NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1413 by repository stars
Last release 1 months ago
21 Aug 2026
Ships fairly regularly
a new release about every 3 months
Most releases are documented
notes for 7 of 10 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
86 releases · first in 2018
Upgrade the Go toolchain baseline and CI to Go 1.26.6, resolving all 19 reachable standard-library vulnerabilities reported for Go 1.26.0.
github.com/quic-go/quic-go from v0.59.0 to v0.61.0 to resolve the reachable HTTP/3 QPACK trailer expansion vulnerability.golang.org/x/net to v0.58.0 and its related x/crypto, x/sys, and x/text dependencies.github.com/klauspost/compress to v1.19.2, resolving its reported s2 out-of-bounds read vulnerability.go test ./...go test -race ./...govulncheck -show verbose ./... reports zero reachable or imported-package vulnerabilities.golang.org/x/crypto/openpgp remains an upstream unmaintained package with no fixed version. It is transitively required by Sarama's Kerberos dependency path but is not imported or called by HMQ.x/crypto SSH/agent advisories and one x/net/html parser advisory with no patched version. They are not reachable from HMQ according to govulncheck; the required modules remain for Sarama Kerberos support and the x/net/websocket transport.One column per quarter.
Fix MQTT subscription topic validation to reject malformed UTF-8 and null characters.
github.com/Shopify/sarama to github.com/IBM/sarama v1.50.1.go test ./...go test -race ./broker ./broker/lib/sessions ./broker/lib/topics ./plugins/bridgeNothing published for this version
Nothing published for this version
fix: #215 upgrage: deps
fix: #215
upgrage: deps
Nothing published for this version
Merge pull request #206 from xinkonglili/weilili
Nothing published for this version
Nothing published for this version
Merge pull request #202 from xinkonglili/weilili
Nothing published for this version
Bump google.golang.org/protobuf from 1.30.0 to 1.33.0
Bump google.golang.org/protobuf from 1.30.0 to 1.33.0 (#196)
Bumps google.golang.org/protobuf from 1.30.0 to 1.33.0.
---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Merge pull request #193 from spit4520/master
Merge pull request #193 from spit4520/master
HOTFIX | Fixed pubMsg when WillTopic is null
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →