Evidence ledger
One row per claim in What the vendor cannot host, you will maintain: ten years of Alibaba's published middleware: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.
Field guide: What the vendor cannot host, you will maintain: ten years of Alibaba's published middleware
Research date: 2026-10-11. Every URL below was fetched in this session on 2026-10-11.
Hunt constraint, stated up front
This session's egress policy permitted github.com, raw.githubusercontent.com,
repo1.maven.org, archive.apache.org, www.apache.org, pypi.org, proxy.golang.org,
registry.npmjs.org, index.crates.io, pkg.go.dev and hub.docker.com. It refused every
engineering-blog, documentation, conference-video, preprint and digital-library host tried,
including slack.engineering, infoq.com, usenix.org, arxiv.org, medium.com,
web.archive.org, dubbo.apache.org, cncf.io and aws.amazon.com: CONNECT returned 403
from the egress proxy. Alibaba's own engineering blogs and its Chinese-language conference
material were therefore out of reach.
Two consequences, both recorded in the guide rather than papered over:
- The guide is built from the artefact record: Maven Central upload dates, GitHub
repository state, advisories, commit and pull-request history, in-repository design
proposals, and the project documentation that is stored as Markdown inside GitHub
repositories. The
blog,talkandpapertiers are empty on purpose. - There is no production telemetry in this guide. No Double 11 request rate, no cluster utilisation figure, no incident blast radius. Where the record carries only a vendor's unquantified claim, the guide says so.
Method note for the release-cadence counts
Counts are of version directories in a Maven Central artefact listing, grouped by the upload
date Maven Central displays. Excluded: alpha, beta, preview, snapshot, -rc, .rc,
-m<N> qualifiers and the .android / .graal platform variants. 2026 is a partial year
(through the dates shown). The method counts published artefacts, not features, and a project
can be healthy with few releases; it is used here only to compare one project against another
over the same period and against its own history.
Ledger
| # | Org | Title | Tier | Published | Checked | URL | Claim taken from it | Supporting quote or figure |
|---|---|---|---|---|---|---|---|---|
| 1 | Alibaba | alibaba/fastjson repository |
source | archived 2026-07-29 | 2026-10-11 | https://github.com/alibaba/fastjson | The 15-year in-process JSON library is now read-only, and the README's remedy is a different library | Archive banner: "This repository was archived by the owner on Jul 29, 2026. It is now read-only."; About section: "FASTJSON 2.0.x has been released, faster and more secure, recommend you upgrade"; README: "we recommend you [upgrade] to the latest version"; 25.6k stars, 3,983 commits |
| 2 | Maven Central | com.alibaba:fastjson artefact listing |
source | listing read 2026-10-11 | 2026-10-11 | https://repo1.maven.org/maven2/com/alibaba/fastjson/ | The 1.x line peaked at 47 releases in 2020, stopped after 1.2.83 in May 2022, and emitted one final artefact on the day the repository was archived | 1.x final releases per year: 2012:12, 2013:11, 2014:13, 2015:4, 2016:16, 2017:34, 2018:20, 2019:26, 2020:47, 2021:6, 2022:25, 2023-2025:0, 2026:1. First upload 2012-02-07 (1.1.15). 1.2.83/ dated 2022-05-22; 1.2.84/ dated 2026-07-29 |
| 3 | Maven Central | com.alibaba:fastjson version 1.2.84 directory |
source | 2026-07-29 | 2026-10-11 | https://repo1.maven.org/maven2/com/alibaba/fastjson/1.2.84/ | The last 1.x artefact was published hours before the repository went read-only, with no repository left to explain it | All 24 files (fastjson-1.2.84.jar, .pom, sources, javadoc, signatures and digests) carry the timestamp 2026-07-29 07:24 |
| 4 | Maven Central | com.alibaba:fastjson 2.x releases on the 1.x coordinate |
source | listing read 2026-10-11 | 2026-10-11 | https://repo1.maven.org/maven2/com/alibaba/fastjson/ | The archived project's coordinate is still being published to, by the successor's compatibility artefact | 2.x releases on the com.alibaba:fastjson coordinate per year: 2022:23, 2023:22, 2024:9, 2025:7, 2026:5; latest 2.0.65 dated 2026-09-02, after the 2026-07-29 archive |
| 5 | GitHub Advisory DB | GHSA-xjrr-xv9m-4pw5, "Improper Input Validation in alilibaba:fastjson" (CVE-2017-18349) | postmortem | 2018-10-24 | 2026-10-11 | https://github.com/advisories/GHSA-xjrr-xv9m-4pw5 | The first public link in the chain: a JSON parse call reaching arbitrary code execution | Critical, CVSS 9.8, CWE-20; affected com.alibaba:fastjson <= 1.2.24, patched 1.2.31; description cites "parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products", with a crafted rmi:// URI in the dataSourceName field; EPSS 39.24% |
| 6 | GitHub Advisory DB | GHSA-pv7h-hx5h-mgfj, "Unsafe deserialization in com.alibaba:fastjson" (CVE-2022-25845) | postmortem | 2022-06-11 | 2026-10-11 | https://github.com/advisories/GHSA-pv7h-hx5h-mgfj | Four years later the same mechanism returned by defeating the default protection, and the published remedy was an opt-in mode | High, CVSS 8.1, CWE-502; affected >= 1.2.25, < 1.2.83, patched 1.2.83; advisory describes deserialisation of untrusted data "bypassing the default autoType shutdown restrictions"; stated workaround: "you can enable" safeMode |
| 7 | GitHub Advisory DB | GHSA-jm7w-5684-pvh8, "FASTJSON Includes Functionality from Untrusted Control Sphere" (CVE-2025-70974) | postmortem | 2026-01-09 | 2026-10-11 | https://github.com/advisories/GHSA-jm7w-5684-pvh8 | The 2017 fix was incomplete, and the gap was exploited for three years before this advisory existed | Critical, CVSS 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; affected below 1.2.48, patched 1.2.48; advisory states fastjson before 1.2.48 mishandles autoType, that an @type key naming a Java class can cause its public methods to run leading to JNDI injection, that it was exploited in the wild from 2023 through 2025, and that it stems from an incomplete fix for CVE-2017-18349 |
| 8 | GitHub Advisory DB | GHSA-crf3-v9rr-v7hj, "fastjson has a remote code execution (RCE) vulnerability" (CVE-2026-16723) | postmortem | 2026-07-23 | 2026-10-11 | https://github.com/advisories/GHSA-crf3-v9rr-v7hj | The last advisory against the 1.x line has no patched version recorded and does not require the unsafe feature to be enabled | Critical, CVSS 9.0; affected com.alibaba:fastjson >= 1.2.68, <= 1.2.83; "Patched versions: None"; advisory states the flaw is exploitable under the default configuration with no AutoType enablement or classpath gadget required; published 2026-07-23, last updated 2026-08-07 |
| 9 | GitHub Advisory DB | Advisory search, query fastjson |
source | search run 2026-10-11 | 2026-10-11 | https://github.com/advisories?query=fastjson | Most current advisories naming this library are filed against other people's applications, years after the library's own fixes | 20 advisories returned. 12 are against downstream products (JSH_ERP, WukongCRM, ktg-mes, MSFM, Alldata, uzy-ssm-mall, applyCT), dated between 2024-02-29 and 2025-11-25, each described as a fastjson deserialization vulnerability in that product |
| 10 | Alibaba | alibaba/fastjson2 repository |
source | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/fastjson2 | The successor inverted the dangerous default and declines to promise compatibility | Highlights: "AutoType disabled by default"; comparison table gives AutoType as "Enabled with whitelist" in 1.x and "Disabled by default (more secure)" in 2.x; circular-reference detection and Smart Match default off; groupId change from com.alibaba to com.alibaba.fastjson2; on the compatibility package, "100% compatibility is not guaranteed" |
| 11 | Alibaba | alibaba/Sentinel README |
vendor | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/Sentinel | The flow-control library's own framing: a decade of Alibaba's scheduled peak, a paid edition, and a specification as the future | "A powerful flow control component enabling reliability, resilience and monitoring for microservices"; "covered almost all the core-scenarios in Double-11 (11.11) Shopping Festivals in the past 10 years"; points readers to Alibaba Cloud's Microservice Engine (MSE) and a Sentinel enterprise edition; says the community is working on a traffic-governance and fault-tolerance specification and links to OpenSergo |
| 12 | Maven Central | com.alibaba.csp:sentinel-core artefact listing |
source | listing read 2026-10-11 | 2026-10-11 | https://repo1.maven.org/maven2/com/alibaba/csp/sentinel-core/ | The in-process flow-control library decelerated from monthly to annual, and its 2.0 line never left alpha | Final releases per year: 2018:7, 2019:12, 2020:2, 2021:3, 2022:3, 2023:1, 2024:1, 2025:1, 2026:1. First upload 2018-07-26 (0.1.0); latest 1.8.10 dated 2026-05-21; the only 2.0 artefact is 2.0.0-alpha/ dated 2023-02-14 |
| 13 | Alibaba | alibaba/Sentinel commit history, master |
source | newest commit 2025-10-16 | 2026-10-11 | https://github.com/alibaba/Sentinel/commits/master | Commits stop, and the last substantive work on the 2.0 ideas is dated August 2023 | Newest commits: 2025-10-16 "Removed the unnecessary blank lines (#2424)"; 2024-09-19 "fix: an inaccurate error message when parsing a log level from a string (#3221)"; 2024-02-01 "dashboard support regex match (#3305)"; 2023-08-16 "Merge pull request #3182: Add Sentinel 2.0 zero-trust basic implementation" and "Add sentinel-datasource-xds module for supporting zero-trust with xDS" |
| 14 | Alibaba | alibaba/Sentinel open pull requests, oldest first |
source | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/Sentinel/pulls?q=is%3Apr+is%3Aopen+sort%3Acreated-asc | 168 open pull requests, the oldest opened seven years ago by the project's own lead maintainer | Oldest open: #925 "Add customized biz exception log support in Tracer" by sczyh30, opened 2019-07-17; #1007 opened 2019-08-21; #1453 opened 2020-05-04; the repository shows 168 open pull requests |
| 15 | Alibaba | alibaba/Sentinel closed-unmerged pull requests |
source | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/Sentinel/pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged+sort%3Acomments-desc | 493 contributions were closed without merging, and a batch of long-open ones were closed years after they were filed | Filter total: 493. Examples closed 2025-10-09: #1118 "Add Sentinel MyBatis adapter module" (28 comments), #1336 "Highly performance for write metric", #1535 "Add a new metric repository with low memory(#1530)", #3116 "Add global fallback support for AspectJ annotation extension"; #76 closed 2025-09-04 |
| 16 | Alibaba | alibaba/Sentinel PR #3618, "feat: add Jakarta EE Servlet 6.0 adapter module (#2998)" |
source | opened 2026-05-14, closed 2026-06-16, unmerged | 2026-10-11 | https://github.com/alibaba/Sentinel/pull/3618 | Support for the current Servlet API was still unlanded in 2026, on at least the third attempt, with development confined to the maintenance branch | Adds a sentinel-web-servlet-jakarta module using jakarta.servlet-api 6.0.0 behind a JDK 17+ profile; description says it replaces PR #3001, "which was closed without merge"; maintainer LearningGp, 2026-06-11: "Active development is currently on the 1.8 branch, so I had to change the base branch of this PR to 1.8" and "The PR is currently unmergeable due to these conflicts"; closed by the author 2026-06-16 as superseded by #3627 |
| 17 | OpenSergo | opensergo/opensergo-specification repository |
adr | read 2026-10-11 | 2026-10-11 | https://github.com/opensergo/opensergo-specification | The specification intended to move governance out of the library exists as documents only, with no releases and no named backers | "Universal cloud-native microservice governance specification"; README: "an open, language-agnostic cloud-native service governance specification that is close to business semantics"; 56 commits, 792 stars, 28 issues, no releases listed, Contributors and Used-by sections empty |
| 18 | OpenSergo | opensergo/opensergo-specification commit history, main |
source | newest commit 2023-03-29 | 2026-10-11 | https://github.com/opensergo/opensergo-specification/commits/main | The specification has not been touched in three and a half years, while the library that points to it still points to it | Newest commit 2023-03-29 "Update docs and fix typo (#78)"; previous 2023-03-14, 2023-02-15, 2023-01-18 "Add draft doc of OpenSergo traffic-lane spec v1alpha1 (#52)"; first commits 2022-04-12 |
| 19 | Alibaba | alibaba/nacos README |
vendor | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/nacos | The registry and configuration server is presented with a hosted route as the easiest path | "an easy-to-use platform designed for dynamic service discovery and configuration and service management"; "It can also be directly activated and used through the microservice engine (MSE) provided by Alibaba Cloud"; describes deploying on cloud as "the easiest and most convenient way to start Nacos"; 33.4k stars |
| 20 | Alibaba | alibaba/nacos release 2.0.0 |
source | 2021-03-20 | 2026-10-11 | https://github.com/alibaba/nacos/releases/tag/2.0.0 | The server changed its client protocol wholesale, and the change is recorded as a feature list rather than a measured result | "This version add Grpc as the translating to replace HTTP between client and server"; items include "Add gRPC connection core feature to Nacos", "Config module support gRPC", "Naming module support gRPC", "Nacos gRPC Client support reconnection", "Support push data by gRPC", "Load balance for Connection", "Support basic connection limit", "Support upgrading and downgrading"; no throughput or capacity figure given |
| 21 | Maven Central | com.alibaba.nacos:nacos-api artefact listing |
source | listing read 2026-10-11 | 2026-10-11 | https://repo1.maven.org/maven2/com/alibaba/nacos/nacos-api/ | The out-of-process server shipped every year for nine years with no deceleration | Final releases per year: 2018:9, 2019:12, 2020:7, 2021:6, 2022:7, 2023:7, 2024:9, 2025:9, 2026:10. First upload 2018-09-14 (0.2.0); latest in listing 3.2.4 dated 2026-08-27 |
| 22 | Alibaba | alibaba/nacos releases page |
source | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/nacos/releases | In 2026 the same server is being extended into agent infrastructure, which is where the new work went | 3.2.4 (2026-08-27) "Bugfix and security-hardening release ... including deprecated AI API restrictions and JRaft authentication"; 3.3.0-BETA (2026-08-06) "adding Agent management, Agentic Resource Discovery, dynamic plugin configuration, and distributed locks"; 3.2.2 (2026-05-29) "external AI registry imports"; 3.3.0-RC expands "AI Registry, DNS service discovery" |
| 23 | GitHub Advisory DB | GHSA-36hp-jr8h-556f, "Authentication Bypass" (CVE-2021-29441) | postmortem | 2021-04-27 | 2026-10-11 | https://github.com/advisories/GHSA-36hp-jr8h-556f | The externalised control plane identified its own peers by a client-supplied header | High, CWE-290 "Authentication Bypass by Spoofing"; affected com.alibaba.nacos:nacos-common < 1.4.1, patched 1.4.1; EPSS 83.483% (100th percentile); advisory describes AuthFilter containing a bypass that lets Nacos servers skip authentication checks, keyed on the user-agent header, so a credential-less request is accepted when the user-agent is set to Nacos-Server, with the impact that "This issue may allow any user to carry out any administrative tasks on the Nacos server"; references issue alibaba/nacos#4701 and PR #4703 |
| 24 | GitHub Advisory DB | Advisory search, query nacos |
source | search run 2026-10-11 | 2026-10-11 | https://github.com/advisories?query=nacos | The same trust-boundary class recurs in the server over two years | 7 advisories: CVE-2021-29441 and CVE-2021-29442 both published 2021-04-27; CVE-2021-36162 "Incorrect Access Control in Nacos" 2021-08-02; CVE-2021-44667 "Cross-site Scripting" 2022-03-12; CVE-2021-43116 "Use of Hard-coded Credentials in Nacos" (nacos-client, High) 2022-07-06; CVE-2023-39106 "Nacos Spring vulnerable to Unsafe Deserialization" 2023-08-21 |
| 25 | Apache Dubbo | apache/dubbo README |
source | read 2026-10-11 | 2026-10-11 | https://github.com/apache/dubbo | The 2.x line that most of the installed base ran is end of life, and the 3.x line carries a different wire protocol | About: "The java implementation of Apache Dubbo. An RPC and microservice framework"; version table lists Dubbo 3 highlights including Triple (gRPC-compatible) protocol and REST support and a "+30% Performance" claim for 3.2.16; all Dubbo 2 releases are marked end-of-life; 3.3.6 is the most recent listed release; 41.6k stars |
| 26 | Apache Dubbo | migration-service-discovery.md, Dubbo documentation source |
adr | repository file, read 2026-10-11 | 2026-10-11 | https://raw.githubusercontent.com/apache/dubbo-website/master/content/en/overview/mannual/java-sdk/reference-manual/upgrades-and-compatibility/migration-service-discovery.md | The project states the registration-model decision as a pure scale decision, and the default transition carries a memory cost | "For old Dubbo 2 users, there are two choices when upgrading to Dubbo 3, and the only consideration for the decision is performance."; "If your cluster size is not large, and you have not encountered any performance issues such as address pushing while using Dubbo 2, you can continue using interface-level service discovery."; "If your cluster size is larger and you have encountered issues such as spike in service discovery load while using Dubbo 2, it is recommended to migrate to the new application-level service discovery."; register-mode options are "interface, instance, all"; dual registration and dual subscription are "the default behavior of the current framework", and "Future versions may switch to single registration and single subscription at the application level" |
| 27 | Maven Central | org.apache.dubbo:dubbo artefact listing |
source | listing read 2026-10-11 | 2026-10-11 | https://repo1.maven.org/maven2/org/apache/dubbo/dubbo/ | The framework's output concentrated in the Dubbo 3 push and fell away afterwards | Final releases per year: 2019:7, 2020:3, 2021:14, 2022:17, 2023:24, 2024:9, 2025:7, 2026:1. First upload on the Apache coordinate 2019-01-21 (2.7.0); latest in listing 3.2.20 dated 2026-05-17 |
| 28 | Apache Seata | apache/incubator-seata README |
casestudy | read 2026-10-11 | 2026-10-11 | https://github.com/apache/incubator-seata | One component's full lifecycle is written down: internal system, then cloud product, then open source, then foundation | The Alibaba middleware team started the TXC project in 2014; it became the Aliyun product GTS in 2016; in 2019 the open-source project Fescar was started "based on TXC/GTS"; Ant Financial joined and Fescar was renamed Seata; "In October 2023, Seata entered the Apache Incubator"; Maven badge shows v2.5.0; 26k stars |
| 29 | Apache RocketMQ | apache/rocketmq README |
vendor | read 2026-10-11 | 2026-10-11 | https://github.com/apache/rocketmq | The broker's public claims are capacity adjectives rather than measurements | "Apache RocketMQ is a distributed messaging and streaming platform with low latency, high performance and reliability, trillion-level capacity and flexible scalability"; feature list includes "Million-level message accumulation capacity in a single queue"; quick start uses the 5.5.1 binary release; RIPs are hosted on the project wiki |
| 30 | Apache RocketMQ | RocketMQ Improvement Proposal index (project wiki) | adr | read 2026-10-11 | 2026-10-11 | https://github.com/apache/rocketmq/wiki/RocketMQ-Improvement-Proposal | A public proposal register records which architectural ambitions shipped and which did not, including the one about the next decade | 70 entries with Accepted / Activity / Release columns. RIP-11 "Evolution of The Next Decade Architecture for RocketMQ": accepted yes, active, Release no. RIP-39 "Support gRPC Protocol": Release yes. RIP-55 "Support Remoting Protocol in RocketMQ Proxy Module": Release yes. RIP-57 "Tiered storage for RocketMQ": Release yes. RIP-17 "RocketMQ HTTP Proxy Support": "waiting for owners", Release no. RIP-77 "Deprecate and Remove ACL 1.0": Release yes |
| 31 | Koordinator | koordinator-sh/koordinator README |
source | read 2026-10-11 | 2026-10-11 | https://raw.githubusercontent.com/koordinator-sh/koordinator/main/README.md | The node-level layer states its goal as density and interference control, with no published utilisation figure | "Koordinator is a QoS based scheduling system for hybrid orchestration workloads on Kubernetes. Its goal is to improve the runtime efficiency and reliability of both latency sensitive workloads and batch jobs, simplify the complexity of resource-related configuration tuning, and increase pod deployment density to improve resource utilization."; benefits listed qualitatively, including "reducing interference between containers" |
| 32 | Koordinator | docs/proposals directory listing |
adr | read 2026-10-11 | 2026-10-11 | https://github.com/koordinator-sh/koordinator/tree/main/docs/proposals | Design proposals are dated in their filenames and span 2022 to 2026, with a template in the repository | Directories api-machinery, forecasting, koordlet, scheduling; files include 20220402-improve-the-efficiency-of-nodemetric.md, 20221205-cpu-schedule-latency.md, 20230608-nri-mode-resource-management.md, 20230613-node-prediction.md, 20260609-scheduler-scalability-test-harness.md, YYYYMMDD-template.md |
| 33 | Koordinator | 20230608-nri-mode-resource-management.md proposal |
adr | creation-date 2023-06-08, last-updated 2023-06-15 | 2026-10-11 | https://raw.githubusercontent.com/koordinator-sh/koordinator/main/docs/proposals/20230608-nri-mode-resource-management.md | Enforcement of resource policy moved into the container runtime because both earlier placements had stated limits | Front matter names authors and reviewers and the dates; "its runtime hooks support two working modes for different scenarios: Standalone and Proxy. However, both of them have some constraints"; "We'd like to integrate NRI framework to address Standalone and Proxy constraints based on this community recommend mechanism"; the flow subscribes to "pod/container lifecycle events from container runtime (e.g. containerd, crio)" and returns "OCI spec format response"; user stories include "I want to apply QoS policy before pod's status become running" and "I want to deploy koordinator cluster without restart"; has Goals, Non-Goals, Risks and Mitigations and Alternatives sections |
| 34 | Alibaba | alibaba/spring-cloud-alibaba README |
vendor | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/spring-cloud-alibaba | The glue library that leads to the paid service is current with the ecosystem it targets, and names the features reserved for the paid edition | "Spring Cloud Alibaba provides a one-stop solution for application development for the distributed solutions of Alibaba middleware"; components listed are Sentinel, Nacos, RocketMQ, Seata plus Alibaba Cloud OSS, SMS and SchedulerX; the enterprise version of Microservices Engine (MSE) is described as adding governance features such as "Grayscale Release" and "Service Warm-up", plus an enterprise registration and configuration centre and an enterprise cloud native gateway; latest branch "Corresponds to Spring Cloud 2025.1.x & Spring Boot 4.0.x, JDK 17 or later versions are supported" |
| 35 | Maven Central | com.alibaba.cloud:spring-cloud-alibaba-dependencies listing |
source | listing read 2026-10-11 | 2026-10-11 | https://repo1.maven.org/maven2/com/alibaba/cloud/spring-cloud-alibaba-dependencies/ | The glue kept releasing through 2026 while the library it wraps did not | Releases per year: 2019:6, 2020:8, 2021:7, 2022:4, 2023:2, 2024:11, 2025:3, 2026:1; first 1.5.0.RELEASE dated 2019-08-01; latest 2025.1.0.0 dated 2026-02-06 |
| 36 | Alibaba | alibaba/spring-ai-alibaba repository |
source | read 2026-10-11 | 2026-10-11 | https://github.com/alibaba/spring-ai-alibaba | The pattern is running again in the agent era: a new in-process framework whose dynamic behaviour is delegated to the same registry server | About: "Agentic AI Framework for Java Developers"; tagline "A production-ready framework for building Agentic, Workflow, and Multi-agent applications"; the spring-boot-starters module provides "Starters integrating Agent Framework with Nacos to provide A2A and dynamic config features"; quick start directs users to Aliyun Bailian for an API key; 11.0k stars; Maven Central badge 1.1.2.2 |
Tier counts
postmortem 6, source 20, adr 5, casestudy 1, vendor 4, blog 0, paper 0, talk 0.
Distinct hosts: 3 (github.com, raw.githubusercontent.com, repo1.maven.org). Distinct
organisations publishing the artefacts: Alibaba, Apache Dubbo, Apache Seata, Apache RocketMQ,
Koordinator, OpenSergo, GitHub Advisory Database, Maven Central.
What the record does not contain
- No incident review from Alibaba. Severity, exploitability and affected ranges are published; duration, customer impact and detection delay are not.
- No production scale or cost figure. The only quantities offered publicly are adjectives ("trillion-level capacity") and one unquantified decade claim about Double 11.
- No stated reason for any deceleration or archive. The guide's reading of why the in-process components stalled is inference from dated artefacts, labelled as such in the page.