NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2098 by repository stars
Last release 2 days ago
16 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 31 of 31 stable releases
Nothing withdrawn
no release was ever pulled
7 months old
95 releases · first in 2026
One column per month.
Minimum version bump from 0.x to 1.0: public API (config format, CLI flags, audit schema, Prometheus metrics) is now stable. Breaking changes will fol…
Pipelock 1.0.0 is the production-ready release. All scanning layers, proxy modes, and MCP security features are stable and commercially supported.
X-Pipelock-Agent header > ?agent= query param > _default fallback--agent flag for MCP proxy: select agent profile for MCP proxy sessions/stats breakdownX-Pipelock-Agent header stripped before forwarding to upstream (prevents agent impersonation)pipelock license keygen, pipelock license issue, and pipelock license inspect CLI commands with build-time public key embeddingwrite-persist and persist-callback patterns with argument-aware exec-to-persist reclassificationrequest_body_scanning defaults in programmatic config (previously only available via preset files)tool_chain_detection section added to all config presets--home flag for signing/keygen/verify/TLS CLI commands (container and rootless environment support)http.Transport with connection pooling across intercepted CONNECT tunnelsInstallCA refactored for testable OS-specific branches (certgen coverage improved)Defaults() for DLP patterns, tool chain detection, and policy rulesNothing published for this version
Dependency review GitHub Actions workflow: blocks PRs that introduce dependencies with known vulnerabilities
pipelock tls init command: generates a local CA key pair for TLS interceptionpipelock tls show-ca command: displays the CA certificate (PEM) for manual trustpipelock tls install-ca command: installs the CA into the system trust storetls_interception config section with enabled, ca_cert, ca_key, cert_ttl, and passthrough_domains fields. Hot-reload wiring for CA config changes./health endpointpipelock_tls_intercept_total, pipelock_tls_handshake_duration_seconds, pipelock_tls_request_blocked_total, pipelock_tls_response_blocked_total, pipelock_tls_cert_cache_size Prometheus metricstls_authority_mismatch, tls_response_blocked audit events with MITRE technique labelstls_interception section defaultspipelock report command: reads JSONL audit logs and produces HTML, JSON, or Ed25519-signed evidence bundle reports with risk rating, event categories, timeline histogram, and evidence appendix. Supports --format, --output, --sign, and --config flags.inputSchema at all nesting depths, expands underscore/hyphen/camelCase names, and scans for exfiltration intent (catches the CyberArk attack variant where data theft is encoded in parameter names while descriptions stay clean)Config.Hash() for deterministic SHA256 of raw config file bytes (used in signed reports)ActionAsk treated as block inside intercepted tunnels (no HITL terminal available in TLS context)LoadCA validates cert.IsCA, KeyUsageCertSign, and key correspondence. Rejects cert_ttl <= 0 and group/world-readable CA keys.v1/latest instead of pinned version numbers so guides stay current across releasesNothing published for this version
Kill switch API token can now be set via PIPELOCK_KILLSWITCH_API_TOKEN environment variable, overriding the kill_switch.api_token config field. Enable
PIPELOCK_KILLSWITCH_API_TOKEN environment variable, overriding the kill_switch.api_token config field. Enables Kubernetes deployments to source the token from a Secret instead of a ConfigMap.sensitive (scan listed headers only) and all (scan everything except structural headers, including header names). Joined scan catches secrets split across multiple headers.request_body_scanning config section with enabled, action, max_body_bytes, scan_headers, header_mode, sensitive_headers, and ignore_headers fieldspipelock_body_dlp_hits_total and pipelock_header_dlp_hits_total Prometheus countersbody_dlp and header_dlp audit event typesinternal/extract) used by both proxy body scanning and MCP input scanninghostile-model config preset for agents running uncensored or jailbroken modelsforward_proxy.sni_verification: true. pipelock_sni_total Prometheus counter tracks matches.pipelock claude hook/setup/remove commands for Claude Code hook integration224.0.0.0/4, ff00::/8) added to default SSRF internal address listhttp://[::1%25eth0]/ no longer skip CIDR checks. Zone IDs are stripped before IP parsing.pipelock cursor install now writes Cursor's v1 hooks.json format (map keyed by event name with version field). Previously wrote a flat array that Curs
pipelock cursor install now writes Cursor's v1 hooks.json format (map keyed by event name with version field). Previously wrote a flat array that Cursor silently ignored, causing hooks to never fire.pipelock cursor install now preserves args fields on existing hooks during merge. Previously, non-pipelock hooks with args arrays lost their arguments after install or upgrade.pipelock preflight now scans both v1 and legacy hooks.json formats. Previously only understood the legacy format and would false-positive on v1 files.pipelock verify-install command: 10 deterministic checks verifying scanning pipeline and network containment. Produces human-readable or --json output
pipelock verify-install command: 10 deterministic checks verifying scanning pipeline and network containment. Produces human-readable or --json output with optional Ed25519 --sign for tamper-evident reports. Supports --output to write results to file.pipelock cursor hook subcommand: Cursor IDE hook integration. Reads hook events from stdin, evaluates DLP, injection, and tool policy, writes allow/deny JSON to stdout. Always exits 0 with JSON permission field as the authoritative decision. Without --config, uses a security-focused default profile with 9 tool policy rules, MCP input scanning, and response scanning enabled.pipelock cursor install subcommand: writes hooks.json to register pipelock with Cursor. Supports --global (default, ~/.cursor/) and --project (.cursor/ in cwd). Atomic writes via temp file + rename, .bak backup, idempotent merge with existing hooks, upgrade-safe replacement of stale entries.internal/decide package: shared decision engine for evaluating agent actions against pipelock's scanning pipeline. Supports shell execution, MCP tool calls, and file read events with per-finding action semantics (block vs warn) and enforce flag override.pipelock audit --preflight scanner: detects dangerous IDE configuration files (.cursor/mcp.json, .vscode/mcp.json) in project directories that could override agent security settings. Reports threat level (critical/high/medium/low) with actionable remediation steps.//nolint:gosec G304 suppressions with filepath.Clean() across production and test code (84 occurrences in 26 files). No behavioral change.//nolint:goconst directives, extracted named constantstests/ws-helper/main.go: errcheck on conn.Close(), noctx on net.Listenpipelock diagnose command: fully local end-to-end configuration verification. Spins up a mock upstream and temp proxy, runs 6 checks (health, fetch al
pipelock diagnose command: fully local end-to-end configuration verification. Spins up a mock upstream and temp proxy, runs 6 checks (health, fetch allowed/blocked, hint presence, CONNECT allowed/blocked). Exit 0 on pass, 1 on failure, 2 on config error. Supports --json and --config.explain_blocks config field (opt-in, default false): blocked responses include actionable hints explaining why a request was blocked and how to fix it. Fetch proxy gets a JSON hint field, CONNECT and WebSocket get an X-Pipelock-Hint header. Hints are per-scanner (DLP, blocklist, SSRF, entropy, rate limit, etc.).scanner.ScannerDLP, scanner.ScannerBlocklist, etc.): 12 exported constants matching existing on-wire metric label valuesproxy.Handler() method: returns the composed HTTP handler for use with httptest.NewServer or custom listenersexamples/quickstart/): production-ready two-network architecture with internal: true isolation, opt-in verification suite (5 tests: network isolation, DLP, response injection, MCP tool poisoning), attacker container for reproducible demosgenerate mcporter now preserves per-server extra fields (alwaysAllow, disabled, metadata, headers, etc.) during wrapping. Previously only command, args, and env survived.ws_protocol labelNothing published for this version
WebSocket MCP transport: --upstream ws:// and wss:// for MCP proxy connections, with the same 6-layer scanning pipeline as stdio and HTTP modes
--upstream ws:// and wss:// for MCP proxy connections, with the same 6-layer scanning pipeline as stdio and HTTP modespipelock generate mcporter CLI: wraps MCP server configs with pipelock scanning. Reads any JSON with mcpServers, preserves env blocks, detects already-wrapped servers, idempotentpipelock-init container image: Alpine-based multi-arch image for K8s initContainer deployments, replaces multi-line wget/tar/chmod scripts with cp /pipelock /shared-bin/pipelockpipelock_kill_switch_active{source} Prometheus gauge via custom collector (fresh state per scrape, four sources: config, api, signal, sentinel)pipelock_info{version} build information metricmetrics_listen config field runs /metrics and /stats on a dedicated port, preventing agents from scraping operational metadata. Changes rejected on hot-reload with a warning..github/workflows/reusable-scan.yml) with 7 configurable inputs and score, findings-count, critical-count outputsdocs/metrics.md): all 20 metrics with scrape config and PodMonitor exampleexamples/prometheus/pipelock-alerts.yaml)$instance filter variablefilterAndActOnResponseScan helper: extracted response scan action handling (suppress, block, ask, strip, warn) to eliminate duplication between raw HTML and extracted text scan pathsinternal: [] in YAML config now correctly disables SSRF checks. Previously, ApplyDefaults() treated explicit empty slices the same as absent fields, filling in default CIDRs. This blocked legitimate Docker container traffic on private IPs (172.x.x.x).baseDomain() now correctly groups evil.co.uk instead of merging all .co.uk domains into one rate limit bucketws_protocol instead of policy. The policy label is now exclusively for MCP tool policy violations. MITRE mapping: ws_protocol maps to T1071 (Application Layer Protocol), policy remains T1059 (Command and Scripting Interpreter). Update any dashboards or alert rules that filter on scanner="policy" for WebSocket-specific events.internal/wsutil package extracted: shared WebSocket utilities (fragment reassembly, close frames, error classification) used by both the HTTP WS proxy and MCP WS transportscanner as a structured field with MITRE technique mapping (previously embedded in reason string)docs/configuration.md, forward proxy quick start moved to collapsible sectionpipelock check (works without running the proxy)golang.org/x/net promoted from indirect to direct dependency (publicsuffix for ccTLD handling)Kill switch: emergency deny-all with four activation sources (config, SIGUSR1 signal, sentinel file, HTTP API), OR-composed so any single source block
POST /api/v1/killswitch (activate/deactivate) and GET /api/v1/killswitch/status (per-source state) with bearer token auth, rate limiting, and input hardening (MaxBytesReader, DisallowUnknownFields, strict EOF enforcement)api_listen config field runs the kill switch API on a dedicated port, preventing agents from deactivating their own kill switch in sidecar deploymentsinfo, warn, critical), configurable instance_id, and async buffered deliverysuppress entries with rule name, path glob, and reason) or inline // pipelock:ignore source commentskill_switch_active fieldxapp-), JWT Token, Google OAuth Client IDinclude_defaults config field: when true (default), user-defined DLP patterns are merged with built-in defaults by name, so new default patterns are automatically added on binary upgrade without requiring config changes. Set include_defaults: false to use only user-defined patterns (previous behavior). Same field available for response_scanning.docs/guides/suppression.md): documents all three suppression layers (inline comments, config entries, --exclude flag), available rule names, path matching styles, and GitHub Action integrationtransport, tools, policy, jsonrpc for clearer separation of concernsinternal/normalize with ForPolicy variant for MCP tool policy command matchingWebSocket proxy: /ws?url=ws://... endpoint with bidirectional frame relay, DLP + injection scanning on text frames, fragment reassembly, message size
/ws?url=ws://... endpoint with bidirectional frame relay, DLP + injection scanning on text frames, fragment reassembly, message size limits, SSRF-safe upstream dialer, auth header forwarding with DLP scanning, concurrency limits, connection lifetime and idle timeout controls, and Prometheus metricswebsocket_proxy section in config with max_message_bytes, scan_text_frames, allow_binary_frames, strip_compression, max_connection_seconds, idle_timeout_seconds, origin_policy, and max_concurrent_connections/health endpoint includes websocket_proxy_enabled fieldwebsocket_proxy defaults (disabled by default)--exclude flag for pipelock audit and pipelock git scan-diff: filter findings by path using globs (*.generated.go) or directory prefixes (vendor/). Repeatable for multiple patterns.exclude-paths input: newline-separated path patterns passed to both audit and scan-diff stepsClose 9 scanner evasion bypasses found during red team testing: hex/base64-encoded secrets in URL query params and path segments, vowel-fold flag corr
(?im) patterns, strip mode fail-open when detection came from non-redactable passes, and missing normalization passes on decoded response content (PR #135)MCP HTTP reverse proxy: --mcp-listen + --mcp-upstream flags on pipelock run create an HTTP-to-HTTP scanning proxy with bidirectional JSON-RPC 2.0 vali
--mcp-listen + --mcp-upstream flags on pipelock run create an HTTP-to-HTTP scanning proxy with bidirectional JSON-RPC 2.0 validation, Authorization header DLP scanning, and fail-closed parse error handling (PR #127)pipelock mcp proxy --listen :8889 --upstream http://host/mcp for deployments that only need MCP scanning without the fetch/forward proxy (PR #127)v*.*.*) prevents floating tags like v1 from triggering spurious GoReleaser releases (PR #126)v1 floating tag after each semver release so the GitHub Action always resolves to the latest version (PR #126)mcp_input_scanning.action changed from warn to block when auto-enabled in proxy mode, preventing credential forwarding in balanced configs (PR #127)HTTP forward proxy: standard CONNECT tunneling and absolute-URI HTTP forwarding on the same port as the fetch proxy. Set HTTPS_PROXY=http://localhost:
HTTPS_PROXY=http://localhost:8888 and all agent HTTP traffic flows through the scanner pipeline. Configurable tunnel duration and idle timeout controls (PR #123)luckyPipewrench/pipelock): composite action for CI/CD agent security scanning with checksum-verified binary download, multi-arch (amd64/arm64) and multi-OS (Linux/macOS) support, fail-closed audit gate, PR diff secret scanning, inline GitHub annotations on findings, and job summary (PR #125)config package (ActionBlock, ActionWarn, ActionAsk, ActionStrip, ActionForward), replacing ~70 hardcoded literals across 12 files (PR #124)MCP --env flag: pass specific environment variables to child processes without exposing the full environment (PR #119)
--env flag: pass specific environment variables to child processes without exposing the full environment (PR #119)<IMPORTANT>, <system>) and dangerous capability patterns (file exfil, cross-tool manipulation) hardened via adversarial testing (PR #117)internal/normalize package: consolidate Unicode normalization pipeline, add ForPolicy variant for command matching (PR #116)MCP Streamable HTTP transport: pipelock mcp proxy --upstream bridges stdio clients to remote MCP servers over HTTP with SSE stream support and session
pipelock mcp proxy --upstream <url> bridges stdio clients to remote MCP servers over HTTP with SSE stream support and session lifecycle management (PR #112)mcp_tool_policy blocks dangerous commands (rm -rf, curl to external, chmod 777) before MCP tools execute, with pairwise token matching and whitespace normalization (PR #107)dlp.secrets_file config loads explicit secrets from file, scans URLs and MCP tool arguments for raw + base64/hex/base32 encoded variants including unpadded forms (PR #111)pipelock test CLI command: validates scanner coverage against loaded config with structured pass/fail output per scanner layer (PR #109)pipelock check before pipelock run since check doesn't need a running proxy (PR #113)DEMO_TMPDIR instead of TMPDIR to avoid shadowing POSIX env var (PR #113)MCP transport abstraction: MessageReader/MessageWriter interfaces decouple scanning from stdio framing, preparing for HTTP transport
MessageReader/MessageWriter interfaces decouple scanning from stdio framing, preparing for HTTP transportNO_COLOR env var support and TTY detection--interactive flag for live presentations (pauses between scenarios)docs/guides/crewai.md)docs/guides/langgraph.md)WriteMessage size guard (10 MB limit) prevents unbounded memory allocation on malformed inputmaxLineSize guard on stdio message reader for consistency with write pathparams field bypassed input scanning entirelyViolationPermissions field visibility, HITL reload-to-ask warning, stale commentiterativeDecode consolidated into single exported function (was duplicated across scanner paths)syncWriter and StdioWriter now wrapped with contextsigstore/cosign-installer from 3.10.1 to 4.0.0Nothing published for this version
MCP tool description scanning: detects poisoned tool descriptions containing hidden instructions ( tags, file exfiltration directives, cross-tool mani
<IMPORTANT> tags, file exfiltration directives, cross-tool manipulation)mcp_tool_scanning config section (action: warn/block, detect_drift: true/false)mcp proxy mode unless explicitly configureddescription and title fields from nested inputSchema objectsCODEOWNERS file for automatic review assignmentworkflow_dispatch) for OpenSSF Scorecard workflow& in target URLs silently truncated secrets from DLP scanner%00, %08, %09, %0a in target URLs broke DLP regex matchingname field bypassed tools/list scanning entirelyShouldSkip())Nothing published for this version
govulncheck CI job scanning Go dependencies for known vulnerabilities
govulncheck CI job scanning Go dependencies for known vulnerabilitiesgo mod verify step in CI and release pipelinesgh attestation verify)id-token and attestations permissions for provenance signingpermissions: contents: read in CI workflow (least privilege)continue-on-error with final verification (prevents cascading failures)::warning annotation instead of silent fallbackgovulncheck, cyclonedx-gomod, and crane pinned to specific versions (not @latest)checkDLP (was only on MCP text scanning side)ExtractText now joins blocks with space separator (was \n, allowing between-word injection splits to evade detection)CompileDLPPatterns now applies (?i) prefix, matching URL scanner behaviorcheckRateLimit now uses baseDomain() normalization, preventing per-subdomain rate limit evasionnormalizeWhitespace() for Ogham space (U+1680), Mongolian vowel separator (U+180E), and line/paragraph separatorsValidateAgentName now rejects names containing .. or equal to .norm.NFKC.String() before DLP pattern matching, consistent with response scanningMCP input scanning: bidirectional proxy now scans client requests for DLP leaks and injection in tool arguments
mcp_input_scanning config section (action: warn/block, on_parse_error: block/forward)mcp proxy mode unless explicitly configured.toUpperCase() or mixed-case secrets\x00 injectiongo vet and go mod verify steps, combined duplicate test runs, added job timeoutson_parse_error changed from block to forward (consistent with observe-only philosophy)ask action for input scanning (no terminal interaction on request path)enabled and action fields (unconfigured = both at zero values)Audit log sanitization: ANSI escapes and control characters stripped from all log fields (internal/audit/logger.go)
internal/audit/logger.go)github_pat_ fine-grained PATs and Stripe keys ([sr]k_(live|test)_)-racemaxStripDepth=4) prevents stack overflow from nested JSON arrayssk-svcacct- (was sk-(proj|svcacct)-, overlapping with existing sk-proj- pattern)--json flag for git scan-diff command (CI/CD integration)
--json flag for git scan-diff command (CI/CD integration)-race::ffff:127.0.0.1 now normalized via To4() before CIDR matchingjson.RawMessage with recursive string extraction fallback--no-prefix git diff bypass: parser accepts +++ filename without b/ prefixerror.message and error.data) now scanned for injection0.0.0.0/8 and 100.64.0.0/10 (CGN/Tailscale)ReadHeaderTimeout added to HTTP server (Slowloris protection)text types)HOMEBREW_TAP_TOKEN secret for cross-repo accessNothing published for this version
pipelock audit command: scans projects for security gaps, generates score (0-100) and suggested config (internal/projectscan/)
pipelock audit command: scans projects for security gaps, generates score (0-100) and suggested config (internal/projectscan/)pipelock demo command: 5 self-contained attack scenarios (DLP, injection, blocklist, entropy, MCP) using real scanner pipelinedocs/owasp-agentic-top15-mapping.md, 12/15 threats covered)make bench target (~3 microseconds per allowed URL)configs/grafana-dashboard.json, 7 panels, 3 rows)CLAUDE.md)-racelogs commandNothing published for this version
MCP stdio proxy mode: pipelock mcp proxy -- wraps any MCP server, scanning responses in real-time (internal/mcp/proxy.go)
pipelock mcp proxy -- <command> wraps any MCP server, scanning responses in real-time (internal/mcp/proxy.go)action: ask prompts for y/N/s with configurable timeout (internal/hitl/)configs/claude-code.yaml, configs/cursor.yaml, configs/generic-agent.yamldocs/guides/claude-code.md)git describe failure no longer produces empty version string- and _ charactersbufio.Reader access on timeoutfolder renamed to directory in Homebrew brews configFile integrity monitoring for agent workspaces (pipelock integrity init|check|update)
pipelock integrity init|check|update)** doublestar support)--json flag)--manifest flag)pipelock keygen|sign|verify|trust)~/.pipelock/ with versioned format headerspipelock mcp scan)--json output mode (one verdict per line) and --config flag-racejson.RawMessage null bypass prevention (MCP result always scanned regardless of error field)Nothing published for this version
CodeQL security scanning workflow
-raceCLI commands write to cmd.OutOrStdout() instead of os.Stdout (cobra-idiomatic)
cmd.OutOrStdout() instead of os.Stdout (cobra-idiomatic)run command uses cmd.Context() as signal parent for testabilityyaml.Unmarshal)-raceFetch proxy server with /fetch, /health, /metrics, and /stats endpoints
/fetch, /health, /metrics, and /stats endpoints*.pastebin.com)max_requests_per_minuteX-Pipelock-Agent header identifies calling agents; agent name included in audit logs and fetch responses--config)run, check, generate config, generate docker-compose, logs, git scan-diff, git install-hooks, version, healthcheckconfigs/balanced.yaml, configs/strict.yaml, configs/audit.yamlpipelock generate docker-compose)pipelock_requests_total, pipelock_scanner_hits_total, pipelock_request_duration_seconds-raceNothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →