NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #77 by repository stars
Last release today
09 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
12424 releases · first in 2013
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
agent: Fixed a bug in HTTP handlers where URLs were being decoded twice [GH-13264]
agent: Use SHA256 instead of MD5 to generate persistence file names.
SECURITY:
IMPROVEMENTS:
BUG FIXES:
add_headers directive named Host the header is not set for v1/internal/ui/metrics-proxy/ endpoint. [GH-13071]NOTES:
agent: Added a new check field, disable_redirects, that allows for disabling the following of redirects for HTTP checks. The intention is to default t
SECURITY:
disable_redirects, that allows for disabling the following of redirects for HTTP checks. The intention is to default this to true in a future release so that redirects must explicitly be enabled. [GH-12685]IMPROVEMENTS:
DEPRECATIONS:
tls_cipher_suites will no longer be honored, and tls_prefer_server_cipher_suites is now ignored. [GH-12766]BUG FIXES:
agent: Use SHA256 instead of MD5 to generate persistence file names.
SECURITY:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
agent: Use SHA256 instead of MD5 to generate persistence file names.
SECURITY:
IMPROVEMENTS:
BUG FIXES:
snapshot save command now saves the snapshot with read permission for only the current user. [GH-11918]…in the default namespace. This change fixes CVE-2021-41805.
SECURITY:
acl:write permission in the default namespace. This change fixes CVE-2021-41805.FEATURES:
BUG FIXES:
NodeService struct properly to avoid a data race. [GH-11940]1.3.3 which fixes a bug where a read replica node can trigger a raft election and become a leader. [GH-11958]consul acl token list. [GH-11926]license_path setting in config filesService.Namespace into available variables for dashboard_url_templates [GH-11640]Nothing published for this version
ci: Upgrade golang.org/x/net to address CVE-2021-44716 [GH-11856]
SECURITY:
ci: Upgrade to Go 1.16.12 to address CVE-2021-44716 [GH-11808]
SECURITY:
BUG FIXES:
…in the default namespace. This change fixes CVE-2021-41805.
SECURITY:
acl:write permission in the default namespace. This change fixes CVE-2021-41805.IMPROVEMENTS:
main [GH-11417]BUG FIXES:
BUG FIXES:
sso/oidc: (Enterprise only) Add support for providing acr_values in OIDC auth flow [GH-11026]
FEATURES:
IMPROVEMENTS:
Forwarded, Via, X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Proto. [GH-11107]BUG FIXES:
Nothing published for this version
Nothing published for this version
Nothing published for this version
tls: The fix for CVE-2021-37219 introduced an issue that could prevent TLS certificate validation when intermediate CA certificates used to sign serve…
KNOWN ISSUES:
SECURITY:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
INITIALIZING state. [GH-10630]Nothing published for this version
Nothing published for this version
xds: ensure envoy verifies the subject alternative name for upstreams CVE-2021-32574 [GH-10621]
KNOWN ISSUES:
use_streaming_backend=false if using WAN federation over mesh gateways when upgrading to 1.10.1 and are working to address this issue in a future patch release.SECURITY:
FEATURES:
redirect-traffic command in a provided Linux namespace. [GH-10564]iptables rules in a provided Linux namespace. [GH-10564]IMPROVEMENTS:
acl:write [GH-10546]DEPRECATIONS:
RotationPeriod field from the Consul CA provider, it was not used for anything. [GH-10552]BUG FIXES:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
xds: remove deprecated usages of xDS and drop support for envoy 1.13.x [GH-9602]
BREAKING CHANGES:
PUT and DELETE methods on the /v1/operator/license endpoint will now return 405s, the consul license put and consul license reset CLI commands have been removed and the LicensePut and LicenseReset methods in the API client have been altered to always return an error. [GH-10211]start_join and retry_join configurations for determining the servers to query for the license. Therefore one must be set to use license auto-retrieval. [GH-10248]FEATURES:
consul connect redirect-traffic command to allow excluding inbound and outbound ports,
outbound CIDRs, and additional user IDs from traffic redirection. [GH-10134]consul connect redirect-traffic command for applying traffic redirection rules when Transparent Proxy is enabled. [GH-9910]envoy_prometheus_bind_addr, envoy_stats_bind_addr, and ListenerPort from Expose config
from inbound traffic redirection rules if proxy-id flag is provided to the consul connect redirect-traffic command. [GH-10134]iptables package for applying traffic redirection rules with iptables. [GH-9910]iptables package. [GH-10134]IMPROVEMENTS:
Expose.Checks is true in proxy's configuration. [GH-10173]ExposedPort to the health check API resource. [GH-10173]Content-Type header is now always set when a body is present in a request. [GH-10204]consul connect envoy --envoy_statsd_url flag will now resolve the $HOST_IP environment variable, as part of a full url. [GH-8564]-proxy-id and Expose.Checks is set. [GH-10173]prometheus-backend-port and prometheus-scrape-port to consul connect envoy to support envoy_prometheus_bind_addr pointing to the merged metrics port when using Consul Connect on K8s. [GH-9768]consul license inspect CLI command for inspecting a license without applying it..license_path configuration, the CONSUL_LICENSE environment variable or the CONSUL_LICENSE_PATH environment variable [GH-10210]use_streaming_backend to default to true so that streaming is used by default when it is supported. [GH-10149]BUG FIXES:
rpc_max_conns_per_client could not be changed by reloading the
config. [GH-8696]NOTES:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
agent: Added a new check field, disable_redirects, that allows for disabling the following of redirects for HTTP checks. The intention is to default t
SECURITY:
disable_redirects, that allows for disabling the following of redirects for HTTP checks. The intention is to default this to true in a future release so that redirects must explicitly be enabled. [GH-12685]DEPRECATIONS:
tls_cipher_suites will no longer be honored, and tls_prefer_server_cipher_suites is now ignored. [GH-12767]BUG FIXES:
ca: support using an external root CA with the vault CA provider [GH-11910]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
sentinel: (Enterprise Only) Sentinel now uses SHA256 to generate policy ids
IMPROVEMENTS:
BUG FIXES:
snapshot save command now saves the snapshot with read permission for only the current user. [GH-11918]…in the default namespace. This change fixes CVE-2021-41805.
SECURITY:
acl:write permission in the default namespace. This change fixes CVE-2021-41805.BUG FIXES:
consul acl token list. [GH-11926]license_path setting in config filesService.Namespace into available variables for dashboard_url_templates [GH-11640]Nothing published for this version
ci: Upgrade golang.org/x/net to address CVE-2021-44716 [GH-11858]
SECURITY:
ci: Upgrade to Go 1.16.12 to address CVE-2021-44716 [GH-11807]
SECURITY:
…in the default namespace. This change fixes CVE-2021-41805.
SECURITY:
acl:write permission in the default namespace. This change fixes CVE-2021-41805.IMPROVEMENTS:
main [GH-11417]BUG FIXES:
Nothing published for this version
sso/oidc: (Enterprise only) Add support for providing acr_values in OIDC auth flow [GH-11026]
FEATURES:
IMPROVEMENTS:
Forwarded, Via, X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Proto. [GH-11107]BUG FIXES:
tls: The fix for CVE-2021-37219 introduced an issue that could prevent TLS certificate validation when intermediate CA certificates used to sign serve…
KNOWN ISSUES:
SECURITY:
IMPROVEMENTS:
BUG FIXES:
INITIALIZING state. [GH-10630]Nothing published for this version
Nothing published for this version
xds: ensure envoy verifies the subject alternative name for upstreams CVE-2021-32574 [GH-10621]
SECURITY:
BUG FIXES:
debug: capture a single stream of logs, and single pprof profile and trace for the whole duration [GH-10279]
IMPROVEMENTS:
license_path configuration, the CONSUL_LICENSE environment variable or the CONSUL_LICENSE_PATH environment variable. On server agents this configuration will be ignored. Client agents and the snapshot agent will use the configured license instead of automatically retrieving one. [GH-10441]BUG FIXES:
agent: ensure we hash the non-deprecated upstream fields on ServiceConfigRequest [GH-10240]
IMPROVEMENTS:
-force-without-cross-signing flag to the ca set-config command.
connect/ca: The ForceWithoutCrossSigning field will now work as expected for CA providers that support cross signing. [GH-9672]metrics API now includes cluster member counts, reporting clients on a per segment basis. [GH-10340]BUG FIXES:
consul connect envoy command to deadlock when attempting to start envoy. [GH-10324]X-Consul-Effective-Consistency header to be missing on
request for service health [GH-10189]Add content-type headers to raw KV responses to prevent XSS attacks CVE-2020-25864 [GH-10023]
SECURITY:
IMPROVEMENTS:
AutopilotServerHelath now handles the 429 status code returned by the v1/operator/autopilot/health endpoint and still returned the parsed reply which will indicate server healthiness [GH-8599]BUG FIXES:
advertise_addr_ipv6 to advertise_addr_wan_ipv6 [GH-9851]Nothing published for this version
Nothing published for this version
connect: if the token given to the vault provider returns no data avoid a panic [GH-9806]
IMPROVEMENTS:
BUG FIXES:
ui: Add additional search/filter status pills for viewing and removing current filters in listing views [GH-9442]
FEATURES:
IMPROVEMENTS:
-cluster-id and common-name to consul tls ca create to support creating a CA for Consul Connect. [GH-9585]BUG FIXES:
Your coding agent can read these notes before it upgrades. Set up the MCP server →