Sling v1.6.5 (2026-10-08T21:12:01Z)
New Features
- External secret manager references: Connections,
envblocks and expressions can use secret references (op://,ref+awssecrets://,ref+vault://,ref+sling://, and more). Supported providers include 1Password, AWS Secrets Manager and SSM, Azure Key Vault, GCP Secret Manager, Vault/OpenBao, Doppler, Infisical, Bitwarden, Akeyless, Keeper, Conjur, Delinea, Kubernetes, SOPS, HTTP JSON, file and exec. Configure them in the newsecret_providersblock ofenv.yaml. A projectenv.yamlcan declare its own providers. Usefrom:to merge a full JSON/YAML secret into a connection. Sling redacts secret values in log output. secret()function: New expression function that resolves a secret reference, e.g.secret("op://vault/item/field").- Stream hook modifiers: A stream hook stage now replaces only the same default stage. Use
+pre/pre+(also forpost,pre_merge,post_merge) to prepend or append to the default hooks. - SSH host key verification: SSH connections and tunnels now verify the host key against
ssh_host_key,ssh_known_hostsand~/.ssh/known_hosts. Sling warns by default and rejects in strict mode (ssh_strict_host_key). Newssh_ciphersandssh_kex_algorithmsproperties. - Single stage map for
transforms:transformsaccepts one stage map ({col: expr}). Invalid shapes now give an error that lists the valid shapes. - Wildcard no-match warning: A wildcard stream that matches no object now shows a warning task, instead of a silent success.
- Chunk part selection by base name: Select a chunked stream by its base name to run all its chunk parts.
- ClickHouse
merge_insertperformance: TheNOT INkey set now includes only keys that are also in the source, so merges into large targets scan less data. - Redshift loads without idle transaction: Redshift temp table loads do not open a transaction during extraction, which saves Serverless RPUs.
- Clearer error messages: ClickHouse connections to an HTTP port name the correct native port. A table-create race names the concurrent process. API specs show the error text of XML failure responses (e.g. Sage Intacct).
Bug Fixes
delete_missing: softrow return: Sling now clears_sling_deleted_atwhen a soft-deleted row comes back in the source.delete_missingdisable values:none,falseandoffnow disable the option, instead of an error.- Transforms on MySQL byte values: Transforms now get normalized values for all rows, not only the first 900. This fixes time functions and string comparisons on MySQL
DATETIME/VARCHARcolumns.date_parsealso accepts values that are already datetimes. replace_accentsrace: Fixed panics and hangs when many goroutines usereplace_accents. Also fixed related channel races in batches and merged dataflows.- ADBC DDL lock hang: With
SLING_USE_ADBC, Sling commits the open transaction before the ADBC import, so an MSSQL truncate does not lock the load. - StarRocks reserved column names: Stream load and
INSERTnow quote column names such asdefault,keyandrows. - DuckDB cancel race: A late cancel no longer stops the next query.
sling conns teston unresolved type: The test now fails when Sling cannot resolve the connection type (e.g. a missing secret reference).- Postgres environment variables: Sling unsets PG environment variables that
lib/pqdoes not support, which prevented a connection panic. - Log setup deadlock: Fixed a deadlock when env file loading wrote logs during log file setup.