Skip to content

v1.1.176

Choose a tag to compare

@socket-release-bot socket-release-bot released this 08 Apr 08:12
· 7 commits to main since this release
Immutable release. Only release title and notes can be modified.

v1.1.176 Release Notes

New Features:

  • External Registry Cooldown Protection: Block recently-published packages from unsupported registries via publish-date checks
  • Full Decision Logging for Unsupported Registry Routes: Unified SOCKET_DECISION logs, Splunk HEC, and webhook events for cooldown-checked routes
  • Client IP Detection: Correctly identify real client IPs behind load balancers, CDNs, or reverse proxies (X-Forwarded-For, X-Real-IP, CF-Connecting-IP)

New Options:

  • Auto-Discovery: supported_ecosystems_only (default: true) — only generate API-checked routes for Socket-supported ecosystems
  • Configurable Logging for Unmatched Routes: socket.log_no_route (default: true)
  • Connection Pooling Tuning: nginx.keepalive_pool_size (default: 64)

Fixes:

  • Consistent Event Action Values: Normalized to canonical enum values (error, warn, monitor, ignore) across all outputs
  • Metadata Filtering Events: Decisions now correctly sent to Socket dashboard, Splunk, and webhooks
  • Artifactory Cargo Route Fix: Support /v1/crates/ paths (Artifactory) in addition to /api/v1/crates/ (crates.io)
  • Improved Container Shutdown: Background daemons properly terminated, no orphaned processes

Improvements:

  • Binary Download Performance: Chunked streaming with increased concurrency, fixes Cargo and Conda download issues
  • Local Cache Stale-While-Revalidate: In-memory cache now mirrors Redis stale-while-revalidate behavior
  • Cooldown Caching Without Redis: Local in-memory fallback makes cooldown viable in single-instance deployments