Virtual Registry 0.11.0

Released: 2026-06-03

Varnish version: 6.0.18r1

Artifact Firewall version: 0.3.1

Added

  • Added support for caching Debian apt artifacts.
  • Added disable_cache option to disable artifact caching on a per-registry basis.
  • Added support for caching responses from the GitHub REST API on GitHub.com and GitHub Enterprise Server (GHES). This includes metadata endpoints, SHA-addressed git objects and source archives, and release-asset and Actions artifact downloads served via signed-blob redirects.
  • Added HMAC signing of /redirectz URL matrix parameters, emitted as an additional ;sig=... matrix parameter. Enable via virtual_registry.redirects.signing.enabled; the signing key is read from the environment variable named in virtual_registry.redirects.signing.key_env.
  • Added option to disable the /redirectz endpoint entirely through virtual_registry.redirects.enabled.
  • Added Varnish Enterprise license reload when supervisor is reloaded via SIGHUP
  • Bumped Artifact Firewall to 0.3.0, which adds Maven support, per-version artifact preflight blocking, ruleset persistent storage, and the ability to disable rules at runtime via the admin API. The Supervisor continues to run the firewall in integrated deployment mode behind Virtual Registry, and now registers manifest transformers for the NuGet and Maven ecosystems in addition to npm and PyPI.
  • Added top-level otel.endpoint configuration that sets OTEL_EXPORTER_OTLP_ENDPOINT, used by all signals when no signal-specific endpoint is configured. The OTLP SDK auto-appends /v1/<signal> for HTTP protocols.

Fixed

  • Fixed default configuration values being silently lost when a user-provided YAML file set only a subset of fields in the same section.
  • Fixed Artifact Firewall returning 503 when firewall.address was omitted from config.
  • Fixed fsnotify on user-provided certificates so that they are reloaded when files change on disk.

®Varnish Software, Wallingatan 12, 111 60 Stockholm, Organization nr. 556805-6203