NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #742 by repository stars
Last release 2 days ago
06 Oct 2026
Ships unpredictably
gaps range from 1 weeks to 2.2 years
Most releases are documented
notes for 6 of 7 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
63 releases · first in 2016
Release Build (from refs/tags/v1.4.0/f392bdae4120f8a898644056546bfea33eeee783)
Release Build (from refs/tags/v1.4.0/f392bdae4120f8a898644056546bfea33eeee783)
certstrap-darwin-arm64 and certstrap-linux-arm64, plus a SHA256SUMS file for all binaries.init and revoke now create CRLs with Go's x509.CreateRevocationList. It requires the CA certificate to have a subject key ID and, if the certificate lists key usages, the CRL signing usage. CAs created by certstrap already have both, so this only affects CA certificates added to a depot by another tool.revoke still reads the v1 CRLs written by earlier releases. The CRLs it writes are v2, with a CRL number that goes up by one on each revoke.--version now comes from Go build info. go install github.com/square/certstrap@v1.4.0 reports 1.4.0. Builds without git metadata, including the Docker image, report (devel).Full Changelog: v1.3.0...v1.4.0
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Exclude the deprecated PEM functions from CI lints by @jdtw in #125
Release Build (from refs/tags/v1.3.0/1377eabdd8242bc353dcebf879a3b077413036c2)
pathlen on CA certificates and intermediate CA by @socheatsok78 in #135Full Changelog: v1.2.0...v1.3.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
New Features Add revoke command to add certificate to CA's CRL ( #58 ) Add URI SAN support to the request-cert command via --uri flag ( #63 ) New API
New Features
Add revoke command to add certificate to CA's CRL (#58)
Add URI SAN support to the request-cert command via --uri flag (#63)
New API in pkix package (#71)
New flags that allow to override default file inputs and outputs. request-cert command takes --key and --crt flags and sign command takes --csr and --crt. (#81)
Bugfixes
Support CSR issued by Microsoft certreq tool (#50)
Remove global state from pkix package (using when using it as a library) (#77)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
New Features Add new --expires flag for finer expiry selection, deprecates old --years flag
New Features
Add new --expires flag for finer expiry selection, deprecates old --years flag (#47)
Nothing published for this version
New Features Add command to issue intermediate CA certificates
Nothing published for this version
Nothing published for this version
./certstrap.go --version was returning the incorrect version. This is fixed in v1.0.1
./certstrap.go --version was returning the incorrect version. This is fixed in v1.0.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →