Skip to content

Hecate v1.0.2

Latest

Choose a tag to compare

@github-actions github-actions released this 13 Nov 11:02

Hecate v1.0.2

Released: 2025-11-13

Highlights

  • Security hardening: Added overflow-safe math helpers and enforced TLS 1.2+ for both VIP listeners and HTTPS health probes. WAF counters, cache stats, and stickiness windows now clamp untrusted values before converting to signed integers.
  • Static analysis clean pass: Addressed every blocking gosec finding (G115/G402/G101) by sanitizing conversions, annotating intentional literals, and removing InsecureSkipVerify. Trivy already passed; gosec now reports zero high-severity issues.
  • Release automation: The release workflow now creates a GitHub Release (with notes pulled from docs/releases/<version>.md) after pushing multi-arch images to ghcr.io/arencloud/hecate-*.

Changelog

  • Enforce safe numeric conversions and tighten TLS defaults across balancer, WAF, metrics, cache, and health runner code paths.
  • Annotate intentional literals to silence false-positive credential findings in tests/dev defaults.
  • Extend .github/workflows/release.yml with an automatic GitHub Release publication step.

Verification

  • go test ./...
  • HECATE_ADMIN_SEED_PASSWORD=change-me HECATE_E2E_SKIP_BROWSER_INSTALL=1 go test -tags e2e ./tests/e2e/harness
  • gosec ./... (zero high-severity results)