9.22.0-beta.1
This is a beta release adding support for Redis 8.10, new commands, and a large batch of stability and parser-robustness fixes. The 9.22.0 GA release will follow once client-side caching and auto-pipelining are merged.
- Default configuration values changed (#3918): read/write timeouts, retry backoff, cluster state reload interval, and TCP keep-alive defaults are now aligned with the cross-SDK configuration proposal (see the highlight below). Explicitly configured values are unaffected.
WaitAOFreturn type corrected (#3888):WaitAOFnow returns*IntSliceCmd, matching the two-integer reply ofWAITAOF(previously*IntCmd, which failed to parse the reply at runtime). Code referencing the old return type needs a one-line update.
This release adds support for Redis 8.10. The README's supported-versions list now includes Redis 8.10, and CI runs the full suite against the redislabs/client-libs-test:8.10.0 image by default (#3920, #3940).
Coverage for the new commands and options that ship with Redis 8.10:
HIMPORT(#3919) — bulk hash import via server-side fieldsets, exposed asHImportPrepare,HImportSet,HImportDiscard, andHImportDiscardAll. Fieldsets are session state scoped to a single physical connection, which does not mix well with connection pooling — so the client keeps a versioned fieldset registry and lazily replays thePREPAREon whichever pooled connection executes aSETthat needs it, at most once per connection, with no extra round trip (thePREPAREis injected into the same write as theSET).LMOVEM/BLMOVEM(#3913) — move multiple elements between lists in one call.SUNIONCARD/SDIFFCARD(#3897) — cardinality of set union/difference without materializing the result.XREAD/XREADGROUPMAXCOUNTandMAXSIZE(#3898) — bound how much data a stream read returns.TS.READ(#3896),TS.QUERYLABELS(#3926),TS.NRANGE/TS.NREVRANGE(#3870) with multiple aggregators per key (#3937), andEXCLUDEEMPTYonTS.MRANGE/TS.MREVRANGE(#3912) — new time-series query surface.FT.ALIASLIST(#3925),COLLECTreducer forFT.AGGREGATE(#3886),RERANKon HNSW vector fields inFT.CREATE(#3927), andFT.HYBRIDtimeout warnings (#3911) — search coverage.
Default configuration values now follow the cross-SDK configuration proposal shared by all Redis client libraries (#3918):
| Setting | Old default | New default |
|---|---|---|
ReadTimeout / WriteTimeout |
3s | 5s |
| Retry backoff (min/max) | 8ms / 512ms | 10ms / 1s |
| Cluster state reload interval | 10s | 60s |
| TCP keep-alive | 5min period | 30s idle / 5s interval / 3 probes (net.KeepAliveConfig) |
Applications that set these values explicitly are unaffected; applications relying on the old defaults inherit the new ones.
A systematic audit fixed data races across the client — hooks (AddHook, #3868), Ring.SetAddrs (#3862), cluster node slices (#3861), pub/sub reconnect (#3906), maintenance notifications (#3894, #3872), pool handoff (#3876), and redisotel (#3881) — and hardened the RESP parsers against malformed or unexpected replies: over-reads on nil replies (#3874), integer overflow when skipping map/attribute bodies (#3877), unhashable RESP3 map keys (#3873), odd-length flat replies (#3900), mismatched declared array lengths (#3907), unexpected extra reply frames (#3884), and nil elements in numeric/bool slice replies (#3922).
PeekPushNotificationName blocked until 36 bytes were buffered, so a short subscribe confirmation (channel name of six or fewer characters) on an otherwise idle connection hung PubSub.Receive forever — a regression introduced in 9.20.1 by #3842. The peek now parses whatever is already buffered and only waits for one more byte when the frame prefix is valid but incomplete. Fixes #3935.
The cluster transaction pipeline treated a MULTI...EXEC block as independently retryable commands, which could scatter a transaction across nodes or send malformed transactions on retry. Redirects (MOVED/ASK/TRYAGAIN) and aborts are now handled at the whole-transaction level, matching Redis transaction semantics: the transaction is re-routed and retried as a unit, never partially (#3909) by @cxljs.
rediscmd.AppendCmd — used by redisotel and rediscensus to render commands into span attributes — now redacts credential arguments as <redacted>: AUTH, HELLO ... AUTH, CONFIG SET of requirepass / masterauth / TLS key passphrases, ACL SETUSER password rules, and MIGRATE ... AUTH/AUTH2. The client sends HELLO ... AUTH on every handshake and AUTH on every streaming-credentials rotation through the regular hook chain, so tracing hooks previously captured credentials even when the application never issued an auth command itself (#3939) by @saddamr3e.
HIMPORTcommand family:HImportPrepare/HImportSet/HImportDiscard/HImportDiscardAllwith lazy per-connection fieldset prepare replay (#3919) by @ndyakovLMOVEM/BLMOVEM: move multiple list elements in one call, withCOUNT(up to N) orEXACTLY(all-or-nothing) semantics viaLMoveMArgs(#3913) by @ofekshenawaSUnionCard/SDiffCard: cardinality of set union/difference (#3897) by @ofekshenawaXRead/XReadGroupMAXCOUNT/MAXSIZE: bound stream read responses by entry count or payload size (#3898) by @ofekshenawaTS.READ: read samples from a series starting at a given timestamp, withTSReadEarliest(-),TSReadLatest(+), andTSReadNew($) sentinels (#3896) by @ofekshenawaTS.QUERYLABELS: query label names/values across time series (#3926) by @ndyakovTS.NRANGE/TS.NREVRANGE: range queries across multiple series (#3870) by @ofekshenawa, with multiple aggregators per key (#3937) by @ndyakovTS.MRANGE/TS.MREVRANGEEXCLUDEEMPTY: skip series with no samples in the result (#3912) by @ofekshenawaFT.ALIASLIST: list all index aliases (#3925) by @ndyakovFT.AGGREGATECOLLECTreducer: collect grouped values into an array (#3886) by @ndyakovFT.CREATERERANK:RERANKparameter on HNSW vector field definitions (#3927) by @ofekshenawaFT.HYBRIDtimeout warnings: timeout warnings are now populated in hybrid search results (#3911) by @ofekshenawaFT.HYBRIDKNNSHARD_K_RATIO(Redis 8.8+): per-shard K ratio for KNN clauses (#3841) by @ndyakov
- PubSub
Receivehang: peek push-notification names without demanding 36 buffered bytes, fixing a hang on short subscribe confirmations (fixes #3935, regression from 9.20.1) (#3936) by @ndyakov - Cluster transactions: re-route the whole tx pipeline on redirect/abort instead of per-command (#3909) by @cxljs
- Credential leak in traces:
rediscmd.AppendCmdredacts credential arguments (AUTH,HELLO ... AUTH,CONFIG SETsecret params,ACL SETUSERpassword rules,MIGRATE AUTH/AUTH2), soredisotel/rediscensusspan attributes no longer contain passwords (#3939) by @saddamr3e WaitAOFreturn type: returns*IntSliceCmdmatching the two-integerWAITAOFreply (#3888) by @CipherN9Ring.Publishrouting: publish to the shard that owns the topic instead of a round-robined one (#3893) by @dkindel- Pool
OnRemovehooks: fireOnRemoveonputConneviction paths so removal hooks see every evicted connection (#3932) by @cxljs UniversalClientInfoMap: addedInfoMapto theCmdableinterface (#3904) by @nazarli-shabnamSlowLogGetcontext: pass the caller's context instead of a background one (#3915) by @sonnemuskModuleLoadexnil config: return an error instead of panicking on nil config (#3916) by @sonnemuskParseURLIPv6 hosts: keep single brackets for IPv6 hosts without a port (#3882) by @sueun-devParseURLdurations: treat unit durations<= 0as disabled (#3866) by @sueun-dev- Nil
*uint8encoding: encode nil*uint8as"0"like other numeric pointers (#3869) by @sueun-dev JSONSliceCmdread errors: return the read error fromreadReplyinstead of swallowing it (#3903) by @saddamr3e- RESP parser hardening: reconcile declared entry-array lengths (#3907), handle nil elements in int/uint/bool slice parsers (#3922), drain unexpected reply frames (#3884), reject odd-length flat replies in Z/KeyValue parsers (#3900), avoid int overflow when skipping map/attr bodies (#3877), don't over-read nil replies in
Reader.Discard(#3874) by @saddamr3e; reject unhashable keys in RESP3 map parsing (#3873) by @iabdullah215 - Data races: hook state during
AddHook(#3868),onNewNodeduringRing.SetAddrs(#3862), shared masters/slaves slices in cluster (#3861), sharedopt.Addrduring pub/sub reconnect (#3906),clusterStateReloadCallbackin maintnotifications (#3894), conn reader inisHealthyConnduring handoff (#3876) by @saddamr3e; handoff race window in maintnotifications (#3872) by @ndyakov redisotel: useObservableCounterfor cumulative pool stats (#3914) by @Solaris-star; avoid a data race on shared attributes duringMinIdleConnswarmup (#3881) by @ndyakov
- Cross-SDK default alignment: new defaults for timeouts, retry backoff, cluster state reload, and TCP keep-alive (#3918) by @ndyakov
- CI on Redis 8.10: 8.10 made the default test version (#3920) with version gating by major.minor (#3908) by @ofekshenawa; the test stack now runs the GA
redislabs/client-libs-test:8.10.0image and 8.8 was dropped from the CI matrix (#3940) - Type-safe atomics: use typed
sync/atomicvalue types (#3860) and remove the deadassertUnstableCommandRESP3 path (#3928) by @cxljs - Docs: clarify that
ExpireTime/PExpireTimereturn Unix timestamps (#3917) by @sonnemusk; remove a duplicate example step (#3875) by @andy-stark-redis
We'd like to thank all the contributors who worked on this release!
@andy-stark-redis, @CipherN9, @cxljs, @dkindel, @iabdullah215, @nazarli-shabnam, @ndyakov, @ofekshenawa, @saddamr3e, @Solaris-star, @sonnemusk, @sueun-dev
9.22.0-beta.1
This is a beta release adding support for Redis 8.10, new commands, and a large batch of stability and parser-robustness fixes. The 9.22.0 GA release will follow once client-side caching and auto-pipelining are merged.
- Default configuration values changed (#3918): read/write timeouts, retry backoff, cluster state reload interval, and TCP keep-alive defaults are now aligned with the cross-SDK configuration proposal (see the highlight below). Explicitly configured values are unaffected.
WaitAOFreturn type corrected (#3888):WaitAOFnow returns*IntSliceCmd, matching the two-integer reply ofWAITAOF(previously*IntCmd, which failed to parse the reply at runtime). Code referencing the old return type needs a one-line update.
This release adds support for Redis 8.10. The README's supported-versions list now includes Redis 8.10, and CI runs the full suite against the redislabs/client-libs-test:8.10.0 image by default (#3920, #3940).
Coverage for the new commands and options that ship with Redis 8.10:
HIMPORT(#3919) — bulk hash import via server-side fieldsets, exposed asHImportPrepare,HImportSet,HImportDiscard, andHImportDiscardAll. Fieldsets are session state scoped to a single physical connection, which does not mix well with connection pooling — so the client keeps a versioned fieldset registry and lazily replays thePREPAREon whichever pooled connection executes aSETthat needs it, at most once per connection, with no extra round trip (thePREPAREis injected into the same write as theSET).LMOVEM/BLMOVEM(#3913) — move multiple elements between lists in one call.SUNIONCARD/SDIFFCARD(#3897) — cardinality of set union/difference without materializing the result.XREAD/XREADGROUPMAXCOUNTandMAXSIZE(#3898) — bound how much data a stream read returns.TS.READ(#3896),TS.QUERYLABELS(#3926),TS.NRANGE/TS.NREVRANGE(#3870) with multiple aggregators per key (#3937), andEXCLUDEEMPTYonTS.MRANGE/TS.MREVRANGE(#3912) — new time-series query surface.FT.ALIASLIST(#3925),COLLECTreducer forFT.AGGREGATE(#3886),RERANKon HNSW vector fields inFT.CREATE(#3927), andFT.HYBRIDtimeout warnings (#3911) — search coverage.
Default configuration values now follow the cross-SDK configuration proposal shared by all Redis client libraries (#3918):
| Setting | Old default | New default |
|---|---|---|
ReadTimeout / WriteTimeout |
3s | 5s |
| Retry backoff (min/max) | 8ms / 512ms | 10ms / 1s |
| Cluster state reload interval | 10s | 60s |
| TCP keep-alive | 5min period | 30s idle / 5s interval / 3 probes (net.KeepAliveConfig) |
Applications that set these values explicitly are unaffected; applications relying on the old defaults inherit the new ones.
A systematic audit fixed data races across the client — hooks (AddHook, #3868), Ring.SetAddrs (#3862), cluster node slices (#3861), pub/sub reconnect (#3906), maintenance notifications (#3894, #3872), pool handoff (#3876), and redisotel (#3881) — and hardened the RESP parsers against malformed or unexpected replies: over-reads on nil replies (#3874), integer overflow when skipping map/attribute bodies (#3877), unhashable RESP3 map keys (#3873), odd-length flat replies (#3900), mismatched declared array lengths (#3907), unexpected extra reply frames (#3884), and nil elements in numeric/bool slice replies (#3922).
PeekPushNotificationName blocked until 36 bytes were buffered, so a short subscribe confirmation (channel name of six or fewer characters) on an otherwise idle connection hung PubSub.Receive forever — a regression introduced in 9.20.1 by #3842. The peek now parses whatever is already buffered and only waits for one more byte when the frame prefix is valid but incomplete. Fixes #3935.
The cluster transaction pipeline treated a MULTI...EXEC block as independently retryable commands, which could scatter a transaction across nodes or send malformed transactions on retry. Redirects (MOVED/ASK/TRYAGAIN) and aborts are now handled at the whole-transaction level, matching Redis transaction semantics: the transaction is re-routed and retried as a unit, never partially (#3909) by @cxljs.
rediscmd.AppendCmd — used by redisotel and rediscensus to render commands into span attributes — now redacts credential arguments as <redacted>: AUTH, HELLO ... AUTH, CONFIG SET of requirepass / masterauth / TLS key passphrases, ACL SETUSER password rules, and MIGRATE ... AUTH/AUTH2. The client sends HELLO ... AUTH on every handshake and AUTH on every streaming-credentials rotation through the regular hook chain, so tracing hooks previously captured credentials even when the application never issued an auth command itself (#3939) by @saddamr3e.
HIMPORTcommand family:HImportPrepare/HImportSet/HImportDiscard/HImportDiscardAllwith lazy per-connection fieldset prepare replay (#3919) by @ndyakovLMOVEM/BLMOVEM: move multiple list elements in one call, withCOUNT(up to N) orEXACTLY(all-or-nothing) semantics viaLMoveMArgs(#3913) by @ofekshenawaSUnionCard/SDiffCard: cardinality of set union/difference (#3897) by @ofekshenawaXRead/XReadGroupMAXCOUNT/MAXSIZE: bound stream read responses by entry count or payload size (#3898) by @ofekshenawaTS.READ: read samples from a series starting at a given timestamp, withTSReadEarliest(-),TSReadLatest(+), andTSReadNew($) sentinels (#3896) by @ofekshenawaTS.QUERYLABELS: query label names/values across time series (#3926) by @ndyakovTS.NRANGE/TS.NREVRANGE: range queries across multiple series (#3870) by @ofekshenawa, with multiple aggregators per key (#3937) by @ndyakovTS.MRANGE/TS.MREVRANGEEXCLUDEEMPTY: skip series with no samples in the result (#3912) by @ofekshenawaFT.ALIASLIST: list all index aliases (#3925) by @ndyakovFT.AGGREGATECOLLECTreducer: collect grouped values into an array (#3886) by @ndyakovFT.CREATERERANK:RERANKparameter on HNSW vector field definitions (#3927) by @ofekshenawaFT.HYBRIDtimeout warnings: timeout warnings are now populated in hybrid search results (#3911) by @ofekshenawaFT.HYBRIDKNNSHARD_K_RATIO(Redis 8.8+): per-shard K ratio for KNN clauses (#3841) by @ndyakov
- PubSub
Receivehang: peek push-notification names without demanding 36 buffered bytes, fixing a hang on short subscribe confirmations (fixes #3935, regression from 9.20.1) (#3936) by @ndyakov - Cluster transactions: re-route the whole tx pipeline on redirect/abort instead of per-command (#3909) by @cxljs
- Credential leak in traces:
rediscmd.AppendCmdredacts credential arguments (AUTH,HELLO ... AUTH,CONFIG SETsecret params,ACL SETUSERpassword rules,MIGRATE AUTH/AUTH2), soredisotel/rediscensusspan attributes no longer contain passwords (#3939) by @saddamr3e WaitAOFreturn type: returns*IntSliceCmdmatching the two-integerWAITAOFreply (#3888) by @CipherN9Ring.Publishrouting: publish to the shard that owns the topic instead of a round-robined one (#3893) by @dkindel- Pool
OnRemovehooks: fireOnRemoveonputConneviction paths so removal hooks see every evicted connection (#3932) by @cxljs UniversalClientInfoMap: addedInfoMapto theCmdableinterface (#3904) by @nazarli-shabnamSlowLogGetcontext: pass the caller's context instead of a background one (#3915) by @sonnemuskModuleLoadexnil config: return an error instead of panicking on nil config (#3916) by @sonnemuskParseURLIPv6 hosts: keep single brackets for IPv6 hosts without a port (#3882) by @sueun-devParseURLdurations: treat unit durations<= 0as disabled (#3866) by @sueun-dev- Nil
*uint8encoding: encode nil*uint8as"0"like other numeric pointers (#3869) by @sueun-dev JSONSliceCmdread errors: return the read error fromreadReplyinstead of swallowing it (#3903) by @saddamr3e- RESP parser hardening: reconcile declared entry-array lengths (#3907), handle nil elements in int/uint/bool slice parsers (#3922), drain unexpected reply frames (#3884), reject odd-length flat replies in Z/KeyValue parsers (#3900), avoid int overflow when skipping map/attr bodies (#3877), don't over-read nil replies in
Reader.Discard(#3874) by @saddamr3e; reject unhashable keys in RESP3 map parsing (#3873) by @iabdullah215 - Data races: hook state during
AddHook(#3868),onNewNodeduringRing.SetAddrs(#3862), shared masters/slaves slices in cluster (#3861), sharedopt.Addrduring pub/sub reconnect (#3906),clusterStateReloadCallbackin maintnotifications (#3894), conn reader inisHealthyConnduring handoff (#3876) by @saddamr3e; handoff race window in maintnotifications (#3872) by @ndyakov redisotel: useObservableCounterfor cumulative pool stats (#3914) by @Solaris-star; avoid a data race on shared attributes duringMinIdleConnswarmup (#3881) by @ndyakov
- Cross-SDK default alignment: new defaults for timeouts, retry backoff, cluster state reload, and TCP keep-alive (#3918) by @ndyakov
- CI on Redis 8.10: 8.10 made the default test version (#3920) with version gating by major.minor (#3908) by @ofekshenawa; the test stack now runs the GA
redislabs/client-libs-test:8.10.0image and 8.8 was dropped from the CI matrix (#3940) - Type-safe atomics: use typed
sync/atomicvalue types (#3860) and remove the deadassertUnstableCommandRESP3 path (#3928) by @cxljs - Docs: clarify that
ExpireTime/PExpireTimereturn Unix timestamps (#3917) by @sonnemusk; remove a duplicate example step (#3875) by @andy-stark-redis
We'd like to thank all the contributors who worked on this release!
@andy-stark-redis, @CipherN9, @cxljs, @dkindel, @iabdullah215, @nazarli-shabnam, @ndyakov, @ofekshenawa, @saddamr3e, @Solaris-star, @sonnemusk, @sueun-dev
Release 1.83.0
- server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable
GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT. - xds/rbac: Support
MetadataandRequestedServerNamepermissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in
NotRule/NotIdpermissions. - xds/rbac: Support the deprecated
source_ipprincipal identifier by treating it as equivalent todirect_remote_ip. - xds: Fix panic when parsing route header matchers configured with empty
exact_match,prefix_match, orsuffix_matchstrings. (#9223)
- xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the
force-xdstarget URI query parameter. (#9133) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (#9145)
- authz: Add
OnPolicyUpdatecallback toFileWatcherOptionsto notify when an authz policy is loaded or updated. (#9142)- Special Thanks: @hnefatl
- xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true. (#9119)
- This feature can be enabled by setting environment variable
- xds: Add support for xDS-based HTTP CONNECT proxies.
- This feature can be enabled by setting environment variable
GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true. (#9151)
- This feature can be enabled by setting environment variable
- xds: Add support for
contains_matchin route header matchers. (#9223)
- credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (#9197)
- grpc: Fix compilation on Plan 9 targets (
GOOS=plan9), broken since v1.81.0. (#9255)- Special Thanks: @Yusufihsangorgel
Version 1.60.1 (2026-07-29)
- feat(consumer): add rebalance protocol plumbing by @dnwe in https://github.com/IBM/sarama/pull/3670
- feat: add Kafka versions 4.1.2, 4.2.1 and 4.3.1 by @dnwe in https://github.com/IBM/sarama/pull/3675
- feat: raise default Kafka version to 2.8.0 by @dnwe in https://github.com/IBM/sarama/pull/3676
- feat(consumer): add cooperative sticky assignor by @dnwe in https://github.com/IBM/sarama/pull/3671
- feat: add TransactionClusterAdmin for KIP-664 detection APIs by @adrian-januzi in https://github.com/IBM/sarama/pull/3669
- feat(offset): commit revoked partitions on cooperative rebalance by @dnwe in https://github.com/IBM/sarama/pull/3688
- fix(consumer): preserve pauses across reassignment by @dnwe in https://github.com/IBM/sarama/pull/3681
- fix(producer): wake stranded brokerProducer when partition unmutes by @dnwe in https://github.com/IBM/sarama/pull/3692
- fix(deps): update module github.com/klauspost/compress to v1.19.1 by @renovate[bot] in https://github.com/IBM/sarama/pull/3649
- chore(deps): update ossf/scorecard-action action to v2.4.4 by @renovate[bot] in https://github.com/IBM/sarama/pull/3683
- refactor(consumer): separate join and sync round by @dnwe in https://github.com/IBM/sarama/pull/3680
- @adrian-januzi made their first contribution in https://github.com/IBM/sarama/pull/3669
Full Changelog: https://github.com/IBM/sarama/compare/v1.60.0...v1.60.1
1.14.49
- Release vtable and cursor handles when SQLite destroys them by @mattn in https://github.com/mattn/go-sqlite3/pull/1429
- Do not clobber SQLite's default cost estimates in BestIndex by @mattn in https://github.com/mattn/go-sqlite3/pull/1430
- Translate SQL NULL filter arguments to nil like goVUpdate by @mattn in https://github.com/mattn/go-sqlite3/pull/1431
- Identify updated row by argv 0 in goVUpdate by @mattn in https://github.com/mattn/go-sqlite3/pull/1432
- Ignore Used for constraints SQLite marked not usable by @mattn in https://github.com/mattn/go-sqlite3/pull/1433
- Reject nil module and nil BestIndex result by @mattn in https://github.com/mattn/go-sqlite3/pull/1434
- Fail upgrade tool on download and write errors by @mattn in https://github.com/mattn/go-sqlite3/pull/1435
- Fix off-by-one truncating SQL in fuzz target by @mattn in https://github.com/mattn/go-sqlite3/pull/1436
- Fix wrong results and cursor state sharing in series example by @mattn in https://github.com/mattn/go-sqlite3/pull/1437
- Use the table name from xCreate args in vtable example by @mattn in https://github.com/mattn/go-sqlite3/pull/1438
- Close leaked rows in hook example by @mattn in https://github.com/mattn/go-sqlite3/pull/1439
- Close prepared statement and fail if limit is not enforced in limit example by @mattn in https://github.com/mattn/go-sqlite3/pull/1440
- Upgrade SQLite to version 3053004 by @mattn in https://github.com/mattn/go-sqlite3/pull/1442
Full Changelog: https://github.com/mattn/go-sqlite3/compare/v1.14.48...v1.14.49
pdfcpu v0.14.0-rc.1 — Release Candidate
This is a release candidate.
Please test it with your existing PDF workflows and report regressions or compatibility issues in the v0.14.0-rc.1 feedback discussion.
This prerelease focuses on reliability, predictable error handling, safer file operations, and fewer external dependencies.
The github.com/pkg/errors dependency is gone. Error handling has been migrated throughout the codebase to standard Go patterns.
Errors now retain useful operation and input context, and exported sentinel errors make failures easier to classify with errors.Is and errors.As.
Public API boundaries now validate nil and invalid arguments instead of risking panics. Multi-input operations return joined errors where appropriate, while the CLI presents concise errors without exposing stack traces by default.
File operations are safer as well: output is staged before replacement, existing files and permissions are preserved on failure, filesystem aliases and output collisions are detected, and temporary-file cleanup has been hardened across platforms.
CLI users should see clearer and more complete diagnostics, particularly for batch validation, merging, attachments, encryption, certificates, fonts, and page operations.
Other notable changes include:
- JSON output for certificate listing.
- Support for the
OneColumnpage layout. - Optional installed-font selection for
fonts cheatsheet. - Improved attachment glob handling.
- Stricter validation of ordered, unique page split points.
- Clearer certificate-import and replacement behavior.
- Improved reporting when one or more inputs in a batch fail.
The public API now offers more consistent reader/writer and file-based entry points, along with exported errors that callers can inspect without parsing error strings.
New and expanded API support includes:
- Grid operations.
- Raw signature validation.
- Machine-readable certificate listing.
- List-oriented bookmark, box, form-field, image, property, permission, and viewer-preference operations.
- Explicit handling policies for unsupported resources during extraction.
- Transactional certificate and TrueType collection installation.
Callers that compare complete error strings should migrate to errors.Is or errors.As, as many errors now include additional operation and source context.
Signature, timestamp, PKCS#7, certificate-chain, and revocation processing received substantial hardening. This area remains under active development, and further work on signature creation, validation, revocation, and interoperability is ongoing.
Remote image fetching for create and form inputs now rejects private and local destinations, including redirects and DNS results. Access to private revocation endpoints must be explicitly allowed through allowedRevocationHosts.
The external github.com/hhrutter/lzw and github.com/hhrutter/pkcs7 dependencies have been replaced by internal implementations. Remaining dependencies have been updated.
The experimental Windows 7 build is being discontinued because the request for community testing received no response. It relied on an unofficial patched Go toolchain and could not be tested on Windows 7 in CI. Official Go releases require Windows 10 or Windows Server 2016 or later.
This release also includes numerous fixes across parsing, validation, forms, fonts, attachments, merging, page trees, annotations, images, encryption, and digital signatures, backed by substantially expanded regression and error-path coverage.
As a prerelease, v0.14.0-rc.1 is intended for testing.
Please try it with your CLI and API workflows and report any regressions before the final v0.14.0 release.
Many of the fixes in this release began with reports from you - the pdfcpu users. Thanks everyone who opened issues, provided reproducible examples, tested fixes, and helped identify difficult PDF edge cases. Your feedback directly improves pdfcpu's reliability.
- 2f43fd6cc2905173df03e5436da00208e2231a71 fix Windows test portability
- 5f7bf42782d8a66f99a07dc908d899f8c57e9325 bump version
- 029fa541626fa0e57417c162e2d8022d66b7f777 harden recursive action and bead validation
- 5538e8a28362a2a299741a38acc3c9c4ded3f5a8 fix #1383
- 4b6b06b727a2da26edace0cf01e4167ee2c8fa10 fix #1448
- f3c9ed641f4d71cba01d79013b1d4ddc0184b6c5 cleanup error handling
- e7973f530e0c26ef737fbf09fd9d67386fb061a7 harden integer validation and CI permissions
- 4dc0e627dd83b91ae2d18f5c71c4d687158f92d8 fix #1440
- 1fa26614a5d3ef31895e16a9841ae3b0241b18b6 fix #1439
- 0f5d517ad38696bf5f1e8a8629b213b37359d082 fix #1438
- e413baf0ee4d2217c925f2c575f699642735f9f6 fix #1437
- d2488f1ac57a3bf29b74e170c0abffbf92ff2949 fix #1431
- 5a2455464d47d3def7dc1e557d4b39e1bfa5fdd3 cleanup error handling
- 997afda467c0ac1b951afa8e0cb76a77d3ec1b4e hide stack traces from default API and CLI errors
- 29f40fc7931e7ee86740a108edba6964d3f5a2e0 clarify encryption error classification
- 63bf1f77b96cf9b38606d40dcb9f3aaa17848cd9 fix(cli): surface multi-input command errors
- 553aa81578d64639464f937f4304ef2b3410a50d fix(cli): return batch validation and merge source errors
- 73c7c23f26b3a4f12b5f00bcf674d11fc2f5ab64 api: add source context to merge errors
- cd741d7cd6236aff035fc5e6204c5c892401ff4d api: harden error and nil argument handling
- ae3023dea86744ed5daa4889e888000c8a83c3c9 fix #1051
- fd3c42b27a2390c4d08e023752dfc6f82ddc2eb2 add regression test for #1059
- db89772699f8e7c11ae8cb9ed28ad56e591cef0e fix #1088
- 6d12b95a71b821e6f17ac17a53188de42f92f4a0 fix #1091
- 04d6bbe64ad95fc8b870ee82a06648490374557d fix #866
- 75ded47336131eeb1c88832cdf490aa27ae0dade fix #1101
- 85bb38147fadcb427b990f608828cb63fab393b3 fix #1123
- 8231174c537540e2f0e53afa10425a32c4f50018 fix #1127
- b897b5fc2151faeb0e1636a37afc439f7b6f04d1 fix #1161
- c5124d8b968e4edab3a7d8ea5a0db2517f229640 upgrade dependencies
- 6e318a071bfa1b55237693af76cd85c084609804 fix #415
- 7623a909bc0e0a2238e9f7a955986502b5bb5f84 fix #1265
- a35e551de8735de4df863c0169b0016158acda4d add regression test for #1271
- 63ad8b674b94c7e40b137775c2db40b8e3e97980 fix #1279
- 34a477540d47b5c4e66c34cf34c9ce16b58b02e0 Harden remote image fetching for create/form inputs
- ee19119ca7ca1629f790c864773e70f7acf90188 fix #1282
- 5868dc5c717b9326db5332f96d5997e19b23e2c5 fix #1311
- ca9e9aa7599b53919f8339a97fd4ce199842b20f fix #1325
- 85f5d1176d6c88b270e6f3bcd200f8db6995e8d7 fix #1326
- dfb3b495547f0f893c64a2435375aaf96c531698 internalize PDF LZW filter implementation
- 6c60ed40edde055ef6ec65cb125cf8534ae991a4 fix #1302
- def15db189d09ee1ce3d193407929cf479bc0674 fix #1340
- 66f98fd3ef7f8ba7cb290273984f5ba5433462a7 fix #1387
- a496812e7b3273a20ca1f3c9b5767480379e900e fix #1419
- 30b7bc52d63c2d6500c01f45116c77bfef77ee2e fix #1417
- e711196a14d0e8b7998e58d7c367e010b03ba3ef fix #1403
- dbf99078520ccc6b1d4e4f42e09972de4dbaa60d fix #1274
- d79565d9795ad58541a145bdfd717c39cd87d6f2 add regression test for invalid destination stream #933
- 887462d0ebdc0a8b4f5890ab2fc80b0fc165c89e fix #1289
- d5ec9d33375077d7f4d2146fef0534fde0b81178 Add xref stream regression tests for #399 and #401
- 89d4bc11226cd053313cf9b6aa0f796f5139bba7 fix #990
- d01e39156fbe63af408843aee507603771d5f79f fix #1385
- b45031cb2eccfa228ac0d7f8fcbbe85f3843987c Fix tmp file handling & permissions
- b17661e880e6c11136acfaba3515f88ba5274fe9 Add missing guards
- 7bde99e930bac475b1fbcbd8c28b25a209b1009c Fix #1404
Wails v3.0.0-alpha2.119
- Update documentation for multiple languages to include architecture diagrams in PR by @taliesin-ai
🤖 This is an automated nightly release generated from the latest changes on master.
Installation:
go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-alpha2.119
v1.73.0
- test: fix host comparison in FuzzURIParse by @ReneWerner87 in https://github.com/valyala/fasthttp/pull/2313
- perf: avoid redundant scans when parsing request headers by @ReneWerner87 in https://github.com/valyala/fasthttp/pull/2312
- Fix temp file leak in SaveMultipartFile on cross-device rename failure by @itxaiohanglover in https://github.com/valyala/fasthttp/pull/2311
- re-enable forcetypeassert by @Harshal96 in https://github.com/valyala/fasthttp/pull/2316
- test: normalize Go test names by @Harshal96 in https://github.com/valyala/fasthttp/pull/2317
- feat: prefix sentinel error strings by @Harshal96 in https://github.com/valyala/fasthttp/pull/2319
- fix(pprofhandler): use exact path matching to prevent debug data exposure by @xbrxr03 in https://github.com/valyala/fasthttp/pull/2302
- avoid following a symlink when writing the FS compressed cache by @alhudz in https://github.com/valyala/fasthttp/pull/2321
- refactor: improve internal interface names by @Harshal96 in https://github.com/valyala/fasthttp/pull/2318
- fix: lowercase error strings by @Harshal96 in https://github.com/valyala/fasthttp/pull/2320
- perf: reduce redundant scans and allocations in hot paths by @ReneWerner87 in https://github.com/valyala/fasthttp/pull/2322
- validate domain and path cookie attribute values on parse by @alhudz in https://github.com/valyala/fasthttp/pull/2315
- chore(deps): bump securego/gosec from 2.27.1 to 2.28.0 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2328
- chore(deps): bump actions/setup-go from 6 to 7 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2329
- fix: preserve pre-set status code in NewFastHTTPHandler by @xbrxr03 in https://github.com/valyala/fasthttp/pull/2323
- chore(deps): bump github.com/klauspost/compress from 1.19.0 to 1.19.1 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2331
- reject backslash '..' traversal in fs handler on windows by @alhudz in https://github.com/valyala/fasthttp/pull/2327
- fix: reject Windows alternate data stream paths in FS by @dev-willbird1936 in https://github.com/valyala/fasthttp/pull/2335
- chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2307
- chore(deps): bump github.com/andybalholm/brotli from 1.2.1 to 1.2.2 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2308
- chore(deps): bump github.com/klauspost/compress from 1.18.6 to 1.18.7 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2309
- chore(deps): bump github.com/klauspost/compress from 1.18.7 to 1.19.0 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2314
- chore(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2326
- chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2324
- chore(deps): bump golang.org/x/net from 0.56.0 to 0.57.0 by @dependabot[bot] in https://github.com/valyala/fasthttp/pull/2325
- @itxaiohanglover made their first contribution in https://github.com/valyala/fasthttp/pull/2311
- @Harshal96 made their first contribution in https://github.com/valyala/fasthttp/pull/2316
- @dev-willbird1936 made their first contribution in https://github.com/valyala/fasthttp/pull/2335
Full Changelog: https://github.com/valyala/fasthttp/compare/v1.72.0...v1.73.0
Wails v3.0.0-alpha2.118
- Provide default paths for icon generation inputs and outputs in PR by @taliesin-ai
- Add source entry modules to runtime package.json sideEffects in PR by @savely-krasovsky
- Add licence and provenance section to contributing guide in PR by @taliesin-ai
- Apply scoped GTK4 frameless CSS to remove border radius in PR by @savely-krasovsky
- Handle cursor position failures gracefully on Windows for popup menus and screen enumeration in PR by @wayneforrest
- macOS open-file dialog filters extensions correctly and validates allowed files by suffix in PR by @phergul
- Guard Windows dark-mode initialization against nil API calls in PR by @roachadam
- Fix 32-bit build failure in the updater: the
maxArchiveTotalSizeconstant (2 GiB) overflowed the platformintwhen passed tofmt.ErrorfonGOARCH=386. It is now explicitly typedint64. - Fix a nil-pointer panic on startup when a window uses a Dark (or system-dark) title bar on Windows builds that do not load the dark-mode uxtheme APIs, such as Windows 10 1809 / Windows Server 2019 (build 17763). The
AllowDarkModeForWindowcalls in the window theme setup are now nil-guarded, matching the guard already used inw32.SetMenuTheme.
🤖 This is an automated nightly release generated from the latest changes on master.
Installation:
go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-alpha2.118
v5.3.1
lego is an independent, free, and open-source project, if you value it, consider supporting it! ❤️
Everybody thinks that the others will donate, but in the end, nobody does.
So if you think that lego is worth it, please consider donating.
For key updates, see the changelog.
Due to an error related to Snapcraft, some artifacts of the v5.3.0 release have not been published.
This release contains the same things as v5.3.0.