NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #79 by repository stars
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 15 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
866 releases · first in 2022
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Suppressed staticcheck warnings for deprecated protobuf fields. #7261
Fixed session extension and SSH authentication always using the device code flow on Linux.
#7187
Added Windows DNS configuration to the debug bundle.
#7196
Added a CI check for translation key parity.
#6852
Preserved the account email on Android logout while removing it when a profile is deleted.
#7200
Ranked Windows route candidates using combined route and interface metrics.
#7210
Skipped IPv6 route tests when the default next hop is unusable.
#7212
Passed the stored email as a login hint from the UI and preserved it on logout.
#7199
Fixed inconsistencies in the CI gomobile init process.
#7229
Deleted Windows NRPT rules by enumerating the registry instead of relying on a rule count.
#7195
Declared multi-buffer support for the loopback XDP program.
#7230
Exposed SSH functionality on Android.
#7156
Handled Android network changes without restarting the engine.
#7144
Cleared stale installer results before starting updates.
#7204
Stopped the UI before silent Windows updates and suppressed installer reboots.
#7209
Reported network addresses on Android for posture checks.
#7235
Restarted the UI using the user's environment block after updates.
#7245
Switched client tests to go.uber.org/mock.
#7253
Renamed TURN-specific WireGuard proxy terminology to relayed connections.
#7231
Fixed staticcheck findings after upgrading golangci-lint.
#7266
Added missing anonymization and SSH privilege translations.
#7269
Added a lazy connection override and device name reporting to the WASM client.
#7276
Documented the mutual exclusivity of ports and port_ranges in policy rules.
#7158
Refused usage limits that one-off setup keys cannot honor.
#7220
Switched management tests to go.uber.org/mock.
#7253
Suppressed staticcheck warnings for deprecated protobuf fields.
#7261
Added support for non-interactive, environment-driven installations in getting-started.sh.
#7168
Updated the Agent Network documentation.
#7020
Prevented overriding the dashboard image in Enterprise migrations.
#7206
Skipped store migrations for PostgreSQL deployments.
#7207
@SunsetDrifter made their first contribution in #7158
Full Changelog: v0.77.0...v0.77.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Reworked Agent Network endpoint identity and settings bootstrap. #7085
Reworked Agent Network endpoint identity and settings bootstrap.
#7085
Added a proxy-connect authorizer seam for Agent Network.
#7136
Added reverse proxy usage accounting for activity tracking.
#7116
Added strict anonymization level and MAC address anonymization to debug bundles.
#7102
Declared the xdg-utils dependency for NetBird UI packages.
#7126
Fixed credentials used for GTK3 package uploads.
#7125
Prevented WireGuard packets from being misrouted to the STUN handler.
#7059
Updated the NetBird Wails fork to remove the native WebView2 dependency.
#7128
Migrated the relay QUIC tracer to qlog and upgraded quic-go to v0.59.1.
#7124
Derived Windows SSH privilege checks from the user token and group membership.
#6966
Adjusted the GTK3 release job.
#7163
Fixed a macOS DNS panic caused by malformed scutil output.
#7180
Added a fallback to per-IP ACL rules when ipset is unavailable.
#6332
Gated IPv6 forwarding on overlay IPv6 while preserving host Router Advertisement acceptance.
#6221
Removed installer registry handlers for Windows autostart Run keys.
#7183
Added Crowdin configuration for UI translation synchronization.
#7155
Fixed Crowdin export paths and export options.
#7162
Updated the documentation to direct translation contributions to Crowdin.
#7161
Allowed external test suites to reuse the NetBird end-to-end test harness.
#7176
Improved the release pipeline to build release branches and delay marking releases as "latest" until signing is complete.
#7171
Full Changelog: v0.76.3...v0.77.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[management] prewarm a posture check cache on network map generation by @pascal-fischer in #7093
Full Changelog: v0.76.2...v0.76.3
Nothing published for this version
[misc] add AGENTS.md file by @mlsmaycon in #7014
Full Changelog: v0.76.1...v0.76.2
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[client] Support Android session expiry handling by @pappz in #6945
Full Changelog: v0.76.0...v0.76.1
Nothing published for this version
Nothing published for this version
[infrastructure] Deprecate legacy Dex and Zitadel getting-started scripts by @TechHutTV in #6952
Fixes a local privilege escalation in the client daemon (GHSA-qcpp-8vwj-hhwr). The daemon's local control interface accepted any local caller without authentication, so an unprivileged user on the same machine could enable the embedded SSH server, turn on SSH root login and disable SSH authentication, and then open a root shell. Every version from 0.5.0 to 0.75.1 is affected: on Linux, macOS and FreeBSD through the world-writable Unix socket, and on Windows through the loopback TCP listener, which carried no caller identity at all. Reported by @neewek.
The daemon now derives each local caller's identity from the kernel and requires root, or an administrator on Windows, to enable the SSH server, enable SSH root login, disable SSH authentication, or to change the management URL or deregister the peer while that profile has the SSH server enabled. On Windows it serves a named pipe instead of loopback TCP, and existing installations are migrated automatically.
Upgrade note: if you enable any of those settings from a script or an unprivileged session, run the command with sudo, or from an elevated prompt on Windows. Turning them off is unchanged, and so is everything else on the socket.
Learn more here
Full Changelog: v0.75.1...v0.76.0
Nothing published for this version
Nothing published for this version
Added prompt cache token and cost accounting to Agent Network usage. #6900
Added prompt cache token and cost accounting to Agent Network usage.
#6900
Added support for Claude Opus 5.
#6895
Scoped Agent Network model allowlists per policy, group, and provider.
#6905
Reconcile routed AllowedIPs when a lazy connection becomes idle.
#6863
Fetch FreeBSD port files from the GitHub mirror instead of cgit.
#6880
Restored the missing backup.Reset behavior.
#6883
Made Test_ConnectPeers deterministic under Docker/eBPF kernel and Darwin CI.
#6884
Export agent version information for iOS.
#6918
Use platform-specific installer URLs for manual update downloads.
#6922
Exit the GUI immediately when the Windows session ends.
#6878
Fixed stale routing peers after removing overlapping-prefix networks.
#6799
Added ReapplyMatching support to the dedicated AllowedIPsRefCounter.
#6935
rootless-latest Docker image tag.Full Changelog: v0.75.0...v0.75.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Removed the deprecated Hello handshake and gob token decode . #6783 by @lixmal
This release ships a complete rewrite of the desktop client. We went ahead and replaced the old Fyne-based tray application with a new Wails v3 app backed by a React and TypeScript frontend, and it is a massive upgrade. You get a proper main connection view, an exit-node switcher, a networks and peers browser with detail panels, profile management, full settings, debug-bundle creation, and a first-run welcome flow, all in one place instead of buried in a tray menu. #6473 by @pappz and @heisbrot
The new UI is also translated into 10 languages now, and session handling got a lot smarter, so you actually know when your session is about to expire instead of finding out the hard way. Do note that launch-on-login is now enabled by default on fresh GUI installs, so if you manage devices through MDM, the disableAutostart setting is enforced on every launch to keep that under your control.
netbird login improvements. #6473disableAutostart on every GUI launch, not just fresh installs. #6782 by @riccardomanfrinLearn more:
dashboard_features account setting #6742 and the agent_network_only account setting #6736, with agent_network_only requiring dashboard_features.agent_network to be enabled #6750 — all by @mlsmayconmetadata_disabled option. #6791 by @mlsmayconX-Real-Ip headers only from configured trusted proxies. #6833 by @pappz--ignore-scripts in frontend CI. #6859 by @pappzFull Changelog: v0.74.7...v0.75.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →