v0.55.8

Try our Chrome extension

Chrome store icon Chrome Webstore

Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!

Changedetection.io needs your support!

You can help us by supporting changedetection.io on these platforms;

The more popular changedetection.io is, the more time we can dedicate to adding amazing features!

Many thanks :)

changedetection.io team

Not yet seconds ago
            False
        
Not yet seconds ago
Current erroring screenshot from most recent request

Triggered text Ignored text Blocked text

13 hours ago
    Skip to content

      Navigation Menu

            Sign in Appearance settings
                * Platform
                        + AI CODE CREATION
                            o GitHub Copilot Write better code with AI
                            o GitHub Copilot app Direct agents from issue to merge
                            o MCP Registry Integrate external tools
                        + DEVELOPER WORKFLOWS
                            o Actions Automate any workflow
                            o Codespaces Instant dev environments
                            o Issues Plan and track work
                            o Code Review Manage code changes
                            o Code Quality Enforce quality at merge
                        + APPLICATION SECURITY
                            o GitHub Advanced Security Find and fix vulnerabilities
                            o Code security Secure your code as you build
                            o Secret protection Stop leaks before they start
                        + EXPLORE
                            o Why GitHub
                            o Documentation
                            o Blog
                            o Changelog
                            o Marketplace
                      View all features
                * Solutions
                        + BY COMPANY SIZE
                            o Enterprises
                            o Small and medium teams
                            o Startups
                            o Nonprofits
                        + BY USE CASE
                            o App Modernization
                            o DevSecOps
                            o DevOps
                            o CI/CD
                            o View all use cases
                        + BY INDUSTRY
                            o Healthcare
                            o Financial services
                            o Manufacturing
                            o Government
                            o View all industries
                      View all solutions
                * Resources
                        + EXPLORE BY TOPIC
                            o AI
                            o Software Development
                            o DevOps
                            o Security
                            o View all topics
                        + EXPLORE BY TYPE
                            o Customer stories
                            o Events & webinars
                            o Ebooks & reports
                            o Business insights
                            o GitHub Skills
                        + SUPPORT & SERVICES
                            o Documentation
                            o Customer support
                            o Community forum
                            o Trust center
                            o Partners
                      View all resources
                * Open Source
                        + COMMUNITY
                            o GitHub Sponsors Fund open source developers
                        + PROGRAMS
                            o Security Lab
                            o Maintainer Community
                            o Accelerator
                            o GitHub Stars
                            o Archive Program
                        + REPOSITORIES
                            o Topics
                            o Trending
                            o Collections
                * Enterprise
                        + ENTERPRISE SOLUTIONS
                            o Enterprise platform AI-powered developer platform
                        + AVAILABLE ADD-ONS
                            o GitHub Advanced Security Enterprise-grade security features
                            o Copilot for Business Enterprise-grade AI features
                            o Premium Support Enterprise-grade 24/7 support
              * Pricing
                Type / to search
                Sign in
              Sign up Appearance settings
      You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert

              Uh oh!

              There was an error while loading. Please reload this page.

              hashicorp / consul Public
              * Notifications You must be signed in to change notification settings
              * Fork 4.6k
                * Star 30k
          * Code
          * Issues 1.3k
          * Pull requests 83
          * Actions
          * Projects
          * Security and quality 0
          * Insights
          Additional navigation options
                  * Code
                  * Issues
                  * Pull requests
                  * Actions
                  * Projects
                  * Security and quality
                  * Insights

        Releases: hashicorp/consul

              Releases Tags
            Releases · hashicorp/consul

                Release list

                    * v2.0.3
                    * v2.0.2
                    * v2.0.1
                    * v2.0.0
                    * v2.0.0-rc2
                    * v2.0.0-rc1
                    * v1.22.7
                    * v1.22.6
                    * v1.22.5
                    * v1.22.4
                    Previous Next
                Jump to release
                        * v2.0.3
                        * v2.0.2
                        * v2.0.1
                        * v2.0.0
                        * v2.0.0-rc2
                        * v2.0.0-rc1
                        * v1.22.7
                        * v1.22.6
                        * v1.22.5
                        * v1.22.4
                    Previous Next

                v2.0.3

                              v2.0.3 Latest
                              Latest
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 07 Aug 17:25
                              v2.0.3
                              d0f2be9
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          2.0.3 (August 7, 2026)

                          SECURITY:

                            * Update brace-expansion to address GHSA-rgw5-rvv9-x895 (DoS via unbounded intermediate arrays). [GH-23786]
                            * Update fast-uri to address GHSA-7p8r-x3mc-p8w7 (Host Confusion via backslash authority introducer). [GH-23786]
                            * Update golang.org/x/text to v0.39.0 to address GO-2026-5970. [GH-23761]
                            * Update google.golang.org/grpc to v1.82.1 to address GHSA-hrxh-6v49-42gf. [GH-23761]
                            * Update socket.io-parser to address CVE-2026-69185 (Zero-attachment Memory Exhaustion). [GH-23786]
                            * Upgrade to use Go 1.26.5. This resolves vulnerabilities
                              GO-2026-4970 (os).
                              GO-2026-5856 (crypto/tls). [GH-23761]
                            * agent: Fixed a denial-of-service vulnerability where GET /v1/agent/connect/ca/roots
                              and POST /v1/agent/connect/authorize used the agent-side cache unconditionally, even
                              when http_config { use_cache = false } was configured by the operator. A remote caller
                              could bypass this setting and grow the agent cache without bound by varying the request
                              ACL token. Both endpoints now skip the cache and issue a direct RPC when use_cache is
                              disabled. (SECVULN-50292, SECVULN-50293) [GH-23797]
                            * agent: Fixed a nil-pointer dereference panic in ShadowServiceRouterConfigEntry.CheckEnt
                              when a service-router config entry contained a route with a nil Destination. A crafted
                              snapshot restore or replication message containing such an entry could crash the FSM
                              decode path. The nil guard now treats a missing destination as non-enterprise data and
                              continues decoding safely. (SECVULN-50291) [GH-23797]
                            * agent: Fixed a security bypass where a user-supplied public listener
                              (envoy_public_listener_json) with an HTTP Connection Manager filter would skip Consul's
                              inbound request-normalization defaults. An attacker could exploit the un-normalized path
                              to bypass L7 intention deny rules using percent-encoded path equivalents. Consul now
                              injects path normalization (enabled by default, unless the mesh config option
                              InsecureDisablePathNormalization is set) on every HCM filter chain in user-provided
                              public listeners before L7 intention enforcement is applied. (SECVULN-50295) [GH-23797]
                            * agent: Fixed an unauthenticated denial-of-service vulnerability where
                              PUT /v1/agent/check/update/:id, PUT /v1/agent/check/register,
                              PUT /v1/agent/service/register, and POST /v1/agent/connect/authorize
                              decoded unbounded JSON request bodies before resolving the caller's ACL
                              token. An unauthenticated caller could retain multiple large JSON decoder
                              buffers concurrently inside the Consul process before each request was
                              rejected with HTTP 403, causing attacker-controlled heap growth. All four
                              endpoints now cap the request body at 512 KiB before any decoding occurs,
                              returning HTTP 413 for oversized bodies. This limit applies to chunked
                              transfer encoding as well as declared Content-Length.
                              (SECVULN-50418) [GH-23796]
                            * agent: Fixed an unauthenticated denial-of-service vulnerability where the external gRPC
                              and gRPC-TLS listeners accepted an unlimited number of TCP connections per source IP
                              before any request processing, ACL check, or rate limiting could occur. A remote attacker
                              could exhaust agent file descriptors, goroutines, and memory by opening many connections
                              and withholding the gRPC or TLS handshake. A new per-client-IP connection limiter is now
                              applied before the gRPC server observes the connection, controlled by the new
                              limits.grpc_max_conns_per_client configuration option (default 100). The gRPC handshake
                              timeout has also been reduced from the library default of 120 seconds to 20 seconds.
                              (SECVULN-50294) [GH-23797]

                          IMPROVEMENTS:

                            * ui: migrate yadda/Gherkin acceptance tests to native QUnit (harness, intentions/create, components, settings) [GH-23741]
                            * xds: Add two new opt-in ProxyDefaults.spec.config keys for controlling the server response header on API Gateway HTTP listeners: envoy_suppress_envoy_headers (removes the header entirely) and envoy_server_header_name (renames it to a custom value). If both are set, suppress takes precedence. [GH-13027]

                          BUG FIXES:

                            * agent: Stop logging the raw ACL token in debug-level content-type logs. [GH-23731]
                            * api-gateway: Fixed a regression that caused an HTTP API gateway to reject its configuration with an "inconsistent protocols" error (resulting in intermittent 503s) when a backend service's service-router composed a route to a destination in a different service, namespace, or partition during discovery-chain synthesis. [GH-23793]
                            * serf: Fix WAN flood-join to ignore non-alive destination members (leaving/left/failed), allowing rejoined servers to heal back to alive in WAN membership. [GH-23709]
                            * xds: Addition of XFCC headers to GPRC request similar to HTTP request for connect-proxy inbound listener [GH-23744]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v2.0.2

                              v2.0.2
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 08 Jul 10:39
                              v2.0.2
                              ca5bc12
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          2.0.2 (July 8, 2026)

                          SECURITY:

                            * Upgrade alpine base image version to 3.24 to address [CVE-2026-41989], [ALPINE-CVE-2026-2100]. [GH-23711]
                            * dependency: Upgrade Serf and Memberlist to use the latest versions. [GH-23704]
                            * xds: Return errors when injecting the L4 intention (RBAC) filter or the mTLS transport socket onto an inbound public listener, so the listener is not served without intention enforcement or mTLS. [GH-23686]

                          FEATURES:

                            * config-entry(api-gateway): (Enterprise only) Add ExtAuthzFilter to HTTPRoute Filters and gateway-wide ExtAuthz toggle to the api-gateway config entry [GH-23703]
                            * config-entry: (Enterprise only) Addition of External Processor (ext_proc) Envoy Extension support to api-gateway and connect-proxy [GH-23705]

                          IMPROVEMENTS:

                            * ci: upgrade GitHub Actions that used the deprecated Node 20 runtime to Node 24, and restore GOTOOLCHAIN=auto after setup-go so backward-compatibility and integration test lanes resolve the correct Go toolchain. [GH-23687]
                            * connect: update support for nomad and vault version to v2.0.3 [GH-23624]
                            * deps: Migrate armon/go-metrics to hashicorp/go-metrics and update Go dependencies across all modules [GH-23635]

                          BUG FIXES:

                            * xds: only emit the client cert SDS block when both CertFile and KeyFile are set. [GH-23679]

                          KNOWN ISSUES:

                            * consul-k8s: In setups using consul OSS version, consul-k8s-connect-injector fails to come up because of a missing CRD RouteExtProc. A new version(2.0.2-oss) of consul helm chart is released to resolve this issue. Use the Chart version '2.0.2-oss' for OSS distribution of consul of this release v2.0.2.
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v2.0.1

                              v2.0.1
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 19 Jun 07:23
                              v2.0.1
                              16a4c49
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          2.0.1 (June 18, 2026)

                          SECURITY:

                            * Upgrade go version to 1.26.4 to address GO-2026-5039, GO-2026-5038,GO-2026-5037 [GH-23637]
                            * connect: Upgrade envoy version to 1.37.4, 1.36.8, 1.35.12; Add new version of Envoy 1.38.2 and remove 1.34.14 [GH-23664]

                          IMPROVEMENTS:

                            * dockerfile: layer reduction by merging RUN commands and minor changes following best practices. [GH-23650]
                            * product-telemetry: product usage reporting now preserves export cadence across restarts and leader re-elections by resuming from the last successful export time, preventing delays
                            * server: Auth method TokenNameFormat field accepts OIDC and JWT claim mapping values [GH-23616]
                            * ui: Removed block-slot addon dependency [GH-23481]

                          BUG FIXES:

                            * connect: Strip the x-forwarded-client-cert header from inbound HTTP requests before forwarding them to local service instances. [GH-23544]
                            * server: Fixed a bug where renaming a server (or wiping and rejoining it with the same IP and Raft node ID) could cause an out-of-order serf event to evict the live leader from the internal server lookup, resulting in Raft leader not found in server lookup mapping (HTTP 500) errors on follower RPCs until the next member event resynced the mapping. [GH-23533]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              🚀 2 neomafo88 and brandon-welsch reacted with rocket emoji
                                All reactions
                                  * 🚀 2 reactions
                              2 people reacted

                v2.0.0

                              v2.0.0
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 24 May 05:55
                              v2.0.0
                              1b36932
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          2.0.0 (May 22, 2026)

                          SECURITY:

                            * connect: Upgrade envoy version to 1.37.2 and newer versions [GH-23469]
                            * go: Upgrade go version to 1.26 [GH-23493]
                            * agent: Increased default HTTP server timeouts to prevent breaking long-polling blocking queries. read_timeout and write_timeout are now set to 15 minutes (up from 30 seconds), while read_header_timeout (10s) and idle_timeout (120s) still provide protection against Slowloris attacks. All timeouts remain configurable via the http_config block. [GH-23267]
                            * api-gateway, terminating-gateway: Apply HTTP request path normalization on api-gateway and terminating-gateway HTTP listeners to prevent L7 intention RBAC bypass via non-normalized paths (CVE-2024-10005). [GH-23534]
                            * docker: update ubi base image to ubi9-minimal:9.7. [GH-23553]
                            * docker: Upgrade curl to >= 8.20.0 from Alpine edge in the container image to address
                              CVE-2026-6429,
                              CVE-2026-4873,
                              CVE-2026-5773,
                              CVE-2026-6253,
                              CVE-2026-6276,
                              CVE-2026-7168,
                              CVE-2026-5545.
                              Alpine 3.23 stable does not yet carry the patched version. [GH-23750]
                            * docker: Update to UBI base image to 9.8 for fixing [CVE_2026-2100] [GH-23588]

                          FEATURES:

                            * (Enterprise Only) update to go-licensing/v4 and go-census/v3 inorder to adapt to new licenses of PAO.
                            * Global Rate Limiter: (Enterprise Only) a new "rate-limit" config entry kind that enables dynamic, cluster-wide RPC rate limiting stored in Raft and automatically replicated to all servers. This allows operators to apply or adjust global rate limits at runtime without restarting Consul servers — a critical capability for emergency scenarios where the cluster is under excessive load.
                            * api-gateway: Added SDS certificate support for API Gateway listeners, including listener-level default TLS certificates and HTTP/TCP route service TLS SDS overrides. Service overrides inherit the listener SDS cluster when omitted, and gateway validation/xDS generation now rejects conflicting override mappings to keep certificate selection deterministic. [GH-23354]
                            * api-gateway: add support for gateway-level default upstream limits and route service-level limit overrides for MaxConnections, MaxPendingRequests, and MaxConcurrentRequests. [GH-23396]
                            * api: Added new API "/v1/internal/rpc/methods" that lists all RPC method names. Requires an operator:read ACL token. This is useful when users want to configure rate limits that exclude specific RPC endpoints. [GH-23329]
                            * ca: (Enterprise Only) Added new Connect CA provider for Cyberark WIM (connect.ca_provider = "pan-distributed-issuer"), enabling Consul to issue certificates through Cyberark WIM.
                            * server: (Enterprise Only) add stable cluster identity and leader-gated global registry sync for service summary publishing.
                            * telemetry: (Enterprise Only) Product telemetry for self-managed Consul with anonymous, opt-in usage reporting.
                            * mesh: (Enterprise Only) Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.

                          IMPROVEMENTS:

                            * agent: (Enterprise Only) Add eventually-consistent background cache for Enterprise usage metrics, reducing GET /v1/operator/usage latency from O(PNK) to O(1) and lowering CPU/memory pressure during high-frequency scraping via a watch-driven maintainer goroutine.
                            * mesh: (Enterprise Only) Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.
                            * terminating-gateway: Updated the cluster upstream tls to use sds instead of static certs, allowing for dynamic certificate updates without needing to restart the terminating gateway. [GH-23288]
                            * telemetry: Add certificate expiry monitoring with Prometheus metrics (labeled with datacenter/partition/namespace), structured logging with configurable severity thresholds, and enhanced Connect CA API to include NotAfter field for root and intermediate certificates. [GH-23147]
                            * deps: Upgrade github.com/hashicorp/vault/sdk from v0.7.0 to v0.25.1 and github.com/hashicorp/vault/api from v1.12.2 to v1.16.0. [GH-23574]
                            * test-integ: upgrade testcontainers-go (v0.22.0->v0.40.0) and docker/docker (v24.0.5->v28.5.1) in the integration test module. This removes opencontainers/runc as a Go dependency of the test framework. These are test infrastructure dependencies only and have no impact on the consul binary or any consul deployment. [GH-23573]
                            * xds: add Consecutive5xx, ConsecutiveGatewayFailure, and EnforcingConsecutiveGatewayFailure fields to PassiveHealthCheck, allowing operators to configure Envoy outlier detection thresholds for 5xx responses and gateway failures (502/503/504) on upstreams defaults.

                          BUG FIXES:

                            * audit-logging: (Enterprise Only) Fixed JSON unmarshall error when array of obj is passed for auditReq body.
                            * cli: Enhanced error messages in consul config write command to provide actionable guidance when config entries cannot be modified due to references by gateways or routers. [GH-22921]
                            * xds: Fixed XDS package to generate correct endpoints and cluster configurations for API Gateways when peered, and updated the API Gateway update handler to propogate mesh gateway config to its upstreams. [GH-23454]
                            * XDS: Fixes issue with mesh-gateway in remote mode on AWS EKS, as DNS hostnames are assigned to AWS NLBs instead of IPs and envoy's EDS endpoint validation expects address to be an IP. Now EDS load assignment is skipped for non-peer remote mesh gateway targets with hostname based gateways keeping CDS/EDS in sync. [GH-23543]
                            * api-gateway: resolve service subsets for routes during API gateway discovery chain synthesis. [GH-23294]
                            * ui: Fix broken documentation links [GH-23578]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              🎉 7 tristanmorgan, bugcysg, Alexsandr-Random, kirychukyurii, i0tool5, brandon-welsch, and mehdiMj-ir reacted with hooray emoji
                                All reactions
                                  * 🎉 7 reactions
                              7 people reacted

                v2.0.0-rc2

                              v2.0.0-rc2 Pre-release
                              Pre-release
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 15 May 11:56
                              v2.0.0-rc2
                              c1dcea0
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          2.0.0-rc2 (May 15, 2026)

                          SECURITY:

                            * agent: Increased default HTTP server timeouts to prevent breaking long-polling blocking queries. read_timeout and write_timeout are now set to 15 minutes (up from 30 seconds), while read_header_timeout (10s) and idle_timeout (120s) still provide protection against Slowloris attacks. All timeouts remain configurable via the http_config block. [GH-23267]
                            * api-gateway, terminating-gateway: Apply HTTP request path normalization on api-gateway and terminating-gateway HTTP listeners to prevent L7 intention RBAC bypass via non-normalized paths (CVE-2024-10005). [GH-23534]
                            * docker: update ubi base image to ubi9-minimal:9.7. [GH-23553]
                            * security: Fixed Consul transaction endpoint authorization bypasses where service and check mutations could be authorized using request-provided names while applying changes by ID, including a bypass using the reserved consul service name. [GH-12716]

                          BUG FIXES:

                            * XDS: Fixes issue with mesh-gateway in remote mode on AWS EKS, as DNS hostnames are assigned to AWS NLBs instead of IPs and envoy's EDS endpoint validation expects address to be an IP. Now EDS load assignment is skipped for non-peer remote mesh gateway targets with hostname based gateways keeping CDS/EDS in sync. [GH-23543]
                            * api-gateway: resolve service subsets for routes during API gateway discovery chain synthesis. [GH-23294]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 2 i0tool5 and Alexsandr-Random reacted with thumbs up emoji 🚀 1 i0tool5 reacted with rocket emoji
                                All reactions
                                  * 👍 2 reactions
                                  * 🚀 1 reaction
                              2 people reacted

                v2.0.0-rc1

                              v2.0.0-rc1 Pre-release
                              Pre-release
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 29 Apr 17:34
                              v2.0.0-rc1
                              cf4eda6
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          2.0.0-rc1 (April 29, 2026)

                          SECURITY:

                            * connect: Upgrade envoy version to 1.37.2 and newer versions [GH-23469]
                            * go: Upgrade go version to 1.26 [GH-23493]

                          FEATURES:

                            * (Enterprise Only) update to go-licensing/v4 and go-census/v3 inorder to adapt to new licenses of PAO.
                            * Global Rate Limiter: (Enterprise Only) a new "rate-limit" config entry kind that enables dynamic, cluster-wide RPC rate limiting stored in Raft and automatically replicated to all servers. This allows operators to apply or adjust global rate limits at runtime without restarting Consul servers — a critical capability for emergency scenarios where the cluster is under excessive load.
                            * api-gateway: Added SDS certificate support for API Gateway listeners, including listener-level default TLS certificates and HTTP/TCP route service TLS SDS overrides. Service overrides inherit the listener SDS cluster when omitted, and gateway validation/xDS generation now rejects conflicting override mappings to keep certificate selection deterministic. [GH-23354]
                            * api-gateway: add support for gateway-level default upstream limits and route service-level limit overrides for MaxConnections, MaxPendingRequests, and MaxConcurrentRequests. [GH-23396]
                            * api: Added new API "/v1/internal/rpc/methods" that lists all RPC method names. Requires an operator:read ACL token. This is useful when users want to configure rate limits that exclude specific RPC endpoints. [GH-23329]
                            * ca: (Enterprise Only) Added new Connect CA provider for Cyberark WIM (connect.ca_provider = "pan-distributed-issuer"), enabling Consul to issue certificates through Cyberark WIM.
                            * server: (Enterprise Only) add stable cluster identity and leader-gated global registry sync for service summary publishing.
                            * telemetry: (Enterprise Only) Product telemetry for self-managed Consul with anonymous, opt-in usage reporting.
                            * mesh: (Enterprise Only) Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.

                          IMPROVEMENTS:

                            * agent: (Enterprise Only) Add eventually-consistent background cache for Enterprise usage metrics, reducing GET /v1/operator/usage latency from O(PNK) to O(1) and lowering CPU/memory pressure during high-frequency scraping via a watch-driven maintainer goroutine.
                            * mesh: (Enterprise Only) Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.
                            * terminating-gateway: Updated the cluster upstream tls to use sds instead of static certs, allowing for dynamic certificate updates without needing to restart the terminating gateway. [GH-23288]
                            * telemetry: Add certificate expiry monitoring with Prometheus metrics (labeled with datacenter/partition/namespace), structured logging with configurable severity thresholds, and enhanced Connect CA API to include NotAfter field for root and intermediate certificates. [GH-23147]

                          BUG FIXES:

                            * audit-logging: (Enterprise Only) Fixed JSON unmarshall error when array of obj is passed for auditReq body.
                            * cli: Enhanced error messages in consul config write command to provide actionable guidance when config entries cannot be modified due to references by gateways or routers. [GH-22921]
                            * xds: Fixed XDS package to generate correct endpoints and cluster configurations for API Gateways when peered, and updated the API Gateway update handler to propogate mesh gateway config to its upstreams. [GH-23454]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                                All reactions

                v1.22.7

                              v1.22.7
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 25 Apr 07:38
                              v1.22.7
                              c18bcb9
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          1.22.7 (April 21, 2026)

                          SECURITY:

                            * security: update google.golang.org/grpc to fix CVE-2026-33186 [GH-23379]
                            * security: upgrade go.opentelemetry.io/otel to 1.42.0 to remediate CVE-2026-24051 (Path Hijacking / Untrusted Search Paths on macOS). [GH-23387]
                            * test-sds-server: bump github.com/hashicorp/consul to v1.22.5 in integration test module to align with the CVE-2026-2808 fixed release line. [GH-23437]
                            * ui: (Enterprise only) Backport Rollup update to 2.80.0 for release/1.21.x to address CVE-2026-27606 (SECVULN-38912).

                          IMPROVEMENTS:

                            * acl: Addition of TokenNameFormat field to auth-method and parse the same for token name [GH-23444]
                            * discovery-chain: removes the use of hashstructure_v2 ([github.com/mitchellh/hashstructure/v2] from compiled discovery chain hashing and replaces it with explicit custom hash implementations. [GH-23393]
                            * ui: removed consul docs website related code as it is being maintained in a separate internal repository. [GH-23398]

                          BUG FIXES:

                            * api-gateway: fix HTTPRoute PathPrefix routing to preserve the original request path when replacePrefixMatch is not configured [GH-23390]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 4 bugcysg, i0tool5, tristanmorgan, and Alexsandr-Random reacted with thumbs up emoji
                                All reactions
                                  * 👍 4 reactions
                              4 people reacted

                v1.22.6

                              v1.22.6
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 26 Mar 10:44
                              v1.22.6
                              9756668
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          1.22.6 (March 23, 2026)

                          SECURITY:

                            * security: upgrade envoy version to 1.35.9 and 1.34.13 [GH-23372]
                            * security: update google.golang.org/grpc to fix CVE-2026-33186 [GH-23379]
                            * security: upgrade go version to 1.25.8 [GH-23322]
                            * security: bump golang.org/x/* dependencies to align with consul-enterprise and address security vulnerabilities. [GH-23322]

                          IMPROVEMENTS:

                            * api-gateway: Add support to disable traffic with weight 0 in services for HTTPRoute backends, allowing explicit zero-weight backends to be excluded from traffic. [GH-23216]
                            * ui: Fixed Consul UI to work in non-secure environments by enabling Ember Data's UUID polyfill for crypto.randomUUID. [GH-23341]
                            * ui: Fixed Consul UI services page navigation by ensuring route transitions trigger the expected model hook behavior after Ember upgrade. [GH-23271]
                            * ui: Replaced deprecated SideNav component with AppSideNav for improved navigation structure. [GH-23289]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              🎉 3 tristanmorgan, i0tool5, and guohuaw622-arch reacted with hooray emoji
                                All reactions
                                  * 🎉 3 reactions
                              3 people reacted

                v1.22.5

                              v1.22.5
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 27 Feb 07:18
                              v1.22.5
                              3a6dbfc
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          1.22.5 (February 26, 2026)

                          SECURITY:

                            * security: upgrade go version to 1.25.7 [GH-23204]
                            * dockerfile: the Consul build Go base image to alpine3.23 [GH-23194]
                            * connect: Migrate to aws-sdk-go-v2 from aws-sdk-go (v1). Also updated consul-awsauth and go-secure-stdlib/awsutil dependencies to their v2 versions. [GH-23109]
                            * security: Configure HTTP server timeouts to prevent Slowloris denial-of-service attacks on agent HTTP endpoints and pprof endpoints. [GH-22739]
                            * security: Patched Vault CA provider to prevent arbitrary file reads via Kubernetes, JWT, and AppRole methods. [GH-23249]
                            * security: Introduced debounce timing for synchronization operations within federationStateAntiEntropySync. [GH-23196]

                          IMPROVEMENTS:

                            * api-gateway: Fixed "duplicate matcher" errors in Envoy when using multiple file-system certificates on a single TLS listener. The certificates are now consolidated into a single filter chain, allowing Envoy to select the correct one. [GH-23212]
                            * agent: Fix vault provider failure when signing intermediate CA with isCA=true in CSR [GH-23202]
                            * cli: Added --aws-iam-endpoint flag to consul login command for AWS IAM auth method to support custom IAM endpoint configuration [GH-23109]
                            * docs: Refreshed the security documentation to include the new HTTP server timeout defaults and relevant configuration options. [GH-23246]
                            * api: Cancel context check for watches cache fetch to stop execution when manager deregisters the watch. [GH-23157]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 1 i0tool5 reacted with thumbs up emoji 🚀 1 i0tool5 reacted with rocket emoji
                                All reactions
                                  * 👍 1 reaction
                                  * 🚀 1 reaction
                              1 person reacted

                v1.22.4

                              v1.22.4
                            Compare

                                  Choose a tag to compare

                                      Sorry, something went wrong.

                                Filter
                                  Loading

                                        Sorry, something went wrong.

                                          Uh oh!

                                          There was an error while loading. Please reload this page.

                                  No results found

                                View all tags
                              hc-github-team-es-release-engineering released this 19 Feb 05:41
                              v1.22.4
                              c32a5a6
                                      This commit was created on GitHub.com and signed with GitHub’s verified signature.
                                    GPG key ID: B5690EEEBB952194
                                      Verified
                                    Learn about vigilant mode.

                          ⚠️ Important Notice

                          We have identified an issue in Consul and Consul Enterprise Feb Patch Release (1.22.4, 1.22.4-ent, 1.21.10-ent, 1.18.20-ent) that requires a corrective patch release.

                          We recommend that customers avoid using these versions in production environments and wait for the upcoming patch release.

                          Customers who have upgraded to these versions should temporarily revert to the previous stable release while we prepare a corrected update.

                          A new patched release is expected by the end of the this month.

                          Further updates will be shared once the new version is available. We apologize for the inconvenience and appreciate your patience.

                          1.22.4 (February 18, 2026)

                          SECURITY:

                            * security: upgrade go version to 1.25.7 [GH-23204]
                            * dockerfile: the Consul build Go base image to alpine3.23 [GH-23194]
                            * connect: Migrate to aws-sdk-go-v2 from aws-sdk-go (v1). Also updated consul-awsauth and go-secure-stdlib/awsutil dependencies to their v2 versions. [GH-23109]
                            * security: Configure HTTP server timeouts to prevent Slowloris denial-of-service attacks on agent HTTP endpoints and pprof endpoints. [GH-22739]

                          IMPROVEMENTS:

                            * api-gateway: Fixed "duplicate matcher" errors in Envoy when using multiple file-system certificates on a single TLS listener. The certificates are now consolidated into a single filter chain, allowing Envoy to select the correct one. [GH-23212]
                            * agent: Fix vault provider failure when signing intermediate CA with isCA=true in CSR [GH-23202]
                            * cli: Added --aws-iam-endpoint flag to consul login command for AWS IAM auth method to support custom IAM endpoint configuration [GH-23109]
                            * api: Cancel context check for watches cache fetch to stop execution when manager deregisters the watch. [GH-23157]
                          Assets 2
                            Loading

                                    Uh oh!

                                    There was an error while loading. Please reload this page.

                              👍 2 i0tool5 and EtienneBruines reacted with thumbs up emoji 🚀 1 i0tool5 reacted with rocket emoji 👀 2 cr0c0dylus and afdjpc reacted with eyes emoji
                                All reactions
                                  * 👍 2 reactions
                                  * 🚀 1 reaction
                                  * 👀 2 reactions
                              4 people reacted
                Previous 1 2 3 4 5 … 26 27 Next
                Previous Next

  Footer

      © 2026 GitHub, Inc.

    Footer navigation

      * Terms
      * Privacy
      * Security
      * Status
      * Community
      * Docs
      * Contact
      * Manage cookies
      * Do not share my personal information
    You can’t perform that action at this time.
For now, Differences are performed on text, not graphically, only the latest screenshot is available.

Screenshot requires a Content Fetcher ( Sockpuppetbrowser, selenium, etc ) that supports screenshots.