You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Sling v1.6.5 (2026-10-08T21:12:01Z)
New Features
External secret manager references: Connections, env blocks and expressions can use secret references (op://, ref+awssecrets://, ref+vault://, ref+sling://, and more). Supported providers include 1Password, AWS Secrets Manager and SSM, Azure Key Vault, GCP Secret Manager, Vault/OpenBao, Doppler, Infisical, Bitwarden, Akeyless, Keeper, Conjur, Delinea, Kubernetes, SOPS, HTTP JSON, file and exec. Configure them in the new secret_providers block of env.yaml. A project env.yaml can declare its own providers. Use from: to merge a full JSON/YAML secret into a connection. Sling redacts secret values in log output.
secret() function: New expression function that resolves a secret reference, e.g. secret("op://vault/item/field").
Stream hook modifiers: A stream hook stage now replaces only the same default stage. Use +pre / pre+ (also for post, pre_merge, post_merge) to prepend or append to the default hooks.
SSH host key verification: SSH connections and tunnels now verify the host key against ssh_host_key, ssh_known_hosts and ~/.ssh/known_hosts. Sling warns by default and rejects in strict mode (ssh_strict_host_key). New ssh_ciphers and ssh_kex_algorithms properties.
Single stage map for transforms: transforms accepts one stage map ({col: expr}). Invalid shapes now give an error that lists the valid shapes.
Wildcard no-match warning: A wildcard stream that matches no object now shows a warning task, instead of a silent success.
Chunk part selection by base name: Select a chunked stream by its base name to run all its chunk parts.
ClickHouse merge_insert performance: The NOT IN key set now includes only keys that are also in the source, so merges into large targets scan less data.
Redshift loads without idle transaction: Redshift temp table loads do not open a transaction during extraction, which saves Serverless RPUs.
Clearer error messages: ClickHouse connections to an HTTP port name the correct native port. A table-create race names the concurrent process. API specs show the error text of XML failure responses (e.g. Sage Intacct).
Bug Fixes
delete_missing: soft row return: Sling now clears _sling_deleted_at when a soft-deleted row comes back in the source.
delete_missing disable values: none, false and off now disable the option, instead of an error.
Transforms on MySQL byte values: Transforms now get normalized values for all rows, not only the first 900. This fixes time functions and string comparisons on MySQL DATETIME/VARCHAR columns. date_parse also accepts values that are already datetimes.
replace_accents race: Fixed panics and hangs when many goroutines use replace_accents. Also fixed related channel races in batches and merged dataflows.
ADBC DDL lock hang: With SLING_USE_ADBC, Sling commits the open transaction before the ADBC import, so an MSSQL truncate does not lock the load.
StarRocks reserved column names: Stream load and INSERT now quote column names such as default, key and rows.
DuckDB cancel race: A late cancel no longer stops the next query.
sling conns test on unresolved type: The test now fails when Sling cannot resolve the connection type (e.g. a missing secret reference).
Postgres environment variables: Sling unsets PG environment variables that lib/pq does not support, which prevented a connection panic.
Log setup deadlock: Fixed a deadlock when env file loading wrote logs during log file setup.