Releases: JingYiJun/MoltSSH
Release list
v0.4.1
MoltSSH v0.4.1
MoltSSH v0.4.1 makes tagged release notes easier to scan and keep current without changing the CLI, transport, wire protocol, configuration, or binary behavior.
Highlights
- Tagged releases now prepend an optional curated summary to GitHub-generated pull request categories, contributor credits, and the full changelog link.
- Rerunning the release workflow regenerates the automated section before updating the existing release.
- Maintainer documentation now explains the release labels and the boundary between curated and generated content.
Compatibility and Security
- This release has no runtime, CLI, wire protocol, or TOML configuration changes.
- MoltSSH servers still provide no application-layer authentication and must remain behind a protected private access layer or authenticated reverse proxy.
Verification
- The workflow passed
actionlintand YAML language-server diagnostics. - GitHub's release-notes API was exercised against the real repository configuration, including label-based category generation.
- The full Go unit, race, and Docker/OpenSSH multipath smoke suites remained green.
What's Changed
Features
- ci: generate hybrid release notes by @JingYiJun in #3
Full Changelog: v0.4.0...v0.4.1
v0.4.0
MoltSSH v0.4.0
MoltSSH v0.4.0 makes the project easier to install, inspect, operate, and
contribute to while preserving the existing moltssh.v1 wire protocol and
TOML configuration model.
Highlights
- Discover every command through root and command-specific help, including
moltssh help COMMAND. - Inspect release provenance with
moltssh versionormoltssh --version,
including the release version, full source commit, and Go toolchain. - Install the latest tagged release with
go install github.com/jingyijun/moltssh/cmd/moltssh@latest. - Diagnose configuration, probe, proxy, and server failures with clearer
context and actionable next steps. - Receive an explicit warning when the unauthenticated raw server listener is
exposed beyond loopback. - Understand the data path and failover model through the architecture diagram
in the English and Chinese READMEs. - Use the new contributing, code-of-conduct, security, changelog, and release
documentation when evaluating or extending the project.
Reliability and Release Engineering
- Failed path probes now return a non-zero command status while retaining
structured, redacted path diagnostics. - Release binaries embed the release version and full source commit.
- Tagged releases use checked-in release notes and publish SHA-256 checksums.
- CI uses the Node 24-based
actions/checkout@v7andactions/setup-go@v7
while retaininggo.sum-based cache invalidation.
Compatibility Notes
- The
moltssh.v1wire protocol and TOML schemas are unchanged. - Existing
proxy,server, andprobeconfiguration remains TOML-only. - Automation invoking
moltssh probeshould expect a non-zero exit status when
any configured path fails; the structured probe records remain available for
troubleshooting.
Verification
The release passed:
- Go pure-source line-count enforcement.
- Unit tests and Go race tests.
- Docker/OpenSSH multipath smoke testing with live failover from a fast path to
a slower relay path without restarting the remote command. - GitHub Actions workflow linting and YAML language-server diagnostics.
- Release-binary checksum,
moltssh version, andmoltssh --helpvalidation.
Security and Known Limitations
- The server has no application-layer authentication and must remain behind a
protected private access layer or authenticated reverse proxy. - Sessions are held in memory and do not survive a MoltSSH server restart.
- WebSocket is the only implemented transport; QUIC remains future work.
- Release binaries are provided for Linux amd64/arm64, macOS amd64/arm64, and
Windows amd64.
Review the
v0.3.1...v0.4.0 source changes
and read the
MVP transport and security model
before deployment.
build-79f601c30235
build-49707125477a
build-1dbeb0daa63b
build-4d15dfd3655d
v0.3.1
MoltSSH v0.3.1
MoltSSH v0.3.1 fixes cold-start latency by activating the first healthy path as
soon as it becomes available. The client no longer waits for every configured
path probe before starting the SSH byte stream.
Highlights
- Start on the first available healthy WebSocket path.
- Continue probing remaining paths in the background.
- Preserve the existing
moltssh.v1protocol and TOML schema. - Keep reusable probe promotion, session resume, heartbeat, and last-known-good
startup behavior from v0.3.0.
Verification
The release passed:
- Unit tests.
- Go race tests.
- Docker/OpenSSH multipath smoke testing with live failover from a fast path to
a slower relay path without restarting the remote command.
Known Limitations
- The server has no application-layer authentication and must remain behind a
protected private access layer or authenticated reverse proxy. - Sessions are held in memory and do not survive a MoltSSH server restart.
- WebSocket is the only implemented transport; QUIC remains future work.
- Release binaries are provided for Linux amd64/arm64, macOS amd64/arm64, and
Windows amd64.
Review the
v0.3.0...v0.3.1 source changes
and read the
MVP transport and security model
before deployment.
v0.3.0
MoltSSH v0.3.0 improves multipath connection latency, failover behavior, and dial observability.
Highlights:
- Probe enabled paths concurrently with bounded fan-out and deterministic ranking.
- Direct-dial an advisory persisted last-known-good path while probing alternatives in the background.
- Promote a successful probe WebSocket into the formal MoltSSH session without redialing.
- Monitor the active path with in-session ping/pong heartbeats instead of rebuilding DNS/TCP/TLS/WebSocket connections.
- Reconnect with immediate first attempt, capped exponential backoff, full jitter, and the existing resume deadline.
- Report DNS, TCP, TLS, WebSocket upgrade, MoltSSH hello, probe RTT, total latency, and failed phase with secret-aware log redaction.
- Split tunnel runtime responsibilities into focused Go files and enforce the project pure-LOC limit in CI.
Compatibility:
- No moltssh.v1 wire-protocol change.
- No TOML schema or configuration-field change.
- The last-known-good cache stores only a version and accepted path name; cache failures remain non-fatal.
Validation:
- Go unit and race tests.
- Docker end-to-end SSH multipath failover smoke test.
- Warm-start last-known-good direct-dial verification.
- Linux amd64/arm64, macOS amd64/arm64, and Windows amd64 release builds with SHA256SUMS.