NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #987 most downloaded on crates.io
A rate-limiting implementation in Rust
Last release 9 months ago
16 Dec 2025
Ships fairly regularly
a new release about every 3 months
Most releases are documented
notes for 21 of 24 stable releases
1 version withdrawn
withdrawn after publishing
7 years old
25 releases · first in 2019
Merge pull request #291 from boinkor-net/release/governor/0.10.4
Merge pull request #291 from boinkor-net/release/governor/0.10.4
release: governor v0.10.4
Another bug-fix release to repair the documentation build on
docs.rs for good: The doc_auto_cfg feature was deprecated,
this version switches to the feature doc_cfg.
Merge pull request #289 from boinkor-net/release/governor/0.10.3
Merge pull request #289 from boinkor-net/release/governor/0.10.3
release: governor v0.10.3
One column per quarter.
Merge pull request #283 from boinkor-net/release/governor/0.10.2
Merge pull request #283 from boinkor-net/release/governor/0.10.2
release: governor v0.10.2
hashbrown dependency to require version 0.16.
Thanks, @cratelyn!Merge pull request #278 from boinkor-net/release/governor/0.10.1
Merge pull request #278 from boinkor-net/release/governor/0.10.1
release: governor v0.10.1
Merge pull request #267 from boinkor-net/release/governor/0.10.0
Merge pull request #267 from boinkor-net/release/governor/0.10.0
release: governor v0.10.0
Merge pull request #265 from boinkor-net/release/governor/0.9.0
Merge pull request #265 from boinkor-net/release/governor/0.9.0
release: governor v0.9.0
Merge pull request #261 from boinkor-net/release/governor/0.8.1
Merge pull request #261 from boinkor-net/release/governor/0.8.1
release: governor v0.8.1
Merge pull request #253 from boinkor-net/release/governor/0.8.0
Merge pull request #253 from boinkor-net/release/governor/0.8.0
release: governor v0.8.0
Fixed the long-standing confusion of rate-limiting "tolerance" vs. "burst capacity": Tolerance is indicated with one cell less than burst capacity would be. The code treated the two as the same thing, leading to spurious single cells being allowed through when the clock advanced. (#107, #249). This confusion has finally been identified and fixed by @jonasmalacofilho in #251.
This should not affect the public API, but any clients subject to rate-limiting may see a slightly fairer treatment.
Merge pull request #248 from boinkor-net/release/governor/0.7.0
Merge pull request #248 from boinkor-net/release/governor/0.7.0
release: governor v0.7.0
This is a quick bug-fix release to address the semver incompatibility in 0.6.4. It is functionally identical to 0.6.4, with the exception of the dashmap version upgrade.
Merge pull request #243 from boinkor-net/release/governor/0.6.4
Merge pull request #243 from boinkor-net/release/governor/0.6.4
release: governor v0.6.4
This release has been yanked because it violates Semantic Versioning
ideals: The Clock argument type in functions like direct_with_clock
changed, which breaks existing code.
Instead of 0.6.4, please use 0.7.0.
https://docs.rs/governor now lists the features required for feature-gated types and functions.
A
RateLimiter
now has a
clock
method to retrieve the clock providing its timestamps. Added by
@max-heller in
#232.
Clocks
no longer need to be Clone. Changed by
@max-heller in
#232.
governor now depends only on
futures-util and
futures-executor instead of
the much larger futures crate. Fixed by
@negezor in
#239.
Just another bug-fixed release process. This time, it should actually release out of github actions.
The governor repo now lives in the boinkor-net github organization. No ownership has changed (@antifuchs still manages this org), but this makes it ea
The governor repo now lives in the boinkor-net github
organization. No ownership has changed (@antifuchs still manages
this org), but this makes it easier to securely manage the CI and
release setup.
The .per_second constructor for Quota now constructs a quota
that ensures all rate-limiting calls succeed when given values in
excess of 1 billion (previously, this would result in rate limiters
that would incorrectly reject values). Reported in
#203.
QuantaUpkeepInstant now properly advances
forward.
no_std is now properly
supported:
Instead of parking-lot, governor now uses the spinning_top crate in
no_std mode.
Type aliases DefaultDirectRateLimiter and DefaultKeyedRateLimiter to cut down on type-typing of typical rate limiters in struct and function definitio
DefaultDirectRateLimiter and
DefaultKeyedRateLimiter to cut down on type-typing of typical rate
limiters in struct and function definitions. Requested in
#85..check_n and .until_n (and their keyed counterpart)
have changed to return a nested Result - the outer indicating
whether the check could ever succeed and the inner one indicating
the rate limiting result, if it could succeed.QuantaUpkeepClock structure. All lower-resolution quanta
timekeeping used by governor will now be relative to that reference
instant.Fixed quota reporting for positive rate limiting decisions when StateInformationMiddleware is in use with a real clock. Reported in #157
StateInformationMiddleware is in use with a real clock. Reported
in #157Fixed a bug in StateSnapshot::remaining_burst_capacity: Now returns the correct number of cells after enough time has passed. Thanks to @holmesmr for
Upgraded dashmap back to 5.1.0.
Downgraded dashmap to 4.0.2 as a remediation for RUSTSEC-2022-0002 via #104.
You can now alter&expand the information returned from a rate limiter by attaching middleware to it using .with_middleware:: () at construction time.
You can now alter&expand the information returned from a rate
limiter by attaching middleware to it using
.with_middleware::<YourClass>() at construction time.
This is an incompatible change, as the type signature of RateLimiter gained an additional generic parameter. See the pull request and issue #66 for details.
Arc guide section to use Arc::clone() instead of limiter.clone().quanta dependency
to 0.8.0, speeding up the quanta clock by a bit. This changes the
upkeep clock interface incompatibly: The quanta upkeep Builder
structure got renamed to quanta::Upkeep.nanos module is now public, allowing other crates to implement
the Clock trait.std feature, governor will no longer pull in the
hashbrown crate.Nothing published for this version
…result in trees using governor pulling in a vulnerable smallvec version.
Several dependencies' minimum versions were bumped, including a
version bump of
smallvec, a transitive
dependency which could previously result in trees using governor
pulling in a vulnerable smallvec version.
The ShrinkableKeyedStateStore trait now has required len and is_empty methods, which are also made available on any RateLimiter that uses a shrinkable
ShrinkableKeyedStateStore trait now has required len and
is_empty methods, which are also made available on any
RateLimiter that uses a shrinkable (Hashmap / Dashmap backed)
state store. Thanks to @lytefast for
the idea and pull request
on ratelimit_meter!MonotonicClock and SystemClock struct definitions now are
proper "empty" structs. Any non-Default construction of these clocks
must now use MonotonicClock instead of MonotonicClock().clock::ReasonablyRealtime trait got simplified and no longer
has any required methods to implement, only one default method.spin crate with parking_lot for no_std contexts.New type RateLimiter, superseding the DirectRateLimiter type.
This changelog!
New type RateLimiter, superseding the DirectRateLimiter type.
Support for keyed rate limiting in RateLimiter, which allows users
to keep a distict rate limit state based on the value of a hashable
element.
Support for different state stores:
Support for different clock kinds:
Quota constructors now support a separate .allow_burst method
that specifies a maximum burst capacity that diverges from the
default.
New constructor Quota::with_period allows specifying the exact
amount of time it takes to replenish a single element.
Quota::new constructor has some very confusing modalities, and
should not be used as-is.check_n, causing calls with n = burst_size + 1 to return a "not yet" result instead of a "this will
never work" result.Initial release: A "direct" (a single rate-limiting state per structure) rate limiter that works in an async context, using atomic operations.
Initial release: A "direct" (a single rate-limiting state per structure) rate limiter that works in an async context, using atomic operations.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →