fix(deps): update module github.com/caddyserver/caddy/v2 to v2.11.7 #14
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
dawid/caddy-cdn-ranges!14
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/all-patch"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v2.11.4→v2.11.7Release Notes
caddyserver/caddy (github.com/caddyserver/caddy/v2)
v2.11.7Compare Source
This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. If you're on 2.11.6, we recommend upgrading. It also adds support for the brand new
Incrementalheader field (RFC 10036).Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.
Highlights
Fixed: crash and dropped streams caused by the new idle timeouts. 2.11.6 introduced default idle read/write timeouts, which caused some problems:
In 2.11.6, the request body's idle deadline could outlive the handler that set it:
POST, were cut off exactly 60 seconds after the body was read. (#8103)Both are fixed in #8107. Thanks @steadytao!
Over HTTP/2, streaming responses that paused between writes for longer than
write_idle(1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks @WeidiDeng! (#8118, #8119)Fixed: placeholders for missing cookies are empty again. Since 2.11.6, places that keep unknown placeholders as written, like
respondheaders, would output{http.request.cookie.*}literally when the cookie wasn't in the request. The same happened to{http.request.tls.*}on plain HTTP requests. Both are empty again. Thanks @steadytao! (#8019)New: support for the
Incrementalheader field (RFC 10036). It's the standard replacement for NGINX's proprietaryX-Accel-Bufferingheader. If an upstream response hasIncremental: ?1,reverse_proxyforwards it immediately, the same asflush_interval -1, andencodestreams it instead of holding it back. Great for Mercure, SSE and other streaming apps.request_buffersorresponse_buffersoptions would prevent incremental forwarding, Caddy responds with501 Not Implementedinstead of silently buffering, as the RFC requires.proxy_status_nameoption adds aProxy-Statusheader to those responses, explaining why the message was refused.Thanks @dunglas! (#8020)
Faster TLS handshakes: When nothing subscribes to certificate events and debug logging is off, CertMagic no longer builds event data for every handshake. Certificate lookup per handshake is about twice as fast, with 10 allocations instead of 15. Thanks @u5surf! (#8010)
Unix sockets: When a reload moves a listener (or the admin endpoint) off a Unix socket, the old socket now closes right away and its file is removed. Before, clients connecting to the old path would hang until the next garbage collection, about 2 minutes later. Thanks @littfed! (#8061)
Headers handler: Multiple
Set-Cookievalues in a JSON config'ssetare now sent as separate header fields, instead of being joined with commas into one field that clients can't parse. Thanks @Indra55! (#8080)caddy fmtno longer deletes an opening brace at the very end of the input. Thanks @n0liu! (#8047)What's Changed
New Contributors
Full Changelog: https://github.com/caddyserver/caddy/compare/v2.11.6...v2.11.7
v2.11.6Compare Source
This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!
We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.
Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.
⚠️ Please read the breaking changes below before upgrading. Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it.
Highlights
url_patternrequest matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matchingurl_patternCEL function too. Thanks @dunglas! (#7787)timeoutshandler directive for per-route tuning. (#7913)tls_automate_namesglobal option: Manage certificates for names without serving them in a site block. (#8015)expected_underscore_headersserver option: If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. (#7809)versions 3upstreams now honortls_trust_pool(#8042)random_choosepolicy distributes correctly now (#7873)encodenow stream immediately instead of being buffered. (#7905)importnow works inside named routes (#7986), and quoted braces are treated as literal arguments (#7875).set_cookielog filter (#7888)roll_intervalaccepts days (d) (#7900){http.request.proto_name}placeholder (#7782)SERVER_ADDR(#7912)authenticationproviders no longer clobber each other's responses (#7904)⚠️ Breaking changes
431 Request Header Fields Too Large. If you need more, raise it with themax_header_sizeserver option.read_body_idleandwrite_idlein thetimeoutsserver option, or per-route with thetimeoutsdirective. (#7913).are now dropped, the same way underscores were in 2.11.4. PHP folds.to_, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the newexpected_dot_headersserver option.client_authno longer applies to more specific hostnames that have their own site blocks. For example,public.example.comno longer inherits mTLS from*.example.com. If you were counting on that inheritance, configureclient_authon the specific site explicitly. (#7920)named_routes(#7800)forward_authuri(#7814)weighted_round_robinweights (#7807)browsefile_limit(#7988)mapinputs (#8067)mapdestination placeholders (#8074)@version separators (#7974)/loadnow returns400with warnings inside a valid JSON body when a config is invalid. Before, it returned200with two concatenated JSON objects. (#7267)methodmatcher values are normalized to uppercase, somethod getnow matchesGETrequests. (#7832)Security fixes
Thank you to everyone who reported responsibly and helped with patches:
forward_authandreverse_proxy, a request could be sent on the wrong upstream connection. Reported by @carlt, fixed by @WeidiDeng. (GHSA-6365-7ppr-5r92, #7859)101 Switching Protocolsresponses too. Thanks @jirn073-76.handle_pathanduristrip_prefix/strip_suffixnow canonicalize the resulting path, so it can't bypass path-based authorization. Thanks @steadytao..(see above) to prevent bypassingforward_auth copy_headerswith PHP/FastCGI backends. Thanks @dunglas.path_regexpmatcher now normalizes Windows backslashes like thepathmatcher does. This completes the fix for CVE-2026-52844. Thanks @thientd. (#7858)Proxyheader is no longer passed to backends asHTTP_PROXY(HTTPoxy). Thanks @bzyy1024. (#7934)413. Thanks @hktitof. (#7969)⚠️ These security patches may be breaking if your application relies on the buggy behaviors.
🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your
go.modfile. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. Note that doing so now also requires Go 1.26.Thank you to everyone who was involved this release, especially our 40 new contributors! 🎉
What's Changed
d(day) inroll_intervaldirective by @mohammed90 in #7900MaxSizeSubjectsListForLogoff-by-one whenmaxToDisplayis0by @mohammed90 in #7970tls_automate_namesglobal option by @IslamElsayed in #8015New Contributors
Full Changelog: https://github.com/caddyserver/caddy/compare/v2.11.4...v2.11.6
v2.11.5Compare Source
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
Branch automerge failure
This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.