Releases: go-kruda/kruda
Release list
v1.8.0
v1.7.2
v1.7.1
v1.7.0
What's Changed
- chore(release): contrib/ws requires core v1.6.0 by @wtigero in #163
- docs: Wing protocol-support matrix, production TLS, and Use()-after-routes warning by @wtigero in #164
- docs: correct App.Serve socket-activation claim for Wing by @wtigero in #165
- docs(mcp): update AI-facing docs for streaming/WebSocket on Wing by @wtigero in #166
- docs: migrate documentation site to custom domain kruda.dev by @wtigero in #167
- docs: add Cloudflare Web Analytics beacon to docs site by @wtigero in #168
- Harden correctness and protocol gates by @wtigero in #169
- Prepare v1.6.1 release by @wtigero in #170
- ci: simplify release notes and refresh docs by @wtigero in #171
- fix: confine static files to configured root by @wtigero in #172
- ci: harden release preflight and security scan by @wtigero in #173
- docs: prepare v1.6.2 release notes by @wtigero in #174
- fix: drain transport before container shutdown by @wtigero in #175
- fix: validate Wing Host before dispatch by @wtigero in #176
- test: wait for Wing HTTP readiness by @wtigero in #177
- fix: complete Wing 100-continue requests by @wtigero in #178
- fix: honor Wing HTTP persistence semantics by @wtigero in #179
- docs: remove stale Wing setup guidance by @wtigero in #180
- Fix onboarding: kruda new produced a project that could not build by @wtigero in #182
- Make the JSON engine deterministic and keep the Wing advisor off the hot path by @wtigero in #181
- security(observability): require grpc v1.82.1 for GO-2026-6061 by @wtigero in #184
- Replace the JSON-engine figures with numbers the repo can reproduce by @wtigero in #183
- Fix the JSON engine signal, and the docs that described it wrongly by @wtigero in #185
- docs: warn that CGO_ENABLED=0 builds get different JSON bytes, and fix the stale package doc by @wtigero in #186
- bench: measure where the JSON engine reaches req/s, and publish it by @wtigero in #187
- fix(examples): refresh observability's go.sum after the grpc bump by @wtigero in #188
- Prepare v1.7.0 by @wtigero in #189
Full Changelog: v1.6.0...v1.7.0
v1.6.2
v1.6.1
What's Changed
- chore(release): contrib/ws requires core v1.6.0 by @wtigero in #163
- docs: Wing protocol-support matrix, production TLS, and Use()-after-routes warning by @wtigero in #164
- docs: correct App.Serve socket-activation claim for Wing by @wtigero in #165
- docs(mcp): update AI-facing docs for streaming/WebSocket on Wing by @wtigero in #166
- docs: migrate documentation site to custom domain kruda.dev by @wtigero in #167
- docs: add Cloudflare Web Analytics beacon to docs site by @wtigero in #168
- Harden correctness and protocol gates by @wtigero in #169
- Prepare v1.6.1 release by @wtigero in #170
Full Changelog: v1.6.0...v1.6.1
v1.6.0
Highlights
- WebSocket on the Wing transport.
contrib/wsnow works on Wing (the default on Linux), previously net/http-only. Register withws.HandleFunc(app, "/ws", handler)— identical on every transport. Wing hands the taken-over connection tocontrib/wsvia the standardhttp.Hijackercontract (a new generickruda.Hijackroute preset); the RFC 6455 frame code is reused unchanged and the inline hot path is untouched. contrib/wsframe-parser hardening (RFC 6455 §5). Rejects undefined/reserved opcodes, fragmented control frames, oversized control frames (closing an unbounded-allocation DoS), non-minimal length encodings, and unmasked client frames.- Wing retains the
Connectionrequest header —c.Header("Connection")now works on Wing (required for the upgrade handshake). - New
App.Serve(ln net.Listener)— run the app on a pre-created listener (graceful restart, socket activation, testing).
See the CHANGELOG for full details.
contrib: contrib/ws is re-tagged separately to publish Wing WebSocket support.
v1.5.0
Added
- Server-Sent Events and streaming on the Wing transport.
c.SSE()andc.Stream()
now work on Wing (the default on Linux) via the newkruda.Streamroute preset —
app.Get("/events", h, kruda.Stream). Previously they returned an error unless the route
ran on net/http. Streaming dispatches via Takeover and does not affect the inline hot
path; a slow/stuck client is bounded byWriteTimeout, and a client disconnect cancels
the handler context (SSEStream.Done()fires). ATestClient.SSE(path)helper decodes the
emitted events for unit tests. The fasthttp transport (macOS dev default) does not support
streaming —c.SSE()there now returns an actionable error pointing tokruda.NetHTTP(). WithHeaderLimit(n)option. Configures the maximum total request-header size
(default 8 KB → HTTP 431). Clients sending largeAuthorization/Cookieheaders (big
JWTs) previously hit a spurious 431 with no escape hatch.- Environment configuration for the Wing safety bundle.
WithEnvPrefixnow also reads
<PREFIX>_HEADER_LIMIT,<PREFIX>_TRUST_PROXY,<PREFIX>_MAX_CONNS,
<PREFIX>_MAX_CONNS_PER_IP,<PREFIX>_ACCEPT_RATE_PER_SEC, and
<PREFIX>_ACCEPT_RATE_BURST, so Kubernetes/ConfigMap deployments can tune the v1.4.0
accept-side DoS limits and proxy trust without code changes.
Security
- Raised the minimum Go to 1.25.11 (1.25 line) or 1.26.4 (1.26 line). go1.25.10
and go1.26.0–1.26.3 carry stdlib CVEs GO-2026-5037 (crypto/x509 quadratic verify) and
GO-2026-5039 (net/textproto error-message injection); the new floor clears both.
Breaking
- Removed the no-op
WithHTTP3option and theConfig.HTTP3field. They advertised
HTTP/3 (QUIC) serving, but it was never implemented — nothing consumed the flag, so a
caller got the standard net/http fallback (HTTP/1.1 + HTTP/2), not QUIC. HTTP/3 is not on
the roadmap, so the dead API is removed rather than left as a misleading promise
(rationale:docs/decisions/0001-break-api-in-v1-minor.md). TLS is unaffected — use
WithTLS(certFile, keyFile).
v1.4.0
Changes since v1.3.1
2b6c917 docs: fix v1.4.0 release-record gaps found in review
c51586e chore(release): date-stamp v1.4.0 changelog (2026-06-27)
fb5e324 docs: complete v1.4.0 changelog, fix doc refs, revalidate perf at HEAD
12d6a80 docs(wing): note per-IP cap must key on socket peer, not XFF
ddc48b0 feat(resource): input validation + OpenAPI 3.1 for auto-CRUD
2e67c20 fix(prometheus): defer in-flight gauge Dec so a panic can't leak it
1b282e4 fix(middleware): Logger records real latency (was always 0)
2ba7676 feat(wing): accept-side DoS limits — connection cap, per-IP, accept-rate
8b02738 test(bench): obs enabled-path A/B + HPA note; drop dead response-side traceparent inject (D3)
f124309 fix(wing): close takeover File on shutdown to prevent fd double-close
927c066 fix(wing): shared takeover body budget + pipelined-after-body byte preservation
8c77fc4 feat: typed-handler test client + OpenAPI 3.1 polish (D4)
1348c4e feat: turnkey observability (contrib/observability) + WithLogEnricher core seam
88acc18 fix(wing): XFF dedicated fields and segmentation-independent 431
3fe1fc2 Wing: enforce request-size contract (BodyLimit/HeaderLimit/TrustProxy + 413/431/501)
4e9d300 ci: enforce doc correctness for exported APIs and current guides
1eed571 bench: add realistic API profile route across kruda/fiber/actix
c57decb feat: opt-in RFC 9457 problem+json error responses
Performance
Run benchmarks: go test -bench=. -benchmem -count=5 -tags kruda_stdjson ./bench/...
What's Changed
- feat: opt-in RFC 9457 problem+json error responses by @wtigero in #131
- bench: add realistic API profile route across kruda/fiber/actix by @wtigero in #132
- ci: enforce doc correctness for exported APIs and current guides by @wtigero in #133
- Wing: enforce request-size contract (BodyLimit/HeaderLimit/TrustProxy + 413/431/501) by @wtigero in #134
- Wing: X-Forwarded-For/X-Real-IP dedicated fields + 431 for oversized header line by @wtigero in #135
- feat: turnkey observability (contrib/observability) + WithLogEnricher core seam by @wtigero in #136
- feat: typed-handler test client + OpenAPI 3.1 polish (D4) by @wtigero in #137
- Wing: shared takeover body budget + pipelined-after-body byte preservation by @wtigero in #138
- fix(wing): close takeover File on shutdown to prevent fd double-close by @wtigero in #139
- test(bench): observability enabled-path A/B + quantified HPA note (D3) by @wtigero in #140
- feat(wing): accept-side DoS limits (connection cap, per-IP, accept-rate) by @wtigero in #141
- fix(middleware): Logger records real latency (was always 0) by @wtigero in #142
- fix(prometheus): defer in-flight gauge Dec so a panic can't leak it by @wtigero in #143
- feat(resource): input validation + OpenAPI 3.1 for auto-CRUD by @wtigero in #144
- docs(wing): note per-IP cap must key on socket peer, not XFF by @wtigero in #145
- docs(changelog): complete v1.4.0 entries + fix stale counts and tag refs by @wtigero in #146
- chore(release): date-stamp v1.4.0 changelog by @wtigero in #147
- docs: fix v1.4.0 release-record gaps found in review by @wtigero in #148
Full Changelog: v1.3.1...v1.4.0
v1.3.1
Changes since v1.3.0
0c2bd70 release: stamp v1.3.1 — takeover spin removes db/queries p99 trade; perf audits
b231dd0 bench: low-concurrency latency profiles + finding
f026f73 bench: runtime footprint measurement + finding
99686e3 test: lock Wing string-lane zero-alloc; record hot-path allocation audit
8856117 Wing: adaptive spin before netpoller park on takeover keep-alive read
9a0c9f8 docs: DB-route ceiling evidence + Preset godoc example
Performance
Run benchmarks: go test -bench=. -benchmem -count=5 -tags kruda_stdjson ./bench/...
What's Changed
- docs: DB-route ceiling evidence + Preset godoc example by @wtigero in #125
- Wing: adaptive spin before netpoller park on takeover keep-alive read by @wtigero in #126
- test: lock Wing string-lane zero-alloc; record hot-path allocation audit by @wtigero in #127
- bench: runtime footprint measurement + finding by @wtigero in #128
- bench: low-concurrency latency profiles + finding by @wtigero in #129
- release: stamp v1.3.1 — takeover spin removes db/queries p99 trade by @wtigero in #130
Full Changelog: v1.3.0...v1.3.1