Skip to content

v1.6.5

Latest

Choose a tag to compare

@flarco flarco released this 08 Oct 21:12
7641892

Sling v1.6.5 (2026-10-08T21:12:01Z)

New Features

  • External secret manager references: Connections, env blocks and expressions can use secret references (op://, ref+awssecrets://, ref+vault://, ref+sling://, and more). Supported providers include 1Password, AWS Secrets Manager and SSM, Azure Key Vault, GCP Secret Manager, Vault/OpenBao, Doppler, Infisical, Bitwarden, Akeyless, Keeper, Conjur, Delinea, Kubernetes, SOPS, HTTP JSON, file and exec. Configure them in the new secret_providers block of env.yaml. A project env.yaml can declare its own providers. Use from: to merge a full JSON/YAML secret into a connection. Sling redacts secret values in log output.
  • secret() function: New expression function that resolves a secret reference, e.g. secret("op://vault/item/field").
  • Stream hook modifiers: A stream hook stage now replaces only the same default stage. Use +pre / pre+ (also for post, pre_merge, post_merge) to prepend or append to the default hooks.
  • SSH host key verification: SSH connections and tunnels now verify the host key against ssh_host_key, ssh_known_hosts and ~/.ssh/known_hosts. Sling warns by default and rejects in strict mode (ssh_strict_host_key). New ssh_ciphers and ssh_kex_algorithms properties.
  • Single stage map for transforms: transforms accepts one stage map ({col: expr}). Invalid shapes now give an error that lists the valid shapes.
  • Wildcard no-match warning: A wildcard stream that matches no object now shows a warning task, instead of a silent success.
  • Chunk part selection by base name: Select a chunked stream by its base name to run all its chunk parts.
  • ClickHouse merge_insert performance: The NOT IN key set now includes only keys that are also in the source, so merges into large targets scan less data.
  • Redshift loads without idle transaction: Redshift temp table loads do not open a transaction during extraction, which saves Serverless RPUs.
  • Clearer error messages: ClickHouse connections to an HTTP port name the correct native port. A table-create race names the concurrent process. API specs show the error text of XML failure responses (e.g. Sage Intacct).

Bug Fixes

  • delete_missing: soft row return: Sling now clears _sling_deleted_at when a soft-deleted row comes back in the source.
  • delete_missing disable values: none, false and off now disable the option, instead of an error.
  • Transforms on MySQL byte values: Transforms now get normalized values for all rows, not only the first 900. This fixes time functions and string comparisons on MySQL DATETIME/VARCHAR columns. date_parse also accepts values that are already datetimes.
  • replace_accents race: Fixed panics and hangs when many goroutines use replace_accents. Also fixed related channel races in batches and merged dataflows.
  • ADBC DDL lock hang: With SLING_USE_ADBC, Sling commits the open transaction before the ADBC import, so an MSSQL truncate does not lock the load.
  • StarRocks reserved column names: Stream load and INSERT now quote column names such as default, key and rows.
  • DuckDB cancel race: A late cancel no longer stops the next query.
  • sling conns test on unresolved type: The test now fails when Sling cannot resolve the connection type (e.g. a missing secret reference).
  • Postgres environment variables: Sling unsets PG environment variables that lib/pq does not support, which prevented a connection panic.
  • Log setup deadlock: Fixed a deadlock when env file loading wrote logs during log file setup.