Compatibility

The supported JDK, build-tool, and framework matrix for the Repost Java client, plus the dependency, redaction, native-image, and FIPS posture.

AxisSupported
JDK11, 17, 21, 25 (current security-update builds). The client is Java 11 bytecode; build with JDK 21.
Build toolsMaven 3.9.0+ (pinned current 3.9.16); Gradle via the Kotlin SDK.
Spring Boot4.0.7 (compiled), 4.1.0 (verified), on JDK 17/21/25.
Jakarta CDI / MicroProfileCDI 4.0.1, MicroProfile Config 3.1 (WildFly, Open Liberty, Payara).
Vert.x4.5.29, 5.1.4 (certified).
Quarkus / MicronautFramework-neutral core only (no dedicated extension or native image yet).
PlatformServer-side JVM. No Android: the client carries a publish credential.

Support status and end-of-life follow the upstream JDK, framework, and build-tool schedules; see sdk/jvm/compatibility-matrix.toml in the release for the pinned lines.

Security posture

  • Dependencies. The runtime carries a source-verified, relocated Apache HttpClient/HttpCore baseline and JSpecify annotations. Nothing else leaks onto your classpath. The micrometer, opentelemetry, Spring, and Jakarta APIs are needed only when you use those modules.
  • Proxy, TLS, and mTLS. Configured through HttpTransportOptions. See Configuration. HTTP redirects are disabled.
  • Redaction. The SDK's own diagnostics, observer events, telemetry, exception messages, and model toString() are credential- and payload-free: a model renders only its type and the names of set fields, never their values, and an exception message is a fixed string keyed on the error code. The SDK does not scrub PII you place inside an event payload; that data is the event you are publishing and is sent to Repost as-is.
  • Native image. One framework-neutral-core GraalVM native smoke (25.0.3) is validated; native support for the framework modules is not certified.
  • FIPS. This release is not FIPS-certified. It uses the platform JCA and standard TLS; using it in a FIPS deployment requires your own certified provider and JDK.

Continue