NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #714 most downloaded on Packagist
RoadRunner: High-performance PHP application server and process manager written in Go and powered with plugins
Last release 3 months ago
17 Jun 2026
Ships fairly regularly
a new release about every 4 weeks
Rarely documented
notes for 10 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
269 releases · first in 2018
🐛 CVE Fixes: Updated Go toolchain to 1.26.4 to resolve CVE-2026-42504 . Note: fiber is only used transitively by the fileserver plugin, BUG #2355 (tha…
🚀 v2025.1.15 🚀
🎯 Core
One column per quarter.
🐛 CVE Fixes: Updated Go toolchain to 1.26.3 and bumped github.com/gofiber/fiber/v2 to v2.52.13 to resolve CVE-2026-33811 , CVE-2026-33814, CVE-2026-39…
🚀 v2025.1.14 🚀
🎯 Core
🧰 Plugins
🧪 Temporal
🐛 CVE Fixes : Updated dependencies and Go version to 1.26.2 to resolve CVE-2026-32280 and CVE-2026-39883 ( go/stdlib ), CHORE (thanks @rebecca-canyon…
1.26.2 to resolve CVE-2026-32280 and CVE-2026-39883 (go/stdlib), CHORE (thanks @rebecca-canyon)🐛 CVE Fix (deps) : Updated google.golang.org/grpc to v1.79.3 to resolve CVE-2026-33186 — a server-side authorization bypass where malformed :path head…
google.golang.org/grpc to v1.79.3 to resolve CVE-2026-33186 — a server-side authorization bypass where malformed :path headers could circumvent path-based restricted deny rules in gRPC interceptors, CHORE (thanks @rebecca-canyon)🐛 OTEL Semconv : Fixed a regression where the OpenTelemetry plugin failed to start due to conflicting semconv Schema URLs ( v1.39.0 vs v1.40.0 ); upda
otel pluginv1.39.0 vs v1.40.0); updated semconv to v1.40, BUG (thanks @dmitryuk)🐛 CVE Fixes (deps) : Updated Go packages to resolve CVE-2026-27141 and CVE-2026-25882 , Issue (thanks @Orrison )
grpc plugin** (globstar/recursive) and brace expansion {pattern1,pattern2} in grpc.proto configuration paths, FR (thanks @Nyholm)1.26.1 to address CVE-2026-25679, CVE-2026-27142, CVE-2026-27137 in go/stdlib, Issue (thanks @Orrison)🐛 Gzip Middleware : Fixed a regression where responses could be encoded with zstd after upgrading to v2025.1.7 ; the middleware now enforces gzip-only
🐛 Go Version : Updated minimum Go version to 1.26 to address CVE-2025-61726 in go/stdlib BUG (thanks @Orrison )
1.26 to address CVE-2025-61726 in go/stdlib BUG (thanks @Orrison)✨ Go Version : Updated minimum Go version to 1.25.5 .
1.25.5.✨ SIGUSR2 Signal Support : Added support for the SIGUSR2 signal on Unix-like systems to enable graceful process restarts. When the configuration file
SIGUSR2 signal on Unix-like systems to enable graceful process restarts. When the configuration file is a symlink, RoadRunner will properly re-read the configuration from the symlink target after restart FR (thanks @koren88)1.25.4.v2025.1.5 with an updated template that pinned third-party dep tablewriter that caused problems when building RR.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →