github livekit/egress v1.15.0

5 hours ago

Changelog

Security

  • Update Chrome to 154.0.8037.57 (from 150.0.7871.46), which closes CVE-2026-85046 and CVE-2026-87491, two V8 remote code execution bugs exploited in the wild, along with the 108 fixes in Chrome 154. Egress runs Chrome without a sandbox unless enable_chrome_sandbox is set, so web egress of untrusted URLs on earlier versions exposes the egress process (#1387, #1412)
  • Reject a request-supplied S3 assume_role_external_id by default (#1392)
  • Update grpc and the OpenTelemetry SDK to patched releases (#1367, #1380, #1395)

Added

  • SDK-source compositing for room composite egress (#1195)
  • Native OCI Object Storage upload backend (#1406)
  • Track egress v2 passthrough with TrackEgress parity (#1342)
  • max_encoder_threads config to cap encoder thread count (#1354)
  • Opt-in psrpc bus compression (#1373)
  • Config hook to tee the log stream and the handler's structured lines (#1404)
  • Retry the Chrome launch when it fails to start (#1403)

Changed

  • Run tini as PID 1 from the first container instruction so SIGTERM is never swallowed (#1384)
  • Stop disabling egress pods when UpdateEgress fails (#1401)
  • Run the burst-estimation start gate on SDK A/V requests (#1402)
  • Skip the memory kill when no handler accounts for the usage (#1386)
  • Disable the whisper and validate GStreamer plugins from 1.28 on (#1389)
  • Report the egress session lifecycle to the reporter and construct psrpc servers with observability (#1357, #1377)
  • Export only livekit_egress_ metric families from the handler (#1376)
  • Reduce redundant info logs and log destination-caused failures at warn (#1341, #1407)
  • Update Go to 1.26.8 (#1390, #1397)
  • Update GStreamer to 1.24.13 and pin the version once in .gst-version (#1371, #1382, #1388)
  • Update protocol for log redaction and correct memory usage reads, and server-sdk-go for the sender report domain guard (#1340, #1374, #1405)
  • Document backup storage config in the README (#1414)

Fixed

  • Fill audio gaps after resampling to stop A/V drift in mixed audio outputs (#1368)
  • Send EOS for every appsrc linked into the pipeline (#1358)
  • Gate EOS on playing for non-live pipelines (#1411)
  • Scale compositor inputs to their cell, not the canvas (#1410)
  • Fix the Chrome viewport to be exact (#1400)
  • Cancel an abandoned Chrome before a web egress retry (#1422)
  • Fix another memory leak source for web streams (#1356)
  • Bound websocket sink writes with a write deadline (#1353)
  • Don't misclassify aborted egresses as failed (#1375)
  • Use UTC for the {utc} filename template (#1416)
  • Handle the go-gst retraction of all released versions (#1369)
  • Dependency and CI maintenance: Renovate grouping and pins, publish-chrome automation, stream output verification in tests, dependency updates (#1186, #1343, #1344, #1345, #1346, #1355, #1359, #1360, #1361, #1362, #1364, #1370, #1378, #1381, #1383, #1393, #1408, #1425)

Don't miss a new egress release

NewReleases is sending notifications on new releases.