Update dependency com.alibaba:fastjson to v2.0.64 - #15
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
May 12, 2024 04:13
f737984 to
c47c994
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
June 1, 2024 09:30
c47c994 to
505bb9d
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
July 14, 2024 02:19
505bb9d to
b3b77a3
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
September 16, 2024 16:36
b3b77a3 to
ea92520
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
January 11, 2025 18:29
ea92520 to
9249485
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
February 14, 2025 03:39
9249485 to
30cf469
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
February 22, 2025 02:27
30cf469 to
3cf3fcd
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
March 31, 2025 06:40
3cf3fcd to
6d60943
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
May 28, 2025 07:04
6d60943 to
3ec29f7
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
July 30, 2025 06:57
3ec29f7 to
96d25d4
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
September 22, 2025 02:28
96d25d4 to
2b4850c
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
October 25, 2025 14:08
2b4850c to
c3f278b
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
November 10, 2025 17:00
c3f278b to
17a9bf9
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
February 7, 2026 09:49
17a9bf9 to
7f220e2
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
May 5, 2026 16:08
7f220e2 to
a2de788
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
July 29, 2026 11:03
a2de788 to
899f5d1
Compare
renovate
Bot
force-pushed
the
renovate/com.alibaba-fastjson-2.x
branch
from
August 2, 2026 14:43
899f5d1 to
7c5cbd9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.0.48→2.0.64Release Notes
alibaba/fastjson2 (com.alibaba:fastjson)
v2.0.64: fastjson 2.0.64版本发布Compare Source
FASTJSON 2.0.64 Release Notes
Release Date: 2 Aug 2026
Tag: 2.0.64
Overview
This is a bug fix release. It fixes several issues in core serialization/deserialization, Java records support, and the fastjson 1.x compatibility layer. All users are recommended to upgrade.
Bug Fixes
ClassFormatErrorwhen serializing classes with array-typed fields #4009 #4014strBufnot kept in sync after mid-loop growth, which could produce corrupted output #7671 #7676MethodHandles.Lookupinitialization order — initialize before readingIMPL_LOOKUP#7691 #7718additionalItemsschema validation for Java arrays #7709serialVersionUIDtoJSONArrayfor Java serialization compatibility #7687 #7698ParserConfig.propertyNamingStrategyfor fastjson 1.x compatibility #7740Maven Dependency Configuration
Standard Version
Android 5 Optimized Version
Android 8 Optimized Version
中文版本
概述
本版本为问题修复版本,修复了核心序列化/反序列化、Java records 支持以及 fastjson 1.x 兼容层中的多个问题。建议所有用户升级。
问题修复
ClassFormatError的问题 #4009 #4014strBuf未同步,可能导致输出损坏的问题 #7671 #7676MethodHandles.Lookup初始化顺序——在读取IMPL_LOOKUP之前完成初始化 #7691 #7718additionalItemsschema 校验 #7709JSONArray添加serialVersionUID,兼容 Java 序列化 #7687 #7698ParserConfig.propertyNamingStrategy,兼容 fastjson 1.x #7740Maven 依赖配置
标准版本
Android 5 优化版本
Android 8 优化版本
v2.0.63: fastjson 2.0.63版本发布Compare Source
FASTJSON 2.0.63 Release Notes
Release Date: 29 Jul 2026
Tag: 2.0.63 (
82eda3e)Overview
This is a security fix release. It hardens AutoType deserialization and fixes several parser robustness issues (OOM / DoS) that can be triggered by crafted input. All users are strongly recommended to upgrade, especially applications parsing untrusted JSON or JSONB data.
Users who cannot upgrade immediately can mitigate the AutoType issue with
-Dfastjson2.parser.safeMode=true(applications not using a customAutoTypeBeforeHandler).fastjson 1.x users: the same AutoType hardening is available in fastjson 1.2.84.
Security Fixes
ClassLoader/DataSource/RowSetgadget base types — only an accept entry naming the type in full is treated as an explicit opt-in #7703BigIntegerO(n²) DoS with crafted long number literals #7668 #7694BC_BIGINTdeclared-length OOM from crafted payloads declaring a huge length #7669 #7696BC_BINARYdeclared-length OOM #7669 #7705Changes & Bug Fixes
Collectionelements (e.g.HashSet), duplicate elements now serialize as$refwhenReferenceDetectionis on #7678 #7701ObjectWritercreated in the switch block ofgetObjectWriterInternal#7626 #7627getInt/setIntout of lambda to avoid per-call spin #7677 #7693Maven Dependency Configuration
Standard Version
Android 5 Optimized Version
Android 8 Optimized Version
中文版本
概述
本版本为安全修复版本,加固了 AutoType 反序列化校验,并修复了多个可由构造输入触发的解析健壮性问题(OOM / DoS)。强烈建议所有用户升级,尤其是解析不可信 JSON 或 JSONB 数据的应用。
暂时无法升级的用户,可通过
-Dfastjson2.parser.safeMode=true缓解 AutoType 问题(适用于未使用自定义AutoTypeBeforeHandler的应用)。fastjson 1.x 用户:同款 AutoType 加固已在 fastjson 1.2.84 中提供。
安全修复
ClassLoader/DataSource/RowSet等危险基类——只有完整类名的 accept 条目才视为显式放行 #7703BigIntegerO(n²) DoS #7668 #7694BC_BIGINT声明长度 OOM(构造超大长度声明的 payload)#7669 #7696BC_BINARY声明长度 OOM #7669 #7705变更与问题修复
Collection元素(如HashSet)缺少引用检测的问题,开启ReferenceDetection时重复元素现在正确序列化为$ref#7678 #7701getObjectWriterInternalswitch 分支中创建的ObjectWriter未缓存导致的 Metaspace 泄漏 #7626 #7627getInt/setInt移出 lambda,避免每次调用自旋 #7677 #7693Maven 依赖配置
标准版本
Android 5 优化版本
Android 8 优化版本
v2.0.62Compare Source
v2.0.61: fastjson 2.0.61版本发布Compare Source
FASTJSON 2.0.61 Release Notes
Release Date: 07 Feb 2026
Tag: 2.0.61 (
170f71f)Overview
This is a regularly scheduled maintenance release with feature enhancements, performance improvements, and bug fixes. Users should upgrade as needed.
Changes & Bug Fixes
@JsonPropertyon methods was being ignored in record types #3893ArrayIndexOutOfBoundsExceptionissues inJSONReaderUTF8,JSONReaderASCII, andJSONReader#3883@JSONFieldformat #3864TypeUtils.castToTimestampcompatibility issues when upgrading from 1.2.83 #3906 #3907getStringand othergetXXXmethods #3880TypeUtils.castwith Long global converter #3932TimeModulesupport including improvedYearMonthsupport #3934 #3935org.w3c.dom.Node#3960Listsubclasses during deserialization #3926parse(InputStream)overload with default context #3946DirectByteBufferUnsupportedOperationExceptionforjava.nio.ByteBuffer#array#3894PropertyFilter,PropertyPreFilter, etc.) #3877BigIntegerasDoublereadStringperformance inJSONReaderUTF8/JSONReaderUTF16WriteNulls,ErrorOnNullForPrimitives,NotWriteDefaultValue, and other features-Dfastjson2.creator=reflect#1563Maven Dependency Configuration
Standard Version
Android 5 Optimized Version
Android 8 Optimized Version (supports java.time and Optional)
1.x Compatible Version
Spring 5 Extension
Spring 6 Extension
JAX-RS Extension
JAX-RS Jakarta Extension
Related Links
FASTJSON 2.0.61 发布说明
发布日期: 2026年2月7日
标签: 2.0.61 (
170f71f)概述
这是定期维护版本,包含功能增强、性能改进和问题修复。建议用户根据需要升级。
变更与问题修复
@JsonProperty注解在 record 类型的方法上被忽略的问题 #3893JSONReaderUTF8、JSONReaderASCII和JSONReader中的多个ArrayIndexOutOfBoundsException问题 #3883@JSONFieldformat 格式的冲突问题 #3864TypeUtils.castToTimestamp的兼容性问题 #3906 #3907getString等getXXX方法新增默认值参数支持 #3880TypeUtils.cast出现双引号的问题 #3932TimeModule支持,包括改进的YearMonth支持 #3934 #3935org.w3c.dom.Node的序列化支持 #3960List子类在反序列化时无法自动推断泛型类型的问题 #3926parse(InputStream)重载方法 #3946DirectByteBuffer调用java.nio.ByteBuffer#array时的UnsupportedOperationException#3894PropertyFilter、PropertyPreFilter等)#3877BigInteger解析为Double时溢出检查不正确的问题JSONReaderUTF8/JSONReaderUTF16的readString性能WriteNulls、ErrorOnNullForPrimitives、NotWriteDefaultValue等特性的多个问题-Dfastjson2.creator=reflect时的类型转换错误 #1563Maven 依赖配置
标准版本
Android 5 优化版本
Android 8 优化版本(支持 java.time 和 Optional)
1.x 兼容版本
Spring 5 扩展
Spring 6 扩展
JAX-RS 扩展
JAX-RS Jakarta 扩展
相关链接
v2.0.60: fastjson 2.0.60发布Compare Source
这又是一个定期维护的功能增强BUG FIX版本,大家按需升级。
Issues
@ JsonProperties之后结果错误的问题 #3799java.util.Collections#EMPTY_LIST报错的问题 #3828MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.59: fastjson 2.0.59发布Compare Source
这又是一个定期维护的功能增强BUG FIX版本,大家按需升级。
Issues
MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.58: Fastjson 2.0.58版本发布Compare Source
这又是一个定期维护的功能增强BUG FIX版本,大家按需升级。
@JSONField(defaultValue="")和fastjson 1.x不兼容的问题MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.57: Fastjson 2.0.57版本发布Compare Source
这又是一个定期维护的功能增强BUG FIX版本,大家按需升级。
Issues
MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.56: fastjson 2.0.56版本发布,性能进一步提升Compare Source
这个版本进一步提升了性能,并且修复了2.0.54发布以来用户反馈的BUG。
Issues
@type且位置不在json串开始位置时和fastjson 1.x行为不一致的问题 #3284MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.55Compare Source
v2.0.54: fastjson 2.0.54版本发布,性能进一步提升Compare Source
这又是一个性能优化Bug修复的版本更新版本,大家按需升级。
1. 性能优化
这个版本的性能优化包括:
1.1 使用SWAR(SIMD Within A Register)技巧来优化序列化字符串的性能
序列化时,写字符串检测是否存在特别字符是一个性能关键点,这个版本使用SWAR(SIMD Within A Register)的技巧来做快速检测。如下
https://github.com/alibaba/fastjson2/blob/2.0.54/core/src/main/java/com/alibaba/fastjson2/JSONWriterUTF8.java#L484
1.2 优化在JDK 16+的readString性能
在JDK 16+的版本下,使用StringLatin1.indexOfChar方法加速扫描特殊字符,优化readString的性能。这个算法来自 wycst 的贡献。
https://github.com/alibaba/fastjson2/blob/2.0.54/core/src/main/java/com/alibaba/fastjson2/JSONReaderASCII.java#L1445
1.3 int/long/float/double的读取写性能
优化的技巧是一次性读取两个数字,如下:
https://github.com/alibaba/fastjson2/blob/2.0.54/core/src/main/java/com/alibaba/fastjson2/JSONReaderUTF8.java#L3506
这个优化最初灵感源泉来自 https://github.com/wycst/wast 的 io.github.wycst.wast.json.JSONTypeDeserializer.NumberImpl#deserializeInteger所采用的算法,然后做了进一步的改进。
2. Issues
{不报错的问题 #2592fastjson2缺省是能识别Gson的Annotation的,这个可以通过接口或者JVM启动参数关闭
也支持通过JVM启动参数关闭
MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.53: fastjson 2.0.53版本发布Compare Source
这又是一个月度更新版本,大家按需升级。
Issues
2. MAVEN依赖配置
这个版本支持java.time和Optional
3. 相关链接
v2.0.52: fastjson 2.0.52发布Compare Source
这又是一个月度例行发布的BUG FIX版本版本,大家按需升级。
Issues
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.