

02

How it is actually built

What an adopter of this stack ends up running, and the one structural feature that explains which parts survived.

Assemble the published components the way the publisher's own glue library assembles them and you get three layers. Inside the application process: an RPC client, a serializer, a flow-control SDK holding rules in memory, and a transaction resource manager. Outside it, as servers: a registry that is also a configuration store, a transaction coordinator, a message broker. Below both, on the node: a Kubernetes scheduler and an agent that enforces quality-of-service classes per container. Alibaba's Spring Cloud Alibaba README names exactly this set, Sentinel, Nacos, RocketMQ and Seata, plus three cloud-only services, as "a one-stop solution for application development".

The structural feature worth noticing is that every dynamic behaviour in the first layer is a subscription to the second. Sentinel's rules arrive from a datasource, and the datasources people actually use are the registry and configuration server. Dubbo's addresses arrive from the registry. The transaction manager's decisions arrive from the coordinator. The in-process libraries are, functionally, caches with enforcement attached. That is a reasonable design, and it has a consequence nobody wrote down: the server is load-bearing for every library, while no library is load-bearing for the server. When attention became scarce, the direction of that dependency decided what kept being maintained.

The second thing to notice is that the same function keeps migrating outward. Configuration distribution moved from the client polling over HTTP to a server pushing over a persistent connection: Nacos 2.0.0, on 20 March 2021, "add Grpc as the translating to replace HTTP between client and server". Service discovery moved from registering every interface to registering the application instance, which Dubbo's own migration document frames as a pure scale decision. Resource policy moved from a daemon on the node to the container runtime itself: Koordinator's proposal of 8 June 2023 says its two existing modes, standalone and proxy, "have some constraints" and proposes subscribing to pod and container lifecycle events from containerd or CRI-O instead, so that policy can be applied "before pod's status become running".

Each of those moves is a transfer of responsibility from the thing you deploy to the thing somebody operates. That is the mechanism behind the page's argument, stated as the publishers state it: outward migration is sold as performance, scale or convenience, and it also happens to move the code to where a vendor can charge for running it.

Figure 2 · The published stack as an adopter assembles it

Node, platform team

Servers, you run them or rent them

Application process, you deploy this

instance-level
registration

rule datasource

branch register
and commit

QoS applied before start

Dubbo client

Sentinel SDK
rules held in memory

fastjson2
autoType off by default

Seata resource manager

Nacos
registry and config

Seata coordinator

RocketMQ broker

Koordinator scheduler
and koordlet NRI plugin

Node, platform team

Servers, you run them or rent them

Application process, you deploy this

instance-level
registration

rule datasource

branch register
and commit

QoS applied before start

Dubbo client

Sentinel SDK
rules held in memory

fastjson2
autoType off by default

Seata resource manager

Nacos
registry and config

Seata coordinator

RocketMQ broker

Koordinator scheduler
and koordlet NRI plugin

What to notice: every arrow of dynamic behaviour runs from the process to the server, and none runs the other way. Reconstructed from Spring Cloud Alibaba, Nacos, Dubbo and Seata.
Diagram source

Inside the process

Serializer, RPC client, flow-control SDK, transaction resource manager. Upgrades are your deploys, defects are your CVEs, and the end of maintenance is your migration project. Nobody can be paid to operate this layer for you.

Read from: fastjson2, Sentinel, Dubbo

A server you run or rent

Registry, configuration store, coordinator, broker. The publisher can host it, and does: the Nacos quick start calls the hosted route "the easiest and most convenient way to start Nacos". The paid edition is where the governance features live.

Read from: Nacos, RocketMQ, MSE feature list

The node's runtime

Scheduler plus a per-node agent that sets limits through the container runtime. Owned by a platform team, and tracked upstream because the interfaces it hooks, CRI and NRI, belong to the runtime rather than to the publisher.

Read from: Koordinator proposals

03

The decisions that matter

Four forks where this stack went one way, with the stated reason and the condition that flips the answer for a team deciding today.

Decision: where does traffic policy live, in the library or in a control plane?

Chosen
  • Rules in the application process, Sentinel holding them in memory and pulling changes from a datasource
  • Enforcement is local, so it survives the control plane being down and costs no extra hop
Rejected in practice
  • A vendor-neutral governance specification with a control plane, which is what OpenSergo was announced to be
  • Its repository has 56 commits, no releases, and no commit since 29 March 2023, while Sentinel's README still refers readers to it
Flips when
  • You need a policy change to take effect without a deploy across many languages, and you can staff a control plane; then the library becomes the data plane and the rules belong outside it
  • Or when the publisher sells the governance layer, in which case the free library is the part they are least motivated to extend

Decision: register every interface, or register the application instance?

Chosen
  • Dubbo 3 registers the application instance, and by default registers both models at once during migration
  • The project's own words: "the only consideration for the decision is performance"
Rejected
  • Keeping interface-level registration, which Dubbo explicitly says is fine if "your cluster size is not large, and you have not encountered any performance issues such as address pushing"
Flips when
  • Registry push load spikes, which is a function of interfaces multiplied by instances rather than of request volume
  • Note the transition cost the document admits: dual registration and dual subscription are the default, and the framework may later switch to single registration, so the migration has an end state you do not control

Decision: who enforces per-container resource policy on a node?

Chosen
  • A plugin inside the container runtime, through the Node Resource Interface, proposed 8 June 2023 and reviewed in the repository
  • It can act "before pod's status become running" and can be deployed "without restart"
Rejected
  • The two earlier placements, a standalone daemon and a CRI proxy, which the proposal says both "have some constraints"
Flips when
  • Your runtime does not expose the interface, or you cannot accept a plugin in the runtime's failure domain; then the daemon returns, with its late-enforcement window as the accepted cost

Figure 3 · The adoption test, applied before the first import

no

yes

yes

no

yes

no

Does it run inside
your process?

Can the publisher
host it for you?

Does it substitute for
something the publisher sells?

Adopt. The hosted option
is the maintenance plan.

Adopt, and fund
the operator role yourself.

Budget the exit now:
seam, version pin, owned fork.

Check release cadence
and bus factor first.

no

yes

yes

no

yes

no

Does it run inside
your process?

Can the publisher
host it for you?

Does it substitute for
something the publisher sells?

Adopt. The hosted option
is the maintenance plan.

Adopt, and fund
the operator role yourself.

Budget the exit now:
seam, version pin, owned fork.

Check release cadence
and bus factor first.

What to notice: the terminal nodes are commitments of your budget, not opinions about the code. Derived from the fates recorded in the numbers table.
Diagram source
DecisionChosenRejectedBecauseEvidence
Serializer default for types named in the payloadDeny by default, in the successor libraryA maintained whitelist, which 1.x usedFour advisories in nine years, each defeating the previous restrictionfastjson2 README, 2026
Config and discovery transportServer push over gRPCClient polling over HTTPStated as a protocol replacement with no published figureNacos 2.0.0, 2021-03-20
Transaction coordinationA separate coordinator server, now at a foundationKeeping it an internal product onlyInternal project 2014, cloud product 2016, open source 2019, Apache Incubator October 2023Seata README, 2026
Broker evolution governanceA public proposal register with status columnsRoadmaps in blog posts70 proposals, each marked accepted, active and released or not, including one for the next decade's architecture that is not releasedRocketMQ RIP index, 2026
Keeping an in-process library current with its ecosystemMaintenance branch onlyMerging support for the current Servlet APIThree attempts since issue 2998; the 2026 attempt was rebased onto the 1.8 branch, conflicted, and closed unmerged on 16 June 2026Sentinel PR 3618, 2026
Where governance features shipThe paid editionThe open libraryGrayscale release and service warm-up are named as enterprise Microservices Engine featuresSpring Cloud Alibaba README, 2026
04

What broke in production

Four failure classes, read from the advisory record and the artefact timeline, because no incident review from the publisher was reachable.

A word about the evidence before the cards. Alibaba does not publish post-incident reviews on any host this hunt could reach, so none of the entries below carries a duration, a customer count or a detection delay. What is published, dated and specific is the advisory record: severity, affected version range, patched version, and in two cases a statement about exploitation in the wild. Treat the blast radius field as what it says, unpublished, and treat that absence as the finding it is. A library distributed to tens of thousands of applications has no way to tell you how many of them were hit, which is itself an argument for owning the inventory yourself.

Postmortem

The payload was allowed to name the code

AssumptionA JSON parser parses data. Convenience features that let a document name its own Java type are a usability nicety, not an execution path.
What happenedAn attacker-supplied document carrying an @type key names a class; the parser resolves it and calls public methods on the instance, and a field value drives a JNDI lookup to a server the attacker controls. The advisory for CVE-2025-70974 describes exactly this chain and rates it CVSS 10.0.
Blast radiusUnpublished. The advisory states only that the flaw was exploited in the wild from 2023 through 2025, and that it stems from an incomplete fix for CVE-2017-18349.
FixA different library. The successor disables the feature by default, keeps no hardcoded whitelist, and declines to guarantee compatibility with 1.x.
Design ruleNo wire format may name a type unless the set of nameable types is a closed list you ship and review. If a format can name code, it is an interface to your classpath, and it needs the review an interface gets.
Postmortem

Every fix became the next advisory's lower bound

AssumptionThe dangerous behaviour can be fenced off incrementally: block the gadget, publish, move on.
What happenedRead the ranges in order. CVE-2017-18349 affects up to 1.2.24 and is patched in 1.2.31. CVE-2022-25845 affects 1.2.25 upward and is patched in 1.2.83, by "bypassing the default autoType shutdown restrictions". CVE-2026-16723 affects 1.2.68 to 1.2.83 and records no patch. Each fix defined where the next report started.
Blast radiusUnpublished per incident. The shape is visible in the release record instead: 47 releases of the 1.x line in 2020 alone, then nothing between May 2022 and July 2026.
FixA rewrite with the default inverted, and eventually an archive notice. The last 1.x artefact, 1.2.84, was published at 07:24 on 29 July 2026, the same day the repository went read-only.
Design ruleCount the advisories whose affected range begins at a previous patch version. Two is a pattern and three is a design verdict: the feature has to be removed or defaulted off, and no amount of maintenance substitutes for that.
Postmortem

The control plane recognised its own peers by a header

AssumptionServer-to-server traffic inside the cluster is trusted, and can be told apart from user traffic cheaply.
What happenedWith authentication enabled, the registry's auth filter skipped its checks for requests that identified themselves as peer servers, keyed on the user-agent header. A request with no credentials was rejected; the same request with the user agent set to Nacos-Server was accepted. The advisory's impact line: "This issue may allow any user to carry out any administrative tasks on the Nacos server".
Blast radiusUnpublished. The exploit-prediction score recorded on the advisory is 83.483%, in the 100th percentile, which measures likelihood of exploitation rather than observed impact.
FixPatched in 1.4.1, with a second advisory the same day for unauthenticated operations, and a hardcoded-credentials advisory against the client the following year.
Design ruleMoving control out of the process creates a second authentication problem, server to server, that is not the one your users go through. It needs a real identity, a certificate or a signed token, because anything the client can set is something the attacker can set.
Postmortem

The dependency failed slowly, and nothing paged

AssumptionA component backed by a company with a large engineering organisation, 23,000 stars and a decade of production use will keep up with the ecosystem it plugs into.
What happenedSentinel's releases fell to one a year from 2023. Its 2.0 line never left the alpha artefact dated 14 February 2023. Support for the current Servlet API, needed by every application on the current major Spring release, was attempted three times and was still unmerged in June 2026, with the maintainer noting that "active development is currently on the 1.8 branch". 713 issues and 168 pull requests are open, the oldest pull request filed by the project's own lead maintainer on 17 July 2019.
Blast radiusNot an outage, which is the point. The cost lands as an upgrade you cannot do, a framework version you cannot adopt, and a security fix nobody is going to backport.
FixNone published. The successor story was the OpenSergo specification, whose repository stopped in March 2023 with no releases.
Design ruleTreat your dependency's maintenance as an availability dependency with no service-level objective. Measure it the way you measure anything else: releases per year, open pull requests, age of the oldest one, and whether the current language and framework versions are supported on the main branch.

Figure 4 · The path a type-naming payload takes

Server the attackerrunsType resolverparseObjectYour HTTP endpointAttackerServer the attackerrunsType resolverparseObjectYour HTTP endpointAttackerSame chain reported in 2018,2022 and 2026body containing a type-namingkeyparse the bodyresolve the class named in thedatacall public setters onthe instanceJNDI lookup driven by a fieldvalueremote object, then code
Server the attackerrunsType resolverparseObjectYour HTTP endpointAttackerServer the attackerrunsType resolverparseObjectYour HTTP endpointAttackerSame chain reported in 2018,2022 and 2026body containing a type-namingkeyparse the bodyresolve the class named in thedatacall public setters onthe instanceJNDI lookup driven by a fieldvalueremote object, then code
What to notice: the serializer is the one component in the request path that takes instructions from the payload, which is why its defects are remote code execution rather than a parse error. Reconstructed from CVE-2025-70974 and CVE-2017-18349.
Diagram source

Figure 5 · Nine years of one library's advisory chain

2018-10CVE-2017-18349,9.8up to 1.2.24fixed in 1.2.312022-06CVE-2022-25845,8.1from 1.2.25fixed in 1.2.832026-01CVE-2025-70974,10.0below 1.2.48exploited 2023 to20252026-07CVE-2026-16723,9.01.2.68 to 1.2.83no fix recordedarchived 07-29Each patch set the next advisory's lower bound
2018-10CVE-2017-18349,9.8up to 1.2.24fixed in 1.2.312022-06CVE-2022-25845,8.1from 1.2.25fixed in 1.2.832026-01CVE-2025-70974,10.0below 1.2.48exploited 2023 to20252026-07CVE-2026-16723,9.01.2.68 to 1.2.83no fix recordedarchived 07-29Each patch set the next advisory's lower bound
What to notice: the final entry has no patched version, and the repository went read-only six days after it was published. Dates from the GitHub Advisory Database and the Maven Central listing.
Diagram source
One honest complication

The advisory for CVE-2026-16723 records no patched version, and a 1.2.84 artefact exists on Maven Central dated the same day the repository was archived. No artefact this hunt could reach connects the two: there are no release notes, no repository left to hold them, and the advisory was last updated on 7 August 2026 still showing no fix. Whether 1.2.84 addresses that advisory is open. For an adopter the practical reading is worse than either answer: the final state of a 15-year dependency is a jar with no accompanying record.

05

Numbers you can plan against

These are record numbers, counted from artefact listings and advisory fields. None of them is production telemetry, and the difference matters.

MeasureValueComponentContextAs ofSource
Releases per year, in-process flow control7, 12, 2, 3, 3, 1, 1, 1, 1sentinel-core2018 through 2026, final releases only, 2026 partial2026-10-11Maven Central
Releases per year, registry and config server9, 12, 7, 6, 7, 7, 9, 9, 10nacos-apiSame years, same counting method2026-10-11Maven Central
Releases per year, RPC framework7, 3, 14, 17, 24, 9, 7, 1org.apache.dubbo:dubbo2019 through 2026; the peak is the Dubbo 3 push2026-10-11Maven Central
Releases of the 1.x serializer in its worst year47com.alibaba:fastjson 1.x2020, against 4 in 2015 and 0 in 2023 to 20252026-10-11Maven Central
Advisory range that has no patch1.2.68 to 1.2.83com.alibaba:fastjsonCritical, CVSS 9.0, default configuration, no AutoType needed2026-08-07CVE-2026-16723
Advisories naming the serializer that are filed against other people's products12 of 20Downstream applicationsDated 2024-02-29 to 2025-11-25, long after the library's own fixes2026-10-11Advisory search
Open pull requests, and age of the oldest168, oldest 2019-07-17SentinelOldest was filed by the project's lead maintainer2026-10-11GitHub
Pull requests closed without merging493SentinelIncludes a batch of 2018 and 2019 contributions closed in late 20252026-10-11GitHub
Days without a commit, governance specificationabout 1,290OpenSergo specificationDerived: 2023-03-29 to 2026-10-11, still linked from Sentinel's README2026-10-11GitHub
Public proposals, and the share marked released70 listedRocketMQIncludes RIP-11, the next decade's architecture, accepted and active but not released2026-10-11RIP index
Lifecycle of one component, internal to foundation9 yearsSeataTXC 2014, cloud product 2016, open source 2019, Apache Incubator 2023-102026-10-11Seata README

Figure 6 · Releases per year: the library against the server

Bar chart comparing yearly release counts of sentinel-core and nacos-api from 2018 to 2026 04 812 20182019 20202021 20222023 20242025 2026 sentinel-core, the in-process library nacos-api, the server
What to notice: the two lines of work started within two months of each other in 2018 and diverged permanently after 2019. Counted from the Maven Central listings for sentinel-core and nacos-api, checked 11 October 2026. 2026 is a partial year.
Read these carefully

Release counts measure published artefacts, not value, and a stable library can be healthy on one release a year. They are used here only to compare projects over the same period and against their own history, and they agree with the independent signals in the same repositories: open pull-request age, branch policy, and whether the current framework version is supported. Three figures on this page are vendor claims with no measurement attached: that the flow-control library "covered almost all the core-scenarios in Double-11 (11.11) Shopping Festivals in the past 10 years", that the broker has "trillion-level capacity", and the "+30% Performance" line in the RPC framework's version table. Treat them as statements about intent. The quantities nobody has published, and which you therefore have to measure yourself, are the ones that would decide an adoption: request rates these components actually sustain, the utilisation gain the node layer delivers, and how many applications were affected by any of the advisories above.

06

The evidence wall

Every source behind this page, graded. The blog, talk and paper tiers are empty because this session's network policy refused every host that carries them.

Postmortem GitHub Advisory DB2026-07

CVE-2026-16723: fastjson remote code execution

Critical at CVSS 9.0 against versions 1.2.68 to 1.2.83, exploitable in the default configuration with no unsafe feature enabled, and no patched version recorded as of the 7 August 2026 update.

Carry forwardAn in-process dependency can reach end of life while still holding an unfixed critical defect, and the remedy becomes your migration project.
github.com/advisories/GHSA-crf3-v9rr-v7hj
Postmortem GitHub Advisory DB2026-01

CVE-2025-70974: autoType mishandled, CVSS 10.0

States that the defect stems from an incomplete fix for CVE-2017-18349 and that it was exploited in the wild from 2023 through 2025, three years before this advisory was published.

Carry forwardThe gap between exploitation and advisory can be years, so your inventory of what you ship is worth more than any feed you subscribe to.
github.com/advisories/GHSA-jm7w-5684-pvh8
Postmortem GitHub Advisory DB2022-06

CVE-2022-25845: the default restriction bypassed

High at CVSS 8.1, affecting 1.2.25 upward and patched in 1.2.83. The published workaround for anyone who could not upgrade was to turn on an opt-in safe mode.

Carry forwardA workaround that is opt-in is a statement that the default is unsafe. Read it as a design verdict, not a mitigation.
github.com/advisories/GHSA-pv7h-hx5h-mgfj
Postmortem GitHub Advisory DB2018-10

CVE-2017-18349: the first link in the chain

Critical at CVSS 9.8, up to version 1.2.24, patched in 1.2.31. The description runs through a third-party web framework, which is how most organisations met the library in the first place.

Carry forwardTransitive serializers are the ones you do not know you run. Inventory by artefact, not by the dependencies you chose deliberately.
github.com/advisories/GHSA-xjrr-xv9m-4pw5
Postmortem GitHub Advisory DB2021-04

CVE-2021-29441: authentication bypass by spoofing

The registry's auth filter skipped its checks for requests claiming to be peer servers, keyed on the user-agent header. Patched in 1.4.1. The recorded exploit prediction score is 83.483%.

Carry forwardPeer authentication is a separate problem from user authentication, and it cannot be solved with a field the caller controls.
github.com/advisories/GHSA-36hp-jr8h-556f
Postmortem GitHub Advisory DB2021 to 2023

Advisory search: the registry's seven advisories

Two authentication bypasses on the same day in April 2021, incorrect access control in August 2021, cross-site scripting in March 2022, hardcoded credentials in the client in July 2022, unsafe deserialization in the Spring integration in August 2023.

Carry forwardPulling control out of the process does not remove risk, it relocates it to a new trust boundary that needs its own design.
github.com/advisories?query=nacos
Source Alibaba2026-07

fastjson repository, archive notice

"This repository was archived by the owner on Jul 29, 2026. It is now read-only." 25,600 stars, 3,983 commits, and an About line recommending the successor library.

Carry forwardAn archive notice is the clearest maintenance signal a publisher ever sends, and it arrives after the decision that produced it.
github.com/alibaba/fastjson
Source Maven Central2012 to 2026

com.alibaba:fastjson artefact listing

First upload 7 February 2012. The 1.x line peaks at 47 releases in 2020, stops at 1.2.83 on 22 May 2022, and resumes once with 1.2.84 on 29 July 2026. The 2.x compatibility artefact still publishes to the same coordinate, most recently on 2 September 2026.

Carry forwardA coordinate can outlive its repository. Pinning a version is not the same as knowing who maintains it.
repo1.maven.org/maven2/com/alibaba/fastjson/
Source Maven Central2026-07-29

The 1.2.84 directory, timestamped 07:24

All 24 files of the final 1.x release, jar, sources, javadoc, pom, signatures and digests, carry the same timestamp on the day the repository was archived.

Carry forwardArtefact timestamps answer questions release notes will not, and they survive the repository being closed.
repo1.maven.org/maven2/com/alibaba/fastjson/1.2.84/
Source Alibaba2026-10

fastjson2 README, defaults table

AutoType "Disabled by default (more secure)" against "Enabled with whitelist" in 1.x, no hardcoded whitelist, group identifier changed, and on the compatibility package, "100% compatibility is not guaranteed".

Carry forwardWhen the fix is a new coordinate with changed defaults, the upgrade is a code change. Price it as one at adoption time.
github.com/alibaba/fastjson2
Source Advisory search2024 to 2025

Twelve advisories against other people's applications

Of 20 advisories matching the serializer's name, 12 are filed against downstream products, dated between February 2024 and November 2025, each described as a deserialization defect in that product rather than in the library.

Carry forwardAn in-process dependency's defects are reported as your product's vulnerabilities, on a timeline you do not control.
github.com/advisories?query=fastjson
Source Maven Central2022 to 2026

The successor publishing to the predecessor's coordinate

The 2.x compatibility artefact is released under the archived project's group and artefact identifiers, 23 times in 2022 and five times in 2026, most recently on 2 September 2026, a month after the repository went read-only.

Carry forwardA dependency scanner that keys on coordinates will not notice the handover. Check the project behind the coordinate, not only the version.
repo1.maven.org, com.alibaba:fastjson versions
Vendor Alibaba2026-10

Sentinel README

Claims the library "covered almost all the core-scenarios in Double-11 (11.11) Shopping Festivals in the past 10 years", points at the hosted Microservice Engine and an enterprise edition, and refers readers to the OpenSergo specification as the community's direction.

Carry forwardA README is a statement of intent with no date on it. Check every forward reference it makes against that project's commit history.
github.com/alibaba/Sentinel
Source Maven Central2018 to 2026

sentinel-core artefact listing

Seven releases in 2018, twelve in 2019, then two, three, three, and one in each of 2023, 2024 and 2025. The only 2.0 artefact is an alpha dated 14 February 2023.

Carry forwardA version line that stalls at alpha for three years is a roadmap that has been withdrawn without an announcement.
repo1.maven.org/maven2/com/alibaba/csp/sentinel-core/
Source Alibaba2023 to 2025

Sentinel commit history

The newest commit removes blank lines, dated 16 October 2025. Before it, one message fix in September 2024. The last substantive cluster is August 2023, adding a zero-trust implementation and an xDS datasource.

Carry forwardRead the newest three commit messages before adopting. Cosmetic commits at the top of a branch are a maintenance signal.
github.com/alibaba/Sentinel/commits/master
Source Alibaba2019 to 2026

Sentinel open pull requests, oldest first

168 open. The oldest, adding exception logging to the tracer, was filed by the project's lead maintainer on 17 July 2019 and is still open. The next two date from August 2019 and May 2020.

Carry forwardThe age of the oldest open pull request from a maintainer is a better maintenance metric than the issue count.
github.com/alibaba/Sentinel open pull requests
Source Alibaba2025-10

493 pull requests closed unmerged

Including a batch of 2018 and 2019 contributions, among them adapter modules and low-memory metric implementations, closed on 9 October 2025, six years after they were filed.

Carry forwardA mass closure of stale contributions is a declaration about capacity. It is also the moment to check whether you are carrying any of those patches locally.
github.com/alibaba/Sentinel closed pull requests
Source Alibaba2026-06

Pull request 3618: Jakarta Servlet 6 adapter, closed unmerged

Adds a module for the Servlet API that current Spring releases require, behind a Java 17 profile. It replaced an earlier attempt that was also closed without merging. The maintainer moved its base to the 1.8 branch because "active development is currently on the 1.8 branch", after which it was unmergeable.

Carry forwardAsk which branch takes new work. If the answer is a maintenance branch, your framework upgrade path runs through a fork.
github.com/alibaba/Sentinel/pull/3618
Decision record OpenSergo2022 to 2023

OpenSergo specification repository

"An open, language-agnostic cloud-native service governance specification that is close to business semantics." 56 commits, 792 stars, no releases, and the contributors and used-by sections empty.

Carry forwardA specification with no implementations listed and no releases is a position paper. Do not plan a migration against one.
github.com/opensergo/opensergo-specification
Source OpenSergo2023-03

Specification commit history, stopped

Newest commit 29 March 2023, a typo fix. The substantive drafts, traffic routing, fault tolerance, traffic lane and database governance, all land between June 2022 and January 2023.

Carry forwardThe last commit date of the thing your dependency points to as its future is part of your dependency's risk profile.
github.com/opensergo/opensergo-specification/commits/main
Vendor Alibaba2026-10

Nacos README

Describes the registry and configuration server, and says it "can also be directly activated and used through the microservice engine (MSE) provided by Alibaba Cloud", calling the hosted route the easiest way to start.

Carry forwardWhen the quick start offers a hosted option, you are looking at a component whose maintenance has a revenue line behind it.
github.com/alibaba/nacos
Source Alibaba2021-03

Nacos 2.0.0 release notes

"This version add Grpc as the translating to replace HTTP between client and server", with connection load balancing, limits, reconnection and upgrade and downgrade support, and no published throughput figure.

Carry forwardA transport change in a component every service talks to is a compatibility event. Look for the downgrade path before the benchmark.
github.com/alibaba/nacos/releases/tag/2.0.0
Source Maven Central2018 to 2026

nacos-api artefact listing

Between six and twelve releases in every year from 2018 to 2026, with no gap. First upload 14 September 2018, latest in the listing 3.2.4 on 27 August 2026.

Carry forwardCompare the cadence of the server against the library in the same stack. Divergence tells you where the publisher's attention is.
repo1.maven.org/maven2/com/alibaba/nacos/nacos-api/
Source Alibaba2026

Nacos releases: the server becomes an agent registry

2026 releases add an AI registry, agent management, "Agentic Resource Discovery", MCP-related workflows, distributed locks and DNS-based discovery, alongside security hardening.

Carry forwardThe operable component is where a publisher adds the next generation of features, which widens the gap with the library you embedded.
github.com/alibaba/nacos/releases
Decision record Apache Dubbo2026-10

Application-level service discovery migration document

"For old Dubbo 2 users, there are two choices when upgrading to Dubbo 3, and the only consideration for the decision is performance." Dual registration and dual subscription are the default, and future versions may switch to application-level only.

Carry forwardA migration whose end state the framework reserves the right to force is a deadline you have not been given yet.
Dubbo documentation source, GitHub
Source Apache Dubbo2026-10

Dubbo README version table

All Dubbo 2 releases are marked end of life. Dubbo 3 carries a gRPC-compatible protocol, REST support, and a "+30% Performance" claim against an earlier 3.2 release.

Carry forwardEnd of life on the line most of your estate runs is the real upgrade trigger, and it is usually announced in a table rather than a notice.
github.com/apache/dubbo
Source Maven Central2019 to 2026

org.apache.dubbo:dubbo artefact listing

Seven releases in 2019, three in 2020, then 14, 17 and 24 across the Dubbo 3 push of 2021 to 2023, falling to nine, seven and one in the years after.

Carry forwardA release spike is a migration being pushed. Expect the support energy that follows the spike to decline, and plan your own cutover inside it.
repo1.maven.org/maven2/org/apache/dubbo/dubbo/
Case study Apache Seata2014 to 2023

Seata README: a component's whole lifecycle, written down

The Alibaba middleware team started TXC in 2014; it became the cloud product GTS in 2016; the open-source Fescar was started in 2019 "based on TXC/GTS"; Ant Financial joined and it was renamed; "In October 2023, Seata entered the Apache Incubator".

Carry forwardThe sequence internal, then product, then open source, then foundation is the normal path. Where a component sits on it predicts who answers your issue.
github.com/apache/incubator-seata
Decision record Apache RocketMQ2026-10

The RocketMQ improvement proposal register

70 proposals, each with accepted, activity and release status. Tiered storage, gRPC support and the proxy's remoting protocol are released; the HTTP proxy is "waiting for owners"; RIP-11, "Evolution of The Next Decade Architecture", is accepted and active and not released.

Carry forwardA proposal register with a release column is the most honest roadmap a project can publish. Read the unreleased rows first.
github.com/apache/rocketmq/wiki
Vendor Apache RocketMQ2026-10

RocketMQ README capacity claims

"Trillion-level capacity and flexible scalability" and "million-level message accumulation capacity in a single queue", with no measurement, workload or date attached.

Carry forwardCapacity adjectives are not planning numbers. If the publisher will not state the workload, you will be the one producing the benchmark.
github.com/apache/rocketmq
Decision record Koordinator2023-06

NRI mode resource management proposal

Dated 8 June 2023 with named authors and reviewers. Says the two existing modes "have some constraints", proposes a plugin subscribing to runtime lifecycle events, and carries goals, non-goals, risks and alternatives sections.

Carry forwardNode-level policy wants to live as close to the runtime as the runtime will allow. The constraint that moves it is when enforcement happens, not how fast it is.
Koordinator proposal, GitHub
Decision record Koordinator2022 to 2026

The proposals directory

Dated filenames from April 2022 to June 2026, grouped into scheduling, koordlet, forecasting and api-machinery, with a template file in the repository.

Carry forwardA dated proposals directory with a template is a project that argues in public. It is the cheapest due diligence available to an adopter.
github.com/koordinator-sh/koordinator proposals
Source Koordinator2026-10

Koordinator README

States the goal as improving efficiency and reliability for latency-sensitive and batch workloads together, reducing interference between containers, and increasing pod density. No utilisation figure is published.

Carry forwardThe node layer's value is a number only you can measure, because it depends on your workload mix. Expect to run the experiment.
Koordinator README, GitHub
Vendor Alibaba2026-02

Spring Cloud Alibaba README

Assembles the four components plus three cloud-only services, tracks the current Spring and Java releases, and names grayscale release and service warm-up as features of the paid Microservices Engine edition.

Carry forwardThe features held back for the paid edition tell you which capabilities the open library will never grow.
github.com/alibaba/spring-cloud-alibaba
Source Maven Central2019 to 2026

spring-cloud-alibaba-dependencies listing

Releases in every year from 2019, eleven in 2024, latest 2025.1.0.0 on 6 February 2026, while the flow-control library it wraps released once in each of the three preceding years.

Carry forwardGlue that leads to a paid service stays current. That is a property of the business model, not of the engineering.
repo1.maven.org spring-cloud-alibaba-dependencies
Source Alibaba2026-10

Spring AI Alibaba: the pattern restarting

An agent framework for Java with 11,000 stars, whose starters integrate with the same registry server "to provide A2A and dynamic config features", and whose quick start points at the publisher's hosted model service for an API key.

Carry forwardThe shape repeats for every new layer: a free in-process framework, dynamic behaviour delegated to a server, and the server sold as a service. Adopt accordingly.
github.com/alibaba/spring-ai-alibaba
07

Build a miniature, then productionise it

A dependency-fate audit, built in an evening and then turned into something that runs every week.

Pull the cadence curve for ten dependencies

Fetch the artefact listing for your ten most load-bearing third-party components, group version directories by upload year, and print the counts. For Java that is a Maven Central directory listing; the package registries for other languages expose the same dates.

Done when: you have one table of releases per year per dependency, and you can name the two that have decelerated.  Teaches: the publisher's attention is a measurable quantity.

Label each one by where it runs

In your process, a server you operate, a server someone else operates, or the node's runtime. Resist the urge to add categories: the point is the distance from your deployable.

Done when: every row carries a placement and you can say who would ship a fix for it.  Teaches: placement, not popularity, predicts maintenance.

Apply the operability test

For each in-process component, ask whether the publisher sells anything that would be less needed if the library were better. Check the README for an enterprise edition, a hosted option, or a specification it defers to, then check that specification's last commit date.

Done when: each in-process row is marked as neutral, funnel, or substitute for a paid product.  Teaches: how to read a README as a statement of commercial intent.

Put a seam around the riskiest one and time the swap

Wrap it behind an interface you own, implement that interface twice, and measure how long a real swap takes end to end, including the tests you discover are coupled to the library's behaviour.

Done when: you have a number in engineer-days for the exit, and a running build on the alternative.  Teaches: the exit cost is dominated by behavioural coupling, not by the interface.

Measure your own advisory latency

Pick the last three advisories against anything you ship and compute two intervals: publication to your deploy, and the earliest evidence of exploitation to your deploy. The second is the one that matters, and it is usually longer than anyone expects.

Done when: both intervals are on a dashboard with a target.  Teaches: patch latency is a property of your pipeline, not of the publisher.

Run the exit drill on something that still works

Choose a dependency that is healthy, fork it, build from the fork, ship it to a non-critical service, and keep it there for a release cycle. Write down what broke: build provenance, signing, the internal mirror, the dependency that pinned a transitive version.

Done when: a forked build has served production traffic and the runbook exists.  Teaches: owning a fork is an operational capability, and it cannot be acquired during an incident.

Write the gate into your adoption process

Three questions on the intake form: where does it run, who could be paid to operate it, and what does its cadence curve look like over five years. Add one rule: anything in-process with no commercial reason to exist needs a named owner on your side at adoption time.

Done when: the gate has refused or qualified at least one proposed dependency.  Teaches: the cheapest moment to pay for an exit is before the import.

08

Keep hunting

These are the queries and URL shapes that produced this page, under a network policy that allowed only code hosts and package registries. They work on any publisher.

Dated artefacts, when blogs are unreachable

  • https://repo1.maven.org/maven2/<group/path>/<artifact>/
  • https://repo1.maven.org/maven2/<path>/<version>/
  • github.com/<org>/<repo>/releases/tag/<version>

Maintenance signals in a repository

  • github.com/<org>/<repo>/commits/main
  • /pulls?q=is%3Apr+is%3Aopen+sort%3Acreated-asc
  • /pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged+sort%3Acomments-desc

The failure record

  • github.com/advisories?query=<package or project>
  • github.com/advisories/GHSA-xxxx-xxxx-xxxx for ranges and patch state
  • github.com/<org>/<repo>/security/advisories

Arguments the project had in public

  • github.com/<org>/<repo>/tree/main/docs/proposals
  • github.com/<org>/<repo>/wiki for improvement-proposal registers
  • raw.githubusercontent.com/<org>/<docs repo>/<branch>/<path>.md
09

References

  1. Alibaba, fastjson repository, archive notice GitHub, archived 2026-07-29. Checked 2026-10-11.
  2. Maven Central, com.alibaba:fastjson artefact listing Sonatype Maven Central, first upload 2012-02-07. Checked 2026-10-11.
  3. Maven Central, fastjson 1.2.84 files Sonatype Maven Central, uploaded 2026-07-29. Checked 2026-10-11.
  4. GitHub Advisory Database, CVE-2017-18349 Published 2018-10-24. Checked 2026-10-11.
  5. GitHub Advisory Database, CVE-2022-25845 Published 2022-06-11. Checked 2026-10-11.
  6. GitHub Advisory Database, CVE-2025-70974 Published 2026-01-09, updated 2026-10-05. Checked 2026-10-11.
  7. GitHub Advisory Database, CVE-2026-16723 Published 2026-07-23, updated 2026-08-07. Checked 2026-10-11.
  8. GitHub Advisory Database, search for fastjson 20 advisories. Checked 2026-10-11.
  9. Alibaba, fastjson2 repository GitHub. Checked 2026-10-11.
  10. Alibaba, Sentinel repository GitHub. Checked 2026-10-11.
  11. Maven Central, sentinel-core artefact listing First upload 2018-07-26, latest 1.8.10 on 2026-05-21. Checked 2026-10-11.
  12. Alibaba, Sentinel commit history Newest commit 2025-10-16. Checked 2026-10-11.
  13. Alibaba, Sentinel open pull requests, oldest first GitHub. Checked 2026-10-11.
  14. Alibaba, Sentinel closed unmerged pull requests 493 results. Checked 2026-10-11.
  15. Alibaba, Sentinel pull request 3618 Opened 2026-05-14, closed unmerged 2026-06-16. Checked 2026-10-11.
  16. OpenSergo, specification repository GitHub. Checked 2026-10-11.
  17. OpenSergo, specification commit history Newest commit 2023-03-29. Checked 2026-10-11.
  18. Alibaba, Nacos repository GitHub. Checked 2026-10-11.
  19. Alibaba, Nacos 2.0.0 release notes Released 2021-03-20. Checked 2026-10-11.
  20. Alibaba, Nacos releases Latest shown 3.2.4 on 2026-08-27. Checked 2026-10-11.
  21. Maven Central, nacos-api artefact listing First upload 2018-09-14. Checked 2026-10-11.
  22. GitHub Advisory Database, CVE-2021-29441 Published 2021-04-27. Checked 2026-10-11.
  23. GitHub Advisory Database, search for nacos 7 advisories. Checked 2026-10-11.
  24. Apache Dubbo, repository and version table GitHub. Checked 2026-10-11.
  25. Apache Dubbo, application-level service discovery migration document Documentation source in the dubbo-website repository. Checked 2026-10-11.
  26. Maven Central, org.apache.dubbo:dubbo artefact listing First upload on this coordinate 2019-01-21. Checked 2026-10-11.
  27. Apache Seata, repository and project history GitHub. Entered the Apache Incubator 2023-10. Checked 2026-10-11.
  28. Apache RocketMQ, repository GitHub. Checked 2026-10-11.
  29. Apache RocketMQ, improvement proposal index Project wiki, 70 entries. Checked 2026-10-11.
  30. Koordinator, README GitHub, main branch. Checked 2026-10-11.
  31. Koordinator, design proposals directory GitHub, main branch. Checked 2026-10-11.
  32. Koordinator, NRI mode resource management proposal Creation date 2023-06-08, last updated 2023-06-15. Checked 2026-10-11.
  33. Alibaba, Spring Cloud Alibaba repository GitHub. Checked 2026-10-11.
  34. Maven Central, spring-cloud-alibaba-dependencies listing Latest 2025.1.0.0 on 2026-02-06. Checked 2026-10-11.
  35. Alibaba, Spring AI Alibaba repository GitHub. Checked 2026-10-11.