Go SDK 1.9.0
fsthttp: add Headless bot type fsthttp: make fsthttp.Transport (net/http adapter) goroutine-safe fsthttp: improve error messages when fanout is not enabled all: improve error handling in examples and tests
fsthttp: add Headless bot type fsthttp: make fsthttp.Transport (net/http adapter) goroutine-safe fsthttp: improve error messages when fanout is not enabled all: improve error handling in examples and tests
View this release on GitHub. BUG FIXES: fix(service_compute): process healthcheck blocks before backend blocks so backends referencing a healthcheck created in the same apply do not fail with No healthcheck named '<name>' (#1384) fix(service_vcl): process dictionary and response_object blocks before rate_limiter blocks so a rate limiter referencing a dictionary or response object created in the sa…
View this release on GitHub. Bug Fixes: fix(compute): add Python starter kit to the static config (#1877) Enhancements: feat(audit-log): add event-mapping command group (#1875) Dependencies: build(deps): github.com/rogpeppe/go-internal from 1.15.0 to 1.16.0 (#1871)
The Next-Gen WAF Rules and Next-Gen WAF Signals APIs now include a created_by field in responses, identifying the email of the user who created the rule or signal.
Several Next-Gen WAF API endpoints were missing documentation for error response codes they can return. Endpoints across Agents, Agent Keys, Custom Dashboards, Events, Lists, Rate Limited Sources, Redactions, Reports, Requests, Rules, Signals, Simulate, Thresholds, Timeseries, Virtual Patches, Workspace Alerts, and Workspaces now document the full set of error responses they can return.
View this release on GitHub. ENHANCEMENTS: feat(fastly_integration): add support for datadog, jiraissue, jsm, opsgenie, and splunkoncall integration types (#1374) BUG FIXES: fix(service): update versionless name and comment attributes regardless of activate and stage settings (#1369) Dependencies build(deps): google.golang.org/grpc from 1.79.3 to 1.82.1 (#1360) build(deps): github.com/fastly/go-fa…
View this release on GitHub. Bug Fixes: fix(service-version): support autoclone when staging a service version. (#1850) fix(logging): the placement flag for all loggging commands can now be reset back to null by setting it's value to "" when it was previously set to another value (#1855) fix(profile): profiles can now be created and updated with service-limited tokens, which cannot access /current…
Fixed Disallow accessing HTML rewriter elements outside of handlers (#1541) (bf4ac3d) dynamic backends disabled exception (#1535) (432d059) Make headers of cloned requests independent (#1539) (9b34c43) Memory leak in Backend::health_for_name (#1542) (43e03d2) Memory leak in Device::lookup (#1543) (2f02080) URLSearchParams premature free (#1538) (da5146c)
An arbitrary file read vulnerability that can potentially enable remote code execution (RCE) has been found in Ruby on Rails Active Storage and has been assigned CVE-2026-66066. Fastly has created a virtual patch for it that is now available within your account. To activate it and add protection to your services, follow the steps for your control panel below. Next-Gen WAF control panel From the Ru…
Improved logging to include failed-open requests.
Fixed release: target was renamed with this version bump (#1532) (fffa2d2)
Fixed ci: get releases working for real this time (#1531) (0c734bd) Miscellaneous Chores release 3.44.1 (9061855)
Fastly DNS is our authoritative DNS service that leverages Fastly's global, high-performance edge network to serve DNS query responses.
Added bot detection (#1524) (0b26045) Fixed cache: handle error (#1519) (a8d55a8) tests: fix failing cache test (#1520) (8e56d11) tests: Make test suite properly fail when a test fails (#1518) (ea4c7c7)
Fixed Allow 0 ttl for responses (#1498) (55005ce) docs: fix docs generation (b2b4752) fmt: format with updated prettier (c4f36ad) reset SDK state between requests (#1488) (e049f97) Reusable sandbox tests (#1515) (c038f48) tests: only run null-304-body test when http-cache enabled (#1505) (58e72b0)
View this release on GitHub. ENHANCEMENTS: feat(tls_subscription_validation): expose computed certificate_id, allowing issuance-dependent resources to be chained in a single apply (#1345) feat(tls/subscription): include subscription ID and domains in fastly_tls_subscription API error messages so failing resources can be identified when managing many subscriptions (#1344) BUG FIXES: fix(logging): V…
You can now use the Historical Domain Inspector API and the Real-Time Domain Inspector API to understand the distribution of TLS and HTTP versions used by incoming requests.
A chain of vulnerabilities leading to remote code execution (RCE) have been found in WordPress and have been assigned CVE-2026-63030 and CVE-2026-60137, colloquially known as wp2shell. Fastly has created a virtual patch for it that is now available within your account. To activate it and add protection to your services, follow the steps for your control panel below. Next-Gen WAF control panel From…
Removed the Ruby/ERB runtime dependency by generating agent configuration directly in the startup wrapper.
View this release on GitHub. BUG FIXES: fix(ngwaf/signals): increase character limit of the name attribute to 128 (#1338) fix(ngwaf/rules): allow templated_signal rules to be created without conditions (#1330) Dependencies build(deps): go.mongodb.org/mongo-driver from 1.17.4 to 1.17.7 (#1309) build(deps): github.com/fastly/go-fastly/v16 from 15.0.3 to 16.0.0 (#1332) build(deps): github.com/fastly/…
Fixed an issue introduced in 4.80.0 where the agent may not inspect traffic as expected under certain configurations.
Fixed an issue introduced in 4.80.0 where the agent may not inspect traffic as expected under certain configurations. Upgraded to Golang 1.26.4 Improved CMDEXE detection Improved TRAVERSAL detection Improved XSS detection Updated base GeoIP data: July 2026
View this release on GitHub. Bug Fixes: fix(auth): accept SSO JWT audiences with or without a trailing slash when validating the Fastly API endpoint. (#1837) feat(compute): add install-tools command to pre-install the Viceroy binary (#1833) Enhancements: feat(ngwaf/timeseries): add support for account and workspace times series commands (#1823) Dependencies: build(deps): github.com/fastly/go-fastl…
Upgraded to Golang 1.26.4 Improved CMDEXE detection Improved TRAVERSAL detection Improved XSS detection Updated base GeoIP data: July 2026
Five new integration types are now supported in the Notifications API: Datadog, Jira Issue, Jira Service Management, OpsGenie, and Splunk On-Call. You can use these integrations to route observability alerts and audit log event notifications to the tools your team already uses for incident management and issue tracking.
If you don't have access to the Next-Gen WAF in the Fastly control panel, you can now connect your Fastly account to your Next-Gen WAF corp. Once connected, you gain access to the Next-Gen WAF and (if purchased) Bot Management through the Fastly control panel and Fastly API while retaining access to the Next-Gen WAF control panel and Next-Gen WAF API. As your WAF configurations and user accounts a…
We've introduced a new Routing Configurations API that allows you to define routing rules based on URL paths and conditions to route traffic to different services. We've also updated the Domains API to support associating domains with routing configurations, allowing you to apply those rules consistently across multiple domains.
You can now create, manage, and query notification event mappings using the new Event Mappings API. Event mappings define which Fastly audit events trigger notifications to your configured integrations, and for which services or workspaces. Mappings can be scoped account-wide or targeted to specific CDN (VCL) services, Compute (Wasm) services, or Next-Gen WAF workspaces. Two discovery endpoints ar…
You can now use the Historical Stats API and the Real-Time Analytics API to troubleshoot backend Compute errors. Sixteen new metrics attribute each backend Compute error to TLS, HTTP, DNS, connection issues, or other sources.
View this release on GitHub. Enhancements: feat(kvstoreentry/delete): Add support for multiple-key deletion using a key prefix. (#1822) build(dockerfile-go): add Go Dockerfile alongside the existing Node and Rust ones (#1828) feat(compute/deploy): Support 'contentguard' configuration on 'bot_management' product under [setup.products] (#1827) Dependencies: build(deps): github.com/nwaples/rardecode/…