NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #127 by repository stars
Last release 3 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 27 of 28 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
294 releases · first in 2025
One column per month.
Nothing published for this version
Added customization of authorization cookie expiration time with --cookie-expiration-time flag or envvar
--cookie-expiration-time flag or envvarOG_PASSTHROUGH to be true by default, thereby allowing Open Graph tags to be passed through by defaultEnsure regexes can't end in newlines
auth_request directive with AnubisOpera to the generic-browser bot policy rule/myapp)generic-bot-catchall rule because of its high false positive rate in real-world scenariosX-Forwarded-For header unless the remote connects over a loopback address #328HOST header through to the originOG_PASSTHROUGH to be true by default, thereby allowing Open Graph tags to be passed through by defaultNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
> I want to make them pay! All of them! Everyone who ever mocked or looked down on me -- I want the power to make them pay!
Fordola rem Lupis
I want to make them pay! All of them! Everyone who ever mocked or looked down on me -- I want the power to make them pay!
The following features are the "big ticket" items:
-ed25519-private-key-hex-file or ED25519_PRIVATE_KEY_HEX_FILEThe other small fixes have been made:
--debug-x-real-ip-default to --use-remote-address, getting the IP address from the request's socket address instead--debug-benchmark-js flag for testing proof-of-work performance during developmentTrimSuffix instead of TrimRight on containerbuildzizmor for GitHub Actions static analysiszizmor findings--extract-resources flag to extract static resources to a local folderWEBMASTER_EMAIL variable, if it is present then display that email address on error pages (#235, #115)Nothing published for this version
Fixes a recurrence of CVE-2025-24369 due to an incorrect logic change in a refactor. This allows an attacker to mint a valid access token by passing a…
Zenos yae Galvus: Echo 1
Fixes a recurrence of CVE-2025-24369 due to an incorrect logic change in a refactor. This allows an attacker to mint a valid access token by passing any SHA-256 hash instead of one that matches the proof-of-work test.
This case has been added as a regression test. It was not when CVE-2025-24369 was released due to the project not having the maturity required to enable this kind of regression testing.
Nothing published for this version
Nothing published for this version
Nothing published for this version
> Yes...the coming days promise to be most interesting. Most interesting.
Zenos yae Galvus
Yes...the coming days promise to be most interesting. Most interesting.
Headline changes:
--ed25519-private-key-hex or envvar ED25519_PRIVATE_KEY_HEX; if one is not provided when Anubis starts, a new one is generated and loggedCOOKIE_DOMAIN=techaro.lol for all domains under techaro.lolCOOKIE_PARTITIONED=trueMany other small changes were made, including but not limited to:
Users running Anubis' test suite may run into issues with the integration tests on Windows hosts. This is a known issue and will be fixed at some point in the future. In the meantime, use the Windows Subsystem for Linux (WSL).
Nothing published for this version
Nothing published for this version
Remove default RSS reader rule as it may allow for a targeted attack against rails apps #67
Set the X-Real-IP header based on the contents of X-Forwarded-For #62
Livia sas Junius: Echo 1
X-Real-IP header based on the contents of X-Forwarded-For
#62Nothing published for this version
> Fail to do as my lord commands...and I will spare him the trouble of blocking you.
Livia sas Junius
Fail to do as my lord commands...and I will spare him the trouble of blocking you.
Add explanation of what Anubis is doing to the challenge page #25
Administrators can now define artificially hard challenges using the "slow" algorithm:
{
"name": "generic-bot-catchall",
"user_agent_regex": "(?i:bot|crawler)",
"action": "CHALLENGE",
"challenge": {
"difficulty": 16,
"report_as": 4,
"algorithm": "slow"
}
}
This allows administrators to cause particularly malicious clients to use unreasonable amounts of CPU. The UI will also lie to the client about the difficulty.
Docker images now explicitly call docker.io/library/<thing> to increase compatibility with Podman et. al
#21
Don't overflow the image when browser windows are small (eg. on phones) #27
Lower the default difficulty to 5 from 4
Don't duplicate work across multiple threads #36
Documentation has been moved to https://anubis.techaro.lol/ with sources in docs/
Removed several visible AI artifacts (e.g., 6 fingers) #37
Fixed hang when navigator.hardwareConcurrency is undefined
Support Unix domain sockets #45
Allow filtering by remote addresses:
{
"name": "qwantbot",
"user_agent_regex": "\\+https\\:\\/\\/help\\.qwant\\.com/bot/",
"action": "ALLOW",
"remote_addresses": ["91.242.162.0/24"]
}
This also works at an IP range level:
{
"name": "internal-network",
"action": "ALLOW",
"remote_addresses": ["100.64.0.0/10"]
}
Nothing published for this version
Nothing published for this version
Nothing published for this version
Proof-of-work challenges are drastically sped up #19
Phrasing in the warning was replaced from its original placeholder text to something more suitable for general consumption (fd6903a).
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →