NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1455 by repository stars
Last release 1 months ago
26 Aug 2026
Release timing varies
gaps range from 2 weeks to 4 months
Rarely documented
notes for 6 of 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
191 releases · first in 2018
The Telegram provider no longer hard-codes https://api.telegram.org . NewTelegramAPIWithBaseURL takes the base, and every request goes through it, ava
The Telegram provider no longer hard-codes https://api.telegram.org. NewTelegramAPIWithBaseURL takes the base, and every request goes through it, avatar downloads included. An empty base falls back to the public API.
Moving a token-bearing URL off a constant is what the rest of the change is for: the bot token travels in the request path, and the answers now come from a host the library does not control. The base is validated, error text is scrubbed of the token in raw and encoded forms, a success response has to match Telegram's own username shape, and redirects are refused by default because Go copies the previous URL into Referer.
One behaviour change. A caller that relied on the default redirect policy now gets an error on a redirect. A caller-supplied CheckRedirect remains in force.
Also in this release: the Apple public-key test no longer binds a shared port, and the Telegram tests no longer race or depend on order.
Full detail in #316.
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
EmailParams gains HELOHost , which sets the hostname the sender announces in the SMTP greeting. Left empty it stays localhost , so existing configurat
EmailParams gains HELOHost, which sets the hostname the sender announces in the SMTP greeting. Left empty it stays localhost, so existing configurations are unchanged. A relay enforcing reject_non_fqdn_helo_hostname or reject_unknown_helo_hostname refuses the default greeting, and the verification message never leaves.
Verification email delivery is now bound to the request context. TimeOut covered the connection setup only, so a server that accepted the connection and then stalled held the login request for as long as it liked. The send now ends when the request does. Sender implementations that do not offer SendContext keep working through the existing Send.
Also updates dependencies across the root, v2 and example modules, and sets explicit GITHUB_TOKEN permissions in the workflows.
Nothing published for this version
Avatar storage on GridFS destroyed data. Every Put created a new revision under the same filename, so old avatars accumulated, Remove deleted only the
Avatar storage on GridFS destroyed data. Every Put created a new revision under the same filename, so old avatars accumulated, Remove deleted only the newest one and left the avatar readable, and ID could return a stale revision. Cleanup now removes only revisions older than the upload that just completed, so two concurrent uploads for the same user cannot delete each other's file.
Apple public keys are now cached rather than fetched on every login, refreshed when a token names an unknown key so rotation still works, and reused for up to 12 hours if the key service is unreachable. A non-2xx response or an empty key set is rejected instead of being cached as valid.
The post-auth redirect uses 303 instead of 307. Apple's form_post callback arrives as a POST, and a method-preserving redirect replayed it onto the target page, which a static file server answers with 405. This changes the status for the oauth1, oauth2 and verify providers as well.
Two documented parameters now work: session is honoured by the direct and verify providers, and aud is accepted alongside site on the verify confirmation request. Apple no longer forces a persistent cookie when a session-only login was requested. For the direct and verify providers any non-zero sess value now means session-only, where previously only sess=1 did.
The avatar route returns 404 when no avatar store is configured, instead of dereferencing a nil proxy.
Dependencies: go-pkgz/email v0.8.0 and go-pkgz/rest v1.24.0. CI moves to go 1.26 and golangci-lint v2.12.
The GitHub provider can now derive the local user id from the immutable numeric account id instead of the mutable login. This is opt-in and off by def
The GitHub provider can now derive the local user id from the immutable numeric account id instead of the mutable login. This is opt-in and off by default, since enabling it changes the id of every existing GitHub user. Separately, the OAuth1 and OAuth2 callbacks no longer skip the user info HTTP status check, which previously let an error response map every failed login onto one shared user id.
Full Changelog: v1.25.5...v1.25.6
Nothing published for this version
Nothing published for this version
Changes since v1.25.4 #293 redact sensitive auth logging #292 package-wide comment sweep #291 fix misleading and stale docstrings around the security
Full Changelog: v1.25.4...v1.25.5
Nothing published for this version
Nothing published for this version
Security : fixes stored XSS in avatar.Proxy by rejecting non-image avatar content before storage and before serving. Also adds CSP/nosniff headers, We
Security: fixes stored XSS in avatar.Proxy by rejecting non-image avatar content before storage and before serving. Also adds CSP/nosniff headers, WebP-safe validation, ETag parsing fixes, and decompression-bomb checks. Credit to @paskal.
Full Changelog: v1.25.3...v1.25.4
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →