NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2516 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 1 weeks
Some releases are documented
notes for 33 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
554 releases · first in 2017
achcli can check original Nacha file and batch control totals without rewriting the file. achcli -validate-totals file.ach reads stored counts, hashes
achcli can check original Nacha file and batch control totals without rewriting the file. achcli -validate-totals file.ach reads stored counts, hashes, and debit/credit totals and exits 1 if any input fails. JSON input is rejected because that parser recalculates totals.
CTX, ATX, and TRX return, dishonored return, and contested dishonored return entries keep a copied Number of Addenda Records field. Validation checks that the field is numeric instead of matching the reply addenda count. OFFSET companion entries skip that check. CTX returns may keep Addenda05 records with the copied count.
File header FileCreationTime hours must be 00–23. Values such as 2400 and 2900 are rejected.
Full Changelog: v1.63.7...v1.64.0
One column per quarter.
Nothing published for this version
Nothing published for this version
JSON prenote files no longer pick up a generated ADV batch control with service class 280. Decoding keeps ADV control only when the payload includes a
JSON prenote files no longer pick up a generated ADV batch control with service class 280. Decoding keeps ADV control only when the payload includes advBatchControl or the SEC code is ADV. Building a non-ADV batch drops any leftover ADV control so the batch control keeps the header service class (200, 220, or 225 for prenotes). Fixes #1052
IAT batch validation keeps checking addenda trace numbers after a correction entry (Addenda98). A mismatched later entry now fails with ErrBatchAddendaTraceNumber instead of being skipped.
The HTTP server write timeout is configurable with HTTP_WRITE_TIMEOUT (Go duration, default 30s). Set 0 to disable. Invalid or negative values are logged and fall back to 30s.
Full Changelog: v1.63.6...v1.63.7
Nothing published for this version
Nothing published for this version
Nothing published for this version
Batch validation now requires AddendaRecordIndicator to match the addenda on each entry. An indicator of 1 with no addenda, or 0 with addenda, is inva
Batch validation now requires AddendaRecordIndicator to match the addenda on each entry. An indicator of 1 with no addenda, or 0 with addenda, is invalid and can be returned by the Fed as R25.
AddendaRecordIndicator=1 requires at least one addenda record (ErrBatchAddendaRequired)AddendaRecordIndicator=0 requires no addenda records (ErrBatchAddendaIndicator)readACH and writeACH now close their input and output files on every return path.
Full Changelog: v1.63.5...v1.63.6
Nothing published for this version
Nothing published for this version
Zero-dollar CCD and CTX remittance entries are valid Nacha records. ValidAmountForCodes now treats transaction codes 24, 29, 34, 39, 44, 49, and 54 as
Zero-dollar CCD and CTX remittance entries are valid Nacha records. ValidAmountForCodes now treats transaction codes 24, 29, 34, 39, 44, 49, and 54 as zero-dollar remittance codes:
0 parse and validate (fixes #1861)0AllowZeroEntryAmount / AllowInvalidAmounts are unchangedFull Changelog: v1.63.4...v1.63.5
Let the debit-only SEC types validate after a reversal by @karpovantonme in #1842
Full Changelog: v1.63.3...v1.63.4
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix(deps): update module golang.org/x/text to v0.41.0 by @renovate [bot] in #1829
Nothing published for this version
dd7d55d fix(server): reject oversized request bodies instead of truncating
Full Changelog: v1.63.1...v1.63.2
Nothing published for this version
MergeDir stability : complete via channel close and drain instead of cancel-only shutdown, so in-flight parsers are not left blocked on errors (no dea
MaxDollarAmount is per side: debit and credit totals are limited independently to match NACHA file control totals. Mixed debit+credit files under a shared cap may now stay in one file when each side is under the limit (previously a combined running total could split incorrectly).4 * GOMAXPROCS, clamped 8–50) instead of a fixed 50.merge_test.go, merge_dir_test.go, merge_iat_test.go, and merge_internal_test.go.Full Changelog: v1.63.0...v1.63.1
Nothing published for this version
Security — CORS origin allowlist via moov-io/base v0.63.0
Bump github.com/moov-io/base to v0.63.0.
Credentialed CORS no longer reflects arbitrary https:// Origins with Access-Control-Allow-Credentials: true. Existing AddCORSHandler / SetAccessControlAllowHeaders / Wrap call sites now honor base's shared allowlist.
Deploy / upgrade
MOOV_CORS_ALLOW_ORIGINS to a comma-separated list of exact browser Origins where credentialed cross-origin calls are expected (e.g. https://moov.io,https://dashboard.moov.io).http://localhost[:port], http://127.0.0.1[:port]).Access-Control-Allow-Origin / credentials headers.Thanks to @SashaMIT for the CORS allowlist work.
Full Changelog: v1.62.1...v1.63.0
Nothing published for this version
Bump github.com/moov-io/base to v0.62.1 (bugfix)
github.com/moov-io/base to v0.62.1 (bugfix)
pgxpool.Close wait on sql.DB shutdown to avoid process-exit deadlocks (Postgres/AlloyDB)Nothing published for this version
7ddfbec server: configurable max request body size via ACH_MAX_BODY_SIZE
9ae46b9 docs: keep legacy OpenAPI enums, document newer fields as strings
Nothing published for this version
Nothing published for this version
Nothing published for this version
0749797 fix: preserve IATEntryDetail.DFIAccountNumber spaces when PreserveSpaces is set
Nothing published for this version
Nothing published for this version
fix: parse BatchControl by rune to prevent multibyte field misalignment by @dkoosis in #1796
Full Changelog: v1.61.1...v1.61.2
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix(deps): update module golang.org/x/net to v0.54.0 by @renovate [bot] in #1785
Full Changelog: v1.61.0...v1.61.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →