Vendor notices — vendor-sdk

This section is maintained by the vendor. It is mirrored here for convenience and does not represent Mercury Analytics policy.


Advisory VSDK-ADV-2214-WEB — metadata refresh following INC-4471

Published: 2026-09-30 · Issued by: Vendor SDK Support (support@vendor-sdk.io) · Severity: Moderate (data freshness)

Affected versions: 2.4.0 through 2.4.8, where index metadata was cached during the INC-4471 disruption window (06:40–12:20 UTC, 2026-09-30).

Fixed in: 2.4.9, available now from your internal package index.

Details

During the INC-4471 incident, the index metadata service intermittently served records from a stale replica. Customer-side caches built during that window may continue to reference the stale record even though the incident is closed. Release 2.4.9 republishes the metadata records in full.

Recommended customer actions

  1. Confirm the vendor-sdk metadata record served by your internal package index reports version 2.4.9.
  2. If the record still reports an earlier version, refresh your index metadata and install 2.4.9 before your next scheduled build.
  3. Recovery bundles staged locally during the incident window (for example the INC-4471 recovery bundle distributed through customer drop folders) are superseded by this release and can be discarded once 2.4.9 is installed.
  4. Notify your platform group in your internal team chat channel once the upgrade is complete, so vendor adoption can be tracked for the INC-4471 retrospective.

Questions: support@vendor-sdk.io — reference VSDK-ADV-2214-WEB.