Update dependency caddyserver/caddy to v2.11.6 - #301
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/caddyserver-caddy-2.x
branch
from
October 1, 2026 17:15
b790b68 to
6c54d9f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.11.4→v2.11.6Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
caddyserver/caddy (caddyserver/caddy)
v2.11.6Compare Source
This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!
We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.
Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.
Highlights
url_patternrequest matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matchingurl_patternCEL function too. Thanks @dunglas! (#7787)timeoutshandler directive for per-route tuning. (#7913)tls_automate_namesglobal option: Manage certificates for names without serving them in a site block. (#8015)expected_underscore_headersserver option: If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. (#7809)versions 3upstreams now honortls_trust_pool(#8042)random_choosepolicy distributes correctly now (#7873)encodenow stream immediately instead of being buffered. (#7905)importnow works inside named routes (#7986), and quoted braces are treated as literal arguments (#7875).set_cookielog filter (#7888)roll_intervalaccepts days (d) (#7900){http.request.proto_name}placeholder (#7782)SERVER_ADDR(#7912)authenticationproviders no longer clobber each other's responses (#7904)431 Request Header Fields Too Large. If you need more, raise it with themax_header_sizeserver option.read_body_idleandwrite_idlein thetimeoutsserver option, or per-route with thetimeoutsdirective. (#7913).are now dropped, the same way underscores were in 2.11.4. PHP folds.to_, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the newexpected_dot_headersserver option.client_authno longer applies to more specific hostnames that have their own site blocks. For example,public.example.comno longer inherits mTLS from*.example.com. If you were counting on that inheritance, configureclient_authon the specific site explicitly. (#7920)named_routes(#7800)forward_authuri(#7814)weighted_round_robinweights (#7807)browsefile_limit(#7988)mapinputs (#8067)mapdestination placeholders (#8074)@version separators (#7974)/loadnow returns400with warnings inside a valid JSON body when a config is invalid. Before, it returned200with two concatenated JSON objects. (#7267)methodmatcher values are normalized to uppercase, somethod getnow matchesGETrequests. (#7832)Security fixes
Thank you to everyone who reported responsibly and helped with patches:
forward_authandreverse_proxy, a request could be sent on the wrong upstream connection. Reported by @carlt, fixed by @WeidiDeng. (GHSA-6365-7ppr-5r92, #7859)101 Switching Protocolsresponses too. Thanks @jirn073-76.handle_pathanduristrip_prefix/strip_suffixnow canonicalize the resulting path, so it can't bypass path-based authorization. Thanks @steadytao..(see above) to prevent bypassingforward_auth copy_headerswith PHP/FastCGI backends. Thanks @dunglas.path_regexpmatcher now normalizes Windows backslashes like thepathmatcher does. This completes the fix for CVE-2026-52844. Thanks @thientd. (#7858)Proxyheader is no longer passed to backends asHTTP_PROXY(HTTPoxy). Thanks @bzyy1024. (#7934)413. Thanks @hktitof. (#7969)🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your
go.modfile. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. Note that doing so now also requires Go 1.26.Thank you to everyone who was involved this release, especially our 40 new contributors! 🎉
What's Changed
d(day) inroll_intervaldirective by @mohammed90 in #7900MaxSizeSubjectsListForLogoff-by-one whenmaxToDisplayis0by @mohammed90 in #7970tls_automate_namesglobal option by @IslamElsayed in #8015New Contributors
Full Changelog: caddyserver/caddy@v2.11.4...v2.11.6
Configuration
📅 Schedule: (UTC)
* * 1 */3 *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.