Released: 2026-10-06
Varnish version: 6.0.18r5
Artifact Firewall version: 0.7.0
varnishlog-json produced, byte for byte. It was previously rebuilt from the parsed transaction, so anything that reads the log body expecting a fixed JSON shape (a collector transform, a log backend’s parser, a saved query) needs to be checked against the new output before upgrading. Values derived from a transaction are now set as attributes on the record, so read them from there rather than from the body.TraceId, SpanId and TraceFlags as string attributes. Every exporter already sets those natively on the record itself, so a backend that reads them from the attributes has to read the record fields instead.SeverityNumber, so a backend can filter and alert on severity.virtual_registry.purge.allow lists the addresses and CIDR ranges allowed to send PURGE /purgez, in addition to localhost. A purge could only come from the node itself, so a Varnish Broadcaster fanning it out to a cluster, or a webhook from the origin, was refused.max_ttl sets a maximum TTL, including for the packages and version-pinned manifests that were cached indefinitely. A longer TTL is lowered to it and the difference is added to keep, so the object is revalidated with a conditional request once it expires. Content-addressed objects are exempt.book_path to a store, which puts its book, the index MSE4 keeps of what is cached, on a device of its own: MSE4 recommends a fast device for the book’s small random IO and a large one for the store’s sequential IO. size then covers the store alone, so give the book a volume holding book_size plus room for a resize. Set on a cache that already exists, it moves the book on the next start, copying it across and delaying that start.varnish.storage is now refused on reload instead of being accepted and ignored. The file devices are laid out before Varnish starts and mkfs.mse4 will not touch them while it is running, so a reload could never apply the change. Restart the Supervisor to apply one: growing a store or adding a new one keeps the cached objects, and only shrinking drops the objects at the tail.fast_304: false on a registry to go back to the standard path, needed only for a remote whose 304 responses carry an updated Cache-Control or Vary.X-Varnish header to remotes.--validate now fails when it is given no configuration file, through --config or SUPERVISOR_CONFIG. It used to check the built-in defaults alone and report them valid, which read as if the operator’s file had been checked.default: true now logs a warning, since it answers only hosts that start with its name and anything else gets a 404.--defaults panicking instead of printing the default configuration.Content-Length. It had none when the remote compressed the package on request.THESE PACKAGES DO NOT MATCH THE HASHES after a PyPI file was uploaded again under the same name. Relative file links in an HTML simple index now carry the file’s sha256 in a vs-sha256-<hex> path segment, and the file is cached under it. Lockfiles that record file URLs, such as uv.lock, will contain the segment.Error rather than left Unset with the failure visible only in the span attributes. Errors reported by varnishlog-json also populate error.type and error.message again instead of being dropped.19T. Such a size is now given in gigabytes.size or book_size that validation accepts being rejected when the storage is set up. 20TB, 1.5T and 1 GB now work, rather than failing with invalid size format as Varnish starts.mkfs.mse4 failing with No space left on device on stores of 45G and above. The space held back from size for filesystem metadata was a fixed 1G, but that metadata grows with the volume. It is now 3% of size, with 1G as the floor. Existing stores are resized on upgrade, which drops the objects at the tail of each store.gh) never being cached. Its GitHub CLI User-Agent matched the Git client rule, so its REST and GraphQL requests were parsed as Git requests and failed. Only a git/ User-Agent now classifies a request as Git./api/graphql, which was not recognized as a GitHub endpoint./artifactory/api/cargo/<repo>/index/, which was not recognized, so config.json and the index were passed through and cargo downloaded each crate straight from Artifactory.failed to verify the checksum after a crate was uploaded again under the same version. The download URL in config.json now carries the crate’s sha256 from the index in a vs-sha256-<hex> path segment, and the crate is cached under it. A config.json or crate cached by an earlier version is fetched from the remote again after the upgrade.demo-1.0-SNAPSHOT.jar, for the whole package TTL after a deploy replaced it. A file in a SNAPSHOT version that is named -SNAPSHOT rather than after a build timestamp now takes the manifest TTL, like the .pom of the same deploy, so it is revalidated against the remote on every request unless manifest_ttl is set.