Repository navigation
Hecate v1.0.2
Released: 2025-11-13
Highlights
- Security hardening: Added overflow-safe math helpers and enforced TLS 1.2+ for both VIP listeners and HTTPS health probes. WAF counters, cache stats, and stickiness windows now clamp untrusted values before converting to signed integers.
- Static analysis clean pass: Addressed every blocking gosec finding (G115/G402/G101) by sanitizing conversions, annotating intentional literals, and removing
InsecureSkipVerify. Trivy already passed; gosec now reports zero high-severity issues. - Release automation: The release workflow now creates a GitHub Release (with notes pulled from
docs/releases/<version>.md) after pushing multi-arch images toghcr.io/arencloud/hecate-*.
Changelog
- Enforce safe numeric conversions and tighten TLS defaults across balancer, WAF, metrics, cache, and health runner code paths.
- Annotate intentional literals to silence false-positive credential findings in tests/dev defaults.
- Extend
.github/workflows/release.ymlwith an automatic GitHub Release publication step.
Verification
go test ./...HECATE_ADMIN_SEED_PASSWORD=change-me HECATE_E2E_SKIP_BROWSER_INSTALL=1 go test -tags e2e ./tests/e2e/harnessgosec ./...(zero high-severity results)