NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3154 by repository stars
Last release 4 months ago
30 May 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 7 of 7 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
11 releases · first in 2025
One column per month.
ts-ssh v0.8.1 - Bug Fix Release
Release Date: May 2026
Patch release fixing auth URL visibility, SOCKS5 protocol correctness, and an IPv6 bind address parsing bug.
The UserLogf filter that surfaces Tailscale authentication URLs was matching only login.tailscale.com. Re-auth URLs from custom control servers were silently dropped, leaving the user with a hung connection and no URL to visit. The filter now matches any https:// URL in the user-facing log channel.
Read() calls assumed the entire SOCKS5 greeting and CONNECT request arrived in a single TCP segment. Replaced with io.ReadFull for each protocol segment so fragmented messages are handled correctly under real network conditions.ts-ssh -D [::1]:1080 now parses correctly. The old strings.Split approach failed on IPv6 addresses; replaced with net.SplitHostPort which handles bracket notation properly.context.WithCancel in setupDynamicForward was only ever cancelled by the goroutine's own defer — unreachable from the caller. Removed and replaced with errors.Is(err, net.ErrClosed) for the listener shutdown check.net.JoinHostPort is now used when constructing the SOCKS5 dial target so IPv6 destination addresses get correct bracket notation.Security audit logs were recording version 0.4.0 regardless of the actual binary version. The internal/security package now receives the build-time version via security.SetVersion() called from main.
# SOCKS5 with IPv6 bind (now works correctly)
ts-ssh -D [::1]:1080 hostname
# Standard usage unchanged
ts-ssh hostname
ts-ssh user@hostname
ts-ssh -D 1080 hostname
ts-ssh -scp file.txt hostname:/tmp/ts-ssh-v0.8.1-linux-amd64ts-ssh-v0.8.1-linux-arm64ts-ssh-v0.8.1-darwin-amd64ts-ssh-v0.8.1-darwin-arm64ts-ssh-v0.8.1-windows-amd64.exets-ssh-v0.8.1-windows-arm64.exets-ssh-v0.8.1-freebsd-amd64ts-ssh-v0.8.1-openbsd-amd64Each binary includes a .sha256 checksum file:
sha256sum -c ts-ssh-v0.8.1-linux-amd64.sha2562af2c1b - fix: auth URL display and SOCKS5 protocol correctness0cd4051 - fix: use net.SplitHostPort for SOCKS5 bind address parsingDrop-in replacement for v0.8.0. No CLI changes.
Full Changelog: v0.8.0...v0.8.1
ts-ssh v0.8.0 - SOCKS5 Proxy & Enhanced Compatibility
Release Date: January 2026
This release adds SOCKS5 dynamic port forwarding, PTY control, and improved username validation.
-D flag)Full SOCKS5 proxy support for tunneling traffic through your Tailscale connection:
# Start SOCKS5 proxy on localhost:1080
ts-ssh -D 1080 hostname
# Bind to specific address (with security warning)
ts-ssh -D 0.0.0.0:1080 hostname
# Use with curl
curl --socks5 localhost:1080 http://internal-service.example.comVSCode Remote SSH Compatible - Use ts-ssh as a SOCKS proxy for VSCode Remote SSH connections to your Tailnet.
-T flag)Disable pseudo-terminal allocation for non-interactive commands:
# Disable PTY for scripted commands
ts-ssh -T hostname "cat /etc/hostname"
# Useful for piping data
ts-ssh -T hostname "cat /var/log/app.log" | grep errorUsernames with dots are now fully supported:
ts-ssh first.last@hostname
ts-ssh -l john.doe hostname# SSH with SOCKS5 proxy
ts-ssh -D 1080 hostname # SOCKS proxy on localhost:1080
ts-ssh -D 0.0.0.0:1080 hostname # Bind to all interfaces
# Disable PTY
ts-ssh -T hostname command # No pseudo-terminal
# All options combined
ts-ssh -v -D 1080 -T user@hostname commandts-ssh-v0.8.0-linux-amd64ts-ssh-v0.8.0-linux-arm64ts-ssh-v0.8.0-darwin-amd64ts-ssh-v0.8.0-darwin-arm64ts-ssh-v0.8.0-windows-amd64.exets-ssh-v0.8.0-windows-arm64.exets-ssh-v0.8.0-freebsd-amd64ts-ssh-v0.8.0-openbsd-amd64Each binary includes a .sha256 checksum file:
sha256sum -c ts-ssh-v0.8.0-linux-amd64.sha256276ceef - Enhanced SOCKS5 implementation and username validation improvements (#35)This is a backwards-compatible release. All v0.7.0 commands continue to work.
Full Changelog: v0.7.0...v0.8.0
Nothing published for this version
ts-ssh v0.7.0 - Major CLI Simplification
Release Date: November 4, 2025
This release represents a major simplification of ts-ssh, transforming it from a complex multi-modal CLI to a simple, SSH-like command.
"Simplicity over features" - This tool does one thing well: SSH and SCP over Tailscale networks, with a familiar, SSH-like interface.
Now mimics standard SSH command syntax - no subcommands, no complexity.
Before (v0.5.0):
ts-ssh connect hostname
ts-ssh --multi host1,host2,host3
ts-ssh --exec "uptime" --list
ts-ssh --copy file.txt --listAfter (v0.7.0):
ts-ssh hostname
ts-ssh hostname uptime
ts-ssh -scp file.txt hostname:/tmp/--list, --multi, --exec, --copy, --pick)All core functionality is preserved:
# Connect to a host
ts-ssh hostname
ts-ssh user@hostname
ts-ssh user@hostname:2222
# Execute remote command
ts-ssh hostname uptime
ts-ssh user@hostname "ls -la /tmp"
# Options
ts-ssh -v hostname # Verbose mode
ts-ssh -p 2222 hostname # Custom port
ts-ssh -l alice hostname # Specify username
ts-ssh -i ~/.ssh/custom_key hostname # Custom key# Upload file
ts-ssh -scp file.txt hostname:/tmp/
# Download file
ts-ssh -scp hostname:/tmp/file.txt ./
# With specific port/user
ts-ssh -p 2222 -scp file.txt user@hostname:/tmp/ts-ssh --help
ts-ssh --versionThis is a BREAKING release. If you rely on removed features:
Multi-host operations → Use shell loops:
# Old: ts-ssh --exec "uptime" --multi host1,host2,host3
# New:
for host in host1 host2 host3; do
ts-ssh $host uptime
doneParallel execution → Use GNU parallel or xargs:
# Parallel command execution
echo "host1 host2 host3" | xargs -P 3 -n 1 ts-ssh -c uptime
# Or with GNU parallel
parallel ts-ssh {} uptime ::: host1 host2 host3Internationalization → English only
Tmux integration → Use tmux directly
ts-ssh-v0.7.0-linux-amd64ts-ssh-v0.7.0-linux-arm64ts-ssh-v0.7.0-darwin-amd64ts-ssh-v0.7.0-darwin-arm64ts-ssh-v0.7.0-windows-amd64.exets-ssh-v0.7.0-windows-arm64.exets-ssh-v0.7.0-freebsd-amd64ts-ssh-v0.7.0-openbsd-amd64ts-ssh-v0.7.0-all-platforms.tar.gz (127 MB)Each binary includes a .sha256 checksum file. Verify downloads:
sha256sum -c ts-ssh-v0.7.0-linux-amd64.sha256github.com/charmbracelet/fanggithub.com/charmbracelet/lipglossgithub.com/charmbracelet/huhgithub.com/spf13/cobrats-ssh/
├── main.go # ~457 lines - main CLI logic
├── constants.go # ~52 lines
├── main_test.go # ~256 lines
├── main_e2e_test.go # ~410 lines
└── internal/
├── client/ # SSH and SCP clients
├── config/ # Configuration
├── crypto/pqc/ # Post-quantum cryptography
├── errors/ # Error handling
├── platform/ # Platform-specific code
└── security/ # Security validation
Total: ~4,656 lines (down from ~15,000)
All security features maintained:
56da8af - chore: Remove dead code and cleanup codebase (#30)a600998 - Simplify CLI to mimic standard SSH command (#29)8f108b4 - Design Simplified SSH Command Implementation (#28)This simplification was driven by the principle that tools should do one thing well. By focusing on core SSH/SCP functionality over Tailscale, ts-ssh is now more maintainable, easier to understand, and more aligned with Unix philosophy.
Full Changelog: v0.5.0...v0.7.0
Release Date: July 4, 2025 Previous Version: v0.5.0
Release Date: July 4, 2025
Previous Version: v0.5.0
go vet warnings for safer string formattinginternal/i18n package for internal modulestsnet.Server.UserLogf to use dedicated stderr loggergo vet warnings for safer string formattinggo vet warnings, proper formattingT() for main package, i18n.T() for internal packagesThis release supports all major platforms with optimized binaries:
This release represents a significant step forward in ts-ssh's evolution, with major improvements to internationalization, user experience, and code quality. The comprehensive testing and quality assurance process ensured a stable, reliable release.
The translation system consolidation eliminates duplicate code and technical debt while providing a robust foundation for future multilingual expansion. The authentication flow improvements resolve critical user experience issues with tsnet URL display.
Full Changelog: v0.5.0...v0.6.0
Commit Range: View Changes
🤖 Generated with Claude Code
Co-Authored-By: Claude noreply@anthropic.com
Nothing published for this version
🎉 Major User Experience Improvements
Problem Solved: Eliminated verbose, distracting tsnet logging that cluttered SSH connections
2025/06/30 20:19:36 tsnet running state path /home/derek/.config/ts-ssh/tailscaled.state2025/06/30 20:25:11 AuthLoop: state is Running; done-v flagComplete internationalization covering 4+ billion speakers worldwide:
--lang flagDownload the appropriate binary for your platform:
# Linux AMD64
curl -L -o ts-ssh https://github.com/derekg/ts-ssh/releases/download/v0.5.0/ts-ssh-v0.5.0-linux-amd64
chmod +x ts-ssh
# macOS Apple Silicon
curl -L -o ts-ssh https://github.com/derekg/ts-ssh/releases/download/v0.5.0/ts-ssh-v0.5.0-darwin-arm64
chmod +x ts-ssh
# macOS Intel
curl -L -o ts-ssh https://github.com/derekg/ts-ssh/releases/download/v0.5.0/ts-ssh-v0.5.0-darwin-amd64
chmod +x ts-ssh
# Windows AMD64
curl -L -o ts-ssh.exe https://github.com/derekg/ts-ssh/releases/download/v0.5.0/ts-ssh-v0.5.0-windows-amd64.exego install github.com/derekg/ts-ssh@v0.5.0Verify download integrity with checksums:
curl -L https://github.com/derekg/ts-ssh/releases/download/v0.5.0/checksums.sha256
sha256sum -c checksums.sha256git clone https://github.com/derekg/ts-ssh.git
cd ts-ssh
go build -o ts-ssh .# See CLAUDE.md for detailed cross-compilation examples
CGO_ENABLED=0 GOOS=darwin GOARCH=arm64 go build -o ts-ssh-darwin-arm64 .Full Changelog: v0.4.0...v0.5.0
CVE-TS-SSH-001 : Host key verification bypass protections added
This release focuses on security enhancements, post-quantum cryptography preparation, and code quality improvements.
~/.ssh/known_hostssntrup761x25519-sha512@openssh.com and other PQC algorithms--pqc, --pqc-level, --pqc-report for quantum cryptography control--lang es)LANG, TS_SSH_LANG)internal/ package structureinternal/security/ for security operationsinternal/crypto/pqc/ for quantum cryptographyNone - this release maintains full backwards compatibility with existing ts-ssh usage.
# Using go install (recommended)
go install github.com/derekg/ts-ssh@v0.4.0
# Build from source
git clone https://github.com/derekg/ts-ssh.git
cd ts-ssh
git checkout v0.4.0
go build -o ts-ssh .# Use Spanish interface
ts-ssh --lang es --list
# Set permanent language preference
export TS_SSH_LANG=es
ts-ssh --help# Enable PQC monitoring (when available)
ts-ssh --pqc-report
# Future: PQC algorithm selection
ts-ssh --pqc-level 2 your-server # (when PQC is fully implemented)Security:
Features:
Quality:
Documentation:
This release positions ts-ssh as a secure, future-ready SSH client with enterprise-grade security features and quantum-cryptography readiness.
Nothing published for this version
Nothing published for this version
No breaking changes - all existing functionality preserved
⚠️ Note: This project now follows Semantic Versioning. Since the API is still evolving, we're using 0.x.y versions:
--lang, TS_SSH_LANG, LANG, LC_ALL--pick)github.com/rivo/tview, github.com/gdamore/tcell/v2user@host instead of garbled text)i18n_test.go, ssh_helpers_test.go, terminal_state_test.goPre-built binaries for all major platforms:
# Linux AMD64
curl -L -o ts-ssh https://github.com/derekg/ts-ssh/releases/download/v0.3.0/ts-ssh-linux-amd64
chmod +x ts-ssh && sudo mv ts-ssh /usr/local/bin/
# macOS (detect architecture automatically)
curl -L -o ts-ssh https://github.com/derekg/ts-ssh/releases/download/v0.3.0/ts-ssh-darwin-$(uname -m < /dev/null | sed 's/x86_64/amd64/')
chmod +x ts-ssh && sudo mv ts-ssh /usr/local/bin/Download the appropriate .exe file:
git clone https://github.com/derekg/ts-ssh.git
cd ts-ssh
go build -ldflags "-X main.version=v0.3.0" .# Use Spanish interface
ts-ssh --lang es --help
ts-ssh --lang es --list
# Set via environment
LANG=es ts-ssh --help# Interactive host selection
ts-ssh --pick
# Parallel command execution
ts-ssh --exec "uptime" host1,host2,host3 --parallel
# Multi-host file transfer
ts-ssh --copy "localfile host1,host2:/remote/path"Code Quality Metrics:
User Experience:
Semantic Versioning: This release follows semver.org guidelines. Thanks to the Hacker News community for the feedback on proper versioning practices!
Full Changelog: v0.2.0...v0.3.0
Date: 2025-06-18
🧹 Complete TUI Code Cleanup
Removed all dead terminal UI code and dependencies (180+ lines removed):
connectToHostFromTUI functiontuiMode parameter throughout codebasegithub.com/rivo/tview, github.com/gdamore/tcell/v2🔧 SSH Code Consolidation
Major refactoring of SSH connection logic:
executeCommandOnHost helper (~85 lines of duplication removed)ssh_helpers.go🐛 Critical i18n Formatting Fixes
Resolved double-formatting issues affecting user experience:
derek@bar instead of %!!(string=derek)s(MISSING)@%!!(string=bar)s(MISSING)🧪 Enhanced Test Coverage
Comprehensive test suite expansion (14.5% → 22% coverage):
i18n_test.go - Race condition testing for concurrent translationsssh_helpers_test.go - SSH connection and authentication testingterminal_state_test.go - Thread-safe terminal state managementmain_test.go with additional utility function coverage📁 Modular Code Organization
Split monolithic functions into focused, maintainable modules:
main_helpers.go - Command-line argument parsing and operation routingssh_helpers.go - Standardized SSH connection establishmentterminal_state.go - Thread-safe terminal state managementconstants.go - Centralized application constants and configuration🏗️ Race Condition Fixes
Comprehensive thread safety improvements:
📚 Enhanced Documentation
Comprehensive documentation for all public functions:
CLAUDE.md with current architecture overview⚡ Build Improvements
🔒 Better Error Handling
Files Added:
constants.go - Application-wide constantsmain_helpers.go - Refactored CLI argument handlingssh_helpers.go - SSH connection utilitiesterminal_state.go - Thread-safe terminal management*_test.go - Comprehensive test suitesDependencies Removed:
github.com/rivo/tview (TUI framework)github.com/gdamore/tcell/v2 (Terminal cell library)Code Metrics:
Your coding agent can read these notes before it upgrades. Set up the MCP server →