NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #128 by repository stars
Last release today
08 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 27 of 29 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
308 releases · first in 2025
One column per month.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Thoth functionality has been removed. THOTH_URL , THOTH_TOKEN , and THOTH_INSECURE are now deprecated environment variables that will log a warning up…
Final smoke test prerelease before it ships properly, I swear.
geoip block.THOTH_URL, THOTH_TOKEN, and THOTH_INSECURE are now deprecated environment variables that will log a warning upon startup.anubis group and assign all Anubis instances permissions to /var/lib/anubis.COOKIE_PREFIX setting (#1977)USE_SIMPLIFIED_EXPLANATION is now deprecated.pt-PT) localization.As part of a continuous security posture, the following issues were identified and remediated:
Full Changelog: v1.28.0-pre2...v1.28.0-pre3
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: remove client-supplied X-Anubis-* header spoofing vector by @JasonLovesDoggo in #1919
X-Anubis-* header spoofing vector by @JasonLovesDoggo in #1919Full Changelog: v1.28.0-pre1...v1.28.0-pre2
wasm2js in order to make the WebAssembly proof of work checks run in non-wasm environments.wasm2js/wasm-opt WebAssembly modules build reproducibly and fix the build on arm64.npm run test:integration so the Playwright suite can connect to browsers and Firefox can reach the test server again.pass-challenge just issued (#1314).Host header as X-Forwarded-Host in Open Graph requests so backends can dispatch based on host.X-Anubis-* header spoofingnpm run test:integration and the Playwright CI step, which were pinned to playwright@1.61.1 while go.mod's mxschmitt/playwright-go had already been bumped to a client expecting protocol 1.62.x, causing every Playwright-driven test to fail with a version mismatch.Referer header on the request forwarded to the target after a challenge is passed, so server-side logs and analytics no longer see the internal challenge page as the referrer. Add an opt-in --preserve-referer-query-param flag that also appends utm_source/utm_medium query parameters to the post-challenge redirect for client-side analytics tools (e.g. Plausible) that read query parameters instead of document.referrer, which cannot be corrected from the server side (#1596).DENY status code instead of HTTP 500 when a challenged client is rejected for not advertising gzip support, and log that rejection at INFO instead of ERROR. The rejection is deliberate, so it no longer shows up in 5xx rates or as a server fault. The log message text is unchanged, but fail2ban filters that match on the ERROR level need updating (#1009).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release adds WebAssembly based proof of work checks to Anubis. They are documented in the Proof of Work (WebAssembly) page. This uses Rust code c
This release adds WebAssembly based proof of work checks to Anubis. They are documented in the Proof of Work (WebAssembly) page. This uses Rust code compiled to WebAssembly to run proof of work code. When browsers support SIMD, the WASM will use hardware acceleration.
When clients are configured to disable WebAssembly, Anubis falls back to a pure JavaScript implementation of the WebAssembly-based check logic. As clients that disable WebAssembly usually disable the JavaScript JIT (the thing that makes JavaScript fast), this makes checks slower.
Additionally due to complicated facts and circumstances involving it being complicated to pass the messages from the wasm2js world back to JavaScript, the progress bar will not update while a wasm2js check is running. This is a known issue and will be fixed in a later release.
The difficulty values for the WebAssembly based checks are going to be much greater than the equivalent difficulty values for the JavaScript based checks. Generally these count the number of leading bits that much match instead of the number of leading nibbles that must match. Here's a rough translation table:
fast difficulty |
argon2id difficulty |
sha256 difficulty |
hashx difficulty |
|---|---|---|---|
4 |
4 |
16 |
15 |
2 |
2 |
8 |
7 |
6 |
6 |
24 |
20 |
As I'm not certain this will work fine out of the box for a few edge cases, I have disabled these new challenge methods by default. I will enable the new methods by default in a future version after they have been sufficiently tested.
Full Changelog: v1.27.0...v1.28.0-pre1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Breaking change: cookie names are dynamically created based on cookie settings
Anubis v1.27.0 adds Windows Server support, automatically renames cookies based on settings to avoid infinite challenge loops, adds two new localizations, and more.
Anubis tries to avoid breaking changes as much as possible, but sometimes we have to make them for the sake of the users. This is technically a breaking change in something that is not part of the public API of Anubis; but some administrators rely heavily on cookie names in advanced configurations.
It seems that browsers store cookies disambiguated with their options. This means you can have multiple cookies named the same but with different options. Browsers will send these cookies to the server without the list of options. This means that changing any cookie settings requires you to change COOKIE_PREFIX, creating a new "cookie epoch" that will set things properly.
In order to be more robust, Anubis will automatically change cookie names based on the cookie settings. For example, the default configuration creates cookies named techaro.lol-anubis-auth-347ddb4a.
Without this change, changing any cookie setting without every client clearing their cookies causes challenges to become an infinite loop of thrashing, making it appear that Anubis "blocked" them.
If this becomes onerous in practice for administrators of HAProxy and other advanced setups that rely on cookie names, we will add an escape hatch in the policy file.
Anubis now publishes .msi packages, allowing administrators to install and run Anubis on Windows Server. Please read the Windows Server page for more information.
This support is beta-grade as the Anubis team does not have a lot of experience with developing software for Windows Server. Feedback is more than welcome.
Please let us know how it works for you!
latest tagDue to a misconfiguration of the GitHub Action docker/metadata-action, pre-release Docker images previously populated the :latest tag. This means that administrators that expected the :latest tag to result in a stable release of Anubis got a prerelease version suddenly when they ran automatic updates.
If administrators want to opt-in to the prerelease build track of Anubis for more frequent access to new features, they can use the :pre tag:
image: ghcr.io/techarohq/anubis:prehoneypot.ip_log_file is set. See the IP address logging section for more information.(data)/bots/lyrenth.yaml snippet that denies Lyrenth's AIWebIndex crawler and AIWebIndex-Agent on-demand fetcher by user agent and by their published IP ranges. This is imported by (data)/bots/_deny-pathological.yaml.fast challenge is loaded using defer instead of async (#1782).Accept-Language: und (#1776).Git in (data)/clients/git.yaml.v1.27.0-pre1.This will become the stable release on Sunday.
This will become the stable release on Sunday.
fast challenge is loaded using defer instead of async (#1782).latest tag in Docker. Pre-releases can be installed by using the pre tag.Accept-Language: und (#1776).Git in (data)/clients/git.yaml.Full Changelog: v1.27.0-pre3...v1.27.0-pre4
Nothing published for this version
Make the honeypot feature log detected addresses to the disk every minute when honeypot.ip_log_file is set. See the IP address logging section for mor
honeypot.ip_log_file is set. See the IP address logging section for more information.Full Changelog: v1.27.0-pre2...v1.27.0-pre3
Nothing published for this version
Anubis now supports running on Windows as a native service. To use it as a service, install the .msi from the release and follow the Windows direction
Anubis now supports running on Windows as a native service. To use it as a service, install the .msi from the release and follow the Windows directions. Currently Anubis supports Windows 10 / Windows Server 2016 and newer. Older versions of Windows currently not supported due to limits of the Go toolchain.
Please try the Windows release and give feedback! We want to make it as good as it can possibly be.
Note
This was attempted to be release as tag v1.27.0-pre1, but upon doing the release we discovered that our MSI packaging step did not handle the version number v1.27.0-pre1 cleanly. As such, it is suggested to ignore the tag v1.27.0-pre1.
(data)/bots/lyrenth.yaml snippet that denies Lyrenth's AIWebIndex crawler and AIWebIndex-Agent on-demand fetcher by user agent and by their published IP ranges. This is imported by (data)/bots/_deny-pathological.yaml.v1.27.0-pre1.Full Changelog: v1.26.2...v1.27.0-pre2
Nothing published for this version
Nothing published for this version
Automatically verify correct parsing of everything in (data) . While doing post-release checks on v1.26.1, I discovered that I incorrectly merged (dat
Automatically verify correct parsing of everything in (data). While doing post-release checks on v1.26.1, I discovered that I incorrectly merged (data)/services/updown.yaml in such a way that it became syntactically invalid. This has been mended and multiple layers of CI have been put into place to make sure that (data) entries are syntactically and semantically valid.
Full Changelog: v1.26.1...v1.26.2
…from net/http/httputil#ReverseProxy .Director (deprecated) to net/http/httputil#ReverseProxy.Rewrite. This re-enables support for upstreams like gitwe…
The challenge page can now survive transient failures, reduces the number of requests it makes to the Anubis app, and adds exponential backoff with retries to counteract an overwhelmed server being unable to serve any assets.
Previously if any request for JavaScript assets failed, the entire challenge attempt failed and users were forced to manually refresh the page, which is a bit of a bad user experience. This was made worse when the load balancer does not support HTTP/2, did not have resumable sessions enabled, and was implemented with Apache httpd pre-fork; making each asset fetch do its own TCP/TLS handshake. Under periods of heavy load such that TCP/TLS handshakes timed out, this made Anubis unable to fetch assets consistently or even made in-progress challenge attempts fail, which made challenges impossible to pass.
This has been fixed in a few ways:
main.mjs script now has fallback watchdog logic that periodically re-attempts to load the script.Full Changelog: v1.26.0...v1.26.1
Nothing published for this version
Nothing published for this version
fix: small security fixes by @Xe in #1651
Sorry this took so long. A lot of work was done behind the scenes to do mass testing of Anubis on many versions of Google Chrome. After about 10 attempts failed, the current one seems to work, leading to the confidence of being able to cut this release.
This should support Chrome 69 and newer.
(data)/clients/google-user-triggered-fetchers.yaml snippet that allows Google-owned user-triggered fetchers (Google Translate's website translation proxy, Google Read Aloud, Google Messages link previews) by their published IP ranges, fixing the infinite challenge loop for visitors using Google Translate (#444)--target=chrome66 so modern syntax (e.g. optional chaining) is transpiled down. This lowers the minimum supported browser from Chrome 80 to Chrome 66.headers/query map wrappers by implementing map iterators for HTTPHeaders and URLValues (#1465).metrics.debug in the policy file.path_regex and CEL path rules not matching when using Traefik forwardAuth middleware. Anubis now checks X-Forwarded-Uri (Traefik) in addition to X-Original-URI (nginx) when resolving the request path in subrequest mode (#1628).randInt helper so non-positive or platform-overflowing arguments surface a typed CEL error instead of an evaluator panic.X-Http-Fingerprint-JA4H header, taking it off the hot path for configurations that don't use it (#834).httputil.ReverseProxy.Director to Rewrite for Go 1.26 compatibility, preserving the inbound Host and X-Forwarded-*/Forwarded headers.バージョン (version) by @fu-sen in #1527Full Changelog: v1.25.0...v1.26.0
Nothing published for this version
Nothing published for this version
Unless anyone screams, this will be what ships tomorrow.
Unless anyone screams, this will be what ships tomorrow.
(data)/clients/google-user-triggered-fetchers.yaml snippet that allows Google-owned user-triggered fetchers (Google Translate's website translation proxy, Google Read Aloud, Google Messages link previews) by their published IP ranges, fixing the infinite challenge loop for visitors using Google Translate (#444)--target=chrome66 so modern syntax (e.g. optional chaining) is transpiled down. This lowers the minimum supported browser from Chrome 80 to Chrome 66.Full Changelog: v1.26.0-pre1...v1.26.0-pre2
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: small security fixes by @Xe in #1651
Sorry it's been so long between releases. Recovering from surgery sucks.
This release's title will be Papalymo Totolymo.
headers/query map wrappers by implementing map iterators for HTTPHeaders and URLValues (#1465).metrics.debug in the policy file.path_regex and CEL path rules not matching when using Traefik forwardAuth middleware. Anubis now checks X-Forwarded-Uri (Traefik) in addition to X-Original-URI (nginx) when resolving the request path in subrequest mode (#1628).randInt helper so non-positive or platform-overflowing arguments surface a typed CEL error instead of an evaluator panic.X-Http-Fingerprint-JA4H header, taking it off the hot path for configurations that don't use it (#834).httputil.ReverseProxy.Director to Rewrite for Go 1.26 compatibility, preserving the inbound Host and X-Forwarded-*/Forwarded headers.バージョン (version) by @fu-sen in #1527Full Changelog: v1.25.0...v1.26.0-pre1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →