Temporal published server v1.30.7 on 18 September 2026. GitHub marks the tag as a stable release. The change to read first pins Go to 1.25.14, refreshes thrift, grpc, and x/text for CVE cleanup, and adds a Nexus callback toggle so operators can turn off routing that trusts a caller controlled source header.
The full release notes and downloads are on the GitHub release page.
Security pins on the 1.30 line ¶
Pull request 12059 is the only Go version pin on release/v1.30.x. The go directive in go.mod moves from 1.25.11 to 1.25.14. That picks up the standard library security fix from go1.25.13 and stops on the last 1.25 patch. Go 1.25 went end of life when Go 1.27.0 shipped on 19 August 2026, so go1.25.14 closes the line. A later advisory will not reach this branch until it moves to a supported line such as 1.26. A proposal to jump straight to Go 1.26.8 was closed. The diff is toolchain only.
Pull request 12064 sets ServerVersion to 1.30.7 and brings in the pins the notes call CVE fixes. Thrift is 0.24.0, grpc is 1.83.2, and golang.org/x/text is 0.41.0. The prep notes say security issues showed up in the release candidate images that preceded this tag. Dockerfiles already run a blanket apk upgrade, OS package scans were clean, and no Alpine pin list changed. GOTOOLCHAIN=go1.25.14 govulncheck ./... reported 0 affected vulnerabilities.
Pull request 12040 also pins github.com/temporalio/ringpop-go at v0.1.0 and github.com/temporalio/tchannel-go at v1.22.1, replacing untagged commit pins. Ringpop bounds label and member resource use on incoming membership changes and fixes a state transition timer leak. Tchannel returns an error on a malformed call frame instead of panicking.
Image build work in this tag is plumbing. Pull request 10976 refreshes the manual Docker build action that was failing on release/v1.30.x. Pull request 10977 copies docker-bake.hcl from main. Neither changes server runtime behavior.
Nexus callback source header ¶
Legacy Nexus routing that trusts a source header is now gated by pull request 12085 under callback.inspectSourceHeader. The default is true, so mixed version clusters keep the old path during migration. Callbacks that already use temporal://system still route internally with the toggle on or off. The path covers CHASM callbacks and the legacy implementation.
A caller controlled source header that can select internal routing is a privilege escalation path. The default keeps workers that have not moved to temporal://system working, and it leaves that trust in place. Set the key to false after those workers migrate.
Pull request 12032 is test and CI scope. It sets component.nexusoperations.useSystemCallbackURL for the features jobs only. The shipped default stays false, which mixed version deployments with 1.29 need. The rest of that pull request repairs test flakes and does not change the server default.
Schedule iteration caps ¶
Schedule next time search is now bounded. Pull request 11981 picks the list matching performance work from pull request 11014 onto this branch. A schedule spec that excludes too much, including a mirrored include and exclude calendar, could walk GetNextTime toward maxCalendarYear. GetNextTime now returns (GetNextTimeResult, error). The counters are schedule_compute_limit_warning and schedule_compute_limit_exceeded.
Both bounds are dynamic config. scheduler.specWarnIterations defaults to 86400. scheduler.specMaxIterations defaults to 1209600. Raise the max when a real calendar hits the cap, and watch the warning counter first. The author marks the change as relatively high risk because it touches V1 next time computation. A mistake is a nondeterminism bug in running schedule workflows. The error is swallowed on the getNextTimeV1 and getNextTime side effect paths, so cached results keep the same shape. CHASM pieces that do not exist on release/v1.30.x were dropped, including ListMatchingTimes and UpdateFutureActionTimes.
Pull request 11105 is a separate matching service change, picked from pull request 11090. Handler APIs that lacked a panic handler now defer log.CapturePanic. Paths that do not panic are unchanged.
History pages and Elasticsearch time filters ¶
The same labeled bundle in pull request 12040 changes two read paths.
GetWorkflowExecutionHistory and GetWorkflowExecutionHistoryReverse compare branch_token in the page token with the token in mutable state. The check rejects a page after conflict resolution moves the workflow onto another branch. EnablePaginationTokenBranchValidation defaults to true, so the rejection path is live on upgrade. EnablePaginationTokenBranchValidationShadowMode shipped beside it.
Elasticsearch visibility now always writes the nanos component into datetime filters used for pagination. A filter such as StartTime = '2023-04-05T06:07:08Z' used to match a workflow stored as 2023-04-05T06:07:08.100000000Z. That match breaks page boundaries. Missing nanos are filled with zeros. An errors.AsType edit in the original change stayed as errors.As, because this branch is still on Go 1.25.
Upgrade notes ¶
This tag will not absorb a later Go security fix. Move off Go 1.25 before the next standard library advisory.
callback.inspectSourceHeader defaults to true. Set it to false only after worker callbacks use temporal://system. component.nexusoperations.useSystemCallbackURL stays false in the shipped binary.
EnablePaginationTokenBranchValidation defaults to true. A client that keeps a page token across a branch change is rejected instead of reading the old branch. Elasticsearch list queries that omitted nanos can return a different page. Recheck StartTime filters written at whole second precision.
Watch schedule_compute_limit_warning before any namespace hits schedule_compute_limit_exceeded. Raise scheduler.specMaxIterations if an exclude calendar needs more than 1209600 iterations. Roll that change out carefully. V1 schedule determinism is the risk.
Matching panic handlers are additive.
Where to get it ¶
- Release page: https://github.com/temporalio/temporal/releases/tag/v1.30.7
- Repository: https://github.com/temporalio/temporal
- Full changelog: v1.30.6 to v1.30.7
- Tag:
v1.30.7