Ad
 
Learn More
Favicon of Fiber Releases

Fiber Releases

Active

Fiber • Last updated 13 days ago

Activity Score

85/100
Recency:25/30
Cadence:20/30
Completeness:30/30
Health:10/10
  • Updated in the last month
  • 2 updates in last 30 days
  • Complete entries with dates, titles, URLs, and summaries

Recent Updates

v3.5.0

🚀 New Harden proxy middleware ( #4405 ) New proxy.SecurityPolicy with secure defaults: private/loopback upstreams, non-http(s) schemes and HTTPS-to-HTTP redirect downgrades are rejected and hop-by-hop headers stripped. proxy . WithSecurityPolicy (proxy. SecurityPolicy { AllowPrivateIPs : true , // internal upstreams are blocked by default }) https://docs.gofiber.io/middleware/proxy#security Add support for custom binding precedence ( #4544 ) New binding_source struct tag overrides the Bind().All() source order per struct; the resolved order is cached per reflect.Type . type SearchReq struct { Name string `binding_source:"query,header,cookie,body,uri" query:"name" header:"x-name" json:"name"` } https://docs.gofiber.io/api/bind#custom-precedence Add SkipUnmatchedRoutes with two-tier 404/405 fast path ( #4486 ) New fiber.Config option that answers unregistered paths with 404 / 405 before the middleware chain runs (CORS preflight exempt, off by default). app := fiber . New (fiber. Config { SkipUnmatchedRoutes : true , // default: false }) https://docs.gofiber.io/api/fiber#skipunmatchedroutes 🧹 Updates Speed up route matching with a flat tree index, leading-byte candidate rejection and a specialized /const/:param matcher ( #4558 ) Quick-reject routes on precomputed slash-count bounds ( #4517 ) Restore Route inlining lost in the RFC 9110 changes ( #4501 ) Skip the Accept join allocation in the Format emptiness check ( #4503 ) Skip the ip.String() allocation in IsProxyTrusted for CIDR-only trust configs ( #4500 ) Adopt SWAR-accelerated utils helpers in hot-path scanners ( #4536 ) Adopt gofiber/utils v2.2.0 helpers across hot paths ( #4542 ) Adopt gofiber/utils v2.4.0 helpers and optimize adaptor/proxy hot paths ( #4557 ) adaptor: Cut allocations on the net/http bridge ( #4559 ) cache: Optimize key generation and allocation ( #4608 ) cors: Fold preflight Vary calls into one header scan ( #4502 ) csrf: Optimize trusted subdomain matching ( #4543 ) proxy: Optimize balancer round-robin ( #4549 ) session: Use make() to preallocate relevantExtractors ( #4562 ) De-flake the clock-sensitive tests ( #4575 ) 🐛 Fixes Fix open redirects in composed route URLs and redirect rules ( #4584 ) Preserve published route buckets during rebuilds ( #4579 ) URL-encode query values in Redirect.Route ( #4529 ) Accept the full float64 range in the float route constraint ( #4528 ) Match HTTP field names the way a recipient must ( #4585 ) Honor Accept weights followed by whitespace before the comma ( #4550 ) Compare Accept media types case-insensitively ( #4493 ) Honor q=0 rejections in content negotiation ( #4508 ) Honor duplicate Content-Encoding after empty values ( #4514 ) Improve RFC 9110 compliance across req/res/ctx, helpers and middleware ( #4494 ) Avoid reading omitted request bodies in Bind.All ( #4565 ) Combine repeated proxy headers for client IP extraction ( #4568 ) Close the listener on Listen error paths to avoid FD leaks ( #4532 ) Fire OnPostShutdown once with the real shutdown error ( #4531 ) Keep all NewErrorf args when the first isn't a format string ( #4530 ) adaptor: Preserve Connection tokens ( #4606 ) cache: Honor only-if-cached for non-shareable entries ( #4589 ) cache: Stop charging its own latency as response age ( #4578 ) healthcheck: Answer HEAD probes with the GET status ( #4577 ) limiter: Floor sub-second expiration in the sliding window ( #4564 ) proxy: Classify IPv6 transition addresses correctly in upstream validation ( #4553 ) proxy: Guard runtime helpers against DNS rebinding ( #4518 ) proxy: Preserve empty-query URL semantics ( #4513 ) redirect: Rank wildcards behind character classes in rule ordering ( #4607 ) static: Fix leading-slash normalization for fs.FS root paths ( #4507 ) Fix client redirect handling, TLS diagnostics and the JSONP callback ( #4586 ) Fix correctness issues across log injection, cookie jar, routing and Content-Type handling ( #4570 ) 🛠️ Maintenance 22 changes bump github.com/klauspost/compress from 1.19.1 to 1.19.2 ( #4602 ) bump DavidAnson/markdownlint-cli2-action from 24.1.0 to 24.2.0 ( #4583 ) bump release-drafter/release-drafter from 7.6.0 to 7.7.0 ( #4566 ) bump github.com/gofiber/utils/v2 from 2.4.0 to 2.4.1 ( #4567 ) bump github.com/valyala/fasthttp from 1.72.0 to 1.73.0 in the fasthttp-modules group ( #4561 ) bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 ( #4556 ) bump actions/checkout from 7.0.0 to 7.0.1 ( #4551 ) bump github.com/klauspost/compress from 1.19.0 to 1.19.1 ( #4548 ) bump github.com/gofiber/schema from 1.8.2 to 1.8.3 ( #4547 ) bump release-drafter/release-drafter from 7.5.1 to 7.6.0 ( #4546 ) bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 ( #4545 ) bump actions/setup-go from 6.5.0 to 7.0.0 ( #4541 ) bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 ( #4540 ) bump github.com/shamaton/msgpack/v3 from 3.1.2 to 3.2.0 ( #4538 ) bump actions/setup-node from 6.4.0 to 7.0.0 ( #4537 ) bump github.com/gofiber/schema from 1.8.1 to 1.8.2 ( #4535 ) bump github.com/gofiber/utils/v2 from 2.1.1 to 2.1.2 ( #4520 ) bump the golang-modules group with 3 updates ( #4515 ) bump DavidAnson/markdownlint-cli2-action from 23.2.0 to 24.0.0 ( #4506 ) bump golang.org/x/sys from 0.46.0 to 0.47.0 in the golang-modules group ( #4511 ) bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-modules group ( #4509 ) bump github.com/gofiber/schema from 1.8.0 to 1.8.1 ( #4510 ) 📚 Documentation Explain adjacent multi-param capture rules ( #4597 ) Document Ctx as a never-cancelable context ( #4560 ) Move README.md to the repo root so pkg.go.dev renders it ( #4505 ) logger: Explain when the error tag is populated ( #4592 ) 📒 Documentation : https://docs.gofiber.io/ 💬 Discord : https://gofiber.io/discord Full Changelog : v3.4.0...v3.5.0 Thank you @0xghost42 , @ATKasem , @Rachit-Gandhi , @ReneWerner87 , @RubenPari , @SivaPA08 , @aryan-finbox , @aryan262 , @gaby , @james-yusuke , @nikolauspschuetz , @sueun-dev and @sunghyun1999 for making this release possible.

Read more →

v2.52.15

🐛 Bug Fixes idempotency: release MemoryLock keys on unlock #4569 Full Changelog : v2.52.14...v2.52.15

Read more →

v2.52.14

What's Changed 🐛 Bug Fixes backport BalancerForward X-Real-IP overwrite fix to v2 by @terraincognita07 in #4495 New Contributors @terraincognita07 made their first contribution Full Changelog : v2.52.13...v2.52.14

Read more →

v3.4.0

🚀 New Complete HTTP QUERY method support ( #4436 , #4456 ) Adds the HTTP QUERY method ( RFC 10008 ): fiber.MethodQuery , app.Query() routing, safe/idempotent handling in csrf, idempotency, earlydata and cache, plus client.Query() shorthands. app . Query ( "/search" , func ( c fiber. Ctx ) error { return c . Send ( c . Body ()) // QUERY carries the query expression in the body }) https://docs.gofiber.io/client/rest#query Add WithContext variants for session storage I/O ( #4393 ) SaveWithContext , DestroyWithContext , RegenerateWithContext and ResetWithContext propagate deadlines/cancellation to the session storage backend; the plain methods keep working unchanged. sess := session . FromContext ( c ) err := sess . SaveWithContext ( ctx ) // storage write bounded by ctx https://docs.gofiber.io/middleware/session#session-with-context-timeoutscancellation Unify internal and custom constraints into a single interface ( #4397 ) Built-in and custom route constraints now share one ConstraintHandler interface; the optional ConstraintAnalyzer precomputes constraint data at route registration, removing per-request parsing. Existing CustomConstraint implementations keep working unchanged. app . RegisterCustomConstraint ( evenConstraint {}) // implements Name() + Execute() app . Get ( "/items/:id<even>" , handler ) https://docs.gofiber.io/guide/routing#constrainthandler-interface Expose prefork RecoverInterval and ShutdownGracePeriod ( #4491 ) New ListenConfig knobs: PreforkRecoverInterval delays respawning a crashed child (default 0 ) and PreforkShutdownGracePeriod sets how long the master waits after SIGTERM before SIGKILL (default 5s ). app . Listen ( ":3000" , fiber. ListenConfig { EnablePrefork : true , PreforkRecoverInterval : time . Second , PreforkShutdownGracePeriod : 10 * time . Second , }) https://docs.gofiber.io/api/fiber#preforkrecoverinterval 🧹 Updates Reduce avoidable work in the request hot path ( #4490 ) Avoid per-request heap allocation in DefaultErrorHandler ( #4446 ) Use sentinel errors on typed-getter and Range parse failures ( #4448 ) Replace appendLowerBytes with utilsbytes.UnsafeToLower ( #4468 ) Add MIMETextEventStream constant ( #4415 ) Cache binder decoder type metadata across requests ( #4447 ) Eliminate double reflection in binder mergeStruct (-10% allocs) ( #4385 ) Reduce binder data map allocations ( #4379 ) cache: Append canonical key segments into the pooled buffer ( #4450 ) cors: Optimize subdomain origin matching ( #4482 ) cors: Optimize exact-origin lookup to O(1) ( #4368 ) csrf/redirect: Share scheme/host matching and skip url.Parse on the hot path ( #4449 ) Narrow client user hook lock scope safely ( #4375 ) Raise middleware coverage above 90% for timeout, logger, idempotency, limiter, cache ( #4466 ) Cover remaining cors/csrf middleware branches ( #4462 ) Add unit tests for isOriginSerializedOrNull ( #4461 ) Cover session deadline/error paths and delegate Middleware lifecycle methods ( #4435 ) Inject clock to make time-dependent tests deterministic ( #4430 ) Rename benchmark cases ( #4383 ) Remove test-only dead code and add manual deadcode workflow ( #4458 ) Remove dead code flagged by static analysis ( #4454 ) Static analysis cleanups ( #4444 ) Fix modernize lint issues ( #4315 ) 🐛 Fixes Evaluate If-Modified-Since when If-None-Match is absent in Fresh ( #4488 ) Fix open redirect via Redirect().Back() by validating the Referer header origin ( #4370 ) Fix data race on lazy appListKeys generation in Render ( #4440 ) Avoid route fallback errors during server error middleware traversal ( #4426 ) Strip all trusted proxy IPs from X-Forwarded-For chain ( #4394 ) Guard typed-nil errors ( #4407 ) Guard typed-nil Fiber error paths without reflection ( #4372 ) Preserve legacy custom constraint arguments ( #4432 ) Remove unreachable SameSiteDefaultMode case ( #4471 ) Detach quoted filename strings from pooled buffers ( #4374 ) Prevent app.init mutex deadlock on panic ( #4366 ) Enforce CertClientFile for AutoCertManager TLS ( #4312 ) cache: Separate authorization key segment ( #4467 ) cache: Hash QUERY body keys ( #4459 ) cache: Evaluate freshness after locking ( #4419 ) cors: Validate wildcard origins before matching ( #4438 ) cors: Reject empty wildcard labels ( #4437 ) csrf: Validate nested extractor chains ( #4439 ) csrf: Port CORS subdomain match fixes ( #4455 ) etag: Skip Server-Sent Events responses ( #4487 ) Guard extractor introspection cycles ( #4453 ) helmet: Use Scheme() for HTTPS detection and validate HSTS configuration ( #4389 ) hostauthorization: Reject malformed hostnames in wildcard path ( #4408 ) idempotency: Make MemoryLock safe for zero-value use ( #4371 ) limiter: Correct fixed-window hit credit on skipped requests ( #4422 ) logger/cache/storage: Remove unbounded background goroutines ( #4378 ) pprof/proxy: Fix trailing-slash redirect and balancer empty-server panic ( #4421 ) proxy: Bound upstream connections by default ( #4369 ) rewrite/redirect: Anchor rules to the start of the path ( #4483 ) session: Prevent session fixation by preserving successful extractor in chains ( #4469 ) session: Prevent store error disclosure ( #4424 ) session: Restore isFresh field name ( #4477 ) sse: Preserve trailing newlines in event data ( #4414 ) timeout: Isolate default timeout responses ( #4442 ) timeout: Reclaim abandoned fiber.Ctx via ScheduleReclaim latch ( #4359 , #4400 ) Fix client config locking races ( #4470 ) Fix client default access race in Replace/C path ( #4377 ) Handle panics in client execFunc without crashing callers ( #4365 ) Address bugs found in codebase audit ( #4420 ) Fix cleanup follow-ups and regression coverage ( #4380 ) 🛠️ Maintenance 22 changes bump github.com/klauspost/compress from 1.18.7 to 1.19.0 ( #4489 ) bump github.com/klauspost/compress from 1.18.6 to 1.18.7 ( #4485 ) bump github.com/andybalholm/brotli from 1.2.1 to 1.2.2 ( #4484 ) bump github.com/valyala/fasthttp from 1.71.0 to 1.72.0 in the fasthttp-modules group ( #4481 ) bump actions/cache/restore from 6.0.0 to 6.1.0 ( #4480 ) bump actions/cache/save from 6.0.0 to 6.1.0 ( #4479 ) bump release-drafter/release-drafter from 7.5.0 to 7.5.1 ( #4463 ) bump release-drafter/release-drafter from 7.4.0 to 7.5.0 ( #4457 ) bump actions/cache from 5.0.5 to 6.0.0 ( #4452 ) bump actions/setup-go from 6.4.0 to 6.5.0 ( #4451 ) bump actions/checkout from 6.0.3 to 7.0.0 ( #4441 ) bump release-drafter/release-drafter from 7.3.1 to 7.4.0 ( #4434 ) bump golang.org/x/net from 0.55.0 to 0.56.0 in the golang-modules group ( #4425 ) bump github.com/gofiber/schema from 1.7.2 to 1.8.0 ( #4417 ) bump the golang-modules group with 2 updates ( #4416 ) bump golang.org/x/sys from 0.45.0 to 0.46.0 in the golang-modules group ( #4412 ) bump codecov/codecov-action from 6.0.1 to 7.0.0 ( #4413 ) bump actions/checkout from 6.0.2 to 6.0.3 ( #4398 ) bump github.com/gofiber/schema from 1.7.1 to 1.7.2 ( #4396 ) bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 ( #4384 ) bump release-drafter/release-drafter from 7.3.0 to 7.3.1 ( #4314 ) bump the golang-modules group with 3 updates ( #4310 ) 📚 Documentation Restructure routing guide and split handler partials ( #4311 ) Fix Ctx.Scheme/Protocol documentation ( #4473 , #4474 ) Clarify client hook concurrency contract ( #4386 ) keyauth: Fix extractor examples ( #4409 ) Add FAQ troubleshooting entry for the "id <= evictCount" (hpack/gRPC) panic ( #4475 ) Replace interface{} with any (Go 1.18+) ( #4433 ) Document thread-safety contracts for mutex-backed public types ( #4367 ) Enhance sponsorship section in README ( #4402 ) 📒 Documentation : https://docs.gofiber.io/next/ 💬 Discord : https://gofiber.io/discord Full Changelog : v3.3.0...v3.4.0 Thank you @0xghost42 , @Amirhf1 , @DucMinhNe , @Fenny , @MD-Mushfiqur123 , @ReneWerner87 , @alexandear , @fereidani , @gaby , @james-yusuke , @ksw2000 , @nekoworks-magic , @niksis02 , @pageton , @sixcolors and @talktokim for making this release possible.

Read more →

v3.3.0

🚀 New Add support for configuring the Regex engine on the router ( #4254 ) Swap the compiler used for regex() route constraints. Assign a drop-in engine such as coregex.MustCompile for faster matching;Fiber reuses the compiled matcher across requests. app := fiber . New (fiber. Config { RegexHandler : coregex . MustCompile , // default: regexp.MustCompile }) https://docs.gofiber.io/api/fiber#regexhandler Host auth middleware ( #4199 ) New hostauthorization middleware that validates the incoming Host header against an allowlist (exact host, .subdomain wildcard, CIDR range) to protect against DNS rebinding attacks. app . Use ( hostauthorization . New (hostauthorization. Config { AllowedHosts : [] string { "api.myapp.com" , ".myapp.com" , "10.0.0.0/8" }, })) https://docs.gofiber.io/middleware/hostauthorization Delegate implementation to fasthttp/prefork ( #4210 ) Prefork now delegates to fasthttp's prefork package and adds PreforkRecoverThreshold (max child restarts before the master exits) and PreforkLogger to ListenConfig . https://docs.gofiber.io/api/fiber#preforkrecoverthreshold Add support for contextual logs ( #4241 ) Render request-scoped fields in log.WithContext(c) by configuring a template with log.SetContextTemplate , reusing the middleware/logger engine (including ${value:key} for arbitrary context values). log . MustSetContextTemplate (log. ContextConfig { Format : log . RequestIDFormat }) app . Get ( "/" , func ( c fiber. Ctx ) error { log . WithContext ( c ). Info ( "start" ) // renders the request id return c . SendString ( "ok" ) }) https://docs.gofiber.io/api/log#bind-context Add storage backed SharedState for prefork applications ( #4243 ) A prefork-safe, storage-backed key/value store via app.SharedState() for data shared across workers/processes, with JSON/MsgPack/CBOR/XML helpers and automatic key namespacing. app.State() stays process-local. app := fiber . New (fiber. Config { SharedStorage : redis . New (), // any fiber.Storage shared across workers }) app . SharedState (). SetJSON ( "config" , cfg , 0 ) https://docs.gofiber.io/api/state#sharedstate-prefork-safe Add lightweight SSE middleware ( #4239 ) A Fiber-native middleware/sse for Server-Sent Events: SSE headers, event/comment/retry frames, per-write flushing, heartbeats, Last-Event-ID access, and disconnect detection via stream.Context() . app . Get ( "/events" , sse . New (sse. Config { Handler : func ( c fiber. Ctx , stream * sse. Stream ) error { return stream . Event (sse. Event { Name : "message" , Data : fiber. Map { "message" : "hello" }}) }, })) https://docs.gofiber.io/middleware/sse 🧹 Updates Add prefixes to unexported boolean fields ( #4300 ) Improve error messages in SaveFileToStorage ( #4173 ) Streamline request handler selection and context management for improved performance ( #4233 ) 🐛 Fixes Preserve mounted sub-app regex handler during mount prefixing ( #4308 ) Trim only one trailing dot in host normalization ( #4307 ) Reject oversized unknown-length adaptor request bodies ( #4306 ) Fix compress middleware's shouldSkip method to avoid memory growth ( #4284 ) Reject malformed host authorities in hostauthorization ( #4293 ) Synchronize view reloads with template rendering ( #4288 ) Avoid panic for non-struct listeners in TLS config discovery ( #4305 ) Clear plaintext cookie when encryption fails ( #4303 ) Fix regex route constraint parsing with literal > ( #4292 ) Reject empty normalized host before dynamic matching ( #4291 ) Preserve idempotency replay protection for oversized responses ( #4287 ) Enforce CookieJar domain acceptance and host-only cookie matching ( #4282 ) Avoid panic when reading released Fiber context values ( #4271 ) Enforce static root for fs-backed directory serving ( #4277 ) Prevent negative paginate start overflow ( #4272 ) Prevent SharedState namespace key collisions ( #4274 ) Copy FullURL string before returning pooled buffer ( #4275 ) Enforce paginate sort allowlist when AllowedSorts is unset ( #4276 ) Validate and safely apply workflow version updates ( #4273 ) Close BodyStream in adaptor FiberHandler streaming path ( #4267 ) Prevent panic when MsgPack is not configured ( #4268 ) Keep IsFromLocal loopback-only and add unix-socket helper ( #4270 ) Prevent panic when CBOR is not explicitly configured ( #4269 ) Guard session logger tag against released middleware ( #4265 ) Add X-Real-IP protection to Forward and DomainForward variants ( #4261 ) Ensure BalancerForward overwrites X-Real-IP header ( #4260 ) Add test coverage for multipart BodyLimit error handling ( #4237 ) Improve error propagation in Express-style handler ( #4250 ) Remove SSE Next and clarify SSE handler docs ( #4247 ) BasicAuth verifier for unknown users ( #4245 ) 🛠️ Maintenance 13 changes bump github.com/shamaton/msgpack/v3 from 3.1.1 to 3.1.2 ( #4296 ) bump codecov/codecov-action from 6.0.0 to 6.0.1 ( #4294 ) bump actions/add-to-project from 1.0.2 to 2.0.0 ( #4256 ) bump github.com/shamaton/msgpack/v3 from 3.1.0 to 3.1.1 ( #4281 ) bump the golang-modules group with 3 updates ( #4278 ) bump golang.org/x/sys from 0.43.0 to 0.44.0 in the golang-modules group ( #4262 ) bump DavidAnson/markdownlint-cli2-action from 23.1.0 to 23.2.0 ( #4259 ) bump benchmark-action/github-action-benchmark from 1.22.0 to 1.22.1 ( #4258 ) bump github.com/valyala/fasthttp from 1.70.0 to 1.71.0 in the fasthttp-modules group ( #4255 ) bump github.com/klauspost/compress from 1.18.5 to 1.18.6 ( #4249 ) bump DavidAnson/markdownlint-cli2-action from 23.0.0 to 23.1.0 ( #4246 ) bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 ( #4242 ) 📚 Documentation Fix invalid RouteChain method chaining example ( #4304 ) Harden reverse proxy X-Forwarded-For example ( #4266 ) Correct fasthttpctx Done semantics in context guide ( #4264 ) Clarify ${bytesSent} behavior in logger middleware ( #4251 ) Clarify prefork security model and OS-specific socket behavior ( #4240 ) 📒 Documentation : https://docs.gofiber.io/next/ 💬 Discord : https://gofiber.io/discord Full Changelog : v3.2.0...v3.3.0 Thank you @ReneWerner87 , @elton-peixoto-lu , @gaby , @gtoxlili , @lyyvalhalla , @mutantkeyboard , @pageton and @pratikramteke for making this release possible.

Read more →

v2.52.13

What's Changed 🐛 Bug Fixes Escape HTML output in Ctx.Format by @gaby in #4232 Full Changelog : v2.52.12...v2.52.13

Read more →

v3.2.0

🚀 New Add URL() method to Route for generating URLs with parameters ( #4195 ) https://docs.gofiber.io/api/app#getroute Add comprehensive tests for binding to pointer scalar types ( #4191 ) Add response format support to healthcheck middleware ( #4178 ) https://docs.gofiber.io/middleware/healthcheck#config Route Domain() func for host-based routing ( #4100 ) Add pagination middleware ( #4127 ) https://docs.gofiber.io/middleware/paginate Add BindError type with source and field metadata ( #4120 ) https://docs.gofiber.io/api/bind#binderror Add PanicHandler in recover middleware ( #4110 ) https://docs.gofiber.io/middleware/recover#config 🧹 Updates Optimize speed ( #4231 ) Remove duplicate benchmark handling and update benchmark action version ( #4108 ) 🐛 Fixes Fix race condition in TestTimeout_ContextPropagation ( #4119 ) Fix ARMv7 build overflow in etag middleware ( #4190 ) Fix HTML escaping in AutoFormat ( #4228 ) Structured default cache keys, and controls ( #4224 ) Enforce BodyLimit on request decompression and multipart form parsing ( #4213 ) Implement releaseData function for better resource management ( #4209 ) Strip path from referer before matching trusted origins ( #4204 ) Improve clarity for ProxyHeader and TrustProxy configuration ( #4140 ) Prefork children exit immediately in Docker containers ( #4133 ) Fix math.MaxUint32 overflow in etag middleware on 32-bit platforms ( #4135 ) Add nil checks to End() to prevent panic in streaming mode ( #4128 ) Custom binders bypass StructValidator in Body() and Custom() ( #4124 ) 🛠️ Maintenance 43 changes bump actions/setup-go from 6.2.0 to 6.3.0 ( #4114 ) bump golang.org/x/net from 0.50.0 to 0.51.0 in the golang-modules group ( #4113 ) bump github.com/gofiber/schema from 1.7.0 to 1.7.1 ( #4220 ) bump actions/setup-node from 6.3.0 to 6.4.0 ( #4222 ) bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 ( #4221 ) bump github.com/tinylib/msgp from 1.6.3 to 1.6.4 ( #4215 ) bump github/codeql-action from 4.35.1 to 4.35.2 ( #4216 ) bump actions/cache from 5.0.4 to 5.0.5 ( #4214 ) bump actions/github-script from 8.0.0 to 9.0.0 ( #4207 ) bump release-drafter/release-drafter from 7.1.1 to 7.2.0 ( #4206 ) bump the golang-modules group with 2 updates ( #4205 ) bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 ( #4203 ) bump golang.org/x/text from 0.35.0 to 0.36.0 in the golang-modules group ( #4202 ) bump golang.org/x/sys from 0.42.0 to 0.43.0 in the golang-modules group ( #4201 ) bump github.com/valyala/fasthttp from 1.69.0 to 1.70.0 in the fasthttp-modules group across 1 directory ( #4197 ) bump lewagon/wait-on-check-action from 1.6.0 to 1.6.1 ( #4198 ) bump streetsidesoftware/cspell-action from 8.3.0 to 8.4.0 ( #4188 ) bump github.com/andybalholm/brotli from 1.2.0 to 1.2.1 ( #4174 ) bump benchmark-action/github-action-benchmark from 1.21.0 to 1.22.0 ( #4172 ) bump actions/setup-go from 6.3.0 to 6.4.0 ( #4170 ) bump lewagon/wait-on-check-action from 1.5.0 to 1.6.0 ( #4171 ) bump github/codeql-action from 4.35.0 to 4.35.1 ( #4169 ) bump dependabot/fetch-metadata from 2.5.0 to 3.0.0 ( #4165 ) bump codecov/codecov-action from 5.5.3 to 6.0.0 ( #4166 ) bump github/codeql-action from 4.34.1 to 4.35.0 ( #4164 ) bump DavidAnson/markdownlint-cli2-action from 22.0.0 to 23.0.0 ( #4161 ) bump github.com/klauspost/compress from 1.18.4 to 1.18.5 ( #4158 ) bump github/codeql-action from 4.34.0 to 4.34.1 ( #4159 ) bump github/codeql-action from 4.33.0 to 4.34.0 ( #4156 ) bump codecov/codecov-action from 5.5.2 to 5.5.3 ( #4153 ) bump release-drafter/release-drafter from 7.1.0 to 7.1.1 ( #4152 ) bump actions/cache from 5.0.3 to 5.0.4 ( #4151 ) bump release-drafter/release-drafter from 7.0.0 to 7.1.0 ( #4147 ) bump release-drafter/release-drafter from 6.4.0 to 7.0.0 ( #4142 ) bump github/codeql-action from 4.32.6 to 4.33.0 ( #4141 ) bump the golang-modules group with 3 updates ( #4138 ) bump golang.org/x/sys from 0.41.0 to 0.42.0 in the golang-modules group ( #4136 ) bump release-drafter/release-drafter from 6.3.0 to 6.4.0 ( #4137 ) bump github/codeql-action from 4.32.5 to 4.32.6 ( #4131 ) bump release-drafter/release-drafter from 6.2.0 to 6.3.0 ( #4130 ) bump actions/setup-node from 6.2.0 to 6.3.0 ( #4129 ) bump benchmark-action/github-action-benchmark from 1.20.7 to 1.21.0 ( #4126 ) bump github/codeql-action from 4.32.4 to 4.32.5 ( #4123 ) 📚 Documentation Key Value Expectation Notice (KeyAuth Middleware) ( #4183 ) Document array query parameter formats for Query binder ( #4116 ) 📒 Documentation : https://docs.gofiber.io/next/ 💬 Discord : https://gofiber.io/discord Full Changelog : v3.1.0...v3.2.0 Thank you @JonasDoe , @ReneWerner87 , @adrian-lin-1-0-0 , @aviu16 , @gaby , @ha-sante , @loderunner , @meruiden , @mutantkeyboard and @sixcolors for making this release possible.

Read more →

v2.52.12

🐛 Fixes CVE fix GHSA-mrq8-rjmw-wpq3 Full Changelog : v2.52.11...v2.52.12

Read more →

v3.1.0

🚀 New expand middleware context helpers ( #4079 ) app := fiber . New (fiber. Config { PassLocalsToContext : true , // default: false }) // Works for requestid, csrf, session, basicauth, keyauth middlewares app . Use ( requestid . New ()) app . Get ( "/" , func ( ctx fiber. Ctx ) error { // Value helpers from middlewares works now with 3 different context items id := requestid . FromContext ( ctx ) // works always id := requestid . FromContext ( ctx . RequestCtx ()) // works always id := requestid . FromContext ( ctx . Context ()) // works only when `PassLocalsToContext` is true return c . SendString ( id ) }) https://docs.gofiber.io/api/fiber/#passlocalstocontext 🧹 Updates update utils and add go 1.26 for test workflow ( #4087 ) optimize helpers performance ( #4049 ) harden numeric constraint parsing and expand route tests ( #4054 ) 🐛 Fixes harden DefaultRes.Format against nil handler panics ( #4105 ) guard nil request in adaptor LocalContextFromHTTPRequest ( #4097 ) fix Unix-socket support in IsProxyTrusted ( #4088 ) harden proxy nil client handling in Do/Forward paths ( #4083 ) add nil-safety to response decode helpers ( #4081 ) sanitize attachment/download filenames ( #4070 ) harden flash cookie detection ( #4078 ) fix bind struct validation only for struct targets ( #4082 ) enforce Range header limit configuration ( #4071 ) apply limits to msgp serialization ( #4065 ) fix sanitizePath validation logic ( #4064 ) fix Test method returning empty response on timeout ( #4063 ) fix nil pointer dereference in context methods when accessed after release ( #4062 ) retry addon: remove unnecessary sleep after last failed attempt ( #4060 ) make TLS listener config discovery safer ( #4055 ) validate nil services early and during lifecycle ( #4050 ) skip non-string state keys during iteration ( #4048 ) harden Port() handling ( #4051 ) prevent panics on non-string log keys ( #4046 ) 🛠️ Maintenance bump streetsidesoftware/cspell-action from 8.2.0 to 8.3.0 ( #4111 ) bump the golang-modules group with 3 updates ( #4080 ) bump github.com/shamaton/msgpack/v3 from 3.0.0 to 3.1.0 ( #4075 ) bump github.com/klauspost/compress from 1.18.3 to 1.18.4 ( #4076 ) bump github.com/gofiber/schema from 1.6.0 to 1.7.0 ( #4074 ) bump golang.org/x/sys from 0.40.0 to 0.41.0 in the golang-modules group ( #4073 ) bump github/codeql-action from 4.32.3 to 4.32.4 ( #4104 ) bump github/codeql-action from 4.32.1 to 4.32.2 ( #4058 ) bump github/codeql-action from 4.32.0 to 4.32.1 ( #4047 ) 📚 Documentation update versioned storage imports in middleware docs ( #4102 ) update documentation for parser configuration and request handling ( #4096 ) fix invalid Go slice literal in middleware registration example ( #4095 ) document uri struct tag for ctx.Bind().URI() in migration guide ( #4092 ) document logger Stream rename ( #4057 ) 📒 Documentation : https://docs.gofiber.io/next/ 💬 Discord : https://gofiber.io/discord Full Changelog : v3.0.0...v3.1.0 Thank you @ReneWerner87 , @SadikSunbul , @gaby and @sixcolors for making this release possible.

Read more →

v3.0.0

For a detailed view of all changes and the migration guide, visit: https://docs.gofiber.io/whats_new Try our new migration tool to help you upgrade from v2 to v3: go install github.com/gofiber/cli/fiber@latest fiber migrate --to v3 What's Changed 🚀 New Features 🚀 App ( Docs ) Rename WithTlsConfig method to WithTLSConfig in ( #2570 ) Use any as default Message type of Error struct in ( #1925 ) Add support for custom constraints in ( #2807 ) Add support for trusted origins in ( #2910 ) Add DialDualStack option for upstream IPv6 support in ( #2900 ) TrustedOrigins using https://*.example.com style subdomains in ( #2925 ) Add configuration support to c.SendFile() in ( #3017 ) Add CHIPS support to Cookie in ( #3047 ) Add TestConfig to app.Test() for configurable testing in ( #3161 ) Add buffered streaming support in ( #3131 ) Add support for AutoTLS / ACME in ( #3201 ) Add support for configuring TLS Min Version in ( #3248 ) Fix square bracket notation in Multipart FormData in ( #3235 ) Add support for application state management in ( #3360 ) Add support for NewErrorf in ( #3463 ) Add UNIX socket support in ( #3535 ) Add support for Msgpack in ( #3565 ) Add default UTF-8 charset in ( #3583 ) Support for SendEarlyHints in ( #3483 ) Add conditional copy helpers in ( #3703 ) Add request inspection helpers in ( #3727 ) Add support for redacting values in ( #3759 ) Add support for handling unsupported HTTP methods as HTTP 501 in ( #3854 ) Add support for ReloadViews() in ( #3876 ) Expose startup message customization hooks in ( #3824 ) Migrate from UUIDv4 to SecureToken for key generation in ( #3946 ) Add ExpirationFunc for dynamic expiration in ( #3984 ) Auto-enforce Secure=true for Partitioned cookies in Cookie() in ( #3976 ) 📎 Binding ( Docs ) Initial support for binding in ( #1981 ) Bind: add support for multipart file binding in ( #3309 ) Add All method to Bind in ( #3373 ) 🌎 Client ( Docs ) Client refactor in ( #1986 ) Add support for creating Fiber client from existing FastHTTP client in ( #3214 ) Add support for iterator methods to Fiber client in ( #3228 ) Add support for HostClient and LBClient in ( #3774 ) Add support for streaming response bodies in client and response handling in ( #4014 ) 🧠 Context ( Docs ) Convert fiber.Ctx type to interface in ( #1928 ) Add Drop method to DefaultCtx for silent connection termination in ( #3257 ) Add End() method to Ctx in ( #3280 ) Improve and Optimize ShutdownWithContext Func in ( #3162 ) Add support for context.Context in keyauth middleware in ( #3287 ) Fiber.Context implement context.Context in ( #3382 ) Add NewWithCustomCtx initialization helper in ( #3476 ) Add context methods to fiber.Storage interface in ( #3566 ) Add Fiber Context to BasicAuth Authorizer in ( #3621 ) Implement OverrideParam override behavior for DefaultCtx in ( #3962 ) Add context common request helpers in ( #4007 ) Adding GetReqHeaders and GetRespHeaders in ( #2831 ) Add Req and Res API in ( #2894 ) 🔬 Extractors ( Docs ) Introduce Extractor pattern for session ID retrieval in ( #3625 ) Enhance extractor functionality with metadata and security validation in ( #3630 ) Add extractors package in ( #3725 ) 🧰 Generic ( Docs ) Add QueryParser for get query using generic in ( #2776 ) Addition of Locals Function with Go Generics as an Alternative to c.Locals in ( #2813 ) Implement new generic functions: Params, Get and Convert in ( #2850 ) Support generic configurable logger in ( #3705 ) 🚀 Listen ( Docs ) Merge Listen methods & ListenConfig in ( #1930 ) Add support for graceful shutdown timeout in ListenConfig in ( #3220 ) Add TLSConfig to ListenConfig in ( #4024 ) 🔌 Addons/retry ( Docs ) Add retry mechanism in ( #1972 ) 🧬 Middleware – adaptor ( Docs ) Add BodyStream() logic to adaptor.FiberHandler middleware in ( #3799 ) Add local context support to adaptor middleware in ( #3975 ) 🧬 Middleware – basicauth ( Docs ) Add HeaderLimit option to BasicAuth middleware in ( #3620 ) Support hashed BasicAuth passwords in ( #3631 ) 🧬 Middleware – cache ( Docs ) Add Cache Invalidation Option to Cache Middleware in ( #3036 ) Add Max Func to Limiter Middleware in ( #3070 ) Support for disabling response headers in Limiter Middleware in ( #3618 ) 🧬 Middleware – compression ( Docs ) Add support for zstd compression in ( #3041 ) Add support for CBOR encoding in ( #3173 ) 🧬 Middleware – cors ( Docs ) Add support for Access-Control-Allow-Private-Network in ( #2908 ) 🧬 Middleware – csrf ( Docs ) Add support for Sec-Fetch-Site header in CSRF middleware in ( #3913 ) 🧬 Middleware – encryptcookie ( Docs ) Add cookie name authentication for EncryptCookie middleware in ( #3788 ) 🧬 Middleware – favicon ( Docs ) Add MaxBytes to favicon middleware in ( #4016 ) 🧬 Middleware – earlydata ( Docs ) Add earlydata middleware in ( #2270 ) 🧬 Middleware – healthcheck ( Docs ) Migrate HealthChecker to v3 in ( #2884 ) Add Startup Probe to Healthcheck Middleware in ( #3069 ) 🧬 Middleware – idempotency ( Docs ) Add idempotency middleware in ( #2253 ) 🧬 Middleware – keyauth ( Docs ) Add support for custom KeyLookup functions in the Keyauth middleware in ( #3028 ) 🧬 Middleware – logger ( Docs ) Refactor logger middleware in ( #1979 ) Add AllLogger to Config in ( #3153 ) Add Skip function to logger middleware in ( #3333 ) Add predefined log formats in ( #3359 ) Add support for ForceColors in Logger middleware in ( #3428 ) 🧬 Middleware – proxy ( Docs ) Add support for TrustProxy in ( #3170 ) Add KeepConnectionHeader option to Proxy middleware in ( #3662 ) 🧬 Middleware – requestid ( Docs ) Add Context Support to RequestID Middleware in ( #3200 ) Validate HTTP headers in RequestID middleware in ( #3919 ) 🧬 Middleware – responsetime ( Docs ) Add response time middleware in ( #3891 ) 🧬 Middleware – session ( Docs ) Re-write session middleware with handler in ( #3016 ) Add support for Keys() in session middleware in ( #3517 ) 🧬 Middleware – static ( Docs ) Add static middleware in ( #3006 ) 🧬 Middleware – timeout ( Docs ) Add config for Timeout middleware in ( #3604 ) 🔄️ Redirect ( Docs ) New redirection methods in ( #2014 ) 🗺️ Router ( Docs ) Router interface changes in ( #2176 ) Native support for net/http and fasthttp handlers in ( #3769 ) New Route method in ( #2065 ) New mounting system in ( #2022 ) Add support for RebuildTree in ( #3074 ) Add support for Express.js style req/res handlers in ( #3809 ) Add support for DisableAutoRegister of HEAD routes in ( #3817 ) Enhance CheckConstraint method for improved error handling in ( #3356 ) Add Support for Removing Routes in ( #3230 ) Add support for embedded Koa-Style Req and Res structs in ( #3533 ) Support Express-style next callback handlers in ( #4029 ) 🧩 Services ( Docs ) Add Support for service dependencies in ( #3434 ) 🧹 Updates ⚙️ Core & API Replace string functions in ( #3923 ) Update conditional instructions for startup skip in ( #3475 ) Update AGENTS startup instructions in ( #3474 ) Add []byte support to utils.EqualFold in ( #2029 ) Change startup message in ( #2041 ) Update to use gofiber/utils/v2 in ( #2184 ) Router: return status 501 instead of 400 on unknown method in ( #2220 ) Cleanup in ( #2255 ) Fix ContextKey collisions in ( #2781 ) Update Ctx.Format to match Express's res.format in ( #2766 ) Update handler signature for v3 in ( #2794 ) Change interface{} to any in ( #2796 ) Added respects body immutability to ctx.Body() and ctx.BodyRaw() functions. in ( #2812 ) Print to stderr if log fails for default format in ( #2830 ) Clean up errcheck config in ( #2841 ) Update startup message formatting in ( #2847 ) Simplify content negotiation code in ( #2865 ) Rename "ClientNew" Function to "New" in ( #2896 ) Remove repetitive words in ( #2917 ) Improper query/body parsing with embedded structs in ( #2906 ) Improve and simplify logic of ctx.Next() in ( #3063 ) Use Named Fields Instead of Positional and Align Structures to Reduce Memory Usage in ( #3079 ) Use utils Trim functions instead of the strings/bytes functions in ( #3087 ) Consolidate Logic of Handling the Request Body in ( #3093 ) Use msgp for flash message encoding/decoding in ( #3099 ) Replace vendored gorilla/schema package in ( #3152 ) Improve naming convention for Context returning functions in ( #3193 ) Nil pointer dereference with Must Bind binding in ( #3171 ) Mark go1.23 as minimum go version in ( #3226 ) Rename the Method Names of FormData and FormDatas ( #3251 ) in ( #3255 ) Reduce the Memory Usage of ignoreHeaders in ( #3322 ) Migrate randString to rand v2 in ( #3329 ) Sorting error in sortAcceptedTypes in ( #3331 ) Reduce the memory usage of RoutePatternMatch in ( #3335 ) Replace findLastCharsetPosition with strings.LastIndexByte in ( #3338 ) Replace isInCharset with bytes.IndexByte in ( #3342 ) Remove two string fields in DefaultCtx to save 32 bytes in ( #3353 ) Replace treePath with treePathHash in DefaultCtx to reduce memory usage in ( #3368 ) Remove redundant field method in DefaultCtx in ( #3372 ) Add findNextNonEscapedCharPosition for single-byte charset cases in ( #3378 ) Change c.Redirect() default status in ( #3415 ) Improve routing treeBuild flow in ( #3456 ) Make genericParseType return error in ( #3473 ) Update minimum go version to 1.24 in ( #3481 ) Use slices.Contains to simplify code in ( #3486 ) Use maps.Copy to simplify code in ( #3490 ) Update loop syntax for retry mechanism in ( #3516 ) Update codecov configuration in ( #3528 ) Use GetState to reduce duplicate code in ( #3542 ) Improve Cookie() validation in ( #3546 ) Improve Accept* compliance with RFC 9110 in ( #3548 ) Refactor fasthttp iter calls to range loops in ( #3559 ) Add iterator helpers for client types in ( #3560 ) Update utils dependency in ( #3576 ) Refactor Opt-in support for CBOR in ( #3580 ) Simplify generic function calls in ( #3578 ) Replace math/rand with crypto/rand in ( #3508 ) Add sync pool and release helpers for Bind in ( #3660 ) Add CBOR support to AutoFormat() in ( #3665 ) Fix AcceptsLanguages() RFC compliance in ( #3672 ) Respect immutable config in Params(), Protocol(), and Body() in ( #3676 ) Delay routing error creation in ( #3683 ) Using reflect.TypeAssert in ( #3698 ) Handle Transfer-Encoding bodies in HasBody in ( #3748 ) Improve error handling when using storage drivers in ( #3754 ) Use sync.Pool for Client hooks in ( #3758 ) Avoid locking in gc() if nothing to delete in ( #3765 ) Cleanup return error logic in Bind() in ( #3764 ) Update RouteChain function in ( #3761 ) Make boundary a const in ( #3783 ) Preallocate slice size in Client::Param() in ( #3782 ) Skip locking garbage collector if nothing to delete in ( #3787 ) Enhance Body handling in setConfigToRequest for better type su… in ( #3820 ) Improve propagation of context.Context in ( #3822 ) Inline Request state wrappers in ( #3827 ) Remove unneeded "utils" alias in ( #3834 ) Add FullPath() helper to context in ( #3837 ) Handle nil map targets in Binder in ( #3839 ) Extracted generic releasePooledBinder function in ( #3841 ) Return error during EncryptCookie failure in ( #3842 ) Fix gocritic httpNoBody and hugeParam issues in ( #3855 ) Refactor internal errors to use sentinel values in ( #3864 ) Improve byte-range handling for SendFile() in ( #3870 ) Use int64 when dealing with HTTP Ranges in ( #3874 ) Replace strings.TrimSpace with utils.TrimSpace in ( #3918 ) Replace strings.Index with strings.Cut for improved readallity in ( #3956 ) Validate constraint by bit operation in ( #3963 ) Use sync.Pool for form and multipart binding in ( #3967 ) Use sync.Pool for redirect old input map in ( #3971 ) Replace anonymous struct key with named type in ( #4020 ) 🧬 Middleware & Addons Document "null" origin handling in CORS middleware in ( #4001 ) ( Docs ) Refactor CSRF middleware and enhance documentation in ( #3598 ) Fix pprof middleware docs and default config in ( #3642 ) Fix CORS docs and comments in ( #3637 ) Fix CSRF error message mismatch with documentation in ( #3636 ) Refactor filesystem middleware with io/fs in ( #2027 ) ( Docs ) Remove mutex lock in logger middleware in ( #2840 ) Update CSRF and Limiter to remove repetitive names in ( #2846 ) Refactor(middleware/cors): Config, lists as list types. in ( #2962 ) Enforce key length for EncryptCookie middleware default functions in ( #3056 ) Middleware/CORS Remove Scheme Restriction in ( #3163 ) Unify and enhance timeout middleware in ( #3275 ) Simplify HealthCheck middleware in ( #3380 ) Improve proxy middleware in ( #3468 ) Enhance KeyAuth middleware to better comply with RFC 6750 in ( #3482 ) Enhance BasicAuth middleware to better comply with RFC 6750 in ( #3484 ) Improve cache middleware RFC compliance in ( #3488 ) Enhance config validation in EncryptCookie middleware in ( #3491 ) Refactor EnvVar middleware in ( #3513 ) Improve CORS middleware response headers in ( #3505 ) Improve BasicAuth middleware default security in ( #3522 ) Improve static middleware security in ( #3595 ) Remove SHA-1/MD5 support in BasicAuth middleware in ( #3634 ) Remove support for PasswordFromContext from BasicAuth middleware in ( #3638 ) Refactor KeyAuth Middleware: Extractor-Based Configuration and Enhanced Flexibility in ( #3685 ) Return generic errors in KeyAuth middleware in ( #3692 ) Fix CSRF subdomain wildcard boundary in ( #3694 ) Improve Cache middleware defaults in ( #3740 ) Migrate Session middleware to new extractors package in ( #3744 ) Improve Compress middleware RFC compliance in ( #3745 ) Improve KeyAuth middleware RFC compliance in ( #3742 ) Update CSRF middleware to use shared extractors in ( #3746 ) Update keyauth middleware to use shared extractors in ( #3747 ) Fix cache cleanup and redact token values in ( #3757 ) Ensure middleware prefix matching requires slash boundary in ( #3755 ) Reduce the memory usage of cacheableStatusCodes in ( #3789 ) Refactor configuration management for favicon and envvar middlewares in ( #3898 ) Improve Cache middleware compliance in ( #3973 ) Further improvements to Cache middleware in ( #3989 ) Skip caching oversized responses in idempotency middleware in ( #4018 ) ⚡️ Performance & Benchmarks Optimize the menu item text in ( #3267 ) Remove utils.Trim* because stdlib has same performance in go1.19 in ( #2030 ) Performance improvements in ( #2838 ) Add parallel benchmarks to adaptor middleware in ( #2870 ) Expand Tests and Benchmarks for Log package in ( #2886 ) Performance optimizations in ( #2947 ) Add Benchmarks for IsProxyTrusted() in ( #2933 ) Optimize Cache middleware handler in ( #3031 ) Update benchmarks for Logger Middleware in ( #3061 ) Improve performance of Adaptor Middleware in ( #3078 ) Refactor Benchmark Results Workflow in ( #3082 ) Improve performance of helper functions in ( #3086 ) Improve Performance of c.Body() by 125% in ( #3090 ) Add Benchmarks for Rewrite Middleware in ( #3092 ) Optimize IsFromLocal() performance in ( #3140 ) Improve Performance of Fiber Router in ( #3261 ) Improve Performance of getSplicedStrList in ( #3318 ) Optimize routeParser by using sync.Pool in ( #3343 ) Add Immutable benchmarks for default case in ( #3374 ) Performance optimizations in ( #3477 ) Improve performance for "equalFieldType" function in ( #3479 ) Fix compression benchmarks in ( #3561 ) Improve iterator performance. in ( #3562 ) Improve sanitizePath performance in ( #3601 ) Skip unstable GenericParseType benchmarks in ( #3614 ) Reduce allocation in AutoFormat in ( #3652 ) Optimize Fresh header parsing for fasthttp 1.65 in ( #3687 ) Improve Req/Res Benchmarks in ( #3693 ) Improve performance analyseConstantPart in ( #3753 ) Improve allocations for Request Params() in ( #3766 ) Reduce allocations in Request (saves ~16% B/op) in ( #3768 ) Benchmark for cache miss case in ( #3836 ) Improve performance of RebuildTree() by 68% in ( #3895 ) Optimize string handling and memory allocations in ( #3922 ) Improve performance (reduce allocations) in ( #3964 ) 🛠️ Testing & Tooling Use testify for assertion in ( #2036 ) Generate msgp tests in ( #2263 ) V3 Feature: Make app.Test accept a time.Duration timeout in ( #2269 ) Speed up addon/retry tests in ( #2800 ) Re-enable tparallel linter in ( #2801 ) Fix testifylint errors in middleware in ( #2805 ) Fix remaining testifylint errors in ( #2806 ) Fix force type assertions in session_test.go in ( #2815 ) Address multiple lint rules in ( #2869 ) Do not retry flaky tests in ( #2875 ) Enabling shuffling, cleanup and consistency across tests in ( #2931 ) Adding a generator to generate the CTX interface in ( #3024 ) Test(middleware/session): Remove extra release and acquire ctx calls in session_test.go in ( #3044 ) Test(ctx_test): Fix race condition in ( #3081 ) The value of map is unused in uniqueRouteStack in ( #3320 ) Mark unused tests with t.SkipNow in ( #3366 ) Fix proxy middleware tests for offline environments in ( #3467 ) Add unit-test for header injection in ( #3470 ) Add URI Test case for Test_Ctx_Binders in ( #3480 ) Test: Enhance CSRF tests to address unsafe header value issue ( #2045 ) in ( #3485 ) Improve EarlyData middleware tests coverage in ( #3520 ) Improve Idempotency middleware tests coverage in ( #3521 ) Improve Helmet middleware tests coverage in ( #3523 ) Improve Retry addon tests coverage in ( #3526 ) Add missing CSRF token extractor tests in ( #3527 ) Improve hooks test coverage in ( #3524 ) Improve Binder tests coverage in ( #3529 ) Improve CORS tests coverage in ( #3530 ) Improve CSRF tests coverage in ( #3531 ) Improve Router tests coverage in ( #3550 ) Add tests for quoteRawString in ( #3613 ) Fix Makefile to install tools before running them in ( #3612 ) Fix Cookie SameSite constants to Pascal case per RFC specification in ( #3608 ) Fix timing for streaming test in ( #3628 ) Add missing checks in Ctx tests in ( #3670 ) Stabilize interrupted stream writer test in ( #3669 ) Use ephemeral ports in unit tests in ( #3686 ) Use project toolchain for go run tools in ( #3709 ) Expand Binder tests coverage in ( #3714 ) Prevent CopyContextToFiberContext panic and add comprehensive test coverage in ( #3770 ) Add flushing-related unit tests for net/http adaptor in ( #3807 ) Fix fatal error calls in adapter_test.go in ( #3810 ) Test HEAD request compliance in ( #3868 ) Improve OPTIONS wildcard regression test in ( #3869 ) Add table-driven integration tests in ( #3894 ) Improve timing robustness in flaky cache and session tests in ( #3994 ) 🐛 Bug Fixes Fix logger benchmarks in ( #2074 ) Fix benchmark results related to handler, next in ( #2130 ) Testifylint failure that fell through the cracks in ( #2821 ) Inconsistent and flaky unit-tests in ( #2892 ) CORS handling in ( #2938 ) Fix some struct names in comments in ( #2974 ) Fixes #3038 "v3 Flash Message with redirect is not working" in ( #3046 ) Mutex for thread safety in ( #3049 ) Fix data-race with sync.Pool in ( #3051 ) Fasthttp errors cause panic when Params is used in ( #3055 ) Use Content-Length for bytesReceived and bytesSent tags in Logger Middleware in ( #3066 ) Cache middleware: runtime error: "index out of range [0] with length 0" in ( #3075 ) Error check in Form binder in ( #3110 ) Client: fix SetProxyURL functionality in ( #3109 ) Fix handle un-matched open brackets in the query params in ( #3126 ) Fix issue with default logger when creating RequestCtx in ( #3134 ) Fix typo in ( #3145 ) Behavior of DefaultCtx.Fresh when 'Last-Modified' and 'If-Modified-Since' are equal in ( #3150 ) Adaptor middleware duplicates cookies in ( #3151 ) Close File After SaveFileToStorage in ( #3197 ) Make SetValWithStruct set zero values and support more types #3167 in ( #3227 ) Fix EnableSplittingOnParsers is not functional in ( #3231 ) Memory leak removal in the idempotency middleware in ( #3263 ) Make Render bind parameter type any again in ( #3270 ) Fix app.Test() auto-failing when a connection is closed early in ( #3279 ) Align cache middleware with RFC7231 in ( #3283 ) Goroutine leakage in ( #3306 ) GenericParseType parsing large uint leads to overflow in ( #3315 ) Fix handler order in routing in ( #3321 ) Update binder in form_test in ( #3336 ) Fix client iterators when using break statement in ( #3357 ) Fix: Logger Middleware tests to use regex for time validation in ( #3392 ) Handling of next param position in ( #3418 ) Fix redirection flash messages violate cookie structure in ( #3457 ) Fix AGENTS markdown lint in ( #3460 ) Parsing of IPv6 addresses in ( #3466 ) Middlewares immutable config handling in ( #3494 ) Subdomains offset handling in ( #3495 ) Fix Cache-Control header parsing in ( #3534 ) Fix Content-Type comparison in Is() in ( #3536 ) Fix Subdomains() parsing for IDNs in ( #3538 ) Fix Range() parsing of bytes unit in ( #3541 ) Fix Etag validation per RFC 9110 in ( #3554 ) Fix Range() handling of HTTP 416 per RFC 9110 in ( #3552 ) Fix Accept-Language matching per RFC 4647 in ( #3553 ) Fix Cache middleware handling of Age in ( #3547 ) Fix Content-Disposition header per RFC 6266 in ( #3551 ) Fix Body() handling of Content-Encoding per RFC 9110 in ( #3543 ) Fix multipart boundary for Client per RFC 2046 in ( #3563 ) Fix address parsing for leading/trailing spaces in ( #3569 ) Fix missing Allow header in EnvVar middleware per RFC 9110 in ( #3570 ) Fix static/favicon middlewares file descriptor leaks in ( #3579 ) Fix CookieJar domain logic in ( #3564 ) Fix handling of negative BodyLimit in ( #3599 ) Fix MIME type equality checks in ( #3602 ) Fix retry config handling in ( #3609 ) Fix limiter middleware not counting fiber.NewErrorf responses as failed requests in ( #3623 ) Fix race in cookie tests in ( #3629 ) Fix bind All() merging logic in ( #3659 ) Fix Static middleware browser support for subdirectories in ( #3673 ) Fix CORS subdomain wildcard boundary in ( #3690 ) Fix support for context.Context in ( #3720 ) Improve BasicAuth middleware RFC compliance in ( #3743 ) Handle Unix sockets in adaptor middleware in ( #3760 ) Fix usage of runtime RO data for ppc64 and s390x platforms in ( #3772 ) Respect DisablePathNormalizing during client requests in ( #3773 ) Always close form file in ( #3786 ) Fix recover middleware panic output formatting in ( #3816 ) Correct fresh flag logic in getSession in ( #3825 ) Prevent memory corruption in internal memory storage from pooled buffers in ( #3828 ) Avoid writing into released Response in core::execFunc() in ( #3830 ) Remove Flash Cookie from Response headers after parsing in ( #3840 ) Fix binder splitting for pointer-backed slice fields in ( #3844 ) Fix typos in some files in ( #3847 ) Execute middleware routes when handling errors in ( #3846 ) Fix copying of key/values in internal/memory in ( #3829 ) Fix maintain CustomCtx across middlewares in ( #3852 ) Fix default value for MaxFunc in Limiter middleware in ( #3871 ) Fix handling of wildcard matching in acceptsOffer in ( #3880 ) Fix handling of no-body HTTP statuses in ( #3883 ) Fix and improvements for the sliding window Limiter in ( #3893 ) Improve suffix range normalization in ( #3902 ) Enhance Origin and Referer Validation in CSRF middleware in ( #3904 ) Respect Authorization when caching responses in ( #3905 ) Fprint to use format instead of fmtArgs in ( #3925 ) Enforce body limits in SaveFileToStorage in ( #3929 ) V3 fix custom errorhandler invokation in ( #3930 ) Fix example in whats_new.md in ( #3949 ) Ensure flash messages are consumed after retrieval in ( #3936 ) Fix FIPS-140 compliance for EncryptCookie middleware in ( #3955 ) Guard Binds decoder sync.Pool in ( #3969 ) Fix Early-Data trusted proxy handling in ( #3974 ) Preserve session data map across resets in ( #3968 ) Improve cookie decryption handling by deleting invalid cookies after iteration in ( #3988 ) Respect body limit configuration in adaptor middleware in ( #3990 ) Security: Enforce case-sensitive null origin validation in CORS in ( #3995 ) Optimize CORS origin validation to avoid unnecessary processing in ( #3996 ) Validate CORS origins before using AllowOriginsFunc in ( #3991 ) Trim forwarded host values in ( #4012 ) Normalize forwarded scheme parsing in ( #4011 ) Return immediately on timeout and propagate context correctly in ( #4009 ) Trim values from getSplicedStrList in ( #4026 ) Return bytes read from readContent in ( #4027 ) Reload mounted view engines in ReloadViews in ( #4031 ) Handle typed-nil http handler funcs in ( #4030 ) 🛠️ Maintenance Bump github.com/valyala/fasthttp from 1.51.0 to 1.69.0 in ( #2857 , #3000 , #3037 , #3146 , #3183 , #3244 , #3314 , #3391 , #3440 , #3557 , #3586 , #3684 , #3790 , #3819 , #3992 ) Updated fasthttp to 1.54.0 release in ( #3010 ) Bump github.com/gofiber/schema from 1.2.0 to 1.6.0 in ( #3308 , #3462 , #3504 , #3574 ) Bump github.com/gofiber/utils/v2 from 2.0.0-beta.3 to 2.0.0-rc.6 in ( #2935 , #3062 , #3174 , #3389 , #3540 , #3568 , #3689 , #3853 , #3914 , #3926 , #3997 ) Bump github.com/tinylib/msgp from 1.1.8 to 1.6.3 in ( #3147 , #3182 , #3185 , #3240 , #3447 , #3716 , #3823 , #3920 , #3977 , #3978 ) Bump github.com/shamaton/msgpack/v2 from 2.2.3 to 2.4.0 in ( #3678 , #3719 , #3808 ) Bump github.com/klauspost/compress from 1.18.1 to 1.18.3 in ( #3911 , #4013 ) Bump github.com/google/uuid from 1.5.0 to 1.6.0 in ( #2810 ) Bump golang.org/x/crypto from 0.28.0 to 0.45.0 in ( #3243 , #3247 , #3274 , #3305 , #3327 , #3341 , #3395 , #3438 , #3506 , #3737 , #3796 , #3863 , #3882 ) Bump golang.org/x/net from 0.31.0 to 0.47.0 in ( #3293 , #3544 , #3572 , #3738 , #3791 , #3795 , #3861 ) Bump golang.org/x/text from 0.29.0 to 0.33.0 in ( #3797 , #4003 ) Bump golang.org/x/sys from 0.39.0 to 0.40.0 in the golang-modules group in ( #4000 ) Bump github.com/mattn/go-colorable from 0.1.13 to 0.1.14 in ( #3277 ) Bump github.com/fxamacker/cbor/v2 from 2.7.0 to 2.9.0 in ( #3384 , #3581 ) Upgrade shamaton/msgpack from v2.4.0 to v3.0.0 in ( #4023 ) Bump minimum version of Go to 1.21 in ( #2911 ) Bump golangci-lint from v1.56.1 to v1.62.0 in (#2842, #2862, #3029, #3119, #3135, #3196) Make golangci-lint config stricter in (#2874) Add support for longtests during CI in (#3054) Bump nick-fields/retry from 2 to 3 in (#2824) Bump benchmark-action/github-action-benchmark from 1.16.2 to 1.20.7 in (#2827, #2950, #3008, #3177, #3730, #3736) Bump release-drafter/release-drafter from 5 to 6.2.0 in (#2826, #4022, #4025) Bump golangci/golangci-lint-action from 3 to 9.2.0 in (#2855, #2986, #2994, #3896, #3916) Bump github.com/stretchr/testify from 1.8.4 to 1.11.1 in (#2888, #3217, #3712, #3715) Bump codecov/codecov-action from 4.0.1 to 5.5.2 in (#2901, #2941, #2959, #2993, #2999, #3009, #3035, #3154, #3207, #3209, #3210, #3213, #3234, #3256, #3292, #3295, #3334, #3413, #3459, #3701, #3734, #3935) Bump actions/setup-go from 4 to 6.2.0 in (#2789, #3732, #3886, #4006) Bump github/codeql-action from 2 to 4.32.0 in (#2788, #3792, #3866, #3878, #3897, #3910, #3927, #3945, #3950, #4004, #4034, #4036) Bump actions/cache from 3 to 5.0.3 in (#2803, #3944, #3947, #4017, #4040) Bump fuxingloh/multi-labeler from 2 to 4 in (#2856) Bump DavidAnson/markdownlint-cli2-action from 16 to 22.0.0 in (#3128, #3208, #3266, #3453, #3873, #3932) Bump streetsidesoftware/cspell-action from 8.0.0 to 8.2.0 in (#3938, #3993, #4039) Bump kenchan0130/actions-system-info from 1.3.0 to 1.4.0 in (#3492, #3679) Bump actions/setup-node from 4 to 6.2.0 in (#3733, #3804, #3915, #4008) Bump actions/checkout from 3 to 6.0.2 in (#3083, #3681, #3877, #3887, #3917, #4028) Bump lewagon/wait-on-check-action from 1.4.1 to 1.5.0 in (#4033) Bump the golang-modules group with 4 updates in (#3931) Bump the golang-modules group with 2 updates in (#4005) Add go1.22 to test matrix in (#2835) Replace release-drafter autolabel with fuxingloh/multi-labeler in (#3872) Add CODEOWNERS file in (#2851) Update golangci-lint to v1.55.2 in (#2817) Update golangci-lint to enable more lint rules in (#2923) Add support for go1.23 and golangci-lint v1.60.1 in (#3101) Add go1.24 to CI matrix in (#3325) Add modernize lint in (#3590) Add inamedparam linter in (#2848) Remove repo codecov.yml in (#3525) Enable govet shadow in (#3617) Fix benchmark results in (#1982) Fix spelling issues in (#3813) Golangci-lint issue for go1.25.0 in (#3775) Require Go 1.25 in (#3682) Run tests against Apple M1 platform in (#2852) Update AGENTS.md in (#3901) 📚 Documentation Update Version Numbers in Docs in (#2853) Updates to fiberlog benchmarks and documentation in (#3059) Remove deprecated comments and documenting recent changes in (#3498) Update godoc for fiber.New() in (#3928) Undocumented function in session.md in (#2795) Fix typo in documentation in (#2802) Fix a misspelled comment in (#2809) Update Typo documentation in (#2820) Typo in routing.md in (#2836) Fix code snippet indentation in /docs/api/middleware/keyauth.md in (#2868) Fix TrustedProxies documentation related to IP ranges in (#2887) Update docs to reflect fiber.Ctx struct to interface change in (#2880) Improve translation in (#2899) Update Copilot docs and setup in (#3585) Refactor Documenation for HealthCheck in (#2905) Fixed a typo in app.go in (#2912) Cleanup and updates to README files in (#2914) Fix merge conflict in documentation in (#2957) Fix broken link to slim template in FAQ in (#2969) Update config TrustedOrigin comments in (#2963) Consolidate and Document Core Changes in v3 in (#2934) Fix some comments in (#2983) CORS middleware in (#2979) Add docs for new client in (#2991) Update intro.md to make clear fiber.Ctx is not thread-safe. in (#3014) Improve ctx.Locals method description, godoc and example in (#3032) Add zero-allocation section to README in (#3039) Add support for consistent documentation using markdownlint in (#3064) Update example in middleware/cors to v3 in (#3116) Update recover docs to not use reserved keyword in (#3129) Fix typos in client hooks documentation in (#3133) Replaced link to russian mozilla docs in (#3142) Removed zero width white space from logger docs in (#3144) Fix typo on comment in (#3158) Typo in hooks documentation in (#3164) Update README.md in (#3165) Update What's New documentation in (#3181) Clarify SendFile Docs in (#3172) Update intro documentation in (#3204) Updates to API documentation and README in (#3205) Updates to Context documentation in (#3206) Update documentation for Fiber client in (#3249) Fix static middleware CacheDuration data type typo in (#3273) Add ctx.Drop() to whats_new.md in (#3284) Add c.Drop() example to whats_new.md in (#3285) Update intro.md Static Files section in (#3303) Update adapter middleware documentation in (#3317) Add Retry Addon documentation in (#3330) Update Helmet Middleware default values in (#3348) Update helmet.md default values in (#3350) Add more validation examples in (#3369) Update docs for State Management in (#3388) Fix CSRF handler example in (#3412) Adjust Funding Custom URL in (#3432) Fix examples in middleware/session in (#3435) Idempotency add more detailed description for next method in (#3443) Document usage of Custom Tags in Logger middleware in (#3446) Fix typos in (#3464) Fix more typos across code base in (#3465) Fix typos in code and docs in (#3507) Enhance CORS middleware documentation with preflight request details and infrastructure considerations in (#3509) Add custom constraint example in (#3539) Incorrect usage of backslash characters in the constraint … in (#3549) Add net/http compatiblity section in (#3556) Add documentation for Stale() in (#3555) Update utils guide documentation in (#3575) Fix EarlyData middleware docs in (#3646) Fix Skip middleware docs in (#3649) Fix context changes doc in (#3650) Fix RequestID docs in (#3648) Fix Proxy middleware docs in (#3647) Fix Compress middleware docs in (#3645) Fix Cache middleware docs in (#3644) Fix Favicon middleware documentation in (#3640) Fix Static middleware docs in (#3643) Fix Healthcheck middleware documentation in (#3657) Fix KeyAuth middleware docs in (#3641) Improve Timeout middleware documentation in (#3675) Add context guide in (#3677) Add Learning Resources section with Go Interview Practice platform in (#3691) Fix typos in documentation in (#3695) Add early hints documentation in (#3697) Document utils package migration in (#3704) Note CSRF ContextKey removal in (#3706) Note removal of context keys in (#3707) Add migration tool info in (#3708) Improve wording and fix typos in (#3713) Full audit of documentation in (#3717) Add RoutePatternMatch documentation in (#3722) Clarify context interface implementation in (#3729) Ensure all exported elements are documented in (#3752) Document usage of reverse proxies for SendEarlyHints in (#3778) Fix broken link in the Routing guide in (#3831) Update docs/whats_new.md in (#3889) Clarify handler execution order and usage in Add() in (#3890) Update cache migration guidance in (#3908) Clarify client migration examples in (#3921) Add goroutine cancellation example using context.WithTimeout in (#3884) Fix some comments to improve readability in (#3943) Update logger middleware format constants in (#3951) Refresh adaptor middleware guidance in (#3981) Update Services icon and prefork warning for State Management in (#4002) Thank you to all contributors: @ad3n , @akilesh1706 , @alequilesl , @alexandear , @Alijeyrad, @aliziyacevik , @andradei , @arturmelanchyk , @asyslinux, @AuroraTea , @axrav , @balcieren , @Behzad-Khokher , @BigJoe17 , @brunodmartins , @canks69 , @ckoch786 , @cuiweixie , @darwin808 , @dave-gray101 , @deferdeter , @devhaozi , @devhsoj , @Dishank-Sen , @dockercui , @dojutsu-user , @dozheiny , @dreamscached , @duhnnie , @edvardsanta , @efectn , @emirhansirkeci , @ErfanMomeniii , @Fenny , @findfluctuate , @gaby , @gandaldf , @glensargent , @gopkg-dev , @gozeloglu , @grivera64 , @guerzon , @haikalSusanto , @haochunchang , @hcancelik , @hotrungnhan , @hungthai1401 , @imsk17 , @ItsMeSamey , @JIeJaitt , @jsoref , @K0ng2 , @KatzuYoru , @khanhkhanhlele , @kianmeng , @kirankumar-grootan , @kiuber , @KrisCarr , @ksw2000 , @ktat , @LaptopCat , @Larinax999 , @Lars-Schumann , @laughing-nerd , @leonklingele , @linogomez , @luk3skyw4lker , @mazyaryousefinia , @mdelapenya , @mitulagr2 , @miyamo2 , @MonkyMars , @negrel , @nexovec , @nickajacks1 , @nnnkkk7 , @oktayozkan0 , @omaskery , @omer-cengel , @orvillesimba , @pjebs , @rabarar , @racerole , @ReneWerner87 , @RezaSi , @ryanbekhen , @s19835 , @SantiagoBobrik , @sebytza23 , @shamaton , @sigmundxia , @SivaPA08 , @sixcolors , @StrawHatHacker , @sunnyyssh , @techerfan , @the-hotmann , @TheAspectDev , @theleeeo , @tongjicoder , @trim21 , @vhespanha , @wangjq4214 , @xEricL , @yinheli , @yorickdewid , @ZihxS , @zingi Full Changelog : v2.52.11...v3.0.0 For a detailed view of all changes and the migration guide, visit: https://docs.gofiber.io/whats_new

Read more →

Uniform Changelog API

Access Fiber changelog updates through our uniform API. Same JSON structure across all sources — no adapter-specific parsing needed.

API Endpoint
GET https://watchchangelog.com/api/v1/entries?source=fiber.releases
Response Sample
{
  "source": "fiber.releases",
  "vendor": "Fiber",
  "id": "tag:github.com,2008:Repository/234231371/v3.5.0",
  "published_at": "2026-08-13T07:24:30.000Z",
  "title": "v3.5.0",
  "url": "https://github.com/gofiber/fiber/releases/tag/v3.5.0",
  "summary": "🚀 New Harden proxy middleware ( #4405 ) New proxy.SecurityPolicy with secure defaults: private/loopback upstreams, non-http(s) schemes and HTTPS-to-HTTP redirect downgrades are rejected and hop-by-hop headers stripped. proxy . WithSecurityPolicy (proxy. SecurityPolicy { AllowPrivateIPs : true , // internal upstreams are blocked by default }) https://docs.gofiber.io/middleware/proxy#security Add support for custom binding precedence ( #4544 ) New binding_source struct tag overrides the Bind().All() source order per struct; the resolved order is cached per reflect.Type . type SearchReq struct { Name string `binding_source:\"query,header,cookie,body,uri\" query:\"name\" header:\"x-name\" json:\"name\"` } https://docs.gofiber.io/api/bind#custom-precedence Add SkipUnmatchedRoutes with two-tier 404/405 fast path ( #4486 ) New fiber.Config option that answers unregistered paths with 404 / 405 before the middleware chain runs (CORS preflight exempt, off by default). app := fiber . New (fiber. Config { SkipUnmatchedRoutes : true , // default: false }) https://docs.gofiber.io/api/fiber#skipunmatchedroutes 🧹 Updates Speed up route matching with a flat tree index, leading-byte candidate rejection and a specialized /const/:param matcher ( #4558 ) Quick-reject routes on precomputed slash-count bounds ( #4517 ) Restore Route inlining lost in the RFC 9110 changes ( #4501 ) Skip the Accept join allocation in the Format emptiness check ( #4503 ) Skip the ip.String() allocation in IsProxyTrusted for CIDR-only trust configs ( #4500 ) Adopt SWAR-accelerated utils helpers in hot-path scanners ( #4536 ) Adopt gofiber/utils v2.2.0 helpers across hot paths ( #4542 ) Adopt gofiber/utils v2.4.0 helpers and optimize adaptor/proxy hot paths ( #4557 ) adaptor: Cut allocations on the net/http bridge ( #4559 ) cache: Optimize key generation and allocation ( #4608 ) cors: Fold preflight Vary calls into one header scan ( #4502 ) csrf: Optimize trusted subdomain matching ( #4543 ) proxy: Optimize balancer round-robin ( #4549 ) session: Use make() to preallocate relevantExtractors ( #4562 ) De-flake the clock-sensitive tests ( #4575 ) 🐛 Fixes Fix open redirects in composed route URLs and redirect rules ( #4584 ) Preserve published route buckets during rebuilds ( #4579 ) URL-encode query values in Redirect.Route ( #4529 ) Accept the full float64 range in the float route constraint ( #4528 ) Match HTTP field names the way a recipient must ( #4585 ) Honor Accept weights followed by whitespace before the comma ( #4550 ) Compare Accept media types case-insensitively ( #4493 ) Honor q=0 rejections in content negotiation ( #4508 ) Honor duplicate Content-Encoding after empty values ( #4514 ) Improve RFC 9110 compliance across req/res/ctx, helpers and middleware ( #4494 ) Avoid reading omitted request bodies in Bind.All ( #4565 ) Combine repeated proxy headers for client IP extraction ( #4568 ) Close the listener on Listen error paths to avoid FD leaks ( #4532 ) Fire OnPostShutdown once with the real shutdown error ( #4531 ) Keep all NewErrorf args when the first isn't a format string ( #4530 ) adaptor: Preserve Connection tokens ( #4606 ) cache: Honor only-if-cached for non-shareable entries ( #4589 ) cache: Stop charging its own latency as response age ( #4578 ) healthcheck: Answer HEAD probes with the GET status ( #4577 ) limiter: Floor sub-second expiration in the sliding window ( #4564 ) proxy: Classify IPv6 transition addresses correctly in upstream validation ( #4553 ) proxy: Guard runtime helpers against DNS rebinding ( #4518 ) proxy: Preserve empty-query URL semantics ( #4513 ) redirect: Rank wildcards behind character classes in rule ordering ( #4607 ) static: Fix leading-slash normalization for fs.FS root paths ( #4507 ) Fix client redirect handling, TLS diagnostics and the JSONP callback ( #4586 ) Fix correctness issues across log injection, cookie jar, routing and Content-Type handling ( #4570 ) 🛠️ Maintenance 22 changes bump github.com/klauspost/compress from 1.19.1 to 1.19.2 ( #4602 ) bump DavidAnson/markdownlint-cli2-action from 24.1.0 to 24.2.0 ( #4583 ) bump release-drafter/release-drafter from 7.6.0 to 7.7.0 ( #4566 ) bump github.com/gofiber/utils/v2 from 2.4.0 to 2.4.1 ( #4567 ) bump github.com/valyala/fasthttp from 1.72.0 to 1.73.0 in the fasthttp-modules group ( #4561 ) bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 ( #4556 ) bump actions/checkout from 7.0.0 to 7.0.1 ( #4551 ) bump github.com/klauspost/compress from 1.19.0 to 1.19.1 ( #4548 ) bump github.com/gofiber/schema from 1.8.2 to 1.8.3 ( #4547 ) bump release-drafter/release-drafter from 7.5.1 to 7.6.0 ( #4546 ) bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 ( #4545 ) bump actions/setup-go from 6.5.0 to 7.0.0 ( #4541 ) bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 ( #4540 ) bump github.com/shamaton/msgpack/v3 from 3.1.2 to 3.2.0 ( #4538 ) bump actions/setup-node from 6.4.0 to 7.0.0 ( #4537 ) bump github.com/gofiber/schema from 1.8.1 to 1.8.2 ( #4535 ) bump github.com/gofiber/utils/v2 from 2.1.1 to 2.1.2 ( #4520 ) bump the golang-modules group with 3 updates ( #4515 ) bump DavidAnson/markdownlint-cli2-action from 23.2.0 to 24.0.0 ( #4506 ) bump golang.org/x/sys from 0.46.0 to 0.47.0 in the golang-modules group ( #4511 ) bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-modules group ( #4509 ) bump github.com/gofiber/schema from 1.8.0 to 1.8.1 ( #4510 ) 📚 Documentation Explain adjacent multi-param capture rules ( #4597 ) Document Ctx as a never-cancelable context ( #4560 ) Move README.md to the repo root so pkg.go.dev renders it ( #4505 ) logger: Explain when the error tag is populated ( #4592 ) 📒 Documentation : https://docs.gofiber.io/ 💬 Discord : https://gofiber.io/discord Full Changelog : v3.4.0...v3.5.0 Thank you @0xghost42 , @ATKasem , @Rachit-Gandhi , @ReneWerner87 , @RubenPari , @SivaPA08 , @aryan-finbox , @aryan262 , @gaby , @james-yusuke , @nikolauspschuetz , @sueun-dev and @sunghyun1999 for making this release possible.",
  "tags": [
    "Fiber",
    "fiber.releases",
    "framework",
    "go",
    "web"
  ]
}

Get Your Free API Key

Sign up to access the full changelog API. All public sources are free — no credit card required.

Sign Up Free →

Tags:

frameworkgoweb

Related Sources

Favicon

 

  
  
Favicon

 

  
  
Favicon

 

  
  

Share: