Try our Chrome extension
Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!Changedetection.io needs your support!
You can help us by supporting changedetection.io on these platforms;
- Rate us at AlternativeTo.net
- Star us on GitHub
- Follow us at Twitter/X
- G2 Software reviews
- Check us out on LinkedIn
- And tell your friends and colleagues :)
The more popular changedetection.io is, the more time we can dedicate to adding amazing features!
Many thanks :)
changedetection.io team
Ještě ne před sekundami.
False
Ještě ne před sekundami
7 hours agoPřejít na samotný snímek
Skip to content
Navigation Menu
Sign in Appearance settings
* Platform
+ AI CODE CREATION
o GitHub Copilot Write better code with AI
o GitHub Copilot app Direct agents from issue to merge
o MCP Registry Integrate external tools
+ DEVELOPER WORKFLOWS
o Actions Automate any workflow
o Codespaces Instant dev environments
o Issues Plan and track work
o Code Review Manage code changes
o Code Quality Enforce quality at merge
+ APPLICATION SECURITY
o GitHub Advanced Security Find and fix vulnerabilities
o Code security Secure your code as you build
o Secret protection Stop leaks before they start
+ EXPLORE
o Why GitHub
o Documentation
o Blog
o Changelog
o Marketplace
View all features
* Solutions
+ BY COMPANY SIZE
o Enterprises
o Small and medium teams
o Startups
o Nonprofits
+ BY USE CASE
o App Modernization
o DevSecOps
o DevOps
o CI/CD
o View all use cases
+ BY INDUSTRY
o Healthcare
o Financial services
o Manufacturing
o Government
o View all industries
View all solutions
* Resources
+ EXPLORE BY TOPIC
o AI
o Software Development
o DevOps
o Security
o View all topics
+ EXPLORE BY TYPE
o Customer stories
o Events & webinars
o Ebooks & reports
o Business insights
o GitHub Skills
+ SUPPORT & SERVICES
o Documentation
o Customer support
o Community forum
o Trust center
o Partners
View all resources
* Open Source
+ COMMUNITY
o GitHub Sponsors Fund open source developers
+ PROGRAMS
o Security Lab
o Maintainer Community
o Accelerator
o GitHub Stars
o Archive Program
+ REPOSITORIES
o Topics
o Trending
o Collections
* Enterprise
+ ENTERPRISE SOLUTIONS
o Enterprise platform AI-powered developer platform
+ AVAILABLE ADD-ONS
o GitHub Advanced Security Enterprise-grade security features
o Copilot for Business Enterprise-grade AI features
o Premium Support Enterprise-grade 24/7 support
* Pricing
Type / to search
Sign in
Sign up Appearance settings
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
Uh oh!
There was an error while loading. Please reload this page.
prometheus / prometheus Public
* Notifications You must be signed in to change notification settings
* Fork 10.8k
* Star 65.6k
* Code
* Issues 513
* Pull requests 385
* Pull requests 381
* Discussions
* Actions
* Projects
* Wiki
* Security and quality 6
* Insights
Additional navigation options
* Code
* Issues
* Pull requests
* Discussions
* Actions
* Projects
* Wiki
* Security and quality
* Insights
Releases: prometheus/prometheus
Releases Tags
Releases · prometheus/prometheus
Release list
* 3.13.2 / 2026-07-29
* 3.13.1 / 2026-07-10
* 3.5.5 / 2026-07-09
* 3.13.0 / 2026-07-01
* 3.13.0-rc.1 / 2026-06-22
* 3.13.0-rc.0 / 2026-06-18
* 3.5.4 / 2026-06-17
* 3.12.0 / 2026-05-28
* 3.12.0-rc.0 / 2026-05-19
* 3.11.3 / 2026-04-27
Previous Next
Jump to release
* 3.13.2 / 2026-07-29
* 3.13.1 / 2026-07-10
* 3.5.5 / 2026-07-09
* 3.13.0 / 2026-07-01
* 3.13.0-rc.1 / 2026-06-22
* 3.13.0-rc.0 / 2026-06-18
* 3.5.4 / 2026-06-17
* 3.12.0 / 2026-05-28
* 3.12.0-rc.0 / 2026-05-19
* 3.11.3 / 2026-04-27
Previous Next
3.13.2 / 2026-07-29
3.13.2 / 2026-07-29 Latest
Latest
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 30 Jul 13:25
Immutable release. Only release title and notes can be modified.
v3.13.2
This tag was signed with the committer’s verified signature.
krajorama George Krajcsovits
GPG key ID: 47A8F9CE80FD7C7F
Verified
Learn about vigilant mode.
bb5dff0
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* [SECURITY] Bump golang.org/x/text to v0.39.0 (CVE-2026-56852) and google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf). #19290 by @krajorama
* [BUGFIX] PromQL: Preallocate the active query tracker file to avoid SIGBUS crashes when the data disk is full. #19289 by @akshajrawat
Full Changelog: v3.13.1...v3.13.2
Contributors
*
*
krajorama and akshajrawat
Assets 40
* prometheus-3.13.2.aix-ppc64.tar.gz
sha256:550f67f8d2566921558033c050da59e67780b5310d93cb8f066b4c1982350220
95.3 MB 2026-07-30T11:59:20Z
* prometheus-3.13.2.darwin-amd64.tar.gz
sha256:e57095aed0b69e10edaee28b92718d4a65f46d466bf93aeda54075e901d15c2a
105 MB 2026-07-30T11:59:27Z
* prometheus-3.13.2.darwin-arm64.tar.gz
sha256:f68ca4f1dbedd6366bbfdd8ac5d2c0b7ba1f273474acc8d38eb33202fbeec7a4
98.9 MB 2026-07-30T11:59:31Z
* prometheus-3.13.2.dragonfly-amd64.tar.gz
sha256:9379ba9ebe185832dd8ac4cf5ced32bde70f1f59dcbfbea7ee244fb019e1c8e8
99.3 MB 2026-07-30T11:59:36Z
* prometheus-3.13.2.freebsd-386.tar.gz
sha256:a712f9c19ed59eb79a876c3aa9e8287572444153e4dc089b41bc4106c196474c
94.3 MB 2026-07-30T11:59:40Z
* prometheus-3.13.2.freebsd-amd64.tar.gz
sha256:f21fb7e7a8bd5f0a0e02d768830913af57fe2d846995b058f2b379aa2fe0b4b7
99.4 MB 2026-07-30T11:59:44Z
* prometheus-3.13.2.freebsd-arm64.tar.gz
sha256:d06d04317306447ae3cfac8f8e03ca5fa23df3b728ca734b7c80cfdcaf9d4b81
90.8 MB 2026-07-30T11:59:49Z
* prometheus-3.13.2.freebsd-armv6.tar.gz
sha256:50553dc96793e2f4f2fc5e44ea2ee7817640e8937cef13bfe793b074827fee86
92.9 MB 2026-07-30T11:59:53Z
* prometheus-3.13.2.freebsd-armv7.tar.gz
sha256:1a9ef7b2429267ddfc4f1d2c936f13b9527a90ab609c05f4fd7cc00bbd421b29
92.8 MB 2026-07-30T11:59:57Z
* prometheus-3.13.2.illumos-amd64.tar.gz
sha256:785add5b4a26565db276b9bb2df87249fe48df0a65caa288e83d21e2ae87df08
99.3 MB 2026-07-30T12:00:01Z
* Source code (zip)
2026-07-30T11:25:10Z
* Source code (tar.gz)
2026-07-30T11:25:10Z
* Release attestation (json)
2026-07-30T11:25:10Z
* Show all 40 assets Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 2 Nachtfalkeaw and liv-io reacted with thumbs up emoji 🎉 3 Cisco30, 0xfeeddeadbeef, and barysdamian91-hash reacted with hooray emoji ❤️ 5 Cisco30, Chengli02, he-sb, jonigl, and sweetburble reacted with heart emoji 🚀 1 derhuerst reacted with rocket emoji
All reactions
* 👍 2 reactions
* 🎉 3 reactions
* ❤️ 5 reactions
* 🚀 1 reaction
10 people reacted
3.13.1 / 2026-07-10
3.13.1 / 2026-07-10
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 10 Jul 10:34
Immutable release. Only release title and notes can be modified.
v3.13.1
This tag was signed with the committer’s verified signature.
krajorama George Krajcsovits
GPG key ID: 47A8F9CE80FD7C7F
Verified
Learn about vigilant mode.
73ff57c
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
This is a bugfix release for 3.13 LTS.
* [BUGFIX] TSDB: Fix the head-chunk cache returning samples from the wrong chunk, or spurious not-found errors, to range queries after head-chunk truncation. #19134
Assets 40
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 8 sweetburble, he-sb, 0xfeeddeadbeef, Prateet-Github, iam-salmankhan, liv-io, shyfly8630, and luv-ops reacted with thumbs up emoji 🎉 2 Sanchit2662 and luv-ops reacted with hooray emoji ❤️ 4 savitarMK, iam-salmankhan, firescry, and luv-ops reacted with heart emoji
All reactions
* 👍 8 reactions
* 🎉 2 reactions
* ❤️ 4 reactions
11 people reacted
3.5.5 / 2026-07-09
3.5.5 / 2026-07-09
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 09 Jul 08:41
Immutable release. Only release title and notes can be modified.
v3.5.5
This tag was signed with the committer’s verified signature.
roidelapluie Julien
SSH Key Fingerprint: 9eNC5Oin1ugTVXQFUl9AInWyqRDljEMJA7TyfXl9Alw
Verified
Learn about vigilant mode.
077b713
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
This release is built with Go 1.25.12 and fixes a security issue in a UI dependency.
* [SECURITY] UI: Bump sanitize-html to v2.17.5 to fix CVE-2026-53606. #19060
Assets 39
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 1 shyfly8630 reacted with thumbs up emoji
All reactions
* 👍 1 reaction
1 person reacted
3.13.0 / 2026-07-01
3.13.0 / 2026-07-01
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 01 Jul 14:09
Immutable release. Only release title and notes can be modified.
v3.13.0
This tag was signed with the committer’s verified signature.
krajorama George Krajcsovits
GPG key ID: 47A8F9CE80FD7C7F
Verified
Learn about vigilant mode.
40af9c2
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
This is a Long Term Support LTS release.
* [SECURITY] UI: Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697
* [CHANGE] UI: Third-party npm dependency licenses are now embedded in the Prometheus binary and served at /assets/third-party-licenses.txt, replacing the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images. #18997
* [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927
* [CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673 CVE-2023-45289). #18949
* [CHANGE] promtool: Relative file paths in the file passed to --http.config.file are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949
* [CHANGE] PromQL: Rename the min() and max() duration-expression functions (experimental feature flag experimental-duration-expr) to min_of() and max_of() to avoid confusion with the min and max aggregate operators. #18687
* [FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573
* [FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859
* [FEATURE] PromQL: Add min_of(a, b) and max_of(a, b) scalar experimental functions, returning the smaller or larger of two scalar values. #18687
* [FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564
* [FEATURE] PromQL: Expose per-query samplesRead (and samplesReadPerStep with stats=all and the promql-per-step-stats feature flag) in the query stats response, and add the prometheus_engine_query_samples_read_total engine counter. samplesRead reflects storage I/O distinct from totalQueryableSamples, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081
* [FEATURE] Scrape: Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling. #18840
* [FEATURE] TSDB: Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding (xor or xor2) at runtime, independently of the --enable-feature=xor2-encoding flag. #18769
* [FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217
* [FEATURE] Scrape: Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of the always_scrape_classic_histograms and scrape_native_histograms scrape configuration via relabeling. #18929
* [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791
* [ENHANCEMENT] PromQL: Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal. #18851
* [ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894
* [PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540
* [PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699
* [PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployments using native histograms with created-timestamp storage enabled (--enable-feature=created-timestamp-zero-ingestion). #18813
* [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS cluster without instances. #18845
* [BUGFIX] Fix race condition in initTime that could cause ErrOutOfBounds. #18629
* [BUGFIX] PromQL: A range query whose end was not aligned to step caused subqueries inside it to evaluate past the parent's last actual step, inflating peakSamples in the query stats and against the query.max-samples limit, and wasting storage I/O reading samples that were never used in the result. #18081
* [BUGFIX] PromQL: A range query containing an at-modifier-unsafe function over a range-vector with an @ modifier (e.g. predict_linear(metric[60s] @ T, X)) silently under-counted totalQueryableSamples for steps after step 0. #18081
* [BUGFIX] PromQL: Fix fill_left/fill_right producing missing samples in range queries when using group_left/group_right. #18850
* [BUGFIX] PromQL: Fix for resets() and changes() in anchored range extenders with histograms. #18906
* [BUGFIX] PromQL: Fix panic on 1[5m] smoothed and similar expressions when extended range selectors are enabled. #18764
* [BUGFIX] PromQL: Fix panic when a smoothed instant vector selector produces no samples for a series. #18943
* [BUGFIX] PromQL: Fix panic when using a parenthesised plain number as an offset (e.g. foo offset -(5)). #18768
* [BUGFIX] promtool: Fix panic when parsing exposition text containing empty braces {}. Via prometheus/common v0.69.0. #18949
* [BUGFIX] Promtool: Fix check healthy and check ready when --url ends with a trailing slash. #18854
* [BUGFIX] Rules: Close PromQL query after each rule evaluation to ensure resources are released. #18733
* [BUGFIX] Scaleway SD: Resolve VPC/IPAM-only instances that have no legacy private_ip or public_ip field, but do have private NICs attached. #18772
* [BUGFIX] TSDB: Do not leak head series when an integer histogram append is rejected (e.g. out-of-order). #18838
* [BUGFIX] UI: Escape label values offered by PromQL autocomplete. #18658
* [BUGFIX] TSDB: Fix chunk snapshot encoding for EncXOR2 chunks, preventing corruption on TSDB restart when EncXOR2-encoded series were present. #18739
* [BUGFIX] TSDB: Store a millisecond timestamp (not a WAL segment number) in walExpiries when a series is evicted via CompactStaleHead/CompactSelectedSeries, so the series's label record is correctly retained in the next WAL checkpoint and replays cleanly. #18847
* [BUGFIX] TSDB: Prevent loss of samples at the chunk-range boundary when CompactSelectedSeries (and CompactStaleHead) evict the series — the per-slice compaction loop now runs one more iteration so the boundary timestamp is captured in a block before the in-memory copy is removed. #18849
Assets 40
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 2 liv-io and tang-yikai reacted with thumbs up emoji 🎉 4 0xfeeddeadbeef, showmidelo, maxlelyonais, and Sanchit2662 reacted with hooray emoji ❤️ 3 he-sb, firescry, and savitarMK reacted with heart emoji 🚀 1 sweetburble reacted with rocket emoji
All reactions
* 👍 2 reactions
* 🎉 4 reactions
* ❤️ 3 reactions
* 🚀 1 reaction
10 people reacted
3.13.0-rc.1 / 2026-06-22
3.13.0-rc.1 / 2026-06-22 Pre-release
Pre-release
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 22 Jun 16:45
Immutable release. Only release title and notes can be modified.
v3.13.0-rc.1
This tag was signed with the committer’s verified signature.
krajorama George Krajcsovits
GPG key ID: 47A8F9CE80FD7C7F
Verified
Learn about vigilant mode.
bd96185
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
Release notes of the 3.13-rc.1 release:
The 3.13.0-rc.0 release was only partially successful due to the migration from NPM to PNPM and subsequent CI issues, so most of the changes in this release candidate are CI/build-related. The only user-facing change is:
* [CHANGE] UI: Third-party npm dependency licenses are now embedded in the Prometheus binary and served at /assets/third-party-licenses.txt, replacing the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images. #18997
Release notes of the 3.13-rc.0 release, as it was not published in partial state:
* [SECURITY] UI: Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697
* [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927
* [CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673 CVE-2023-45289). #18949
* [CHANGE] promtool: Relative file paths in the file passed to --http.config.file are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949
* [CHANGE] PromQL: Rename the min() and max() duration-expression functions (experimental feature flag experimental-duration-expr) to min_of() and max_of() to avoid confusion with the min and max aggregate operators. #18687
* [FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573
* [FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859
* [FEATURE] PromQL: Add min_of(a, b) and max_of(a, b) scalar experimental functions, returning the smaller or larger of two scalar values. #18687
* [FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564
* [FEATURE] PromQL: Expose per-query samplesRead (and samplesReadPerStep with stats=all and the promql-per-step-stats feature flag) in the query stats response, and add the prometheus_engine_query_samples_read_total engine counter. samplesRead reflects storage I/O distinct from totalQueryableSamples, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081
* [FEATURE] Scrape: Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling. #18840
* [FEATURE] TSDB: Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding (xor or xor2) at runtime, independently of the --enable-feature=xor2-encoding flag. #18769
* [FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217
* [FEATURE] Scrape: Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of the always_scrape_classic_histograms and scrape_native_histograms scrape configuration via relabeling. #18929
* [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791
* [ENHANCEMENT] PromQL: Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal. #18851
* [ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894
* [PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540
* [PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699
* [PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployments using native histograms with created-timestamp storage enabled (--enable-feature=created-timestamp-zero-ingestion). #18813
* [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS cluster without instances. #18845
* [BUGFIX] Fix race condition in initTime that could cause ErrOutOfBounds. #18629
* [BUGFIX] PromQL: A range query whose end was not aligned to step caused subqueries inside it to evaluate past the parent's last actual step, inflating peakSamples in the query stats and against the query.max-samples limit, and wasting storage I/O reading samples that were never used in the result. #18081
* [BUGFIX] PromQL: A range query containing an at-modifier-unsafe function over a range-vector with an @ modifier (e.g. predict_linear(metric[60s] @ T, X)) silently under-counted totalQueryableSamples for steps after step 0. #18081
* [BUGFIX] PromQL: Fix fill_left/fill_right producing missing samples in range queries when using group_left/group_right. #18850
* [BUGFIX] PromQL: Fix for resets() and changes() in anchored range extenders with histograms. #18906
* [BUGFIX] PromQL: Fix panic on 1[5m] smoothed and similar expressions when extended range selectors are enabled. #18764
* [BUGFIX] PromQL: Fix panic when a smoothed instant vector selector produces no samples for a series. #18943
* [BUGFIX] PromQL: Fix panic when using a parenthesised plain number as an offset (e.g. foo offset -(5)). #18768
* [BUGFIX] promtool: Fix panic when parsing exposition text containing empty braces {}. Via prometheus/common v0.69.0. #18949
* [BUGFIX] Promtool: Fix check healthy and check ready when --url ends with a trailing slash. #18854
* [BUGFIX] Rules: Close PromQL query after each rule evaluation to ensure resources are released. #18733
* [BUGFIX] Scaleway SD: Resolve VPC/IPAM-only instances that have no legacy private_ip or public_ip field, but do have private NICs attached. #18772
* [BUGFIX] TSDB: Do not leak head series when an integer histogram append is rejected (e.g. out-of-order). #18838
* [BUGFIX] UI: Escape label values offered by PromQL autocomplete. #18658
* [BUGFIX] TSDB: Fix chunk snapshot encoding for EncXOR2 chunks, preventing corruption on TSDB restart when EncXOR2-encoded series were present. #18739
* [BUGFIX] TSDB: Store a millisecond timestamp (not a WAL segment number) in walExpiries when a series is evicted via CompactStaleHead/CompactSelectedSeries, so the series's label record is correctly retained in the next WAL checkpoint and replays cleanly. #18847
* [BUGFIX] TSDB: Prevent loss of samples at the chunk-range boundary when CompactSelectedSeries (and CompactStaleHead) evict the series — the per-slice compaction loop now runs one more iteration so the boundary timestamp is captured in a block before the in-memory copy is removed. #18849
Assets 40
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
3.13.0-rc.0 / 2026-06-18
3.13.0-rc.0 / 2026-06-18 Pre-release
Pre-release
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 09 Jul 08:16
Immutable release. Only release title and notes can be modified.
v3.13.0-rc.0
This tag was signed with the committer’s verified signature.
krajorama George Krajcsovits
GPG key ID: 47A8F9CE80FD7C7F
Verified
Learn about vigilant mode.
f121644
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
* [SECURITY] UI: Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697
* [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927
* [CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673 CVE-2023-45289). #18949
* [CHANGE] promtool: Relative file paths in the file passed to --http.config.file are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949
* [CHANGE] PromQL: Rename the min() and max() duration-expression functions (experimental feature flag experimental-duration-expr) to min_of() and max_of() to avoid confusion with the min and max aggregate operators. #18687
* [FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573
* [FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859
* [FEATURE] PromQL: Add min_of(a, b) and max_of(a, b) scalar experimental functions, returning the smaller or larger of two scalar values. #18687
* [FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564
* [FEATURE] PromQL: Expose per-query samplesRead (and samplesReadPerStep with stats=all and the promql-per-step-stats feature flag) in the query stats response, and add the prometheus_engine_query_samples_read_total engine counter. samplesRead reflects storage I/O distinct from totalQueryableSamples, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081
* [FEATURE] Scrape: Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling. #18840
* [FEATURE] TSDB: Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding (xor or xor2) at runtime, independently of the --enable-feature=xor2-encoding flag. #18769
* [FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217
* [FEATURE] Scrape: Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of the always_scrape_classic_histograms and scrape_native_histograms scrape configuration via relabeling. #18929
* [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791
* [ENHANCEMENT] PromQL: Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal. #18851
* [ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894
* [PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540
* [PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699
* [PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployments using native histograms with created-timestamp storage enabled (--enable-feature=created-timestamp-zero-ingestion). #18813
* [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS cluster without instances. #18845
* [BUGFIX] Fix race condition in initTime that could cause ErrOutOfBounds. #18629
* [BUGFIX] PromQL: A range query whose end was not aligned to step caused subqueries inside it to evaluate past the parent's last actual step, inflating peakSamples in the query stats and against the query.max-samples limit, and wasting storage I/O reading samples that were never used in the result. #18081
* [BUGFIX] PromQL: A range query containing an at-modifier-unsafe function over a range-vector with an @ modifier (e.g. predict_linear(metric[60s] @ T, X)) silently under-counted totalQueryableSamples for steps after step 0. #18081
* [BUGFIX] PromQL: Fix fill_left/fill_right producing missing samples in range queries when using group_left/group_right. #18850
* [BUGFIX] PromQL: Fix for resets() and changes() in anchored range extenders with histograms. #18906
* [BUGFIX] PromQL: Fix panic on 1[5m] smoothed and similar expressions when extended range selectors are enabled. #18764
* [BUGFIX] PromQL: Fix panic when a smoothed instant vector selector produces no samples for a series. #18943
* [BUGFIX] PromQL: Fix panic when using a parenthesised plain number as an offset (e.g. foo offset -(5)). #18768
* [BUGFIX] promtool: Fix panic when parsing exposition text containing empty braces {}. Via prometheus/common v0.69.0. #18949
* [BUGFIX] Promtool: Fix check healthy and check ready when --url ends with a trailing slash. #18854
* [BUGFIX] Rules: Close PromQL query after each rule evaluation to ensure resources are released. #18733
* [BUGFIX] Scaleway SD: Resolve VPC/IPAM-only instances that have no legacy private_ip or public_ip field, but do have private NICs attached. #18772
* [BUGFIX] TSDB: Do not leak head series when an integer histogram append is rejected (e.g. out-of-order). #18838
* [BUGFIX] UI: Escape label values offered by PromQL autocomplete. #18658
* [BUGFIX] TSDB: Fix chunk snapshot encoding for EncXOR2 chunks, preventing corruption on TSDB restart when EncXOR2-encoded series were present. #18739
* [BUGFIX] TSDB: Store a millisecond timestamp (not a WAL segment number) in walExpiries when a series is evicted via CompactStaleHead/CompactSelectedSeries, so the series's label record is correctly retained in the next WAL checkpoint and replays cleanly. #18847
* [BUGFIX] TSDB: Prevent loss of samples at the chunk-range boundary when CompactSelectedSeries (and CompactStaleHead) evict the series — the per-slice compaction loop now runs one more iteration so the boundary timestamp is captured in a block before the in-memory copy is removed. #18849
Assets 40
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 1 shyfly8630 reacted with thumbs up emoji
All reactions
* 👍 1 reaction
1 person reacted
3.5.4 / 2026-06-17
3.5.4 / 2026-06-17
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
github-actions released this 17 Jun 15:14
Immutable release. Only release title and notes can be modified.
v3.5.4
This tag was signed with the committer’s verified signature.
roidelapluie Julien
SSH Key Fingerprint: 9eNC5Oin1ugTVXQFUl9AInWyqRDljEMJA7TyfXl9Alw
Verified
Learn about vigilant mode.
9e1e3b5
This release fixes multiple security issues.
* [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via /-/config endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18650
* [SECURITY] Dependencies: Bump golang.org/x/net to v0.55.0 and OpenTelemetry to v1.43.0 to fix reported CVEs (GO-2026-5026, GO-2026-4918, GO-2026-4985). #18934
* [SECURITY] UI: Bump mantine-ui dependencies (react-router-dom, vitest, vite, postcss) to their patched versions to resolve security advisories. #18935
* [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18792
Contributors
*
*
Phaxma and August829
Assets 39
Loading
Uh oh!
There was an error while loading. Please reload this page.
🎉 1 0xfeeddeadbeef reacted with hooray emoji ❤️ 2 firescry and Chengli02 reacted with heart emoji 🚀 1 sweetburble reacted with rocket emoji
All reactions
* 🎉 1 reaction
* ❤️ 2 reactions
* 🚀 1 reaction
4 people reacted
3.12.0 / 2026-05-28
3.12.0 / 2026-05-28
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
prombot released this 28 May 17:40
Immutable release. Only release title and notes can be modified.
v3.12.0
This tag was signed with the committer’s verified signature.
bwplotka Bartlomiej Plotka
GPG key ID: 8349A522E525B5E9
Verified
Learn about vigilant mode.
9f27dff
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
This release contains security fixes, new features (especially around PromQL and Service Discovery), performance improvements in TSDB, Start Timestamp improvements and numerous bug fixes.
Thanks to all contributors!
Key Highlights
* Security: Two security vulnerabilities have been addressed: a denial of service in remote-write (snappy decompression limit) and a secret exposure leak in STACKIT service discovery.
* PromQL & Metadata: Several features and bug fixes related to the experimental "start timestamps" support, including updates to rate(), irate(), increase(), and resets(). New experimental functions start(), end(), range(), and step() are introduced.
* TSDB Performance: Optimizations in head chunk lookup (constant time) and mmap operations to reduce CPU usage.
* Service Discovery: Added support for DigitalOcean Managed Databases and Outscale VM, along with improvements to AWS SD (IPv6 support for EC2, external ID support).
* UI: Added a web interface for deleting time series and cleaning tombstones.
Changelog
* [SECURITY] Remote: Reject snappy-compressed received requests via Remote Write whose declared decoded length exceeds the 32MB. Thanks to @hibrian827 for reporting it. #18642
* [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via /-/config endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18649
* [CHANGE] TSDB/Agent: Adds Start Timestamp field to all WAL Histogram samples in memory; used st-storage flag is enabled. #18221
* [FEATURE] API: Add /api/v1/status/self_metrics endpoint returning the current state of the Prometheus server's own metrics about itself as JSON. #18411
* [FEATURE] Discovery: Add DigitalOcean Managed Databases service discovery #18287
* [FEATURE] Prometheus: Add support for the aix/ppc64 compilation target #18321
* [FEATURE] Discovery: Add Outscale VM service discovery (outscale_sd_configs) for discovering scrape targets from the Outscale Cloud API. #18139
* [FEATURE] PromQL: Emit a warning when sort, sort_by_label or sort_by_label_desc is used within range (matrix) queries, as these functions do not have effect in that context. #18498
* [FEATURE] PromQL: Add start(), end(), range(), and step() experimental functions #17877
* [FEATURE] PromQL: Update resets() function to consider start timestamp resets. Hidden behind use-start-timestamps feature flag. #18627
* [FEATURE] Prometheus: Promote auto-reload-config as stable #18620
* [FEATURE] TSDB/Agent: Add CheckpointFromInMemorySeries option to agent.DB that enables checkpoint based on in-memory series. #17948
* [FEATURE] UI: Add a web interface for deleting time series and cleaning tombstones, accessible from the Status menu. #18390
* [FEATURE] PromQL: Use start timestamps for rate(), irate(), and increase() calculations, behind a feature flag use-start-timestamps. Doesn't work together with extended range selectors anchored and smoothed. #18344
* [FEATURE] Scrape: Added a feature flag st-synthesis which synthesizes unknown STs for scraped cumulative metrics. Useful when Remote Writing 2.0 with delta or Otel-based backends. #18279
* [FEATURE] promqltest: support @st annotation in load blocks to specify per-sample start timestamps. #18360
* [ENHANCEMENT] API: reject concurrent fgprof profiles. #18651
* [ENHANCEMENT] AWS SD: Add optional external_id field to ECS/MSK/RDS/Elasticache. #18579
* [ENHANCEMENT] AWS SD: Add optional external_id field. #17171
* [ENHANCEMENT] Discovery: Propagate SD target updates faster by introducing dynamic backoff interval instead of static 5s interval for throttling. #18187
* [ENHANCEMENT] Promtool: Add --header flag to query instant command, matching existing query range behaviour. #18418
* [ENHANCEMENT]: AWS SD: Allows EC2 service discovery to discover IPv6 addresses to communicate with target endpoints. The private IPv4 address remains the default when both IPv4 and IPv6 addresses are present. #16088
* [PERF] TSDB: Make head chunk lookup in range queries constant time instead of quadratic time #18302
* [PERF] TSDB: Skip entire stripes in mmapHeadChunks when no series need mmapping, reducing CPU utilization significantly at production-relevant scales. #18541
* [PERF] TSDB: Skip clean series during periodic head chunk mmap using cached head chunk count #18272
* [PERF] PromQL: Address FloatHistogram.KahanAdd performance regression on Go 1.26. #18568
* [BUGFIX] PromQL: Fix info() function incorrectly handling negated __name__ matchers #17932
* [BUGFIX] API: Return duration expressions in /parse_ast. #18624
* [BUGFIX] API: correctly document formats accepted for duration query request parameters (step, timeout and lookback delta) in OpenAPI spec #18305
* [BUGFIX] Scrape: AppenderV2 now tracks staleness even when OOO/duplicate series errors happen similar to AppenderV1 #18567
* [BUGFIX] Config: Validate remote_write queue_config fields at load time to prevent runtime panic and silent misconfiguration. #18209
* [BUGFIX] Discovery/Consul: Add health_filter for Health API filtering, fixing breakage when using Catalog-only fields like ServiceTags in filter. #18479 #18499
* [BUGFIX] OTLP: limit decompressed body size for gzip-encoded OTLP write requests. #18408
* [BUGFIX] PromQL: Fix smoothed rate/increase returning zero instead of no result when all data falls strictly after the query range. #18523
* [BUGFIX] PromQL: Fix metric name not being dropped when last_over_time or first_over_time is applied to subqueries containing name-dropping functions like abs(). #18409
* [BUGFIX] PromQL: Fix missing warning when mixing exponential and custom-bucket histograms in stats queries. #18660
* [BUGFIX] PromQL: Fix parsing of range() keyword in duration expressions such as foo[5m+range()]. #18623
* [BUGFIX] PromQL: Fix smoothed vector selector returning no results in binary operations when the @ modifier is used. #18531
* [BUGFIX] PromQL: Reject NaN, infinite, and out-of-range duration expressions instead of silently producing an out-of-range time.Duration. #18639
* [BUGFIX] Scrape: Fix panic when scraping malformed native histograms. #18414
* [BUGFIX] Scrape: fix panic when scraping a target exposing a summary with no quantiles via the protobuf format. #18382
* [BUGFIX] Scrape: fix scrape failure log file occasionally not applied after a configuration reload. #18421
* [BUGFIX] TSDB: Allow retention percentage with new data path. #18628
* [BUGFIX] TSDB: Preserve decimal precision in percentage-based retention #18374
* [BUGFIX] TSDB: fix prometheus_tsdb_head_chunks going negative after WAL replay #18401
* [BUGFIX] TSDB: panic with native histograms during query of overlapping chunks. #18692
* [BUGFIX] Tracing: fix startup failure for insecure OTLP HTTP tracing #18469
* [BUGFIX] UI: Escape label values offered by PromQL autocomplete. #18658
* [BUGFIX] UI: Improve Y-axis tick label precision for graph values over small ranges. #18682
* [BUGFIX] prometheus_sd_refresh* and prometheus_sd_discovered_targets metrics for specific scrape jobs are deleted when the scrape job is removed. #17614
* [BUGFIX] Remote: fixed validation for received RW2 requests when parsing metadata unit symbols. This fixes a case when request would cause (recovered) handler panic. #18641
* [BUGFIX] TSDB/Agent: fix race in agent appender where concurrent appends for the same label set could produce duplicate in-memory series and duplicate WAL records. #18292
* [BUGFIX] Config: Update --enable-feature flag description and sort feature names. #18487
Contributors
*
*
*
Phaxma, August829, and hibrian827
Assets 40
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 8 liv-io, showmidelo, LMieldazis, sweetburble, GiedriusS, daveprowse, Sanchit2662, and mihalewiktor reacted with thumbs up emoji 🚀 2 0xfeeddeadbeef and une-mouche reacted with rocket emoji
All reactions
* 👍 8 reactions
* 🚀 2 reactions
10 people reacted
3.12.0-rc.0 / 2026-05-19
3.12.0-rc.0 / 2026-05-19 Pre-release
Pre-release
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
prombot released this 19 May 10:46
Immutable release. Only release title and notes can be modified.
v3.12.0-rc.0
This tag was signed with the committer’s verified signature.
bwplotka Bartlomiej Plotka
GPG key ID: 8349A522E525B5E9
Verified
Learn about vigilant mode.
36cf4a8
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
This release contains security fixes, new features (especially around PromQL and Service Discovery), performance improvements in TSDB, Start Timestamp improvements and numerous bug fixes.
Thanks to all contributors!
Key Highlights
* Security: Two security vulnerabilities have been addressed: a denial of service in remote-write (snappy decompression limit) and a secret exposure leak in STACKIT service discovery.
* PromQL & Metadata: Several features and bug fixes related to the experimental "start timestamps" support, including updates to rate(), irate(), increase(), and resets(). New experimental functions start(), end(), range(), and step() are introduced.
* TSDB Performance: Optimizations in head chunk lookup (constant time) and mmap operations to reduce CPU usage.
* Service Discovery: Added support for DigitalOcean Managed Databases and Outscale VM, along with improvements to AWS SD (IPv6 support for EC2, external ID support).
* UI: Added a web interface for deleting time series and cleaning tombstones.
Changelog
* [SECURITY] Remote: Reject snappy-compressed received requests via Remote Write whose declared decoded length exceeds the 32MB. Thanks to @hibrian827 for reporting it. #18642
* [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via /-/config endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18649
* [CHANGE] TSDB/Agent: Adds Start Timestamp field to all WAL Histogram samples in memory; used st-storage flag is enabled. #18221
* [FEATURE] API: Add /api/v1/status/self_metrics endpoint returning the current state of the Prometheus server's own metrics about itself as JSON. #18411
* [FEATURE] Discovery: Add DigitalOcean Managed Databases service discovery #18287
* [FEATURE] Prometheus: Add support for the aix/ppc64 compilation target #18321
* [FEATURE] Discovery: Add Outscale VM service discovery (outscale_sd_configs) for discovering scrape targets from the Outscale Cloud API. #18139
* [FEATURE] PromQL: Emit a warning when sort, sort_by_label or sort_by_label_desc is used within range (matrix) queries, as these functions do not have effect in that context. #18498
* [FEATURE] PromQL: Add start(), end(), range(), and step() experimental functions #17877
* [FEATURE] PromQL: Update resets() function to consider start timestamp resets. Hidden behind use-start-timestamps feature flag. #18627
* [FEATURE] Prometheus: Promote auto-reload-config as stable #18620
* [FEATURE] TSDB/Agent: Add CheckpointFromInMemorySeries option to agent.DB that enables checkpoint based on in-memory series. #17948
* [FEATURE] UI: Add a web interface for deleting time series and cleaning tombstones, accessible from the Status menu. #18390
* [FEATURE] PromQL: Use start timestamps for rate(), irate(), and increase() calculations, behind a feature flag use-start-timestamps. Doesn't work together with extended range selectors anchored and smoothed. #18344
* [FEATURE] Scrape: Added a feature flag st-synthesis which synthesizes unknown STs for scraped cumulative metrics. Useful when Remote Writing 2.0 with delta or Otel-based backends. #18279
* [FEATURE] promqltest: support @st annotation in load blocks to specify per-sample start timestamps. #18360
* [ENHANCEMENT] API: reject concurrent fgprof profiles. #18651
* [ENHANCEMENT] AWS SD: Add optional external_id field to ECS/MSK/RDS/Elasticache. #18579
* [ENHANCEMENT] AWS SD: Add optional external_id field. #17171
* [ENHANCEMENT] Discovery: Propagate SD target updates faster by introducing dynamic backoff interval instead of static 5s interval for throttling. #18187
* [ENHANCEMENT] Promtool: Add --header flag to query instant command, matching existing query range behaviour. #18418
* [ENHANCEMENT]: AWS SD: Allows EC2 service discovery to discover IPv6 addresses to communicate with target endpoints. The private IPv4 address remains the default when both IPv4 and IPv6 addresses are present. #16088
* [PERF] TSDB: Make head chunk lookup in range queries constant time instead of quadratic time #18302
* [PERF] TSDB: Skip entire stripes in mmapHeadChunks when no series need mmapping, reducing CPU utilization significantly at production-relevant scales. #18541
* [PERF] TSDB: Skip clean series during periodic head chunk mmap using cached head chunk count #18272
* [PERF] PromQL: Address FloatHistogram.KahanAdd performance regression on Go 1.26. #18568
* [BUGFIX] PromQL: Fix info() function incorrectly handling negated __name__ matchers #17932
* [BUGFIX] API: Return duration expressions in /parse_ast. #18624
* [BUGFIX] API: correctly document formats accepted for duration query request parameters (step, timeout and lookback delta) in OpenAPI spec #18305
* [BUGFIX] Scrape: AppenderV2 now tracks staleness even when OOO/duplicate series errors happen similar to AppenderV1 #18567
* [BUGFIX] Config: Validate remote_write queue_config fields at load time to prevent runtime panic and silent misconfiguration. #18209
* [BUGFIX] Discovery/Consul: Add health_filter for Health API filtering, fixing breakage when using Catalog-only fields like ServiceTags in filter. #18479 #18499
* [BUGFIX] OTLP: limit decompressed body size for gzip-encoded OTLP write requests. #18408
* [BUGFIX] PromQL: Fix smoothed rate/increase returning zero instead of no result when all data falls strictly after the query range. #18523
* [BUGFIX] PromQL: Fix metric name not being dropped when last_over_time or first_over_time is applied to subqueries containing name-dropping functions like abs(). #18409
* [BUGFIX] PromQL: Fix missing warning when mixing exponential and custom-bucket histograms in stats queries. #18660
* [BUGFIX] PromQL: Fix parsing of range() keyword in duration expressions such as foo[5m+range()]. #18623
* [BUGFIX] PromQL: Fix smoothed vector selector returning no results in binary operations when the @ modifier is used. #18531
* [BUGFIX] PromQL: Reject NaN, infinite, and out-of-range duration expressions instead of silently producing an out-of-range time.Duration. #18639
* [BUGFIX] Scrape: Fix panic when scraping malformed native histograms. #18414
* [BUGFIX] Scrape: fix panic when scraping a target exposing a summary with no quantiles via the protobuf format. #18382
* [BUGFIX] Scrape: fix scrape failure log file occasionally not applied after a configuration reload. #18421
* [BUGFIX] TSDB: Allow retention percentage with new data path. #18628
* [BUGFIX] TSDB: Preserve decimal precision in percentage-based retention #18374
* [BUGFIX] TSDB: fix prometheus_tsdb_head_chunks going negative after WAL replay #18401
* [BUGFIX] TSDB: panic with native histograms during query of overlapping chunks. #18692
* [BUGFIX] Tracing: fix startup failure for insecure OTLP HTTP tracing #18469
* [BUGFIX] UI: Escape label values offered by PromQL autocomplete. #18658
* [BUGFIX] UI: Improve Y-axis tick label precision for graph values over small ranges. #18682
* [BUGFIX] prometheus_sd_refresh* and prometheus_sd_discovered_targets metrics for specific scrape jobs are deleted when the scrape job is removed. #17614
* [BUGFIX] Remote: fixed validation for received RW2 requests when parsing metadata unit symbols. This fixes a case when request would cause (recovered) handler panic. #18641
* [BUGFIX] TSDB/Agent: fix race in agent appender where concurrent appends for the same label set could produce duplicate in-memory series and duplicate WAL records. #18292
* [BUGFIX] Config: Update --enable-feature flag description and sort feature names. #18487
Contributors
*
*
*
Phaxma, August829, and hibrian827
Assets 40
Loading
Uh oh!
There was an error while loading. Please reload this page.
❤️ 4 benahmed911, nicolastakashi, bodz1lla, and savitarMK reacted with heart emoji
All reactions
* ❤️ 4 reactions
4 people reacted
3.11.3 / 2026-04-27
3.11.3 / 2026-04-27
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
prombot released this 27 Apr 15:56
Immutable release. Only release title and notes can be modified.
v3.11.3
This tag was signed with the committer’s verified signature.
roidelapluie Julien
SSH Key Fingerprint: 9eNC5Oin1ugTVXQFUl9AInWyqRDljEMJA7TyfXl9Alw
Verified
Learn about vigilant mode.
eb173f5
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
This release fixes mutiple security issues.
We would like to thank the following people for the responsible disclosures:
* Shadowbyte (4c1dr3aper) - Charlie Lewis for the Remote-Read snappy decode vulnerability.
* Brett Gervasoni for the AzureAD OAuth client_secret vulnerability.
* @iiihaiii and @ngocnn97 for the Old UI XSS vulnerability.
* [SECURITY] AzureAD remote write: Fix OAuth client_secret being exposed in plaintext via /-/config endpoint. GHSA-wg65-39gg-5wfj / CVE-2026-42151 #18590
* [SECURITY] Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. GHSA-8rm2-7qqf-34qm / CVE-2026-42154 #18584
* [SECURITY] UI: Fix stored XSS via unescaped le label values in old UI heatmap chart tick labels. GHSA-fw8g-cg8f-9j28 #18588
Contributors
*
*
ngocnn97 and iiihaiii
Assets 39
Loading
Uh oh!
There was an error while loading. Please reload this page.
👍 2 sweetburble and mur-me reacted with thumbs up emoji ❤️ 4 karimz1, gabriellxxix, mur-me, and savitarMK reacted with heart emoji
All reactions
* 👍 2 reactions
* ❤️ 4 reactions
5 people reacted
Previous 1 2 3 4 5 … 37 38 Next
Previous Next
Footer
© 2026 GitHub, Inc.
Footer navigation
* Terms
* Privacy
* Security
* Status
* Community
* Docs
* Contact
* Manage cookies
* Do not share my personal information
You can’t perform that action at this time.
Tip: Zvýrazněte text, který chcete sdílet nebo přidat do seznamů ignorovaných.
— Download difference patch
For now, Differences are performed on text, not graphically, only the latest screenshot is available.
Snímek obrazovky vyžaduje aktivaci nástroje Playwright/WebDriver