Skip to content

release(1.4.0): the websocket guard, the status route and the adapter lifecycle surface - floor guard-core-go v4.3.2 - #30

Merged
rennf93 merged 1 commit into
masterfrom
release/v1.4.0
Oct 9, 2026
Merged

rennf93 merged 1 commit into
masterfrom
release/v1.4.0

Conversation

@rennf93

@rennf93 rennf93 commented Oct 9, 2026

Copy link
Copy Markdown
Member

Release PR for echo-guard v1.4.0 (the Go family 1.4.0 wave; the tag IS the release for a Go module).

What ships

  • The websocket handshake guard (feat(echo): the websocket handshake guard #26): GuardWebSocket(engine, c) over the upgrade request, WebSocketHTTPStatus (503/403), the ws request shim mirroring _WebSocketGuardRequest.
  • The reference status route (feat(echo): the status route #27): AddStatusRoute(e, engine, path) serving the engine initialization snapshot JSON at /_guard/status.
  • The adapter lifecycle surface (feat(echo): the adapter lifecycle surface #28): MarkInitialized, GetInitializationStatus, Reset, AgentStats, RefreshCloudIPRanges over the engine handle.
  • Engine floor to v4.3.2: ReDoS static safety (pattern_safety registry-free 94/94), sus-patterns runtime registry, custom_response_modifier (Engine.ModifyResponse), the engine websocket guard with shared suspicious counts, the fifteen SecurityConfig knobs + performance-monitor wiring, the lifecycle/state surface; go-redis v9.23.0 / x/sys v0.48.0 transitively.
  • x/net v0.60.0 explicit indirect floor (cda0754): clears GO-2026-6603/6610/6611/6612/6617 http2 findings reachable through the cloud-refresh lifecycle.
  • Post-transfer metadata: Guard-Core org repoint including the upstream-drift checkout; module paths unchanged.

Gates

  • gofmt -l . clean; go vet ./... clean; staticcheck ./... clean; go build ./... ok
  • go test ./... green; REDIS_HOST=127.0.0.1 go test -tags integration ./... green
  • Coverage gate: 100%

No tags in this PR; the v1.4.0 tag is cut on the squash-merge commit after merge.

… lifecycle surface - floor guard-core-go v4.3.2

The family 1.4.0 wave on Echo: GuardWebSocket plus WebSocketHTTPStatus
(#26), AddStatusRoute (#27), the adapter lifecycle surface (MarkInitialized,
GetInitializationStatus, Reset, AgentStats, RefreshCloudIPRanges, #28).
Raises the engine floor to v4.3.2, pins golang.org/x/net v0.60.0 for the
five 2026 http2 GO advisories reachable through the cloud-refresh
lifecycle, and carries the post-transfer Guard-Core metadata sweep.
@rennf93 rennf93 added no-issue Chore or dependency PR that does not need an issue area: middleware Touches the Echo adapter middleware and request shim dependencies go.mod or go.sum changes tests Test suite changes labels Oct 9, 2026
@github-actions github-actions Bot added the build Module files / packaging label Oct 9, 2026
@rennf93
rennf93 merged commit 4a8f617 into master Oct 9, 2026
15 of 16 checks passed
@rennf93
rennf93 deleted the release/v1.4.0 branch October 9, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: middleware Touches the Echo adapter middleware and request shim build Module files / packaging dependencies go.mod or go.sum changes no-issue Chore or dependency PR that does not need an issue tests Test suite changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant