Repository navigation
Releases: Guard-Core/guard-agent-go
Releases · Guard-Core/guard-agent-go
Release list
v3.2.2
v3.2.2 (2026-10-09)
The family lockstep artifact: the sanitizer export surface, lockstep with guard-agent 3.2.2 (v3.2.2)
About this release
- Lockstep with guard-agent 3.2.2 on PyPI. The Go agent ships the wave's runtime content (the sanitizer export surface) under the same version number the Python reference carries;
version.gomoves to 3.2.2, theagent_versionthe agent reports to the ingestion API.
Added
- The sanitizer export surface (#25, the FEATURE_MATRIX_GO GAP 19 closure): the reference sanitizer family (
guard_agent/utils.py) beyondSanitizeHeaders/TruncatePayload/HashIPexports onto the Go module:GenerateBatchID(the{unix_millis}-{8 hex chars}referencegenerate_batch_idshape, the internalnewBatchIDseam exported),SummarizeResponseBody(the whitespace-collapsing bounded single-line response-body summary with the original-length truncation note),SafeJSONSerialize/SafeJSONDeserialize/SerializationError(the compact-JSON transport serialization with the typed failure, and the object-only tolerant deserialization where a non-object payload or a parse failure returns nil), andValidateConfig(the advisory config audit returning the normalize problems as a list of strings without mutating or applying defaults; construction-time normalize stays the fail-closed surface). The unrepresentable non-ConfigError fallback arm inValidateConfigis dropped so the strict coverage gate stays at 100%. - The
get_statsdict view (#26):Agent.AgentStatsrenders the referenceget_statsdict shape (_client_status.py get_statswith the buffer and transport-lifecycle nested blocks), satisfying guardcore'sAgentStatsProviderseam so the middlewareagent_statsproperty merges it. Keys the Go agent tracks carry the same values as the typedStatssnapshot; the reference's per-loop consecutive-failure counters andlast_status_push_okhave no tracked counterpart and are omitted.
Changed
- Dependencies:
github.com/redis/go-redis/v9to v9.23.0 (#27), the engine-family bump train (guard-core-go #67), carrying the x/sys v0.48.0 line that clears the stdlib-adjacent exposure; govulncheck stays clean.
v3.2.1
v3.2.1 (2026-10-07)
The family lockstep artifact: the 3.2.1 wave tag (v3.2.1)
About this release
- An empty lockstep release for the Guard agent family 3.2.1 wave. No shipped change: no
guardagentcode, dependency, or behavior delta since 3.2.0. The tag exists so the family stays version-aligned while the TypeScript port ships the wave's only runtime fix (the js/polynomial-redos endpoint normalization hardening, guard-agent-ts 3.2.1).
Changed
- Version only.
version.gomoves to 3.2.1 (theagent_versionthe agent reports to the ingestion API). The engine floor stays atgithub.com/rennf93/guard-core-go/v4 v4.3.0.
Compatibility
- Drop-in. Consumers on 3.2.0 can move to 3.2.1 with no code or config changes; the module path and the engine floor are unchanged.
v3.2.0
v3.2.0 (2026-10-01)
The 4.3.0-train artifact: coverage-gate hardening and the engine 4.3.0 floor (v3.2.0)
Added
- The 100% line coverage gate is enforced fail-closed (guard-agent-go #19, #20, #21). The gate now aborts on a missing or empty coverage profile instead of passing silently, the wake-flush coverage branches are deterministic rather than timing-dependent, and the agent surface is covered to the full line floor with real inputs.
- The process scaffold (guard-agent-go #20): the family CI conventions - issue-link, labeler, scheduled lint, dependabot grouping - and the community health files.
Changed
- The engine floor moves to
github.com/rennf93/guard-core-go/v4 v4.3.0(the 4.3.0 train): the agent consumes the engine release that carries the corpus runners, the event-surface closures and the manager-level geo verdicts.
v3.1.0
v3.1.0 (2026-09-27)
Parity release: the 3.0.2 to 3.1.0 agent feature set (v3.1.0)
Added
- AES-256-GCM encrypted ingest. Batches can now be encrypted end to end before they leave the host, matching the Python agent's encrypted ingest contract.
- Recursive sensitive-header redaction. Authorization, cookie, and set-cookie style headers (and their nested occurrences) are redacted before a payload is built.
- Dynamic rules. The agent can pull rule updates from the ingestion API and apply them to the local runtime without a restart.
- Local rate limiters. Token-bucket style local limiting protects the host from event floods before anything is buffered or shipped.
on_errorandmax_payloadconfiguration knobs. Operators choose the failure behavior (log and continue versus surface the error) and cap the serialized payload size.
Changed
version.gois bumped to 3.1.0 so the reportedagent_versionand the User-Agent match the release tag;make bump-versionupdatesversion.goand this changelog.- Parity tests (
parity_test.go) pin the new 3.1.0 surface against the reference Python agent behavior.
v3.0.2
First tagged release: parity with guard-agent 3.0.2 and the /v3 module path (v3.0.2)
Breaking Changes
- Import paths now end in
/v3. The module path isgithub.com/rennf93/guard-agent-go/v3and the release tag isv3.0.2; Go modules reject av3+tag unless the module path carries the/v3suffix, so the migration is mandatory for this release to be fetchable. Update every import fromgithub.com/rennf93/guard-agent-gotogithub.com/rennf93/guard-agent-go/v3(package name staysguardagent). Installation is nowgo get github.com/rennf93/guard-agent-go/v3@v3.0.2.
Added
- First tagged release of the Go agent, at parity with the reference guard-agent 3.0.2 (Python). The port covers the full agent surface: event and metric buffering with at-least-once delivery, the overflow policies, Redis persistence, circuit breaking, and the batch transport.
- The payload-signature contract matches the server.
X-Payload-Signatureis an HMAC over the uncompressed body: the agent signs the body before any compression is applied, and the server verifies the signature after decompression. Compressed batches therefore verify correctly on both the encrypted and unencrypted POST paths. - An mkdocs documentation site under
docs/, covering configuration, the buffering and overflow model, the transport and signing contract, and Redis persistence. - A
basic_usagewiring example (examples/basic_usage) that wires the agent into a guard-core-go engine through the engine'sOnBlocktelemetry seam.
Changed
version.gois bumped to 3.0.2 so the reportedagent_versionand the User-Agent match the release tag, andmake bump-version(via.github/scripts/bump_version.py) now updates bothversion.goand this changelog.- Makefile harmonized with the guard family.
install,test(unit plus-tags integrationwithREDIS_HOSTin docker),lint(gofmtcheck plusgo vet),bump-versionandcleanmatch the conventions used across the Python guard repos.