NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2831 by repository stars
Last release 13 days ago
25 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
189 releases · first in 2021
One column per quarter.
✨ New: example3 (envelope encryption demo)
A small, interface-driven app (same shape as example2) that encrypts text, numbers, and files, with MongoDB as its only database.
ENCRYPTION_SECRET_OLD, set the new one and restart. The master key is re-wrapped automatically.go test ./example3/... needs no database or env vars.⚠️ example3 is a demo and has no authentication. Anyone who can reach it can decrypt tokens, and a file ID alone unlocks its file. Put these routes behind JWT and access control before using them for real (see
example2).
Requires github.com/pilinux/crypt v0.0.30+.
.env.sample files no longer use CORS_ORIGIN=*, because browsers reject * when credentials are allowed. Set your real origin instead.TestMain no longer overwrites your local .env.go get github.com/pilinux/gorest@v1.14.0 && go mod tidy.The library API hasn't changed, so existing apps should build without code changes.
Full Changelog: v1.13.3...v1.14.0
Nothing published for this version
chore: bump indirect dependencies in 1c37216
Full Changelog: v1.13.2...v1.13.3
Nothing published for this version
chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by @dependabot [bot] in #405
Full Changelog: v1.13.1...v1.13.2
Nothing published for this version
Nothing published for this version
fix: handle case-insensitive env values
Full Changelog: v1.13.0...v1.13.1
⚡ asymmetric JWT keys can now be loaded independently
For ECDSA/EdDSA/RSA algorithms, PRIV_KEY_FILE_PATH and PUB_KEY_FILE_PATH are no longer both required.
Whichever key is provided is loaded; only when both are missing does configuration fail.
This enables signer-only (private key) and verifier-only (public key) deployments.
⚡ environment variables are now matched case-insensitively
Keyword/enum values that are compared against fixed literals downstream are normalized so casing no longer matters:
⚡ firewall IP matching hardened
Exact (non-CIDR) IP entries are normalized via net.ParseIP so IPv6 addresses match the client
regardless of case (2001:DB8::1) or form (2001:db8:0:0:0:0:0:1); invalid entries are skipped
instead of being stored as dead keys.
Breaking changes & upgrade notes
This release is a large security-hardening and robustness pass across the auth,
2FA, crypto, database, and middleware layers. It tightens cryptographic
defaults, makes Redis/DB state changes atomic, bounds and hardens the random/
crypto helpers, reworks the Sentry integration, and threads context.Context
through handlers. It also refreshes dependencies and the agent-facing docs.
Full Changelog: v1.12.4...v1.13.0
SecureRandomNumber,ValidateEmail, ValidatePath, FileExist).context.Context, honoring client cancellation andcontext.Context as their first argument. Controllersc.Request.Context(). Update any direct calls to handler.*,service.SendEmail, and service.IsTokenAllowed to pass a context.ACCESS_KEY / REFRESH_KEY values must lengthen them. 10a17fbSERVE_JWT_AS_RESPONSE_BODY now defaults to disabled. Set it explicitly ifSERVE_JWT_AS_RESPONSE_BODY to disabledHASHPASSMEMORY against uint32 overflowresp.Message check in controllersstructs.Map against non-struct dataPasswordUpdateHGET result in PasswordRecoverEXISTS check in PasswordRecoverbig.Int.ExpSecureRandomNumber endpoints and bound edge casesSecureRandomNumber against uint64 overflowSecureRandomNumber retry loopValidateEmail MX lookup with a timeoutValidateEmail skips the RFC 5321 implicit-MX fallbackFileExist returns true only on a successful statValidatePathStrArrHTMLModel example separator in docsCloseAllDB aborts on the first errorerr/sqlDB globalsGetUsers (example2)userID in GetUser (example)golang.org/x/crypto 0.52.0 → 0.53.0 (#397)go.mongodb.org/mongo-driver/v2 2.6.0 → 2.6.1 (#399)go.mongodb.org/mongo-driver/v2 2.6.1 → 2.7.0 (#403)codecov/codecov-action 6 → 7 (#398)actions/checkout 6 → 7 (#402)chore(vulnerability fix): bump github.com/quic-go/quic-go from 0.59.0 to 0.59.1 by @dependabot [bot] in #396
Full Changelog: v1.12.3...v1.12.4
Nothing published for this version
Added DB_URI support for SQL database connections in c5c750b
You can now configure SQL connections with a single DB_URI value.
Behavior:
Supported drivers:
Examples:
DB_URI=postgresql://user:password@host:port/db?sslmode=require&channel_binding=require
Why this matters:
You can now configure Redis with REDIS_URI.
Behavior:
Example:
REDIS_URI=redis://user:password@host:port
Why this matters:
This release is backward-compatible.
Existing setups that use:
will continue to work unless you choose to adopt DB_URI or REDIS_URI.
Full Changelog: v1.12.2...v1.12.3
Nothing published for this version
修复InMemorySecret2FA全局map竞态条件 by @saaa99999999 in #391 (🛠️ vulnerability fix)
Full Changelog: v1.12.1...v1.12.2
Nothing published for this version
chore(deps): bump github.com/getsentry/sentry-go/logrus from 0.43.0 to 0.44.1 by @dependabot [bot] in #366
Full Changelog: v1.12.0...v1.12.1
Nothing published for this version
The minimum Go version is now 1.25.0 . A directory traversal vulnerability in configuration loading has been fixed, nil pointer dereferences in databa…
This release focuses on security hardening, test coverage expansion, and dependency upgrades. The minimum Go version is now 1.25.0. A directory traversal vulnerability in configuration loading has been fixed, nil pointer dereferences in database initialization have been resolved, and new test codes have been added across the database/, config/, lib/, and lib/renderer/ packages.
go directive in go.mod has been upgraded from 1.24.1 to 1.25.0 (b89c241).Fix directory traversal vulnerability in config loading (4771052). The security() and view() config functions previously accepted unsanitized paths for the 2FA QR directory and template directory. A new ensureConfigDir() / sanitizeConfigDir() pipeline now validates that configured paths remain within the workspace root, preventing directory traversal attacks.
Harden lib.ValidatePath() (96be3cd). The path validation function has been rewritten to use filepath.Rel instead of string-prefix matching, which is more robust against edge cases. Empty inputs are now explicitly rejected, and both the full path and allowed directory are cleaned and resolved to absolute paths before comparison.
Fix nil pointer dereference in database initialization (42e50af). InitDB(), InitRedis(), InitMongo(), and InitTLSMySQL() now check whether config.GetConfig() returns nil before dereferencing it, preventing panics when the configuration has not been initialized.
Fix linter error-check warning (0889239). An unchecked error return was corrected to satisfy static analysis requirements.
Extract ensureConfigDir and sanitizeConfigDir (96be3cd, 6cd9468). Duplicated directory-creation logic in the security() and view() config functions has been consolidated into two reusable helpers, reducing code duplication and centralizing the validation logic.
Introduce package-level indirections for testability (42e50af). sql.Open, mysql.RegisterTLSConfig, filepath.Abs, and filepath.Rel are now accessed through package-level variables, allowing tests to inject failures without requiring real infrastructure.
This release adds new test codes and significantly improves coverage for previously untested packages.
InitDB() and GetDB() covering MySQL, PostgreSQL, and SQLite drivers (4ff31a8).InitTLSMySQL() including CA loading, client certificate handling, and TLS registration failures (e821985).CloseSQL(), CloseRedis(), CloseMongo(), and CloseAllDB() (3df555a).renderer.Render() covering JSON and HTML template rendering paths (d589b8b).lib.ValidatePath() with edge cases for traversal patterns, empty inputs, and error injection (4298161).lib.ByteToPNG() with platform-specific test files for Unix (c8e5282).syscall references failed on Windows (e51a5f3).mustGetConfig() test helper function (ffac4fa)..env file (d934a34).securego/gosec binary directly instead of go install (2820b34, 1af2183).database/ (internal) package (3e92b15).| Package | Previous | Updated |
|---|---|---|
github.com/gin-gonic/gin |
v1.11.0 | v1.12.0 (48c7379) |
github.com/getsentry/sentry-go |
v0.42.0 | v0.43.0 (4c1256b) |
github.com/getsentry/sentry-go/logrus |
v0.42.0 | v0.43.0 (4c1256b) |
github.com/mrz1836/postmark |
v1.8.4 | v1.9.0 (dc756ee) |
golang.org/x/crypto |
v0.48.0 | v0.49.0 (918f129) |
| Package | Previous | Updated |
|---|---|---|
golang.org/x/arch |
v0.24.0 | v0.25.0 |
golang.org/x/net |
v0.50.0 | v0.52.0 |
golang.org/x/sync |
v0.19.0 | v0.20.0 |
golang.org/x/sys |
v0.41.0 | v0.42.0 |
golang.org/x/text |
v0.34.0 | v0.35.0 |
README.md to list Go 1.25.0+ as the requirement for v1.12.x and recommend v1.12.x for new projects (b89c241).SECURITY.md to mark v1.11.0 as end-of-life with final release v1.11.1, and add v1.12.0 as the currently supported version (b89c241).Full Changelog: v1.11.1...v1.12.0
security fix: G117 (CWE-499) in 84945f4
strings.SplitSeq to reduce temporary allocations in f515877time.Time json in go modern way in ce4542cbson.D in mongo query (example and example2) in faa5fc8If you are upgrading from v1.10.x, please check the release notes for v1.11.0 and v.1.10.5 for breaking changes and upgrade instructions.
Full Changelog: v1.11.0...v1.11.1
Nothing published for this version
This release introduces significant security enhancements, modernizes the database driver, and includes breaking changes to encryption and dependency…
This release introduces significant security enhancements, modernizes the database driver, and includes breaking changes to encryption and dependency management.
🚨 Breaking Changes
🛡️ Security & Validation
🏗️ Refactoring & Improvements
📦 Dependency Updates
⚙️ CI/CD
Full Changelog: v1.10.6...v1.11.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Compare
Compare
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →