What milvus-io/milvus shipped
Written by FoxPlug from public releases; not affiliated with Zilliz. An automatic summary of the public release, pull request and commit data of github.com/milvus-io/milvus. Zilliz did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Row-level security policy evaluation added, including policy combination, template compilation, and a three-valued local evaluator for write checks. Pull request #52074
- Asynchronous WAL recovery refactored to replace legacy flusher with VChannel/Segment persistence, retained-message completion, and owner-fenced snapshots. Pull request #53595
- Array, struct, and JSON path replacement support added to 3.0 release. Pull request #53746
- Two-phase import ID range assignment implemented for bulk import, replacing broadcast-time sizing and pre-allocation. Pull request #53544
- JSON stats build parallelized, achieving up to 4.15× speedup with concurrent segment processing. Pull request #52120
- Proxy shard leader cache now properly invalidated after QueryCoord channel-balance moves to prevent stale routing. Pull request #53785
- Legacy REST routes removed from metrics port and V1 APIs made optional via proxy.http.enableV1 flag. Pull request #53499
- Timestamptz fields with default values now correctly stored during parquet import instead of being set to NULL. Pull request #53774
- Health checks now require complete component registration before reporting readiness. Pull request #53734
- Misspelled cipherPlugin configuration key corrected from updatePerieldInMinutes to updatePeriodInMinutes with fallback support. Pull request #53826
Why it matters
This week includes critical fixes for proxy cache invalidation after moves and parquet import handling, along with security improvements for REST API exposure and configuration projection safety. New capabilities include row-level security evaluation, two-phase bulk import ID assignment, and JSON path replacement in 3.0.
Changelog entry
- feat: [RLS3] evaluate row-level security policies with policy combination, template compilation, and three-valued local evaluator for write checks Pull request #52074
- enhance: refactor asynchronous WAL recovery and summary persistence with VChannel/Segment persistence and owner-fenced snapshots Pull request #53595
- feat: [3.0] support array, struct and JSON path replacement Pull request #53746
- enhance: assign import ID ranges after preimport via two-phase ImportIDRange message for bulk import Pull request #53544
- enhance: parallelize json stats build achieving up to 4.15× faster performance with concurrent segments Pull request #52120
- fix: drop stale proxy shard leader cache on move to prevent collection-not-loaded routing errors Pull request #53785
- enhance: retire legacy REST routes and make V1 APIs optional via proxy.http.enableV1 flag Pull request #53499
- fix: store Timestamptz default value for null rows in parquet import instead of storing NULL Pull request #53774
- fix: wait for component registration before reporting healthz readiness Pull request #53734
- fix: correct misspelled cipherPlugin.updatePeriodInMinutes config key with fallback support Pull request #53826
- enhance: extract proxy DQL tasks into dql package following proxy task-package split Pull request #53613
- enhance: extract proxy DQL tasks into dql package with 16 task/pipeline files moved to internal/proxy/dql Pull request #53685
Week 40 shipped: RLS policy evaluation, async WAL recovery refactor, JSON stats parallelization (4.15× faster), proxy cache invalidation fixes, and optional V1 API exposure controls.
This week's updates bring critical stability and security improvements to Milvus. We fixed proxy shard leader cache invalidation issues after channel balancing, corrected parquet import handling for nullable Timestamptz fields, and enhanced configuration safety. New capabilities include row-level security policy evaluation and two-phase bulk import ID assignment, while security is improved through REST API exposure controls and configuration projection safety.