Skip to content

0.21.0 - TLS-Inspection / Corporate Proxy Support (All SDKs), Entity List APIs (.NET/PHP/Elixir/C++), Sticky-Value Enforce Options (Node/Python/Go/.NET/PHP), Faster Java User Construction

Choose a tag to compare

@statsig-kong statsig-kong released this 12 Aug 22:00
· 65 commits to main since this release
15ff8f8

Breaking Changes

  • N/A

New Features

  • .NET, PHP, Elixir, C++:
      - Entity-list getters — getFeatureGateList(), getDynamicConfigList(), getExperimentList(), and getLayerList() (idiomatic casing per binding), mirroring the existing getAutotuneList(). Returns the names of all entities in the current config snapshot without running an evaluation or logging an exposure.
  • C FFI:
      - statsig_get_layer_list — layer was the only core list method without a C export, an asymmetry left by the original parity work (which scoped to the gate/config/experiment/autotune set). Wraps the already-present Statsig::get_layer_list().
  • Node.js, Python, Go, .NET, PHP:
      - enforceOverrides / enforceTargeting on the experiment and layer evaluation options (naming per binding: enforce_overrides / enforce_targeting). When a user has a persisted sticky value, a matching console override rule (enforceOverrides) or a failed targeting re-check (enforceTargeting) now takes precedence over the persisted value. Both default to false, so existing behavior is unchanged. Extends the Rust/Java support shipped in 0.20.1 to five more bindings. PHP required no source plumbing — its options already ride through to core as a JSON blob — so support there is now tested and documented rather than newly added.
      - Note: these options are only honored when a persistent storage adapter is configured (pre-existing core behavior).
  • .NET, C++:
      - ObservabilityClient registration on StatsigOptions / StatsigOptionsBuilder, reaching parity with the Go and Node bindings. Implement init, increment, gauge, dist, error, and should_enable_high_cardinality_for_this_tag to route SDK metrics into your own telemetry pipeline. The Rust core and C FFI already supported this; these are the managed/C++ wrappers.

Improvements & Fixes

  • All SDKs (rust core): the SDK now works behind TLS-inspecting corporate proxies (Zscaler, Netskope, Palo Alto), where initialization previously failed outright — every gate evaluated false and the only surfaced error was an opaque error sending request ... status(None). Four fixes, no API surface changes:
      - OS trust roots honored — the HTTP client now trusts the OS trust store and SSL_CERT_FILE / SSL_CERT_DIR alongside the bundled webpki roots, so a corporate root CA installed in the container or OS works with zero SDK configuration.
      - Multi-cert CA bundles — proxy_config.ca_cert_path previously failed the entire client build if any certificate in a standard system bundle was webpki-rejected, then silently fell back to a default client with neither the custom CA nor the proxy. A lenient parser now loads every usable certificate and skips bad entries with a counted warning, and the silent fallback is gone.
      - Actionable TLS errors — request errors now surface the underlying cause (e.g. invalid peer certificate: UnknownIssuer) plus a remediation hint naming the OS trust store, SSL_CERT_FILE, and ca_cert_path.
      - Config no longer bypassed — /v1/sdk_exception (always) and /v1/log_event (with connection reuse enabled) used a bare HTTP client that ignored proxy and CA configuration entirely. Clients are now cached per configuration; the log_event_connection_reuse=false contract is preserved via a cached no-keep-alive client.
      - Behavior notes: a ca_cert_path yielding zero usable certificates now fails requests loudly instead of proceeding without it; network error strings are richer (anything string-matching on the old text will notice); spec-sync, ID-list, and sdk_exception requests now reuse pooled connections. REQUESTS_CA_BUNDLE remains unread — it is a Python-requests convention; use SSL_CERT_FILE.
  • Java: StatsigUser construction is significantly cheaper.

Included In This Release

  • f0916ff statsig-kong[bot]
    • chore: bump version to 0.20.3-rc.2608051827
  • eb596d5 Xin Li (Bot)
    • [automated] sync rc with main
  • b83e8fd statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2608050456 (#3103)
  • 642be57 Jacob O'Quinn
    • [S2SDK-90] cpp: expose entity list functions (incl. layer) (#3098)
  • f830e5b Jacob O'Quinn
    • [S2SDK-89] PHP: expose entity list functions (#3093)
  • 26352f1 Jacob O'Quinn
    • [S2SDK-91] Elixir: expose entity list functions (incl. layer) (#3096)
  • b6cc81e Jacob O'Quinn
    • [S2SDK-88] .NET: expose entity list functions (incl. layer) (#3095)
  • d6fc054 statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2608010300 (#3102)
  • b49c3bd Jacob O'Quinn
    • FFI: expose statsig_get_layer_list (#3094)
  • 82e898c Kenneth Yeh
    • [S2SDK-139] rust: support TLS-inspection environments (native roots, CA bundles, clear errors) (#3034)
  • e1a5020 statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2607310301 (#3101)
  • b8201db Peter Zhu
    • [S2SDK-110] cpp: expose ObservabilityClient on StatsigOptionsBuilder (#3050)
  • 0a1c4a0 Kenneth Yeh
    • ci(java): publish to Maven Central via the Portal API (OSSRH bridge retired) (#3089)
  • 8bb83f5 statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2607300300 (#3097)
  • db2060d Peter Zhu
    • [S2SDK-109] dotnet: expose ObservabilityClient on StatsigOptions (#3049)
  • 75753a0 statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2607290300 (#3092)
  • 1ed80f2 Kenneth Yeh
    • ci(java): one-off recovery workflow to publish stranded 0.20.2 to Central (#3090)
  • fa631ad statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2607250300 (#3091)
  • 0942e06 Peter Zhu
    • [S2SDK-121] php: test + document persistent-assignment enforce_overrides/enforce_targeting (#3047)
  • da4c925 Peter Zhu
    • [S2SDK-117] python: expose enforce_overrides + enforce_targeting persistent-assignment options (#3043)
  • 771bc8c Peter Zhu
    • [S2SDK-119] dotnet: expose EnforceOverrides + EnforceTargeting persistent-assignment options (#3045)
  • fd183ec statsig-kong[bot]
    • [automated] chore: bump version to 0.20.3-beta.2607240300 (#3088)
  • 175a1fe statsig-kong[bot]
    • [automated] chore: bump version to 0.20.2-rc.1 (#3087)
  • 0cd6105 statsig-kong[bot]
    • [automated] chore: bump version to 0.20.2-beta.2607230301 (#3084)
  • e0001b8 Peter Zhu
    • [S2SDK-118] go: expose EnforceOverrides + EnforceTargeting persistent-assignment options (#3044)
  • 7acd3df Peter Zhu
    • [S2SDK-116] node: expose enforceOverrides + enforceTargeting persistent-assignment options (#3042)
  • 44a959c statsig-kong[bot]
    • [automated] chore: bump version to 0.20.2-beta.2607220301 (#3082)
  • 8564e39 Sandeep Madugula
    • [S2SDK-165] java: replace JSON round trip in user construction with a binary payload (#3081)
  • b15d7f1 statsig-kong[bot]
    • [automated] chore: bump version to 0.20.2-rc.2607201629 (#3079)

Full Changelog: 0.20.2...0.21.0