NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1461 by repository stars
Last release today
07 Oct 2026
Release timing varies
gaps range from 8 days to 3 months
Most releases are documented
notes for 3 of 4 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
700 releases · first in 2014
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Repaired the vulnerability workflow's govulncheck installation.
Warning
This release includes breaking changes to the Go API and default behavior. Read the upgrade notes before updating an existing deployment.
This release includes changes merged since v0.0.4 in May 2022.
We'll publish versions more often from here and keep dependencies current. Each release will carry upgrade notes where behavior changes.
acl.DecideArgs. The struct carries the service and destination, along with the requested proxy host. During MITM checks, the request fields expose the current HTTP request (Req) and its original CONNECT request (ConnectReq). (#286, #298)pkg/smokescreen/metrics, where NewStatsdMetricsClient replaces NewMetricsClient. Tags use map[string]string. Update timing calls to TimingWithTags(name, duration, tags, rate) and use StatsdClient() to access the underlying StatsD client. Config.MetricsClient accepts MetricsClientInterface. (#169, #174, #179)Go 1.25.0 or later is required. CI tests Go 1.25 through 1.27. (#306, #305)
Timeout defaults have changed. These values apply through the CLI and NewConfig():
| Setting | Default | Details |
|---|---|---|
| Outbound connection timeout | 10 seconds | Applies when connect_timeout or --timeout is omitted. An explicit 0 disables this deadline. #297 |
| HTTP header, request-read, and response-write timeouts | 300 seconds each | YAML values of 0 retain the defaults. Check the configured durations for long uploads and streaming responses. #276 |
| Idle HTTP keep-alive timeout | 300 seconds with the default read timeout | When idle_timeout is 0, Go uses ReadTimeout for idle keep-alive connections. An explicit nonzero idle_timeout overrides that fallback. |
| DNS lookup deadline | 5 seconds | Set dns_timeout or --dns-timeout to adjust it. Zero selects the default. #280 |
The HTTP settings govern the server created by StartWithConfig. Established CONNECT tunnels follow the configured tunnel idle timeout. Applications supplying their own HTTP server control its deadlines.
Rate limiting and MITM require explicit configuration. When enabled, Prometheus starts a listener at 0.0.0.0:9810/metrics using its defaults.
allow_addresses and deny_addresses. (#237)SmokescreenContext and its decision fields are exported for use by integrations. (#180, #189, #196, #199, #200, #232, #234)proxy_duration_ms metric measures time spent handling a request before dialing the destination. (#175)pkg/smokescreen/hostport and acl.HostMatchesGlob for applications that need the same parsing and matching rules. (#172, #185)X-Server-Ip header. (#263)TrackerInterface. Update calls to NewTracker to pass the metrics interface and an optional success-rate tracker. Instrumented-connection constructors take a project argument, while the wait group is available through Wg(). (#171, #173, #268)Config.Resolver accepts custom resolvers implementing LookupPort and LookupIP. Existing *net.Resolver values satisfy that interface. (#187)project tag. The domain label was removed from connection timing to reduce cardinality. (#259, #268)golang.org/x/net v0.56.0, golang.org/x/text v0.39.0, Logrus v1.9.0, gopkg.in/yaml.v2 v2.4.0, and google.golang.org/protobuf v1.33.0. (#186, #216, #306)Config.RejectResponseHandler is deprecated in favor of RejectResponseHandlerWithCtx. Configurations that set both handlers fail validation. (#232)smokescreen.Version() and smokescreen.VersionID. Applications can read version information through runtime/debug.ReadBuildInfo. (#165)PrivateRuleRanges. Private-address checks use net.IP.IsPrivate(), and callers can set address exceptions through Config. (#160)ACL.ValidateDomainGlobs. Use ValidateDomainGlob for one glob or ValidateRule for a rule. (#178, #225)transport_max_idle_conns and transport_max_idle_conns_per_host take effect on upgrade. (#278)MockMetricsClient. (#233)govulncheck installation. (#306)integration build tag. CI runs them separately from unit tests and checks the vendor tree for drift. (#305)100.64.0.0/10, the well-known NAT64 prefix, 6to4, and Teredo. Explicit allow rules take precedence for these ranges. (#265, #277)master, as well as the weekly schedule. GitHub Actions are pinned to commit SHAs. (#307, #299)Full changelog: v0.0.4...609eb89
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →