Releases: netbirdio/netbird
Release list
v0.77.0
Release Notes for v0.77.0
What's New
Agent Network
-
Reworked Agent Network endpoint identity and settings bootstrap.
#7085 -
Added a proxy-connect authorizer seam for Agent Network.
#7136 -
Added reverse proxy usage accounting for activity tracking.
#7116
Client Improvements
-
Added strict anonymization level and MAC address anonymization to debug bundles.
#7102 -
Declared the
xdg-utilsdependency for NetBird UI packages.
#7126 -
Fixed credentials used for GTK3 package uploads.
#7125 -
Prevented WireGuard packets from being misrouted to the STUN handler.
#7059 -
Updated the NetBird Wails fork to remove the native WebView2 dependency.
#7128 -
Migrated the relay QUIC tracer to qlog and upgraded
quic-goto v0.59.1.
#7124 -
Derived Windows SSH privilege checks from the user token and group membership.
#6966 -
Adjusted the GTK3 release job.
#7163 -
Fixed a macOS DNS panic caused by malformed
scutiloutput.
#7180 -
Added a fallback to per-IP ACL rules when
ipsetis unavailable.
#6332 -
Gated IPv6 forwarding on overlay IPv6 while preserving host Router Advertisement acceptance.
#6221 -
Removed installer registry handlers for Windows autostart Run keys.
#7183
Infrastructure & Documentation
-
Added Crowdin configuration for UI translation synchronization.
#7155 -
Fixed Crowdin export paths and export options.
#7162 -
Updated the documentation to direct translation contributions to Crowdin.
#7161 -
Allowed external test suites to reuse the NetBird end-to-end test harness.
#7176 -
Improved the release pipeline to build release branches and delay marking releases as "latest" until signing is complete.
#7171
Full Changelog: v0.76.3...v0.77.0
v0.76.3
What's Changed
- [management] prewarm a posture check cache on network map generation by @pascal-fischer in #7093
- [client] peer: re-arm the WireGuard watcher after a lazy wake by @riccardomanfrin in #7091
- [infrastructure] Detect community GHCR images during enterprise migration by @jnfrati in #7101
- [client] disambiguate the connection_type metric tag by @riccardomanfrin in #7043
- [management] Affected peers for user updates by @pascal-fischer in #7099
- [infrastructure] add grafana dashboard for licensed management by @mlsmaycon in #7095
- [management] Deny reverse proxy access to pending and blocked users by @mlsmaycon in #7105
Full Changelog: v0.76.2...v0.76.3
v0.76.2
What's Changed
- [misc] add AGENTS.md file by @mlsmaycon in #7014
- [client] Handle interface lookup errors in iOS DNS index helper by @Optic00 in #6999
- [client] iOS - Remove duplicate Login RPCs from the iOS SDK by @evgeniyChepelev in #6931
- [client] Declare GTK4/WebKitGTK runtime deps for the Linux UI packages by @pappz in #6893
- [management] Generic gRPC extension seam for external modules by @bison in #6894
- [management] Resolve agent network permissions per submodule by @mlsmaycon in #7030
- [management] fix handling of empty network map during decode and encode by @pascal-fischer in #6987
- [client] Keep the account email backing the SSO login hint correct by @pappz in #6986
- [client] Android - Create the Android fake IP manager lazily on DNS flag enable by @pappz in #6989
- [client] Android - Serialize Android tunnel reconfiguration callbacks by @pappz in #6990
- [client] Keep the UI running when the notification service fails to start by @lixmal in #6959
- [client] launch macOS GUI as the logged-in user after install/update by @riccardomanfrin in #6962
- [client] Don't ask for an SSO login when the login never reached management by @lixmal in #6983
- [misc] Add android and ios tags to PR title check by @pappz in #7037
- [client, android] Pull fresh TUN settings on Android rebuild by @pappz in #6991
- [client, android] Reuse the persisted configuration when enrolling by @camiloariza in #7022
- [client, android] Reuse the profile's account for Android SSO logins by @pappz in #6988
- [client] Update wails to v3.0.0-beta.3 by @pappz in #7038
- [management] Align agent-network API contracts for API clients by @mlsmaycon in #7026
- [client] Probe the daemon login with IsLoginRequired by @pappz in #7052
- [client, android] Fix profile account path test on Windows by @pappz in #7057
- [client] Fix session expired relogin by @pappz in #7055
- [client] Fix Linux tray right-click opening the main window by @pappz in #7039
- [management] prevent dangling group refs in agent-network ACLs. by @braginini in #7060
- [management] Prevent deleting groups referenced by reverse proxy services by @mlsmaycon in #7062
- [relay] randomize the relay reconnect backoff by @riccardomanfrin in #7067
- [misc] Move enterprise setup to Traefik and harden migration by @bcmmbaga in #7042
- [misc] Expand agent guidelines with security, type-safety and lifecycle conventions by @lixmal in #7076
- [client] Ship a legacy GTK3 UI package for distros without WebKitGTK 6.0 by @pappz in #7040
- [client] Add a UI setting to stay connected after quitting by @pappz in #7078
- [infrastructure] Generate a session cookie encryption key on fresh self-hosted installs by @Optic00 in #7056
- [client] Stop the macOS UI on pkg upgrade by @lixmal in #7079
- [client] Reword the firewalld package comment by @lixmal in #7081
- [client] Update the wails fork reference to the integration branch head by @pappz in #7087
New Contributors
- @camiloariza made their first contribution in #7022
Full Changelog: v0.76.1...v0.76.2
v0.76.1
What's Changed
- [client] Support Android session expiry handling by @pappz in #6945
- [client] Stop and remove the daemon on netbird-ui cask uninstall by @lixmal in #6977
- [misc] Update SECURITY.md by @mlsmaycon in #6981
- [misc] group x package updates and run weekly by @mlsmaycon in #7000
- [client] Fix daemon lock order inversion between SetConfig and login by @lixmal in #6978
- [client] Fix expression order in legacy nftables route rules by @Optic00 in #7011
- [proxy] remove cluster tag from proxy metrics by @pascal-fischer in #6985
- [misc] update contributing guide by @mlsmaycon in #7009
- [client] Restrict debug bundle log path and upload destinations by @lixmal in #6975
- [management, proxy] Management-owned LLM pricing: file-backed defaults + by @braginini in #6965
Agent Network
- The merged PR #6965 requires an upgrade of both Management and Proxy containers.
New proxy under old management silently disables cost metering.
New Contributors
Full Changelog: v0.76.0...v0.76.1
v0.76.0
Security
Fixes a local privilege escalation in the client daemon (GHSA-qcpp-8vwj-hhwr). The daemon's local control interface accepted any local caller without authentication, so an unprivileged user on the same machine could enable the embedded SSH server, turn on SSH root login and disable SSH authentication, and then open a root shell. Every version from 0.5.0 to 0.75.1 is affected: on Linux, macOS and FreeBSD through the world-writable Unix socket, and on Windows through the loopback TCP listener, which carried no caller identity at all. Reported by @neewek.
The daemon now derives each local caller's identity from the kernel and requires root, or an administrator on Windows, to enable the SSH server, enable SSH root login, disable SSH authentication, or to change the management URL or deregister the peer while that profile has the SSH server enabled. On Windows it serves a named pipe instead of loopback TCP, and existing installations are migrated automatically.
Upgrade note: if you enable any of those settings from a script or an unprivileged session, run the command with sudo, or from an elevated prompt on Windows. Turning them off is unchanged, and so is everything else on the socket.
Learn more here
What's Changed
- [management] Force routing-peer DNS resolution for reverse-proxy domain targets by @lixmal in #6872
- [management] Read reverse-proxy service and target columns in Postgres path by @lixmal in #6886
- [client] Expose RenameProfile in the Android profile manager binding by @pappz in #6926
- [client] Build UI release binaries with the production tag by @pappz in #6898
- [client] Escape dots in interface names for sysctl configuration by @stefan-fast in #6930
- [client] Serialize iOS tunnel reconfiguration callbacks by @pappz in #6870
- [client] Unify route selection in the route manager by @pappz in #6928
- [client] parse NB_LAZY_CONN_INACTIVITY_THRESHOLD as a Go duration by @riccardomanfrin in #6947
- [client] Export peer details for Android by @pappz in #6925
- [management] explicit accountID check when deleting a user by @pascal-fischer in #6944
- [infrastructure] Deprecate legacy Dex and Zitadel getting-started scripts by @TechHutTV in #6952
- [client] Fix UI crash on Windows builds without dark-mode support by @lixmal in #6958
- [signal] make pprof configurable by @pascal-fischer in #6963
- [client] Authorize daemon IPC callers by their local identity by @lixmal in #6967
New Contributors
- @stefan-fast made their first contribution in #6930
- @TechHutTV made their first contribution in #6952
Full Changelog: v0.75.1...v0.76.0
v0.75.1
Release Notes for v0.75.1
What's New
Agent Network
-
Added prompt cache token and cost accounting to Agent Network usage.
#6900 -
Added support for Claude Opus 5.
#6895 -
Scoped Agent Network model allowlists per policy, group, and provider.
#6905
Client Improvements
-
Reconcile routed AllowedIPs when a lazy connection becomes idle.
#6863 -
Fetch FreeBSD port files from the GitHub mirror instead of cgit.
#6880 -
Restored the missing
backup.Resetbehavior.
#6883 -
Made
Test_ConnectPeersdeterministic under Docker/eBPF kernel and Darwin CI.
#6884 -
Export agent version information for iOS.
#6918 -
Use platform-specific installer URLs for manual update downloads.
#6922 -
Exit the GUI immediately when the Windows session ends.
#6878 -
Fixed stale routing peers after removing overlapping-prefix networks.
#6799 -
Added
ReapplyMatchingsupport to the dedicatedAllowedIPsRefCounter.
#6935
Infrastructure & Miscellaneous
- Restored the
rootless-latestDocker image tag.
#6914
Full Changelog: v0.75.0...v0.75.1
v0.75.0
Release Notes for v0.75.0
New Feature: Redesigned Desktop Client
This release ships a complete rewrite of the desktop client. We went ahead and replaced the old Fyne-based tray application with a new Wails v3 app backed by a React and TypeScript frontend, and it is a massive upgrade. You get a proper main connection view, an exit-node switcher, a networks and peers browser with detail panels, profile management, full settings, debug-bundle creation, and a first-run welcome flow, all in one place instead of buried in a tray menu. #6473 by @pappz and @heisbrot
The new UI is also translated into 10 languages now, and session handling got a lot smarter, so you actually know when your session is about to expire instead of finding out the hard way. Do note that launch-on-login is now enabled by default on fresh GUI installs, so if you manage devices through MDM, the disableAutostart setting is enforced on every launch to keep that under your control.
- Rebuilt the desktop client as a Wails v3 application with a React + TypeScript frontend, replacing the Fyne UI. #6473
- Added internationalization with 10 locales (English, German, Spanish, French, Hungarian, Italian, Japanese, Portuguese, Russian, and Simplified Chinese), shared between the tray and the frontend. #6473, #6790 by @s-shimizu-clpl
- Added a new system tray with per-platform theme-aware icons, including a native XEmbed host and theme watcher on Linux. #6473
- Improved session handling with an auth session watcher, pending login flow, session-expiration dialog and tray notifications, and
netbird loginimprovements. #6473 - Extended the daemon API with status stream subscription, an event stream, networks and exit-node selection endpoints, and richer full status, with probe throttling to protect the daemon from UI-driven request storms. #6473
- Enabled launch-on-login by default on fresh GUI installs, managed through the daemon as the single source of truth (HKCU on Windows). #6738 by @mlsmaycon
- Enforced MDM
disableAutostarton every GUI launch, not just fresh installs. #6782 by @riccardomanfrin
Learn more:
- Desktop app overview: https://docs.netbird.io/client/desktop-app
- Profiles: https://docs.netbird.io/client/profiles
- Deep dive on the new app: https://netbird.io/knowledge-hub/netbird-v0-75-new-desktop-app
What's Changed
Desktop Client Improvements
- Made the client connect immediately on profile selection, except while managing profiles. #6838 by @pappz
- Brought the connection up in Go after SSO login for a faster, more reliable post-login connect. #6744 by @mlsmaycon
- Kept the session deadline visible across reconnects. #6847 by @pappz
- Fixed the browser dialog not closing during the renew-session flow. #6745 by @heisbrot
- Disconnected the daemon on GUI quit via an async Down call. #6796 by @pappz
- Restored residual state in foreground mode before login. #6707 by @dfry
- Clarified the outdated client overlay wording. #6718 by @heisbrot
- Used menu-bar wording on the macOS welcome screen. #6810 by @heisbrot
- Added SSO login flow timing instrumentation. #6717 by @mlsmaycon
- Updated Wails to v3.0.0-alpha2.117. #6837 by @pappz
Client Improvements
- Added a JSON gateway for the NetBird daemon, exposing the daemon API over HTTP/JSON. #6272 by @jnfrati
- Introduced client-side event aggregation. #6627 by @dmitri-netbird
- Offloaded client config generation to the client, reducing work on the management server. #6711 by @dmitri-netbird
- Warmed lazy connections from the DNS resolver so lazily-connected peers come up faster. #6854 by @mlsmaycon
- Fixed forwarder peers never being excluded from lazy connections. #6674 by @riccardomanfrin
- Fixed WGWatcher silently failing to restart on fast disconnect/reconnect. #6664 by @riccardomanfrin
- Cleared stale UDP checksums in the eBPF XDP proxy after port rewrite. #6861 by @lixmal
- Raised the relay early-message buffer cap to 10,000 to avoid dropping relayed handshakes. #6752 by @riccardomanfrin
- Fixed a nil-context panic in the iOS dynamic route resolver. #6848 by @pappz
- Fixed a DNS probe listener panic on unparseable local addresses. #6797 by @pappz
- Fixed the browser (WASM) relay WebSocket close and raised the RDP dial timeout. #6684 by @lixmal
- Included system events in status conversion. #6746 by @lixmal
- Refreshed WireGuard stats in mobile debug bundles. #6814 by @pappz
- Distinguished empty vs. corrupt state in debug diagnostics. #6816 by @pappz
Management Improvements
- Added the
dashboard_featuresaccount setting #6742 and theagent_network_onlyaccount setting #6736, withagent_network_onlyrequiringdashboard_features.agent_networkto be enabled #6750 — all by @mlsmaycon - Added traffic filters for source and destination ID. #6697 by @pascal-fischer
- Allowed disabling the device code flow when using Dex. #6809 by @pascal-fischer
- Propagated auth grant types for the combined server. #6817 by @pascal-fischer
- Built routes for the peer cache on network map components #6780 and added component types #6866 — both by @pascal-fischer
- Fixed fetching of missing settings in the GetAccount call. #6800 by @dmitri-netbird
- Fixed a duplicate operationId in the OpenAPI spec. #6734 by @CoderSufiyan
- Enabled pprof via an environment variable. #6778 by @pascal-fischer
- Added logging to ephemeral peer deletion. #6747 by @pascal-fischer
Agent Network
- Added Kimi (Moonshot AI) to the provider catalog. #6853 by @mlsmaycon
- Added Bedrock cost-allocation metadata plus a per-provider
metadata_disabledoption. #6791 by @mlsmaycon - Matched Bedrock provider models against the normalized request model. #6773 by @mlsmaycon
- Probed the agent-network endpoint with a GET instead of getent. #6867 by @mlsmaycon
- Fixed the proxy multi-stage Docker build. #6864 by @mlsmaycon
Relay Improvements
- Trusted
X-Real-Ipheaders only from configured trusted proxies. #6833 by @pappz - Removed the deprecated Hello handshake and gob token decode. #6783 by @lixmal
Self-Hosting Improvements
- Added a unified admin CLI for self-hosted helpers. #6507 by @jnfrati
- Simplified the enterprise bootstrap. #6869 by @bcmmbaga
Internal, CI, and Docs
v0.74.7
What's Changed
- [relay] Handle QUIC connections concurrently to prevent handshake head-of-line blocking by @lixmal in #6784
- [client] Reject leading hyphen in getent input to prevent flag injection by @lixmal in #6787
- [client] Sanitize peer FQDN/hostname in generated SSH config by @riccardomanfrin in #6805
- [client] Disable gVisor TCP RACK loss detection on Windows by @lixmal in #6808
- [client] Rename isValidAccessToken to reflect audience-only check by @riccardomanfrin in #6806
- [client] Bind netstack SOCKS5 proxy to 127.0.0.1 by default by @riccardomanfrin in #6812
- [client] Evaluate IP fragments against firewall ACLs by @lixmal in #6781
Full Changelog: v0.74.6...v0.74.7
v0.74.6
v0.74.5
What's Changed
- [proxy] enforce model allowlist for URL-routed providers (Bedrock/Vertex) by @mlsmaycon in #6764
- [management] Remove proxy peer stale deduplication logic by @mlsmaycon in #6768
Full Changelog: v0.74.4...v0.74.5