NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #586 by repository stars
Last release 9 days ago
29 Sep 2026
Release timing varies
gaps range from 8 days to 6 months
Most releases are documented
notes for 11 of 18 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
165 releases · first in 2019
Nothing published for this version
Nothing published for this version
This is strictly opt-in and off by default. It was prompted by an external report and is treated as hardening rather than a vulnerability fix: webhook…
It's been nearly a year since v0.34.1, and v0.35.0 brings a substantial set of improvements for both administrators and on-call users. Highlights include multi-ack escalation policy steps, private contact methods, an alerts view for escalation policies, richer webhook payloads, new webhook and Slack hardening options for admins, and continued progress on Universal Integration Keys and the job queue architecture.
goalert migrate). As always, take and validate a full backup before upgrading.
multi_ack step setting, and the private contact method flag.Webhook.BlockPrivateAddresses, and Slack.DisableBroadcastThreadReplies all default to off and preserve existing behavior unless enabled.Escalation policy steps now have an optional multi-ack setting. When enabled, acknowledging an alert no longer silences notifications for everyone else on that step. Each user activated by the step keeps getting notified until they individually acknowledge.
This is designed for teams where more than one person is expected to respond to every alert: primary/secondary pairs, onboarding shadows, or "whole team on call" policies for major outages. Previously the only workaround was telling people not to acknowledge so they wouldn't stop notifications for others.
What doesn't change:
On a multi-ack step, each user's acknowledgment is recorded in the alert log, so you can see who came online for an incident.
This is an MVP intended to be safe to opt into; we'll refine it based on feedback. Known gaps: alert bundle messages count unacknowledged alerts (so a multi-ack user may see "0 unacknowledged"), and acknowledging an already-acknowledged alert from the web UI does not count as your individual acknowledgment.
API: multiAck on EscalationPolicyStep, and optional multiAck on CreateEscalationPolicyStepInput / UpdateEscalationPolicyStepInput.
Users can now mark a contact method as private, hiding its details (phone number, email address, etc.) from everyone except the owner. This addresses a long-standing request to avoid exposing personal contact details to all users of a GoAlert instance.
(PRIVATE) label to the owner.PRIVATE instead of the destination.Owner's view:
Other users' view:
API: new private field on contact methods, and optional private on the create/update inputs.
Escalation policy detail pages now have an Alerts quick-link that shows alerts across all services assigned to that policy. This makes it easy to see everything a given on-call team is responsible for in one place, with the same filtering and bulk actions available on the service alerts page.
1 PR by @mastercactapusWhen adding a shift to a temporary schedule, you can now select multiple users at once instead of adding each one individually. Each selected user gets their own shift for the chosen time range.
1 PR by @ArunkumarlnrLabels, previously available only on services, can now be set on escalation policies, schedules, and rotations via the GraphQL API. This enables the same ownership/team/cost-center tagging patterns across all of these resource types.
UI support and searching these types by label are planned for a future release.
API: labels field on EscalationPolicy, Schedule, and Rotation; optional labels on the corresponding create inputs; setLabel now accepts these types as targets.
Alert-related webhook notifications now carry significantly more context, making it easier to build automations and integrations without a follow-up API call:
| Payload type | New fields |
|---|---|
AlertStatus |
Summary, Details, ServiceID, ServiceName, Meta, GoAlertURL |
Alert |
GoAlertURL |
AlertBundle |
GoAlertURL |
AlertStatusBundle |
GoAlertURL |
GoAlertURL is a direct link to the alert (or the service's alert list for bundles), built from the configured public URL. Meta contains the alert's key/value metadata.
Example AlertStatus payload:
{
"AppName": "GoAlert",
"Type": "AlertStatus",
"AlertID": 79694,
"Summary": "Disk usage above 90%",
"Details": "Volume /data on db-01",
"ServiceID": "9d1a4f7e-3a2c-4d6b-8f0e-2b7c1e5a9d34",
"ServiceName": "Primary Database",
"Meta": { "host": "db-01", "region": "us-east" },
"LogEntry": "Acknowledged by Jane Doe",
"GoAlertURL": "https://goalert.example.com/alerts/79694"
}A new Block Private Addresses toggle in the Admin → Webhook section rejects webhook deliveries to private, loopback, and link-local addresses (e.g. 10.0.0.0/8, 127.0.0.1, 169.254.169.254). The check happens at connection time against the resolved IP, so DNS names and redirects that resolve to internal addresses are covered as well. Blocked deliveries fail permanently with "destination address is not allowed by administrator" rather than retrying.
This is strictly opt-in and off by default. It was prompted by an external report and is treated as hardening rather than a vulnerability fix: webhooks are disabled by default, the request shape is fixed, and responses are never read.
Two related clarifications for admins:
Webhook.AllowedURLs description and the webhook documentation now make explicit that an empty allowlist permits any destination, including internal ones. If you've enabled webhooks, review this setting.When an alert is acknowledged or closed, GoAlert replies in the original Slack message's thread and, until now, always broadcast that reply to the main channel. A new Disable Broadcast Thread Replies toggle (Admin → Slack) keeps status updates in the thread only, reducing noise in busy channels. Default is off (existing behavior).
1 PR by @AdityaHebballeThe General.ApplicationName setting is now used in the navigation bar and on the login page. Previously these were hardcoded to "GoAlert" even though the browser tab title respected the setting.
The goalert monitor remote monitor no longer requires an ErrorAPIKey in its config. If omitted, a warning is logged instead, which is convenient for test or staging monitors that don't need error reporting.
Continued enhancements to Universal Integration Keys (enabled with --experimental=univ-keys):
color dynamic parameter, supporting good, warning, danger, or a #RRGGBB hex value. Unset or invalid values fall back to the default blue. See the UIK documentation for details.sendSignal mutation: Send a signal message directly to a service via GraphQL, for cases where the programmability of a full integration key isn't needed.sendSignal mutation to directly schedule signal messages by @mastercactapus in #4501Continuing the job queue migration from v0.33/v0.34, alert status updates, rotation changes, and signal processing are now triggered by database triggers that enqueue jobs directly (using LISTEN/NOTIFY), replacing the in-process event bus and the trigger → queue → poll fallback path for rotations. This guarantees no missed events regardless of which instance made the change, and is another step toward first-class multi-instance deployments.
A follow-up fix ensures these trigger-created jobs land in their dedicated queues rather than the default queue, so they're picked up immediately instead of waiting on the polling fallback.
3 PRs by @mastercactapusRepeated deduplication entries for the same alert are now debounced: if a duplicate arrives within 5 seconds of a previous dedup log entry, no additional entry is written. This keeps alert logs readable for noisy sources.
1 PR by @mastercactapususer.name or username fields; linking is only rejected if both the user ID and team ID are missing.GoAlert now builds with Go 1.26, along with updates to all Go dependencies and the build environment image. Deprecated River and net/http APIs were updated accordingly.
The web UI was upgraded from MUI v5 to v6, with list components migrated to the newer CompList implementation as a prerequisite. This is largely invisible to users but keeps the frontend on a supported foundation.
The ongoing JavaScript → TypeScript migration continues, covering the wizard, actions, and remaining top-level config files.
3 PRs by @Azakahul, @KatieMSBFixed several deadlock scenarios in the smoke test harness that caused flaky tests, updated the PR size labeler to work with forks, enabled DCO (Developer Certificate of Origin) checks per org policy, and removed the repo-level code of conduct in favor of the org-wide one.
5 PRs by @KatieMSB, @mastercactapus, @ospo-compliance-botThis release includes routine dependency updates for Go modules, JavaScript packages, and GitHub Actions, including gRPC, cel-go, Vite, Storybook, and CodeQL.
22 PRs by @dependabot[bot]Note: The demo container is published with a separate commit, as the Makefile required a fix.
❯ docker run --rm -it docker.io/goalert/demo:v0.35.0 goalert version
Version: v0.35.0-demofix.1
GitCommit: 524cb0b73540616898fe85de371edd49e8bb1fcc (clean)
BuildDate: 2026-09-21T16:58:50Z
GoVersion: go1.26.6 (gc)
Platform: linux/amd64
Migration: cm-private (#281)
Thanks to our new contributors who helped make this release possible:
Note truncated.
One column per quarter.
feat(docker): update resetdb paths for demo containers in Makefile an…
feat(docker): update resetdb paths for demo containers in Makefile an…
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a maintenance release that includes dependency updates, a memory leak fix, and a quality-of-life improvement for service monitoring.
This is a maintenance release that includes dependency updates, a memory leak fix, and a quality-of-life improvement for service monitoring.
Service details pages now display an aggregated view of recent alert log entries, making it easier to quickly see what's been happening with a service without navigating to the full alerts page.
1 PR by @mastercactapusFixed a long-standing memory leak in the cycle monitor that could cause gradual memory growth over time in long-running deployments.
1 PR by @mastercactapusThis release includes comprehensive dependency updates for both Go and JavaScript packages to ensure security and compatibility.
4 PRs by @dependabot[bot]Full Changelog: v0.34.0...v0.34.1
We're excited to announce GoAlert v0.34.0! This release continues building on the foundation laid in v0.33.0, with significant improvements to messagi
We're excited to announce GoAlert v0.34.0! This release continues building on the foundation laid in v0.33.0, with significant improvements to messaging capabilities, administrative tools, and system reliability.
GoAlert v0.34.0 adds full support for PostgreSQL 17!
For those looking to upgrade their DB without downtime (live migration from old to new), we have documentation around the Switchover feature here. As with any major DB change make sure to take, and validate, a full backup just in case.
While this isn't a new feature, it may be the first time some are hearing about it. For those interested, there is additional information about how it works here and here.
GoAlert now supports Rich Communication Services (RCS) through Twilio. If your Twilio messaging service is configured for RCS, GoAlert will automatically leverage the enhanced messaging capabilities including better delivery tracking and richer content support.
2 PRs by @mastercactapusYou can now mute heartbeat monitors during planned maintenance or expected downtime, preventing unnecessary alerts during known service interruptions. This helps reduce alert fatigue and keeps your alert history clean during maintenance windows.
1 PR by @mastercactapusCalendar subscriptions now support JSON format in addition to existing iCal formats, and you can generate direct links for creating schedule overrides, making it easier to share override creation workflows with team members.
2 PRs by @mastercactapusServices now expose detailed alert statistics through the GraphQL API (alertStats field), providing administrators with better insights into service performance and alert patterns for reporting and analysis.
alertStats field on Service by @mastercactapus in #4293New admin maintenance page provides tools for system maintenance tasks, including the ability to re-encrypt stored data when needed for security or compliance requirements.
1 PR by @mastercactapusThe service search functionality now supports an "only" filter option, allowing for more precise filtering of services.
1 PR by @weefatboiContinued enhancements to the experimental Universal Integration Keys feature (enabled with --experimental=univ-keys):
Enhanced notification system now records and displays complete message status history, providing administrators with full visibility into notification delivery status and helping with troubleshooting delivery issues.
1 PR by @mastercactapusImproved shared locking enables better concurrent work processing, database indexing improvements for better performance with large message volumes, and enhanced testing capabilities for better performance validation.
3 PRs by @mastercactapusAdded comprehensive HTTP security headers and enhanced route security with proper HTTP method restrictions and response codes.
3 PRs by @mastercactapusThis release includes significant architectural improvements that lay the groundwork for future enhancements. Notably, v0.34.0 represents a major milestone in our migration to a job queue architecture, which will enable better multi-instance deployments and improved performance at scale in future releases.
Continued migration of background processes to job queue architecture for better reliability and performance at scale. These improvements are largely invisible to end users but provide a foundation for better multi-instance support and performance improvements in future releases.
11 PRs by @mastercactapus.Start() synchronously by @mastercactapus in #4336Ongoing TypeScript migration, SQLC migration for type-safe database queries, code modernization efforts, and build system improvements including the migration from Yarn to Bun for faster package management.
14 PRs by @Azakahul, @KatieMSB, @cwhy22, @mastercactapusThis release includes comprehensive dependency updates for both Go and JavaScript packages to ensure security and compatibility, along with improvements to our CI/CD pipeline.
Thanks to our new contributors who helped make this release possible:
Full Changelog: v0.33.0...v0.34.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
After a significant hiatus since our last release, we're thrilled to announce GoAlert v0.33.0! This release lays the groundwork for some exciting futu
After a significant hiatus since our last release, we're thrilled to announce GoAlert v0.33.0! This release lays the groundwork for some exciting future features while also delivering numerous fixes and stability improvements to enhance your current experience.
GraphQL API Keys are now fully supported and out of the experimental phase! We've introduced a dedicated editor to manage your API keys more efficiently, simplifying the process of creating, editing, and organizing your keys.
Introducing Alert Metadata: You can now attach arbitrary key-value metadata to alerts, enhancing the context and flexibility of your alerting workflow. This feature allows for more detailed and informative alerts, facilitating better incident management.
To add metadata to an alert, include it in your request parameters or JSON body. For example:
Via URL parameters:
bash
Copy code
/api/v2/generic/incomming?token=<token>&meta=example_key=example_value&meta=example_key2=example_value2
Or in a JSON body:
{
"summary": "test",
"details": "test",
"meta": {
"example_key": "example_value",
"example_key2": "example_value2"
}
}Refer to the documentation (/docs) on your GoAlert instance for more details.
We've introduced several improvements to enhance usability and reliability:
Custom End Time for Service Maintenance Mode: You can now specify a custom end time when putting a service into maintenance mode, giving you more control over maintenance scheduling.
Externally Managed Integration Keys: Integration keys can now be marked as "externally managed," allowing seamless integration with external systems that manage keys.
Improved SMTP Reliability: The remote monitor will now retry sending emails if the SMTP server is unavailable, increasing the robustness of email notifications.
This release includes numerous UI bug fixes and log improvements to enhance stability and user experience. We've addressed issues related to alert details, markdown links, schedule notifications, and more, reducing log noise and fixing various edge-case bugs.
20 PRs by @forfold, @allending313, @cuishuang, @mastercactapusAdministrators can now create Go pprof profiles for performance analysis. By setting the --listen-pprof flag, you can access profiling data to help diagnose and optimize GoAlert's performance.
A significant portion of this release is dedicated to laying the groundwork for upcoming major features:
We are excited to introduce Universal Integration Keys, currently available behind the univ-keys experimental flag. This powerful feature allows you to use Expr expressions to define custom rules for handling incoming messages, providing unprecedented flexibility in configuring alert processing.
With Universal Integration Keys, you can programmatically control how alerts are created, modified, or suppressed based on dynamic conditions. Additionally, you can send "signals" for less critical payloads and pipe a request directly to a Slack message, for example.
For more information, please refer to the Universal Integration Keys documentation.
33 PRs by @forfold, @mastercactapuspending_signals table by @mastercactapus in #3959defaultValue to dynamic action params by @mastercactapus in #3976We have made significant progress towards developing a plugin system for outgoing messages. This new system will allow you to extend GoAlert's notification capabilities by integrating with custom or third-party services.
As part of this effort, all destination structures have been normalized, providing a central registry to manage and register notification destinations. This lays the groundwork for a more modular and extensible notification system, paving the way for future enhancements and custom integrations.
71 PRs by @forfold, @allending313, @ethan-haynes, @mastercactapus, @tony-tvuNote truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Bumps cross-spawn from 6.0.5 to 6.0.6.
Bumps cross-spawn from 6.0.5 to 6.0.6.
updated-dependencies:
Signed-off-by: dependabot[bot] support@github.com
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Welcome to the unveiling of GoAlert v0.32.0! This release is a comprehensive package, featuring a range of exciting new features, critical bug fixes,
Welcome to the unveiling of GoAlert v0.32.0! This release is a comprehensive package, featuring a range of exciting new features, critical bug fixes, and essential developer improvements to elevate your alert management experience.
The 'API Keys' feature is currently an experimental feature. To explore this functionality, administrators must opt in by configuring GoAlert with EXPERIMENTAL=gql-api-keys. As an experimental feature, it may change, and your feedback is appreciated. Caution is advised in production, and expect updates as we refine and enhance its capabilities.
Explore an up-and-coming new feature of GoAlert while it's still in its experimental stage! Once activated, discover the new 'API Keys' option in the admin sidebar, allowing administrators to create and tailor access using GraphQL queries or mutations for a more secure and customizable integration.
More information on implementation details and the decisions around this new feature can be found in an ADR here.
17 PRs by @mastercactapus, @1ddo, @forfoldlistGQLFields query by @mastercactapus in #3276allowedFields to query by @mastercactapus in #3411query field doesn't work by @mastercactapus in #3491Simplify your team's schedule with monthly handoffs! The new 'Monthly' option in Rotations enhances scheduling convenience, ensuring smooth handoffs once a month in GoAlert.
2 PRs by @allending313Elevate service monitoring with new comprehensive metrics in GoAlert. Admins can now keep an eye on service health, check for setup issues, and review notification channels—all in one place for better awareness and management.
5 PRs by @KatieMSBUsers can now opt into subscribe to all shifts on a schedule in GoAlert. Get a complete view of your commitments and your teammates for more comprehensive schedule management.
1 PR by @mastercactapusThe user profile page now renders a calendar for all on-call schedule shifts (broken down by schedule)
2 PRs by @forfoldWe've made a number of QOL improvements including a new splash screen, fixed favicon, labels are visible on services, and improved timestamp support in markdown.
6 PRs by @forfold, @mastercactapusThere were a few new config options and tweaks added for admins, like requiring labels on services and closing stale alerts.
4 PRs by @mastercactapusA number of bug fixes for the Temporary Schedules features have been addressed and some new features!. Soft limits for start and end dates provide better control, default values are now set accurately, and temporary schedules seamlessly merge as intended.
Schedules are now broken down by a default shift length, and while custom shifts remain supported, this intends to make it easier to create and manage even handoffs amongst team members.
Additionally, if you need to edit a temporary schedule, you will now be prompted to confirm the changes, so you know EXACTLY what is being changed before saving!
Lots of bugs were squashed in this update to improve the overall GoAlert experience! Enhancements include improved linter and formatting, optimized search functionalities, enhanced concurrency and performance, streamlined dependency management, meticulous timestamp handling, and robust error handling.
20 PRs by @mastercactapus, @forfold, @KatieMSBIntroducing Architectural Decision Records (ADRs) in GoAlert! We now document key decisions around new and complex features, providing transparent insights into our development process. ADRs serve as a valuable resource for understanding the rationale behind design choices and enhancing collaboratoin within the GoAlert community.
Learn more about ADRs here.
Some of our current ADRs include decisions on tech migrations and the new API key architecture, and can be found here.
1 PR by @mastercactapusWe've invested significant efforts in addressing technical debt by migrating to new technologies. This includes transitions to TypeScript, SQLc, URQL, React Suspense, and React Hooks.
30 PRs by @andrewbenington, @allending313, @mastercactapus, @forfold, @KatieMSB, @tony-tvuNote truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This point release fixes some regressions present in the v0.31.0 release. Additionally, containers and binaries for this version were built with Go 1.
This point release fixes some regressions present in the v0.31.0 release. Additionally, containers and binaries for this version were built with Go 1.21.1.
Full Changelog: v0.31.0...v0.31.1
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →