Changes for version v0.9.0 - 2026-05-09
- Security
- The psgi.request.remote_addr metric is no longer logged unless the secure_set_key is specified in the constructor. This is to avoid leaking personally identifiable information if the connection to the statsd client is not secure, CVE-2026-45179.
- Enhancements
- Added psgix.monitor.statsd_secure_set_add to the environment with a method for securely logging set data.
- Documentation
- Added a SECURITY CONSIDERATIONS section.
- Updated copyright year.
- Updated author email due to issues with cpan.org email forwarding.
- Removed CONTRIBUTING.md due to re-evaluation about some AI-assisted issue reporting.
- Fixed spelling errors.
- Tests
- Added author tests for POD spelling.
- Toolchain
- Stopped signing distributions, since Module::Signature is deprecated.
- Added doap.xml to the distribution.
Modules
send statistics to statsd