Skip to content

Releases: go-kruda/kruda

v1.8.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 10:53
5ff81f1

What's Changed

Full Changelog: v1.7.2...v1.8.0

v1.7.2

Choose a tag to compare

@github-actions github-actions released this 03 Sep 17:26
1e35d17

What's Changed

  • Guard shipped docs against validation rules that do not exist by @wtigero in #193
  • Harden transport security and require Go 1.25.13 by @wtigero in #194
  • Prepare v1.7.2 by @wtigero in #195

Full Changelog: v1.7.1...v1.7.2

v1.7.1

Choose a tag to compare

@github-actions github-actions released this 03 Aug 12:46
c312c56

What's Changed

  • feat: validate by default, and stop panicking on rules that do not exist by @wtigero in #190
  • Support omitempty and dive; rewrite ADR 0002 on the premise that holds by @wtigero in #191
  • Prepare v1.7.1 by @wtigero in #192

Full Changelog: v1.7.0...v1.7.1

v1.7.0

Choose a tag to compare

@github-actions github-actions released this 30 Jul 11:50
537960b

What's Changed

  • chore(release): contrib/ws requires core v1.6.0 by @wtigero in #163
  • docs: Wing protocol-support matrix, production TLS, and Use()-after-routes warning by @wtigero in #164
  • docs: correct App.Serve socket-activation claim for Wing by @wtigero in #165
  • docs(mcp): update AI-facing docs for streaming/WebSocket on Wing by @wtigero in #166
  • docs: migrate documentation site to custom domain kruda.dev by @wtigero in #167
  • docs: add Cloudflare Web Analytics beacon to docs site by @wtigero in #168
  • Harden correctness and protocol gates by @wtigero in #169
  • Prepare v1.6.1 release by @wtigero in #170
  • ci: simplify release notes and refresh docs by @wtigero in #171
  • fix: confine static files to configured root by @wtigero in #172
  • ci: harden release preflight and security scan by @wtigero in #173
  • docs: prepare v1.6.2 release notes by @wtigero in #174
  • fix: drain transport before container shutdown by @wtigero in #175
  • fix: validate Wing Host before dispatch by @wtigero in #176
  • test: wait for Wing HTTP readiness by @wtigero in #177
  • fix: complete Wing 100-continue requests by @wtigero in #178
  • fix: honor Wing HTTP persistence semantics by @wtigero in #179
  • docs: remove stale Wing setup guidance by @wtigero in #180
  • Fix onboarding: kruda new produced a project that could not build by @wtigero in #182
  • Make the JSON engine deterministic and keep the Wing advisor off the hot path by @wtigero in #181
  • security(observability): require grpc v1.82.1 for GO-2026-6061 by @wtigero in #184
  • Replace the JSON-engine figures with numbers the repo can reproduce by @wtigero in #183
  • Fix the JSON engine signal, and the docs that described it wrongly by @wtigero in #185
  • docs: warn that CGO_ENABLED=0 builds get different JSON bytes, and fix the stale package doc by @wtigero in #186
  • bench: measure where the JSON engine reaches req/s, and publish it by @wtigero in #187
  • fix(examples): refresh observability's go.sum after the grpc bump by @wtigero in #188
  • Prepare v1.7.0 by @wtigero in #189

Full Changelog: v1.6.0...v1.7.0

v1.6.2

Choose a tag to compare

@github-actions github-actions released this 18 Jul 19:31
a3c96a7

What's Changed

  • ci: simplify release notes and refresh docs by @wtigero in #171
  • fix: confine static files to configured root by @wtigero in #172
  • ci: harden release preflight and security scan by @wtigero in #173
  • docs: prepare v1.6.2 release notes by @wtigero in #174

Full Changelog: v1.6.1...v1.6.2

v1.6.1

Choose a tag to compare

@github-actions github-actions released this 18 Jul 10:09
cfe67eb

What's Changed

  • chore(release): contrib/ws requires core v1.6.0 by @wtigero in #163
  • docs: Wing protocol-support matrix, production TLS, and Use()-after-routes warning by @wtigero in #164
  • docs: correct App.Serve socket-activation claim for Wing by @wtigero in #165
  • docs(mcp): update AI-facing docs for streaming/WebSocket on Wing by @wtigero in #166
  • docs: migrate documentation site to custom domain kruda.dev by @wtigero in #167
  • docs: add Cloudflare Web Analytics beacon to docs site by @wtigero in #168
  • Harden correctness and protocol gates by @wtigero in #169
  • Prepare v1.6.1 release by @wtigero in #170

Full Changelog: v1.6.0...v1.6.1

v1.6.0

Choose a tag to compare

@wtigero wtigero released this 04 Jul 07:37
d6eea3d

Highlights

  • WebSocket on the Wing transport. contrib/ws now works on Wing (the default on Linux), previously net/http-only. Register with ws.HandleFunc(app, "/ws", handler) — identical on every transport. Wing hands the taken-over connection to contrib/ws via the standard http.Hijacker contract (a new generic kruda.Hijack route preset); the RFC 6455 frame code is reused unchanged and the inline hot path is untouched.
  • contrib/ws frame-parser hardening (RFC 6455 §5). Rejects undefined/reserved opcodes, fragmented control frames, oversized control frames (closing an unbounded-allocation DoS), non-minimal length encodings, and unmasked client frames.
  • Wing retains the Connection request header — c.Header("Connection") now works on Wing (required for the upgrade handshake).
  • New App.Serve(ln net.Listener) — run the app on a pre-created listener (graceful restart, socket activation, testing).

See the CHANGELOG for full details.

contrib: contrib/ws is re-tagged separately to publish Wing WebSocket support.

v1.5.0

Choose a tag to compare

@wtigero wtigero released this 28 Jun 17:16
e8a077b

Added

  • Server-Sent Events and streaming on the Wing transport. c.SSE() and c.Stream()
    now work on Wing (the default on Linux) via the new kruda.Stream route preset —
    app.Get("/events", h, kruda.Stream). Previously they returned an error unless the route
    ran on net/http. Streaming dispatches via Takeover and does not affect the inline hot
    path; a slow/stuck client is bounded by WriteTimeout, and a client disconnect cancels
    the handler context (SSEStream.Done() fires). A TestClient.SSE(path) helper decodes the
    emitted events for unit tests. The fasthttp transport (macOS dev default) does not support
    streaming — c.SSE() there now returns an actionable error pointing to kruda.NetHTTP().
  • WithHeaderLimit(n) option. Configures the maximum total request-header size
    (default 8 KB → HTTP 431). Clients sending large Authorization/Cookie headers (big
    JWTs) previously hit a spurious 431 with no escape hatch.
  • Environment configuration for the Wing safety bundle. WithEnvPrefix now also reads
    <PREFIX>_HEADER_LIMIT, <PREFIX>_TRUST_PROXY, <PREFIX>_MAX_CONNS,
    <PREFIX>_MAX_CONNS_PER_IP, <PREFIX>_ACCEPT_RATE_PER_SEC, and
    <PREFIX>_ACCEPT_RATE_BURST, so Kubernetes/ConfigMap deployments can tune the v1.4.0
    accept-side DoS limits and proxy trust without code changes.

Security

  • Raised the minimum Go to 1.25.11 (1.25 line) or 1.26.4 (1.26 line). go1.25.10
    and go1.26.0–1.26.3 carry stdlib CVEs GO-2026-5037 (crypto/x509 quadratic verify) and
    GO-2026-5039 (net/textproto error-message injection); the new floor clears both.

Breaking

  • Removed the no-op WithHTTP3 option and the Config.HTTP3 field. They advertised
    HTTP/3 (QUIC) serving, but it was never implemented — nothing consumed the flag, so a
    caller got the standard net/http fallback (HTTP/1.1 + HTTP/2), not QUIC. HTTP/3 is not on
    the roadmap, so the dead API is removed rather than left as a misleading promise
    (rationale: docs/decisions/0001-break-api-in-v1-minor.md). TLS is unaffected — use
    WithTLS(certFile, keyFile).

v1.4.0

Choose a tag to compare

@wtigero wtigero released this 27 Jun 14:05
2b6c917

Changes since v1.3.1

2b6c917 docs: fix v1.4.0 release-record gaps found in review
c51586e chore(release): date-stamp v1.4.0 changelog (2026-06-27)
fb5e324 docs: complete v1.4.0 changelog, fix doc refs, revalidate perf at HEAD
12d6a80 docs(wing): note per-IP cap must key on socket peer, not XFF
ddc48b0 feat(resource): input validation + OpenAPI 3.1 for auto-CRUD
2e67c20 fix(prometheus): defer in-flight gauge Dec so a panic can't leak it
1b282e4 fix(middleware): Logger records real latency (was always 0)
2ba7676 feat(wing): accept-side DoS limits — connection cap, per-IP, accept-rate
8b02738 test(bench): obs enabled-path A/B + HPA note; drop dead response-side traceparent inject (D3)
f124309 fix(wing): close takeover File on shutdown to prevent fd double-close
927c066 fix(wing): shared takeover body budget + pipelined-after-body byte preservation
8c77fc4 feat: typed-handler test client + OpenAPI 3.1 polish (D4)
1348c4e feat: turnkey observability (contrib/observability) + WithLogEnricher core seam
88acc18 fix(wing): XFF dedicated fields and segmentation-independent 431
3fe1fc2 Wing: enforce request-size contract (BodyLimit/HeaderLimit/TrustProxy + 413/431/501)
4e9d300 ci: enforce doc correctness for exported APIs and current guides
1eed571 bench: add realistic API profile route across kruda/fiber/actix
c57decb feat: opt-in RFC 9457 problem+json error responses

Performance

Run benchmarks: go test -bench=. -benchmem -count=5 -tags kruda_stdjson ./bench/...

What's Changed

  • feat: opt-in RFC 9457 problem+json error responses by @wtigero in #131
  • bench: add realistic API profile route across kruda/fiber/actix by @wtigero in #132
  • ci: enforce doc correctness for exported APIs and current guides by @wtigero in #133
  • Wing: enforce request-size contract (BodyLimit/HeaderLimit/TrustProxy + 413/431/501) by @wtigero in #134
  • Wing: X-Forwarded-For/X-Real-IP dedicated fields + 431 for oversized header line by @wtigero in #135
  • feat: turnkey observability (contrib/observability) + WithLogEnricher core seam by @wtigero in #136
  • feat: typed-handler test client + OpenAPI 3.1 polish (D4) by @wtigero in #137
  • Wing: shared takeover body budget + pipelined-after-body byte preservation by @wtigero in #138
  • fix(wing): close takeover File on shutdown to prevent fd double-close by @wtigero in #139
  • test(bench): observability enabled-path A/B + quantified HPA note (D3) by @wtigero in #140
  • feat(wing): accept-side DoS limits (connection cap, per-IP, accept-rate) by @wtigero in #141
  • fix(middleware): Logger records real latency (was always 0) by @wtigero in #142
  • fix(prometheus): defer in-flight gauge Dec so a panic can't leak it by @wtigero in #143
  • feat(resource): input validation + OpenAPI 3.1 for auto-CRUD by @wtigero in #144
  • docs(wing): note per-IP cap must key on socket peer, not XFF by @wtigero in #145
  • docs(changelog): complete v1.4.0 entries + fix stale counts and tag refs by @wtigero in #146
  • chore(release): date-stamp v1.4.0 changelog by @wtigero in #147
  • docs: fix v1.4.0 release-record gaps found in review by @wtigero in #148

Full Changelog: v1.3.1...v1.4.0

v1.3.1

Choose a tag to compare

@github-actions github-actions released this 13 Jun 17:25
0c2bd70

Changes since v1.3.0

0c2bd70 release: stamp v1.3.1 — takeover spin removes db/queries p99 trade; perf audits
b231dd0 bench: low-concurrency latency profiles + finding
f026f73 bench: runtime footprint measurement + finding
99686e3 test: lock Wing string-lane zero-alloc; record hot-path allocation audit
8856117 Wing: adaptive spin before netpoller park on takeover keep-alive read
9a0c9f8 docs: DB-route ceiling evidence + Preset godoc example

Performance

Run benchmarks: go test -bench=. -benchmem -count=5 -tags kruda_stdjson ./bench/...

What's Changed

  • docs: DB-route ceiling evidence + Preset godoc example by @wtigero in #125
  • Wing: adaptive spin before netpoller park on takeover keep-alive read by @wtigero in #126
  • test: lock Wing string-lane zero-alloc; record hot-path allocation audit by @wtigero in #127
  • bench: runtime footprint measurement + finding by @wtigero in #128
  • bench: low-concurrency latency profiles + finding by @wtigero in #129
  • release: stamp v1.3.1 — takeover spin removes db/queries p99 trade by @wtigero in #130

Full Changelog: v1.3.0...v1.3.1