Release Notes for v0.70.0
What's New
Client signatures
We've updated our Windows and MacOS installers and binary signatures. This means your users might be prompted again, but we expect minimum impact for most organizations.
Client Improvements
- Suppressed ICE signaling.
#5820 - Prefer systemd-resolved stub over file mode regardless of resolv.conf header.
#5935 - Trusted wg interface in firewalld to bypass owner-flagged chains.
#5928 - Added TTL-based refresh to management DNS cache via handler chain.
#5945 - Increased gRPC health check timeout to 5s.
#5961 - Improved test stability and reliability:
#5953
#5951
#5950
Management Improvements
- Replaced mailru/easyjson with netbirdio/easyjson fork.
#5938 - Checked policy changes before database updates.
#5405 - Propagated context changes to upstream middleware.
#5956 - Added changeable PAT rate limiting.
#5946 - Excluded already expired peers from expiration job.
#5970 - Unified peer-update test timeout via constant.
#5952
Proxy Enhancements
- Set session cookie path to root.
#5915
Self-Hosted Improvements
- Added reverse proxy retention fields to combined YAML.
#5930 - Used cscli lapi status for CrowdSec readiness check in installer.
#5949
Infrastructure & Misc
New Contributors
Full Changelog: v0.69.0...v0.70.0