NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1749 by repository stars
Last release 2 months ago
16 Jul 2026
Ships unpredictably
gaps range from 8 days to 6 months
Rarely documented
notes for 10 of 57 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
95 releases · first in 2022
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[fix] 修复 -q/--quiet 未完全静默的问题:在配合 --no-bar --no-stat 使用时,不再继续向控制台打印 [check] 、 [common] 等结果输出,文件输出不受影响
-q/--quiet 未完全静默的问题:在配合 --no-bar --no-stat 使用时,不再继续向控制台打印 [check]、[common] 等结果输出,文件输出不受影响--crawl 未遵守 --max-length 的问题:默认按配置限制读取响应体,避免爬取大页面时额外放大内存占用;如需完整读取可显式使用 --read-allFull Changelog: v1.3.1...v1.3.2
Nothing published for this version
Nothing published for this version
[feat] 支持在所有请求字段中直接嵌入 mask 表达式( {?...} / {$...} ),包括 -u URL、 -H Header、 --host 、 --cookie 、 --path ,自动提取 mask 生成字典并在请求构建时替换 {{FUZZ}} 占位符;同时支持显式 -w 搭配
{?...} / {$...}),包括 -u URL、-H Header、--host、--cookie、--path,自动提取 mask 生成字典并在请求构建时替换 {{FUZZ}} 占位符;同时支持显式 -w 搭配 {{FUZZ}} 占位符在任意字段中引用同一字典--keys 插件,内嵌 156 条 proton found/keys 模板(覆盖 AWS/GCP/Azure/OpenAI/Slack/GitHub/Stripe 等),-a 自动启用--extract-context)、word matchers 预过滤,新增 9 条 HaE 规则(lfi-indicator/upload-form/url-as-value 等),模板总数 35→45--crawl 在带 base path 的 SPA URL 中二次拼接路径,导致 /base/base/... 和 recon 漏提取的问题# URL 内嵌 mask(等价于 -u http://example.com -w '{$l#3}')
spray -u 'http://example.com/{$l#3}'
# Header 内嵌
spray -u http://example.com -H 'Token: {$d#6}'
# Host 内嵌
spray -u http://example.com --host '{$l#3}.internal.com'
# Cookie 内嵌
spray -u http://example.com --cookie 'sid={$hex#16}'
# 显式 -w + {{FUZZ}} 占位符(多字段同时替换)
spray -u 'http://example.com/{{FUZZ}}' -w '{$d#6}' -H 'Token: {{FUZZ}}'
# 敏感信息检测
spray -u http://example.com --keys
spray -u http://example.com -a # advance 模式自动启用 keysFull Changelog: v1.3.0...v1.3.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[feat] 新增 --poc 插件,基于 neutron 引擎在指纹识别后自动进行漏洞验证,支持 check 模式(exploit 验证)和 brute 模式(默认口令测试),仅对匹配指纹的目标执行 POC,避免盲扫
--poc 插件,基于 neutron 引擎在指纹识别后自动进行漏洞验证,支持 check 模式(exploit 验证)和 brute 模式(默认口令测试),仅对匹配指纹的目标执行 POC,避免盲扫go:embed,源码体积从 125KB 降至 ~1KB + 93KB bin,二进制减小约 28KB,启动更快RunWithArgs 入口点,支持 BeforePrepare/AfterPrepare 生命周期回调与 Help() 函数,便于 aiscan 等外部项目集成doCheck() 在 Handler goroutine 中调用 reqPool.Invoke() 导致循环等待,改为通过 addAddition() 提交请求打破循环依赖reqCount/failedCount 改为 atomic.Int64,done 改为 atomic.Bool,rand.Source 加锁,Invoke 失败正确回退 wg 计数additionCh 未排空导致 wg.Wait 挂起的问题FingerEngine nil 检查与各初始化组件幂等性保护,防止 SDK 嵌入场景下 panic 或重复设置proton_rules.binFull Changelog: v1.2.6...v1.3.0
[fix] 彻底修复生产环境 panic: send on closed channel 崩溃,使用 ctx 作为统一关闭信号,所有 channel 发送均通过 select + ctx.Done() 保护
panic: send on closed channel 崩溃,使用 ctx 作为统一关闭信号,所有 channel 发送均通过select + ctx.Done() 保护addAddition default 分支 wg 泄漏,移除 async goroutine 改为同步阻塞发送BrutePool.Close() 中 analyzeDone 条件写反导致忙等永不执行,替换为 handlerDone chan 机制processCh 从未关闭导致 Handler goroutine 永久泄漏,Close() 中正确关闭并等待 Handler 退出OutputCh/FuzzyCh/checkCh 裸发送在关闭时可能永久阻塞的问题doCrawl 孤儿 wg.Add(1) 无对应 wg.Done() 导致 wg 计数泄漏baseline.NewBaseline 中 raw response 重解析失败导致 baseline 被错误标记为无效的问题,Location 改从 livego build + go test -race,覆盖 ubuntu 与 windowsFull Changelog: v1.2.5...v1.2.6
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[feat] 支持 -o tree 树形输出,便于按 Host/路径查看结果结构
-o tree 树形输出,便于按 Host/路径查看结果结构--host / --path / -X / --body 请求参数,定制化探测更灵活(相关场景: #120 )--recon 在 v1.2.2+ 仅提取 pentest 标签导致 phone/mail/idcard 等信息缺失的问题,恢复信息提取能力,#132--host/host 模式下强制使用 standard client 避免错误 DNS 解析application/*+json)send_data 主动探测路径加载,提升指纹覆盖Full Changelog: v1.2.3...v1.2.5
Nothing published for this version
chore: bump fingers and neutron
chore: bump fingers and neutron
Nothing published for this version
Nothing published for this version
[feat] support --finger-file to dynamically load finger configurations from local file or remote URL, simplifying finger database management
Full Changelog: v1.2.2...v1.2.3
Nothing published for this version
[feat] 支持通配符状态码, example: --black-status +40*,51*,3* , #38
--black-status +40*,51*,3*, #38--fuzzilu or -a 中包含此插件append-rule add short flag -RFull Changelog: v1.2.1...v1.2.2
Nothing published for this version
Nothing published for this version
08ce95b fix: check pool not set headers
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →