Zum Inhalt springen

Caddy Release Notes

21 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Caddy, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.11.7 behebt Regressionen aus 2.11.6

Caddy v2.11.7 behebt Regressionen aus 2.11.6, darunter einen Absturz beim Proxying über HTTP/2 und nach einer Minute abgebrochene Streams, und unterstützt zusätzlich das neue Header-Feld Incremental (RFC 10036).

This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. If you're on 2.11.6, we recommend upgrading. It also adds support for the brand new Incremental header field (RFC 10036).

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

Highlights

  • Fixed: crash and dropped streams caused by the new idle timeouts. 2.11.6 introduced default idle read/write timeouts, which caused some problems:
    • In 2.11.6, the request body's idle deadline could outlive the handler that set it:

      • Over HTTP/2, Caddy could panic with a nil pointer dereference when the reverse proxy was still reading a request body after the handler had returned. (#8101)
      • Over HTTP/1.1, streaming responses to requests with a body, such as SSE clients that open the stream with a POST, were cut off exactly 60 seconds after the body was read. (#8103)

      Both are fixed in #8107. Thanks @steadytao!

    • Over HTTP/2, streaming responses that paused between writes for longer than write_idle (1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks @WeidiDeng! (#8118, #8119) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.11.6: Neuer url_pattern-Matcher und Breaking Changes

Caddy v2.11.6 bringt zahlreiche Verbesserungen und Fehlerbehebungen, darunter den neuen url_pattern-Request-Matcher auf Basis des URLPattern-Standards, und enthält durch Sicherheitshärtung einige Breaking Changes.

This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!

We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

:warning: Please read the breaking changes below before upgrading. Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it.

Highlights

  • New url_pattern request matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matching url_pattern CEL function too. Thanks @dunglas! (#7787) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.11.4

Version 2.11.4 enthält mehrere Sicherheits- und Fehlerbehebungen (u. a. Windows-Backslashes im Pfad-Matcher, Placeholder-Expansion in rewrite, stripHTML in templates, Header mit Unterstrichen), die bei Anwendungen, die sich auf das fehlerhafte Verhalten verlassen, zu Änderungen führen können.

This release patches more security, security-adjacent, and normal bugs. The FrankenPHP project has collaborated on PHP-adjacent patches, which we are grateful for.

The recent surge of patches is mostly attributed to token predictors. We have had to reject more than 75% of "security" reports because they were AI slop spam (or just lazy/incorrect). Please use LLMs and agents wisely to avoid wasting precious maintainer resources. We have started blocking offending accounts that spam slop reports. Thank you to all who submit responsible reports following our security policy to make the project better. We appreciate that the community deems the Caddy project worthy of contribution to improve the broader ecosystem!

Security-related patches:

  • caddyhttp: Normalize Windows backslashes in path matcher (thanks @Vincent550102)
  • rewrite: Prevent placeholder re-expansion in injected query (thanks @WhiskerEnt)
  • templates: Improved stripHTML action to more reliably remove malformed HTML (thanks to @jmrcsnchz)
  • caddyhttp: Ignore header fields with underscores to prevent collisions (thanks @Vincent550102 for the report and @dunglas for the patch)

:warning: These security patches may be breaking if your application relies on the buggy behaviors.

There are also several other various fixes and enhancements by many other contributors. Thank you everyone who participated!

What's Changed …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.11.3

Version 2.11.3 bringt Sicherheitspatches für fastcgi, vars und den Admin-Socket (Auth-Bypass) sowie kleinere Funktionen und Fehlerbehebungen, etwa bei Placeholder-Expansion in vars und TLS-Richtlinien für Tailscale.

This release improves several aspects of Caddy with minor features, bug fixes, and security patches. Thank you to everyone and their bots who contributed to help make this release the best one yet!

Security patches:

  • fastcgi: Carrying over a patch from FrankenPHP for a bug that could allow non-PHP files to be executed; collaborated on by @dunglas, @KC1zs4, and @chenjj.
  • vars: A more thorough fix for https://github.com/advisories/GHSA-m2w3-8f23-hxxf, collaborated by @everping and @vnxme.
  • admin: Array index normalization to prevent remote admin socket auth bypass, by @Amemoyoi and bot.
  • admin: More rigorous path prefix matching to prevent remote admin socket auth bypass, by @Amemoyoi and bot.

We've also merged a couple PRs that fix upstream security bugs in other projects like quic-go and CertMagic. Thank you to @marten-seemann for maintaining quic-go so diligently!

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.11.2

Version 2.11.2 behebt zwei CVEs (forward_auth und vars_regexp), verbessert Reverse Proxy und Metrik-Leistung, führt die globale Option tls_resolvers sowie zstd-Kompression beim Log-Rolling ein (roll_gzip ist veraltet) und basiert auf Go 1.26.1.

Caddy 2.11.2 contains numerous bug fixes and enhancements! I know that's a lame summary but it's really all over the place.

Highlights

  • Reverse proxy got a lot of love with certain edge cases related to PROXY protocol, health check port, and closing body on retries. Dynamic upstreams are now tracked which enables passive health checking.
  • Performance improvements for metrics.
  • New tls_resolvers global option to control DNS resolvers for all sites when using the ACME DNS challenge.
  • Log rolling now supports zstd compression; deprecated roll_gzip, which will be removed in the future. Use roll_compression instead.
  • Refined logging and some error messages.
  • Fixed a bug in rewrite handler that could cause some URIs to not be rewritten when URI path is an escaped form of target path. Thanks to @MaherAzzouzi for the report.

Security fixes

This release fixes two CVEs.

  • @NucleiAv reported a bug in the forward_auth directive that could permit identity injection and potential privilege escalation.
  • @sammiee5311 reported that vars_regexp double-expanded placeholders, allowing some unusual configs to reveal secrets.

In addition:

  • Built on Go 1.26.1 (also released today) which patches several CVEs.
  • Our documentation has been updated to note that file system case sensitivity may affect the behavior of the hide option of the file_server handler. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.11.1

Version 2.11 (erstes Release als 2.11.1) bringt automatische ECH-Schlüsselrotation, zeitbasiertes Log-Rolling, Konfigurations-Reload per SIGUSR1, automatisches Host-Header-Rewriting bei HTTPS-Upstreams, Logging von Request- und Response-Bodies via log_append sowie mehrere Sicherheitspatches und Fehlerbehebungen.

Our community is pleased to announce Caddy 2.11! Of note are new features, numerous bug fixes including several security patches, and various QoL ("quality-of-life") enhancements.

There are no code changes from v2.11.0 other than to a CI job. Due to a recent external change that broke our release process, the first release of 2.11 is v2.11.1.

Special Sponsor Shoutout

Extra big thanks to our major sponsors:

They, along with dozens of smaller sponsors, make this project and new releases possible, together with our maintainer team. Thank you all!

Notable changes

  • Encrypted ClientHello (ECH) keys are rotated automatically.
  • Time-rolling options for logs.
  • SIGUSR1 can now reload configuration if it was initially loaded from a file on the command line and did not get changed via the API.
  • Reverse proxy now automatically rewrites the Host header to the address of the upstream when the upstream is HTTPS (#7454)
  • log_append can now log request and response bodies, useful for debugging.
  • Our project now implements and requires Assistance Disclosures (for AI/LLMs) on issues, PRs, comments, replies, reviews, etc.
  • Many, many other minor improvements and bug fixes.

Thank you to everyone who was involved this release!

:warning: Security patches …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.11.0-beta.2

Die zweite Beta von 2.11 ergänzt kleinere Funktionen wie den Platzhalter {http.request.body_base64}, ECH-Schlüsselrotation, mehrere Zwischenzertifikate in caddypki und das Flag --json für list-modules und behebt einen Fehler beim ZeroSSL-API-Issuer.

Welcome to the second beta version of 2.11. We are closer to a final release. This includes some minor new features and enhancements, and a fix for the ZeroSSL API issuer.

Thank you to everyone who contributed!

Changelog

  • 8a87bb3ffb8706bbfcaada1d52008a8eb07ad790 build(deps): bump github.com/smallstep/certificates (#7381)
  • 7b031e1eb5bc0bae9a8394d93f20399932ebd4d3 build(deps): bump the all-updates group across 1 directory with 12 updates (#7421)
  • be5f49fbeb046fb123583e5887ddf576a312a8e4 caddyhttp: Fix logging on wildcard sites when SkipUnmappedHosts is true (#7372)
  • 6e0cbd0fa0d3022b41fc2c17b80f15402e685643 caddyhttp: create a placeholder for and log ech status (#7328)
  • 4037d0576094c5f9f570825601615b62cb8d85b1 caddyhttp: {http.request.body_base64} placeholder (#7367)
  • 7ebe72bbfe342688a325325ea79e46970d017eb7 caddypki: Add support for multiple intermediates in signing chain (#7057)
  • 3c9c67e804eb3db9a3ac6532ddd2434246058cd5 caddytls: ECH key rotation (#7356)
  • 374b7a637f2b6f8d0f2723ad2e7908a41023e8d5 caddytls: fix preferred chains options by appending values instead of replacing (#7387)
  • 6a4296b1a45d81f52bf8ab01d0bcaa4423fee3ff caddytls: panic when using tls.ca_pool.source.http -> tls.ca (#7393)
  • 9eabd443cb170ed846a70a84acf87002683ad29b cmd: Add --json flag to list-modules command (#7409)
  • b2d21f650a7ecd61d0a7ee85f3d423b89cddc371 go.mod: Upgrade CertMagic and ZeroSSL deps …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.11.0-beta.1

Die erste Beta von 2.11 ist der Test des neuen automatisierten Release-Prozesses und bringt zeitbasiertes Log-Rolling (timberjack statt lumberjack), SIGUSR1-Reload, Named Socket Activation sowie diverse Fehlerbehebungen.

Welcome to the beta version of 2.11. This is the first release made by our new, automated release process developed by @Mohammed90 that was carried out and approved entirely by our maintainer team (together with @francislavoie) without intervention from @mholt, the original Caddy author. This represents a significant step forward in project autonomy and growth, ensuring that the project's stability and longevity is not reliant upon a single person.

This first beta release was primarily to test our new workflow, so there's still a couple things left to do before the stable release.

Featured here are numerous, mostly minor, bug fixes and enhancements, mostly affecting edge cases or niche corners of the software; for example, proxying H2C or HTTP/3, obscure Caddyfile scenarios, and named socket activation.

Some notable changes:

  • SIGUSR1 can be used to reload configuration only if it was loaded from a file using the CLI, and not changed by the API since then.
  • We replaced "lumberjack", our logging library, with a fork "timberjack" that supports the oft-requested time-rolling ability.
  • Caddy can now bind listeners with named socket activation.

Before the final release, we expect ECH key rotation to be enabled as well as a few other patches/features

Thank you to our sponsors and contributors for all that you do! …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.10.2

Der Hotfix 2.10.2 behebt kritische Probleme aus 2.10.1: Reihenfolge der Logger-Initialisierung, eine acme_dns-Regression im Caddyfile und das Importieren verschachtelter Tokens für {block}.

This is a hotfix release to fix a couple critical issues from v2.10.1

What's Changed

Changelog

  • 551f793700fe1550845c824470b623fd1aa03d36 caddyfile: Fix importing nested tokens for {block} (#7189)
  • 16fe83c7afe2152b0bb53ae35078a28f87e6dcf2 http: Make logger first, before TLS provisioning (#7198)
  • 4564261d8350f8010b7e001e646e260e9bba5746 httpcaddyfile: Fix acme_dns regression (#7199)

New Contributors

Full Changelog: https://github.com/caddyserver/caddy/compare/v2.10.1...v2.10.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.10.1

Version 2.10.1 enthält zahlreiche Fehlerbehebungen und Abhängigkeits-Updates (u. a. quic-go v0.51.0, .avif-Unterstützung im file_server) und erfordert Go 1.25.0 oder neuer.

This is probably our biggest patch release ever -- not that lots of things were broken, but there's lots of refinement happening thanks to broader adoption and contributions from many more people. Just look at the New Contributors below!

Anyway, this release does contain some bug fixes and dependency upgrades which we hope will serve you well. Let us know if there's any issues! And thank you to all who contributed, especially our reliable maintainer team!

This version of Caddy requires Go v1.25.0 or newer.

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.10.0

Caddy 2.10 unterstützt Encrypted ClientHello (ECH), standardmäßig die Post-Quantum-Gruppe x25519mlkem768 und experimentelle ACME-Profile, setzt im Reverse Proxy einen Via-Header statt eines doppelten Server-Headers und enthält Fehlerbehebungen.

Caddy 2.10 is here! Aside from bug fixes, this release features:

  • Encrypted ClientHello (ECH): This new technology encrypts the last plaintext portion of a TLS connection: the ClientHello, which includes the domain name being connected to. The draft spec for ECH is almost finalized, so we can now support this privacy feature for TLS. This is a powerful but nuanced capability; we highly recommend reading the ECH documentation on our website.
  • Post-quantum (PQC) key exchange: Caddy now supports the standardized x25519mlkem768 cryptographic group by default.
  • ACME profiles: ACME profiles are an experimental draft that allow you to choose properties of your certificates with more flexibility than traditional CSR methods. For example, Let's Encrypt will issue 6-day certificates under a certain profile. Caddy may eventually use that profile by default.
  • Via header: The reverse proxy now sets a Via header instead of a duplicate Server header. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.9.1

Version 2.9.1 behebt Probleme mit FastCGI, HTTP/3 über Unix-Sockets, Log-Dateiberechtigungen, wiederholten TERM-Signalen und einem ARI-Sonderfall und ergänzt im Caddyfile die match-Subdirektive der header-Direktive für Response-Matching.

This is a patch release fixing a few issues related to FastCGI, HTTP/3 and unix sockets, log file permissions, repeated TERM signals, and an ARI edge case. It also adds Caddyfile support for response matching in the header directive.

Thanks to everyone who reported bugs and helped with fixes!

Changelog

  • 34cff4af7db1365bba6decc647ccfb6bf1b21afd core: Only initiate exit once (should fix #6707)
  • 50778b55425d378f709599c0d424b0138af592f4 fix: disable h3 for unix domain socket (#6769)
  • 0e570e0cc717f02cf3800ae741df70cd074c7275 go.mod: Upgrade CertMagic to 0.21.6 (fix ARI handshake maintenance)
  • e48b75843b7eff2948b573391fb41535b5e333ef header: match subdirective for response matching (#6765)
  • 1f927d6b07d52d7cf46f1f3020c1ea5993a3e5e8 log: Only chmod if permission bits differ; make log dir (#6761)
  • 1bd567d7ad41d5509e2aa60cf36e749f195ad83c reverseproxy: buffer requests for fastcgi by default (#6759)

What's Changed

New Contributors …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.9.0

Caddy 2.9 bringt kleinere neue Funktionen und vor allem Verfeinerungen und Fehlerbehebungen in Bereichen wie Konfiguration, Logging, Reverse Proxy, HTTP/3, Metriken, Sicherheit und TLS-Automatisierung/ACME ARI.

Happy New Year! We're pleased to release Caddy 2.9. Aside from some minor new features, this release is mainly focused on refinements and bug fixes in many areas, including:

  • Config loading
  • Events
  • Logging
  • Placeholders
  • Reverse proxy and HTTP server performance
  • Matchers
  • HTTP (esp. HTTP/3)
  • Metrics (per-host metrics)
  • Security
  • TLS automation & ACME ARI

We realize there is extensive interest in Encrypted Client Hello (ECH) and post-quantum ciphers. These are slated to be supported in Go 1.24, which is scheduled for a stable release in approximately February. We did not want to force users to go through the inconvenience of installing pre-release, non-stock installations of Go, even though the RCs are quite stable and production-ready, in order to even compile Caddy, which is quite common given our plugin ecosystem. We anticipate a Caddy 2.10 release in the near future with these capabilities, built on Go 1.24.

We hope you will enjoy the 2.9 release. Thanks to all contributors, bug reporters, and helpers, and those organizations which deployed pre-release versions to production to help verify patches and features.

Changelog

  • ef4e0224a8495fc29847d865087febdee8736e3b caddyfile: Fix comma edgecase in address parsing (#6616)
  • b116dcea3d022cd2b060a978c499ac17e5d0a2e1 caddyhttp: Add {?query} placeholder (#6714)
  • c216cf551dcbd2de1da1b9fe8a7e179b76827753 caddyhttp: Allow matching Transfer-Encoding, add to access logs (#6629) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.8.4

Der Hotfix 2.8.4 behebt die Regression bei der automatischen Erkennung der Caddyfile aus v2.8.2; der Tag v2.8.3 wurde versehentlich auf dem falschen Commit erstellt und entfällt.

Hotfix for the Caddyfile detection regression in v2.8.2. The v2.8.3 tag was mistakenly made on the wrong commit and is skipped.

Changelog

  • 7088605c cmd: fix regression in auto-detect of Caddyfile (#6362)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy Version 2.8.2

Version 2.8.2 behebt weitere Fehler im Zusammenhang mit ARI, try_files beim Root-Pfad (/) und der Caddyfile-Erkennung per CLI.

A few more fixes of reported bugs related to ARI, try_files with the root path (/), and Caddyfile adapter detection on the CLI. See 2.8.0 release notes for details on 2.8.

Changelog

  • 01308b4b I'm so tired of typos
  • a63767d3 build(deps): bump golangci/golangci-lint-action from 5 to 6 (#6361)
  • f8a2c602 caddyhttp: properly sanitize requests for root path (#6360)
  • b7280e69 caddytls: Implement certmagic.RenewalInfoGetter
  • 15faeacb cmd: fix auto-detetction of .caddyfile extension (#6356)

Full Changelog: https://github.com/caddyserver/caddy/compare/v2.8.1...v2.8.2

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.8.1: Fixes für Verzeichnisrechte und Matcher

Version 2.8.1 behebt Probleme mit Verzeichnisberechtigungen (appDataDir wird mit 0o700 angelegt) und das Zusammenführen aufeinanderfolgender client_ip- oder remote_ip-Matcher.

Quick fixes for a few users related to directory permissions and matcher parsing.

Changelog

  • 40c582ce caddyhttp: Fix merging consecutive client_ip or remote_ip matchers (#6350)
  • a52917a3 core: MkdirAll appDataDir in InstanceID with 0o700 (#6340)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.8.0 mit ARI-Unterstützung und HTTP/3 zu Proxy-Backends

Caddy 2.8.0 bringt hunderte Verbesserungen, darunter ACME Renewal Information (ARI), HTTP/3 zu Proxy-Backends und bessere Skalierbarkeit, außerdem mehr Breaking Changes als üblich durch das Entfernen lange veralteter Funktionen.

Caddy 2.8 is here! With hundreds of improvements, Caddy is more scalable and capable than ever before. Featuring ACME Renewal Information (ARI) support, HTTP/3 to proxy backends, and so much more than we can list in a sentence, we are pleased to bring you one of the biggest Caddy updates yet. Documentation on our website will be updated in the coming days.

We've implemented a ton of improvements, fixes, and awesome new features based on your feedback. While some of them aren't particularly visible changes, they allow Caddy to scale better and be more reliable in demanding deployments. Many of the changes are quality-of-life improvements we hope you'll appreciate. Then there's improvements to ACMEz, CertMagic, and other dependencies which make Caddy better that may not show up in this list.

There was a lot of code that had been documented as deprecated in place for a long time, so this version introduces a few more breaking changes than usual; please review the notes below. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.7.6: Erweiterbare Templates und synchronisierte TLS-Bereinigung

Version 2.7.6 macht die templates-Middleware experimentell erweiterbar, synchronisiert die TLS-Storage-Bereinigung im Cluster und über Neustarts hinweg, wertet Platzhalter in Zertifikatslader-Konfigurationen aus und enthält zahlreiche Fehlerbehebungen.

In this version we've made several fixes and enhancements with help from several contributors. Most changes are small, but some notable ones:

  • The templates middleware is now officially extensible (experimentally). This means modules can add custom functions/actions for templates to execute.
  • TLS storage cleaning is now synchronized across the cluster and remembered across restarts. This should greatly lower costs for expensive storage backends like DynamoDB.
  • Placeholders are now evaluated in config for certificate loaders.
  • Numerous bug fixes.

Thank you to everyone who contributed!

Changelog

  • 65c489a0 Upgrade acmeserver to github.com/go-chi/chi/v5 (#5913)
  • ae5e2d96 caddyfile: Fix variadic placeholder false positive when token contains : (#5883)
  • db55da59 caddyhttp: Adjust scheme placeholder docs (#5910)
  • df5edf6b caddytls: Context to DecisionFunc (#5923)
  • 6d9a8337 caddytls: Sync distributed storage cleaning (#5940)
  • 11a082c0 cmd: Add newline character to version string in CLI output (#5895)
  • 979c413f cmd: upgrade: resolve symlink of the executable (#5891)
  • 64820706 core: Apply SO_REUSEPORT to UDP sockets (#5725)
  • 15adb893 core: quic listener will manage the underlying socket by itself (#5749)
  • 801ec756 fileserver: Add .m4v for browse template icon
  • b809ed71 go.mod: CVE-2023-45142 Update opentelemetry (#5908)
  • b4c7313c go.mod: Upgrade quic-go to v0.39.1
  • 36fce3fa go.mod: update quic-go version to v0.40.0 (#5922) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.7.5: HTTP/2 Rapid Reset behoben, quic-go aktualisiert

Version 2.7.5 behebt den HTTP/2-Rapid-Reset-Angriff und weitere Fehler, aktualisiert quic-go auf v0.39.0 mit aktivierten GSO und ECN, exportiert fileserver.BrowseTemplate, lässt --envfile bestehende Variablen nicht mehr überschreiben und komprimiert application/wasm* standardmäßig.

In this release, we've fixed quite a few small bugs and annoyances, including HTTP/2 Rapid Reset which affected most HTTP/2 implementations.

On a personal note (from @mholt): I recently became a dad! I want to thank our maintainers for helping in so many ways while I've been taking extra time for family. Francis, Matthew, Mohammed, and others -- including all the contributors below, and then some -- are to thank for shipping this release.

Highlights

  • Updated https://github.com/quic-go/quic-go from v0.37.5 to v0.39.0, including many performance improvements. GSO and ECN are now enabled by default, but you may turn them off by setting the QUIC_GO_DISABLE_GSO=true and QUIC_GO_DISABLE_ECN=true environment variables respectively, if they cause you problems. See the quic-go release notes for more details.
  • The file server's fileserver.BrowseTemplate is now exported, so it may be customized by programs embedding Caddy. (ed8bb13c5df7656647ca7fc1fd09237631a6767c)
  • Environment variables loaded with --envfile no longer override existing variables. (#5803)
  • The encode handler now compresses application/wasm* content types by default. (#5869) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Caddy

Caddy 2.7.4: Fehlerbehebungen für On-Demand-TLS und Reverse Proxy

Version 2.7.4 behebt Fehler aus 2.7, darunter die quic-go-Kompatibilität mit Go 1.21, Probleme mit On-Demand-TLS und Race Conditions bei dynamischen Reverse-Proxy-Upstreams.

Caddy 2.7.4 rounds out some bug fixes from the 2.7 release. For example, Go made a last-minute breaking change to a new API that broke quic-go (HTTP/3) on Go 1.21 just before Go 1.21 was released; we resolved a few issues with on-demand TLS that are now much improved from the 2.6 tree; a couple race conditions were fixed in dynamic reverse proxy upstreams. We hope you will be pleased with this new version!

Caddy is on feature freeze until after 2.8 so we can improve our testing situation. These patches have all been tried to ensure they work as intended, but if you notice any issues please report them!

We encourage all users to test this new version and then upgrade. Thanks to all who get involved!

Changelog

  • 080db938 caddytls: Update docs for on-demand config
  • d8135505 cmd: Require config for caddy validate (fix #5612) (#5614)
  • a8492c06 fileserver: Don't repeat error for invalid method inside error context (#5705)
  • 2d7d806f fileserver: Slightly more fitting icons
  • f11c3c9f go.mod: Upgrade CertMagic and quic-go
  • 5b9c850a go.mod: Upgrade golang.org/x/net to 0.14.0 (#5718)
  • 936ee918 reverseproxy: Always return new upstreams (fix #5736) (#5752)
  • 431adc09 templates: Fix httpInclude (fix #5698)

New Contributors

Originalquelle(öffnet in neuem Tab)Problem melden