5 hours ago
openobserve

Release v1.0.0-rc5

📦 Download Binaries from https://openobserve.ai/downloads

What's Changed

Full Changelog: https://github.com/openobserve/openobserve/compare/v1.0.0-rc4...v1.0.0-rc5

12 hours ago
openobserve

Release v1.0.0-rc4

📦 Download Binaries from https://openobserve.ai/downloads

What's Changed

Full Changelog: https://github.com/openobserve/openobserve/compare/v1.0.0-rc3...v1.0.0-rc4

17 hours ago
pingora

Pingora 0.9.0

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

  • Allow sharing backends across load-balancing selectors.
  • Add graceful-upgrade signalling between old and new processes.
  • Add per-listener L4 buffer configuration and socket send/receive buffer settings.
  • Add Tokio blocking-pool configuration, poll-time histograms, and an alternative timer runtime knob.
  • Allow proxy services to override runtime options.
  • Add a working-directory option for daemon mode.
  • Enable adding user context between sessions on the same connection with HttpPersistentSettings.
  • Add socket-cookie access and TCP/TLS establishment timing fields.
  • Make HTTP/2 stream and connection windows configurable.

🚀 Features — Caching (alpha)

  • Add deferred cache-admission policy hooks.
  • Implement DCZ dictionary compression and vary on available-dictionary.
  • Add CacheMeta freshness updates and expiration-at-time support.
  • Support optionally flooring fractional delta-seconds for RFC 9111 handling.
  • Preserve Vary provenance across stale refreshes.
  • Make cache-lock retries configurable and bounded.
  • Add an opt-in purge mode that expires an asset while retaining its body for conditional revalidation and stale serving.
  • Use power-of-two selection for eviction balancing.
  • Add peek_lru, update_or_admit, and non-promoting set_weight operations in lru.
  • Allow adjusting LRU weight limits and reserving capacity.

🔒 Security & Hardening

  • HTTP ambiguity hardening: centralize raw request-target classification so path and authority validation share one parser; reject ambiguous request authorities on ingress and egress; reject forbidden CR/LF bytes in HTTP/2 :path; and reject delimiter bytes in request lines as defense in depth.
  • Sanitize hop-by-hop upstream request headers.
  • Preserve non-origin-form request targets without mangling the URI.
  • Normalize forwarded responses with obsolete HTTP/1.1 response-header line folding.
  • Bound default HTTP/2 server limits to reduce memory-exhaustion exposure.
  • Avoid a process abort while appending oversized header maps by returning an InvalidHTTPHeader error.
  • Fix some unchecked integer conversions.
  • Explicitly prevent reuse of HTTP/1 connections after incomplete responses.
  • Update Prometheus for a security advisory.
  • Replaced unmaintained daemonize crate with daemonix and updated nix to 0.31.x.

🐛 Bug Fixes

  • Fix connection-pool and PoolNode race windows and remove empty entries.
  • Fixed a potential stall on HTTP/1 response-header reads upon forwarding request bodies via a cancel safety fix.
  • Stop waiting on HTTP/2 upstream work after the downstream ends and close timed-out HTTP/2 connections.
  • Drain in-flight HTTP/2 streams during shutdown and retry stream creation on a fresh connection when appropriate.
  • Prevent HTTP/1 upstream reuse after failed writes or incomplete responses.
  • Discard retry buffers after truncation and avoid unnecessary HTTP/2 accept allocations.
  • Skip h2c preface detection on TLS streams.
  • Do not initialize a body reader for HEAD informational responses.
  • Correct HTTP/1 session body-byte accounting.
  • Fix listener-fd inheritance and close transfer sockets during graceful upgrade; mark received listener fds close-on-exec.
  • Remove the duplicate graceful-shutdown sleep and improve load-balancer shutdown responsiveness.
  • Shard proxy shutdown notifications to reduce lock contention and close a lost-wakeup race during graceful shutdown.

⚙️ Miscellaneous

  • pingora-timeout now uses Tokio timeouts for (configurably) long intervals to avoid memory accumulation.
  • Split pingora-prometheus into a separate crate.
  • Forward WriteBuf::chunks_vectored to the wrapped buffer.
  • Replace custom ASCII-trimming helpers with stabilized standard-library methods.
  • Update the MSRV lane and use cargo check for MSRV validation.
  • Improve documentation examples for connection tracing and basic setup.
  • Preserve bound ports in digests after TLS failures.
  • Return an error for divergent multipart cache progress and remove a panic from maybe_cache_meta.
  • Various flaky test fixes.
18 hours ago
superset

superset-helm-chart-0.22.8

Apache Superset is a modern, enterprise-ready business intelligence web application

23 hours ago
node

2026-09-09, Version 26.8.2 (Current), @aduh95

Notable Changes

  • [616bd3fa26] - doc: deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593
  • [ae1801eb55] - meta: refine the security vuln posture for experimental features (James M Snell) #65438
  • [09feba74c8] - deps: update Undici to 8.10.2 (Node.js GitHub Bot) #65788
  • [7efdbe3eb9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542

Commits

  • [d8aedd6584] - build: skip dockit on riscv64 (Stewart X Addison) #62251
  • [1899c274eb] - build: activate correct default flags for riscv64 (Stewart X Addison) #65708
  • [ec8a3be996] - build: derive NODE_ARCH from target_cpu in the GN build (Shelley Vohr) #65491
  • [b73118a507] - build,win: remove LTO parallelisation limit (Stefan Stojanovic) #65535
  • [09feba74c8] - deps: update undici to 8.10.2 (Node.js GitHub Bot) #65788
  • [e47c432dd6] - deps: upgrade npm to 11.19.1 (npm team) #65573
  • [2fd6ce36a9] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #65653
  • [49dec2767a] - deps: update googletest to 36ba75f0ad5383a9759f17f3f72fd4661c72cb6d (Node.js GitHub Bot) #65654
  • [676174a071] - deps: update simdjson to 4.6.9 (Node.js GitHub Bot) #65655
  • [2f1b7fa0bb] - deps: update perfetto to 58.2 (Node.js GitHub Bot) #65656
  • [12acd0ad15] - deps: update zlib to 1.3.2.1-motley-5eb4d7e (Node.js GitHub Bot) #65494
  • [48631c80fb] - deps: update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542
  • [7efdbe3eb9] - deps: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542
  • [bdc75900ee] - doc: replace node:modules documentation header (René) #65800
  • [44c8a499ba] - doc: clarify return type of fs.mkdtemp* (Antoine du Hamel) #65743
  • [025fb5eeb0] - doc: update changelog-maker instructions for releasing (Juan José) #65707
  • [5f64847afa] - doc: add stability status to crypto.setEngine (Antoine du Hamel) #65746
  • [299dee0cb9] - doc: remove outdated TLS authorized warning (Tim Perry) #65597
  • [e97dcc0278] - doc: fix broken using link in ffi.md (Soul Lee) #65632
  • [2c9cc7d237] - doc: fix some broken links (Antoine du Hamel) #65583
  • [0c330ec329] - doc: fix stale TOC in maintaining-dependencies (greenhead) #65523
  • [9c522a3a69] - doc: refactor the AI guidelines (Joyee Cheung) #65269
  • [46cbf1bf8c] - doc: fix triggerAsyncId() comment in async_hooks example (soreavis) #64583
  • [788904ff78] - doc: fix fsPromises.watch overflow value (Matt Radbourne) #64605
  • [3d06ff19e8] - doc: clarify stream direction in options.stdio note (Avocado) #65236
  • [d334838379] - doc: clarify signal listener behavior (Som Samantray) #65243
  • [d55a2bd56a] - doc: add test reporter event lifecycle diagram (sangwook) #63780
  • [c17dfc87de] - doc: discourage AbortSignal cleanup for long-lived resources (Efe Karasakal) #64342
  • [616bd3fa26] - doc: deprecate Server.prototype._listen2 in node:net (Antoine du Hamel) #65593
  • [4e6d7e0ca6] - meta: cleanup targos emeritus changes (Antoine du Hamel) #65738
  • [a70cfe1747] - meta: bump github/codeql-action/init from 4.37.3 to 4.37.9 (dependabot[bot]) #65714
  • [e43a0ad4ce] - meta: bump github/codeql-action/autobuild from 4.37.3 to 4.37.9 (dependabot[bot]) #65717
  • [99e06288f1] - meta: bump actions/checkout from 7.0.0 to 7.0.1 (dependabot[bot]) #65718
  • [89662762b3] - meta: bump cachix/install-nix-action from 31.11.0 to 31.11.1 (dependabot[bot]) #65719
  • [6b8f078672] - meta: bump actions/setup-node from 6.4.0 to 7.0.0 (dependabot[bot]) #65720
  • [6c6fb18e63] - meta: bump step-security/harden-runner from 2.20.0 to 2.21.0 (dependabot[bot]) #65721
  • [0e002e859f] - meta: bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9 (dependabot[bot]) #65722
  • [98aaffe4b9] - meta: bump github/codeql-action/analyze from 4.37.3 to 4.37.9 (dependabot[bot]) #65723
  • [d247cb2975] - meta: document collaborator automation (Filip Skokan) #65671
  • [ae1801eb55] - meta: refine the security vuln posture for experimental features (James M Snell) #65438
  • [fab81d15c3] - test: widen the gap in the resolver maxTimeout comparison (Shelley Vohr) #65780
  • [62e2a6265c] - test: fix the thread-spawn handshake in the WASI threads fixture (Shelley Vohr) #65780
  • [7eb20b1810] - test: only count restarts after the write in watch emit-restarted test (Shelley Vohr) #65780
  • [14c3a77bc5] - test: ignore tunnel resets in proxy invalid-char-in-url test (Shelley Vohr) #65780
  • [ebc99e0560] - test: handle EPIPE in closed channel test (Christian Aurich) #65770
  • [5e73a2ca79] - test: deflake test-permission-net-udp-handle (Christian Aurich) #65767
  • [beb669f7de] - test: deflake test-runner-coverage (Christian Aurich) #65728
  • [ef4b6bfa62] - test: set type=none on IBM i for empty source (Abdirahim Musse) #65545
  • [027eef0691] - test: deflake WASI poll timing checks (Filip Skokan) #65672
  • [a352b0e2fe] - test: skip fs-watch-recursive-delete-race on AIX (Antoine du Hamel) #65698
  • [f9ce35aa43] - test: deflake test-inspect-async-hook-setup-at-inspect (Christian Aurich) #65584
  • [32281cec7b] - test: deflake test-watch-mode-restart-esm-loading-error (Christian Aurich) #65623
  • [79be5d61be] - test: avoid orphaned child on Windows abort test (Kirill Saied) #65451
  • [8972b8540b] - test: fix link-local dgram scope assertion (Filip Skokan) #65629
  • [b7cd1d96de] - test: riscv64: skip node-api sea test (Stewart X Addison) #65569
  • [7eeb9d0e57] - test: mark platform-specific tests as flaky (Filip Skokan) #65562
  • [649ac82bda] - test: account for varied OpenSSL CCM final behaviours (Filip Skokan) #65542
  • [050fb1a15d] - tools: bump @humanfs/node from 0.16.7 to 0.16.8 in /tools/eslint (dependabot[bot]) #65757
  • [5314dda396] - tools: bump browserslist from 4.28.4 to 4.28.8 in /tools/eslint (dependabot[bot]) #65758
  • [5938a08929] - tools: do not hardcode yamllint path (Antoine du Hamel) #65747
  • [d8408f7415] - tools: refine contributor guidance workflow (Filip Skokan) #65745
  • [196e372b69] - tools: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) #65716
  • [7e986b09f6] - tools: do not flag force push as invalid message (Antoine du Hamel) #65700
  • [837ce2ccef] - tools: do not hardcode path to Ruff (Antoine du Hamel) #65681
  • [1c7149a96a] - tools: retry first-time contributor query (Filip Skokan) #65648
  • [bd310a2bea] - tools: query first-time contributor status (Filip Skokan) #65592
  • [ab7b57e547] - tools: offset GitHub crons by 3 minutes (Michaël Zasso) #65612
  • [62ece28eae] - tools: label PRs lacking second approval (Filip Skokan) #65538
  • [68227b4029] - tools: welcome first-time contributors (Filip Skokan) #65533
  • [490dc93e37] - tools: enable concurrency for eslint (Huáng Jùnliàng) #62352
  • [d794676217] - typings: fix fs_event_wrap start filename type (leah-1ee) #65661
  • [29e2b5a325] - typings: add fs_event_wrap internal binding types (leah-1ee) #65661
  • [6357c8f56e] - typings: add stream_pipe internal binding types (Seongeun Lee) #65664
  • [569720ac7f] - typings: add profiler internal binding types (Seongeun Lee) #65660
  • [52ae89c69d] - typings: add ffi internal binding types (Donghoon Kang) #65734
  • [22c7469062] - typings: update zlib binding declarations (이혜미) #65639
1 days ago
openssl

OpenSSL 4.1.0-alpha1

OpenSSL 4.1.0 is a feature release adding significant new functionality to OpenSSL.

This release incorporates the following potentially significant or incompatible changes:

  • Added VC-WIN32-MSVC2013 and VC-WIN64A-MSVC2013 build targets to provide internal functions for bridging the gaps in C99 standard support that are present in MSVC 2013.

  • Added optimized ML-DSA and ML-KEM NTT operations on ppc64le; optimized ML-DSA operations on s390x, and x86_64; AVX-512-optimized SHAKE x4 operations for ML-DSA on x86_64; AVX-512 and VAES optimizations for AES-CBC decryption on x86_64.

  • Changed tsget utility to use Net::Curl::Easy (from the Net-Curl CPAN distribution) instead of the abandoned WWW::Curl::Easy. Users who rely on tsget should install Net::Curl::Easy before upgrading.

  • Dropped Windows-on-Itanium (VC-WIN64I) and Windows CE (VC-CE) targets from Configurations.

  • Dropped no-ecdsa and no-ecdh options from Configure, as these options did not really disable the implementations. Use no-ec to disable the elliptic curve support.

This release adds the following new features:

  • Support for DTLS 1.3 (RFC 9147). Refer to the ossl-guide-dtlsv13(7) manual page for details.

  • Support for RFC 8701 GREASE (Generate Random Extensions And Sustain Extensibility).

  • DTLS support in the SSL listener API.

  • Support for IKEV2 KDF.

  • Initial support for the Elbrus2000 (e2k) architecture.

1 days ago
turso

v0.8.0-pre.10

Install turso_cli 0.8.0-pre.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/tursodatabase/turso/releases/download/v0.8.0-pre.10/turso_cli-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/tursodatabase/turso/releases/download/v0.8.0-pre.10/turso_cli-installer.ps1 | iex"

Download turso_cli 0.8.0-pre.10

File Platform Checksum
turso_cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
turso_cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
turso_cli-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
turso_cli-x86_64-pc-windows-msvc.zip x64 Windows checksum
turso_cli-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
turso_cli-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo tursodatabase/turso

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
1 days ago
node

2026-09-08, Version 24.21.0 'Krypton' (LTS), @aduh95

Notable Changes

  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #63949
  • [6274fccbd9] - deps: update OpenSSL to 3.5.8 (Node.js GitHub Bot) #65542
  • [53cba013c7] - deps: update Undici to 7.29.1 (Node.js GitHub Bot) #65789
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #65024
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #65416
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #64965

Commits

  • [84d706cb9b] - assert: improve documentation wording (Kamal Rawal) #64953
  • [90d127db33] - (SEMVER-MINOR) benchmark: add --analyze mode to compare.js (James M Snell) #65416
  • [ad1d7884c3] - benchmark: add test-only and mock timers cases (Luan Muniz) #64097
  • [1d8f045914] - benchmark: apply highWaterMark in webstreams pipe-to (Matteo Collina) #65138
  • [ed7ba3c993] - benchmark: complete the sqlite is-transaction fix (Edy Silva) #65218
  • [c8837e1aa3] - benchmark: add test runner hooks and options (Luan Muniz) #63754
  • [2ba8661e23] - buffer: prevent string write offset overflow (Matteo Collina) #65043
  • [cc9ee6c2ae] - buffer: treat detached ArrayBuffers as empty (Archkon) #64504
  • [5a5d73e4c5] - build: pass target architecture to small-icu genccode (ulofiai) #65095
  • [273e72d1a5] - build: deprecate always enabled --enable-static (Chengzhong Wu) #65103
  • [89a67246e3] - build: check FIPS option value in node.gyp (Filip Skokan) #64982
  • [2d21f41cd5] - build: handle malformed OpenSSL macros (Filip Skokan) #64982
  • [f62bc0f862] - build,win: add PGO workload scripts (Stefan Stojanovic) #63696
  • [33d0c7dc12] - child_process: keep SIGWINCH from killing on Win (Kirill Saied) #64510
  • [71106e1f17] - crypto: update root certificates to NSS 3.126 (Node.js GitHub Bot) #65495
  • [419af8b86d] - crypto: fix missing error checks on ASN1_STRING_to_UTF8() (Nora Dossche) #65200
  • [8029383f3f] - crypto: use available BoringSSL APIs (Filip Skokan) #65423
  • [a9bd780e19] - crypto: remove obsolete BoringSSL shims (Filip Skokan) #65423
  • [7defefad3f] - crypto: read WebCrypto inputs through primordials (Filip Skokan) #65115
  • [6ed1e38627] - crypto: fix disabling FIPS mode (Filip Skokan) #64982
  • [afca0a912d] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #63949
  • [9b9dd6e9cf] - debugger: wait for target startup (Filip Skokan) #65194
  • [07faaeeffd] - deps: update corepack to 0.36.0 (Node.js GitHub Bot) #65653
  • [53cba013c7] - deps: update undici to 7.29.1 (Node.js GitHub Bot) #65789
  • [0268ca547c] - deps: update archs files for openssl-3.5.8 (Node.js GitHub Bot) #65542
  • [6274fccbd9] - deps: upgrade openssl sources to openssl-3.5.8 (Node.js GitHub Bot) #65542
  • [6bdcd121fa] - deps: update zlib to 1.3.2.1-motley-8002e91 (Node.js GitHub Bot) #65316
  • [c2aa446b6d] - deps: update simdjson to 4.6.7 (Node.js GitHub Bot) #65318
  • [3e58e48ea8] - deps: update googletest to 49495eacfdbda3f4b6ba219923fedbb2e3f99376 (Node.js GitHub Bot) #65317
  • [670b3665c0] - deps: cherry-pick libuv/libuv@e640dc9 (ulofiai) #65118
  • [ca1c67b021] - deps: float ICU-23262 patch for icu78 (René) #64678
  • [4ad043b0aa] - deps: enable AVX-512 OpenSSL asm with clang (Daniel Lemire) #65136
  • [96b4af109b] - deps: update googletest to d89aac5f0dd4021198d903d39de16f896726de21 (Node.js GitHub Bot) #65153
  • [774f663c56] - dgram: don't swallow bind errors when callback is provided (armanmikoyan) #62602
  • [94b118d62e] - diagnostics_channel: validate before channel activation (Trivikram Kamat) #65313
  • [09788665bd] - dns: validate address type in lookupService (Lazizbek Ergashev) #64878
  • [15f95fc0e2] - dns: validate port range in setServers() (René) #65021
  • [37b9e9a154] - dns: fix crash on setServers with port 0 (Lazizbek Ergashev) #65009
  • [cd6205fa0d] - doc: update AHAFS reference link (Taeuk Ha) #65481
  • [0e6f9ae42e] - doc: fix property names in os.networkInterfaces() example (Jihwan) #65469
  • [034a827b41] - doc: fix broken links in cli.md (Donghoon Kang) #65412
  • [eb364621d4] - doc: remove outdated WASI version fallback (이혜미) #65303
  • [b13f425bf8] - doc: fix broken GYP link in n-api.md (Donghoon Kang) #65413
  • [45c4011067] - doc: document that an empty OPENSSL_CONF skips config loading (Orgad Shaneh) #64949
  • [fde6776c5f] - doc: fix broken TLS security level example (soreavis) #65391
  • [290c1fec04] - doc: clarify socket destroyed behavior (Dayun) #65395
  • [a7e8269947] - doc: update outdated nodejs.org guide links (Donghoon Kang) #65394
  • [7809f11249] - doc: clarify that ipv4 mapped to ipv6 are classified as ipv6 (Vedant Kulkarni) #62117
  • [64cd3a6e95] - doc: clarify how fs.Dirent file types are determined (soreavis) #64532
  • [9b92fdce14] - doc: update security release prepare command (Rafael Gonzaga) #64699
  • [6f9b9df3c1] - doc: clarify copyFile symlink behavior (T) #62941
  • [2480acb550] - doc: document setRawMode write access on Windows (Erik Demaine) #63856
  • [a1e9c3a5db] - doc: add missing return types in fs.md (Chaseton Collins) #65307
  • [4533572040] - doc: add missing return types in buffer.md (Yuya Inoue) #65308
  • [39ecedbbd2] - doc: fix lint clean command (greenhead) #65274
  • [0b1fb8fcd8] - doc: fix typo in onboarding.md (서울민트초코) #65295
  • [3165b5d38a] - doc: add missing added: tags to fs.lchmod (Lazizbek Ergashev) #65283
  • [113b808e59] - doc: fix SQLite changeset constant descriptions (greenhead) #65265
  • [c3eb51d5a1] - doc: document open pull request limit (Matteo Collina) #65250
  • [d7accdcd52] - doc: document http2 header constants (Harjoth Khara) #64548
  • [f47111416f] - doc: create ai-guidelines and include to CONTRIBUTING (Rafael Gonzaga) #62105
  • [c3b120e737] - doc: update synopsis (Augustin Mauroy) #65171
  • [39f4c831fd] - doc: fix broken internal links (greenhead) #64901
  • [be25cdd69e] - doc: report proper return type on urlPattern.test (Brian Muenzenmeyer) #64831
  • [1bf7737810] - doc: fix permission documentation examples (greenhead) #64897
  • [b7932e68a1] - doc: document sqlite parameter binding (Guilherme Araújo) #65089
  • [5234a5169c] - doc: finalize statements in sqlite examples (Guilherme Araújo) #65088
  • [39ea929da7] - doc: document quic stopSending() and resetStream() (Issac) #64888
  • [2ba198db73] - doc: clarify sqlite bare parameter default (Sumit Kumar Das) #62009
  • [314f9b200f] - doc: remove usage of util.inherits (Augustin Mauroy) #60817
  • [d82a61662c] - doc: fix grammar in worker_threads.md (이혜미) #64913
  • [44c0c8ff5b] - doc: clarify OpenSSL FIPS configuration (Filip Skokan) #64982
  • [9b2ca70e0d] - doc: remove --expose-gc flag from CLI documentation (Dario Piotrowicz) #58909
  • [a0a12397b9] - doc: document ArrayBuffer support in pbkd2Sync (kyungrae2002) #64976
  • [b48699e077] - doc: correct default highWaterMark values (Yilong Li) #64617
  • [0312ee133c] - esm: avoid super-linear data URL MIME regex (Sumit Kumar Das) #61951
  • [cd84d55c81] - esm: only register text format when enabled (Efe Karasakal) #64992
  • [c0a8ef611e] - esm: fix wasm import name in error message (이혜미) #64950
  • [e6c34f90c2] - events: inline iterationCondition hybrid dispatch closure (Szymon Łągiewka) #64473
  • [6ee4b40c91] - events: inline createEvent hybrid dispatch closure (Szymon Łągiewka) #64473
  • [367549eed5] - fs: use sized reads for large files in readFileUtf8 (Shelley Vohr) #65328
  • [8a5b1ae4c2] - fs: fix realpath of namespaced drive paths (Jason Zhang) #65378
  • [c9233b950d] - fs: fix glob early return skipping sibling entries (Srinu desetti) #64895
  • [bc54dd8905] - fs: pass symlink type in cp when filter is provided (Jerry Zhao) #62654
  • [fcb4333aca] - fs: allocate FSReqPromise stat arrays lazily (Samuel Attard) #63886
  • [c35876154e] - fs: fix out-of-bounds write in mkdtemp for long prefixes (Hierax_Umbra) #64770
  • [b269616936] - fs: treat std::errc::permission_denied as EPERM error (Kirill Saied) #64698
  • [212fe77e76] - fs: add windowsHandle option to file streams (Kirill Saied) #63851
  • [75df6cb435] - http: improve performance with known-length calls to end() (Tim Perry) #65466
  • [48d9cd4a28] - http: cache maxHeaderPairs per header section (GetThatCookie) #64988
  • [04785c8f43] - http: fix keylog listener setup on existing agent sockets (Shani Singh) #65066
  • [4b90031534] - http: emit drain on socket takeover and avoid stale HWM reuse (Naman Trivedi) #64991
  • [83a27559cd] - http2: adapt receive deferral for Node.js 24 (Matteo Collina) #65093
  • [f43bed0ecc] - http2: avoid uaf while receiving and sending rst_stream (esgor) #64166
  • [b42d664321] - inspector: avoid calling into JS from V8 interrupts (Joyee Cheung) #65028
  • [6bf852197d] - lib: use bracket notation instead of startsWith/endsWith for single char (Taejin Kim) #61500
  • [151ca7e104] - lib: harden webidl dictionary member reads (Filip Skokan) #65115
  • [7e8c2c9f44] - lib: use validateArray for array arguments (greenhead) #64959
  • [424fe2bc5a] - lib: add and test [EnforceRange] in webcrypto dictionaries (Filip Skokan) #65091
  • [0529772798] - (SEMVER-MINOR) lib,src: improve histogram implementation (James M Snell) #65024
  • [186e1b76e8] - meta: move targos to emeritus (Michaël Zasso) #65393
  • [b41b07c72a] - meta: add unified http api initiative (James M Snell) #65139
  • [f85b6ecd67] - meta: move one or more collaborators to emeritus (Node.js GitHub Bot) #65182
  • [8f3d01bdce] - meta: add Aviv Keller to .mailmap (Aviv Keller) #65048
  • [cfad1d5b28] - meta: update sccache to 0.17.0 (René) #64985
  • [349c53c441] - module: report unreadable package.json (Paul Bouchon) #65223
  • [bd21e6706e] - module: cache nearest parent package.json per directory (Shelley Vohr) #65326
  • [961bd04370] - module: fix --check on ambiguous ESM files (Paul Bouchon) #65203
  • [f45ef73420] - net: handle undefined parent in _unrefTimer and _destroy (Shivay-98) #64644
  • [41c7062b81] - (SEMVER-MINOR) net: improve performance of net.BlockList (James M Snell) #64974
  • [5197b5a3c5] - (SEMVER-MINOR) perf_hooks: add statistical hypothesis testing to histogram (James M Snell) #65416
  • [1722ddac28] - permission: enforce addon permission in GetLinkedBinding (Rafael Gonzaga) #65432
  • [dff2b675db] - process: validate resource stats array offsets (Archkon) #65098
  • [f277983e7b] - quic: changes for nghttp3_conn_close_stream2 (Marten Richter) #64574
  • [a4c770c78e] - quic: mark drain promise handled (James M Snell) #65319
  • [2460b171c5] - quic: reset rejected HTTP/3 request streams with H3_REQUEST_REJECTED (trivenay) #65442
  • [18a7ccf302] - quic: write desired size needs update on maxstream (Marten Richter) #64768
  • [9017f4a780] - quic: do not destroy incoming streams that have a consumer (trivenay) #65335
  • [ddc41c1ef4] - quic: fix wake up blob (Marten Richter) #64044
  • [88bee43d7c] - quic: convert incoming :status header to number (Hallison Pereira Melo) #63589
  • [cd776fe97c] - quic: fix infinite loop if STOP_SENDING received on a buffering stream (Tim Perry) #64715
  • [4f6eda3c23] - repl: keep entries added while history file is loading (Mhayk Whandson) #64513
  • [cd1e6ce29b] - repl: add benchmarks (Aviv Keller) #64590
  • [2ba740669d] - sea: avoid dangling CLI option pointers (Archkon) #64755
  • [ec5e2d6856] - sea: handle NUL bytes in asset keys (Archkon) #64773
  • [703b854293] - sea: reject trailing content in config JSON (Archkon) #64774
  • [a61a5fdd1c] - sqlite: prevent reentrant session.close() (Trivikram Kamat) #65349
  • [6ae81be0a3] - sqlite: reject statement-less SQL in prepare() (Trevor Burnham) #65157
  • [043dfe4996] - sqlite: reject statement-less SQL in SQLTagStore (Trevor Burnham) #65157
  • [b8faee02e1] - sqlite: check null returns from sqlite value functions (Nora Dossche) #63288
  • [d6d2a71bee] - sqlite: validate maxSize argument in createTagStore() (Anshika Jain) #63792
  • [61a046309f] - sqlite: reject non-positive backup rates (Trivikram Kamat) #64893
  • [514e3f30fb] - sqlite: clear SQLTagStore bindings (Matteo Collina) #65041
  • [c1542255b8] - sqlite: bind Boolean (mike-git374) #62001
  • [cdb732beb5] - sqlite: fix undefined behaviour in Session::Changeset() (Nora Dossche) #63637
  • [fbe8861111] - sqlite: bind ArrayBuffer (mike-git374) #62061
  • [e3c6bd6bc8] - src: add missing vector include (Filip Skokan) #65622
  • [793cf69df8] - src: fix heap value deduplication in embedder graph (Ilyas Shabi) #64801
  • [ea5935b04c] - src: fix out-of-bounds write when transcoding odd-length ucs2 (nashit hayat) #64512
  • [22e5023f4d] - src: escape Windows environment variables in task runner (Antoine du Hamel) #65217
  • [a0f3c62bd9] - src: simplify c++ diagnostics channel API (James M Snell) #65158
  • [8e831a3d2e] - src: make minor cleanup to permission checks (James M Snell) #65158
  • [968b2ca3a3] - src: use DictionaryTemplate for permission diag channel message (James M Snell) #65158
  • [18e16e7f8d] - src: cache permission strings (James M Snell) #65158
  • [c8625a4b6f] - src: add SetAbortHandler (Max H Fisher) #64684
  • [c990140d60] - src: match cmd.exe case-insensitively in task runner (Archkon) #64907
  • [d7463b9dbc] - src: reuse cached env strings in remaining files (Seongeun Lee) #65039
  • [b055a43b93] - src: expose Windows-only fs open flags (Kirill Saied) #64775
  • [7f21e37496] - src: report why --enable-fips failed (Filip Skokan) #64979
  • [8c11beae27] - src: update repeated use strings to env (James M Snell) #64760
  • [9e2c477e26] - stream: normalize fused stateless transform results (Trivikram Kamat) #65367
  • [107e96dd41] - stream: encode whole chunks in TextEncoderStream (Matteo Collina) #65414
  • [164068279b] - stream: prevent share from eagerly draining source (Trivikram Kamat) #65338
  • [93d822bdc1] - stream: drain pending writes before broadcast end (Trivikram Kamat) #65334
  • [6b8b9c362f] - stream: reuse unexposed managed read buffers (GetThatCookie) #64990
  • [4ec4fab367] - stream: avoid duplicated endReadableNT scheduling (Matteo Collina) #65310
  • [86d1196ebf] - stream: decouple transform backpressure changes (Matteo Collina) #65143
  • [b8a7a75b19] - stream: reject pull on signal abort during flush (Trivikram Kamat) #65346
  • [386ed6a06d] - stream: avoid leaking consumers on signal failure (Trivikram Kamat) #65299
  • [74d53bd73b] - stream: use validateObject for zlib/iter params (greenhead) #65015
  • [3a174ce16b] - stream: use validateNumber for BYOB reader options.min (greenhead) #65014
  • [859ea01cb2] - stream: consolidate non-op algorithm callbacks (Matteo Collina) #65138
  • [c577669825] - stream: cut promise churn in webstreams hot paths (Matteo Collina) #65138
  • [d631e910db] - stream: preserve falsy cancellation reasons (Trivikram Kamat) #64705
  • [f9c21eabbd] - stream: use validateBuffer for BYOB reader view (greenhead) #65046
  • [b89c8f5d1e] - stream: fix recursive WritableStream abort (Jeong SeokChan) #64825
  • [39e0457e86] - test: fix link-local dgram scope assertion (Filip Skokan) #65629
  • [1433cf9d5b] - test: account for varied OpenSSL CCM final behaviours (Filip Skokan) #65542
  • [7d135d24b7] - test: convert forEach to for of test-messageevent-brandcheck file (Nachiketa Pathak) #65279
  • [421ee11715] - test: use spawnSyncAndAssert in windowsHide test (Junsoo Ha) #65351
  • [929d5705bc] - test: remove test-debugger-run-after-quit-restart as flaky on macOS (Yuya Inoue) #65424
  • [f38f154c14] - test: simplify test-timers-interval-promisified.js (Donghoon Kang) #65322
  • [a98e27f2a9] - test: add Headers coverage and benchmark (Yagiz Nizipli) #65365
  • [38fdbb62aa] - test: deflake test-net-listen-ipv6only (sangwook) #64173
  • [06c7684b01] - test: use common/child_process spawnSync helpers (Junsoo Ha) #65377
  • [6438c70004] - test: fix Linux debug skip in SEA test guard (구현우) #63751
  • [fe0e4f1b65] - test: avoid timer race in event loop delay test (Trivikram Kamat) #64728
  • [6ff69baea8] - test: enforce exit code in test-http-server-stale-close (Antoine du Hamel) #65198
  • [ba87603016] - test: convert test-async-local-storage-bind to async loop (freida-code) #65270
  • [8d6b89f454] - test: replace forEach() with for...of in parallel tests (Phillip Markert) #65272
  • [a60572a7bb] - test: convert forEach to for in test-constant.js file (NIxxy25) #65271
  • [f82060c6ce] - test: use for-of instead of forEach (Felix P.) #65268
  • [5ded71f9cc] - test: cover realpathSync resolving symlinks after a FIFO stat (Hendrik Liebau) #65113
  • [ac9835225e] - test: account for [EnforceRange] in test-webcrypto-prototype-pollution (Filip Skokan) #65173
  • [550d24277e] - test: update WPT for WebCryptoAPI to 4c2fd05ed5 (Node.js GitHub Bot) #65150
  • [2aa26559f0] - test: update WPT for urlpattern to 4832db4761 (Node.js GitHub Bot) #65151
  • [d45c010108] - test: fix hidden error in test-http-server-stale-close.js (Meghan Denny) #59357
  • [881f8d092d] - test: avoid deadlock issue in pipeline http2 tests to fix flakiness (Tim Perry) #65079
  • [e4b1e3ee75] - test: allow half-open CONNECT tunnel sockets (Trivikram Kamat) #64973
  • [00f4240d48] - test: update passphrases to comply with the next OpenSSL FIPS mode (Filip Skokan) #65077
  • [cf7680efb7] - test: use libuv clock for immediate queue test (Trivikram Kamat) #64889
  • [b0c12772ff] - test: increase timeout in probe-failure-hang-during-evaluate (Joyee Cheung) #64719
  • [7e279104b4] - test: update WPT for WebCryptoAPI to 82c3d9069c (Node.js GitHub Bot) #64977
  • [ac11f88d16] - test,doc: cover and document multi-byte offset/size in randomFill (kyungrae2002) #64834
  • [67da38cada] - test_runner: match dotfiles in default coverage exclude (semimikoh) #63401
  • [b06c61a08f] - test_runner: print coverage and diagnostic info with dot reporter (mag123c) #61423
  • [7cb9c9c126] - test_runner: use run options with isolation="none" (Sylvester Keil) #62269
  • [339acf4201] - test_runner: mock dual-package with conditional exports (Maruthan G) #62943
  • [e7a68bca08] - test_runner: add classname hierarchy for JUnit reporter (mag123c) #60220
  • [6a248acefe] - test_runner: fix junit report on empty diagnostic (Lazizbek Ergashev) #65357
  • [d01dda79b6] - test_runner: do not tag-filter test file wrappers (Chemi Atlow) #65170
  • [32ead10ddd] - test_runner: fix env option validation (Jihwan) #64865
  • [b0ef155440] - tls: throw on invalid ALPNProtocols instead of aborting (Sankalp Thakur) #65076
  • [dcf65c50ce] - tls: fix authorized state on no-cert TLS1.3 client cert resumption (Tim Perry) #64677
  • [b0f54bda78] - tools: improve commit queue failure comment (Filip Skokan) #65433
  • [bc1f2718d5] - tools: fix max body length handler in create-release-proposal.sh (Antoine du Hamel) #65455
  • [bbe76516a9] - tools: bump brace-expansion in /tools/clang-format (dependabot[bot]) #64984
  • [67697debdf] - tools: make env variables consistent in cron jobs (Antoine du Hamel) #65168
  • [ac8a68ec92] - tools: only include fast-tracked and old enough PRs in CQ (Antoine du Hamel) #65197
  • [6d9999fa2e] - tools: remove skip logic in commit-queue.sh (Antoine du Hamel) #65162
  • [60bfa1694e] - tools: bump js-yaml from 4.2.0 to 4.3.1 in /tools/lint-md (dependabot[bot]) #65129
  • [782748527e] - tools: bump js-yaml from 4.2.0 to 4.3.1 in /tools/eslint (dependabot[bot]) #65130
  • [dac257340f] - tools: fix GITHUB_TOKEN permissions for CQ workflow (Antoine du Hamel) #65192
  • [e624785846] - tools: use the read-only token when filtering PRs in CQ (Antoine du Hamel) #65169
  • [7d9dcfaaa7] - tools: delay removal of commit-queue label (Antoine du Hamel) #65101
  • [0d7c7936e7] - tools: move ncu config to global for commit queue (Filip Skokan) #65132
  • [5e1db5a38a] - tools: prefilter commit queue metadata (Filip Skokan) #64343
  • [f41509b91d] - tools: lazy-abort failed PR merges in CQ (Antoine du Hamel) #65004
  • [ceb0e99acd] - tools: sync mk-ca-bundle.pl with curl (Archkon) #64753
  • [600663b23f] - tty: add raw-vt and io raw modes (Samuel Williams) #64140
  • [a40bfc742e] - typings: add signal_wrap internal binding types (Seongeun Lee) #65229
  • [b103a4a3b9] - typings: add diagnostics_channel typings (Seongeun Lee) #65227
  • [e64de34b89] - typings: add watchdog internal binding types (Seongeun Lee) #65228
  • [c57c83b4d1] - typings: add internal_only_v8 binding typeis (Donghoon Kang) #65071
  • [f15e8c9dcd] - typings: add credentials internal binding types (Donghoon Kang) #65036
  • [a500256b0b] - url: skip unused href reuse comparison (Yagiz Nizipli) #65361
  • [58390f8bec] - url: speed up WHATWG URL parsing (Yagiz Nizipli) #65361
  • [7d5428c812] - url: speed up URLSearchParams (Yagiz Nizipli) #65363
  • [8e2461d819] - url: bounds-check short Windows file URL paths (Archkon) #64788
  • [9ffc0da90c] - url: handle unparsable serialized URLs in setters (Matteo Collina) #64651
  • [fa9d4e075d] - util: allow single-line format when break length is infinite (Hamid Reza Ghavami) #64238
  • [b68a7c3862] - util: fix OSC 8 hyperlink stripping in stripVTControlCharacters (Dushyant Singh Hada) #64319
  • [10cbb6dc00] - util: fix formatting of functions returned from getters (Richard Gibson) #64839
  • [64c20b449e] - util: use more primordials in comparisons.js (Ayoub Mabrouk) #61198
  • [cea9786de8] - util: preserve function names without source map names (Hiroki Osame) #65108
  • [35c635b032] - (SEMVER-MINOR) util: add non-throwing MIMEType.parse (James M Snell) #64965
  • [5858c2ba9a] - zlib: validate pledgedSrcSize for sync zstd (Archkon) #64601
2 days ago
turso

v0.8.0-pre.9

Install turso_cli 0.8.0-pre.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/tursodatabase/turso/releases/download/v0.8.0-pre.9/turso_cli-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/tursodatabase/turso/releases/download/v0.8.0-pre.9/turso_cli-installer.ps1 | iex"

Download turso_cli 0.8.0-pre.9

File Platform Checksum
turso_cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
turso_cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
turso_cli-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
turso_cli-x86_64-pc-windows-msvc.zip x64 Windows checksum
turso_cli-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
turso_cli-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo tursodatabase/turso

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>