- Breaking change: TLS hostname verification is now enabled by default for tctl, Cassandra and SQL tools; the old enable-flag is removed and a disable-flag is added to opt out.
- Schema upgrade required before upgrading the server, with persistence changes including atomic counter migration for executions table and new prev transaction ID attribute for history nodes.
- New features: optional TLS certificate provider injection and periodic cert refresh; visibility DB config no longer needed with Elasticsearch; several performance optimizations for NDC replication and DB queries.