- Patched several security vulnerabilities (CVE‑2023‑45283, 45284, 47124, 47633, 47106) by refusing recursive requests, denying URL fragments, and removing backoff for the HTTP challenge.
- Fixed bugs and updated dependencies: stripPrefix middleware retry handling, Consul API version bump, quic‑go upgraded to v0.39.1, and removed deprecated Datadog tracer usage.
- Refreshed documentation (governance review process, metrics header labels, BasicAuth/DigestAuth and ErrorPages examples) and added a new maintainer.