This reference page mirrors the root changelog in
CHANGELOG.mdso the book and repository stay aligned.
[Unreleased]
[0.3.230] - 2026-10-04
Changed
- [Cloud] Audit logs no longer record email addresses, usernames or SAML NameIDs. Member, invitation, SSO login and password-reset events identify people by user id or invitation id; failed logins store a keyed hash of the attempted email instead of the address. (#1087)
- [Cloud] Audit logs are now kept for 400 days and then deleted by a daily retention worker. The append-only trigger allows only this purge, and only for rows past the window;
verify_chaintreats the oldest surviving row as the chain start. (#1087) - [Cloud] Privacy Policy 2.2 and DPA 2.2 describe audit-log retention after account deletion. Terms 2.1 name Delaware as governing law and venue.
- [DevX] The Kubernetes manifests (
k8s/) and the Helm chart now give every MockForge replica its own recorder volume. Previously all replicas mounted one ReadWriteOnce claim holding the recorder’s SQLite database, so pods on other nodes could not start and pods on the same node shared one SQLite file.k8s/deployment.yaml+k8s/pvc.yamlare replaced byk8s/statefulset.yaml(a StatefulSet with avolumeClaimTemplatesentry, onerecorder-db-mockforge-Nclaim per pod), and the HPA now targets it. The Helm chart renders a StatefulSet (plus a<fullname>-headlessService) whenpersistence.enabledis true, the default, and a Deployment without a recorder volume when it is false. Upgrading an existing Helm release replaces its Deployment with a StatefulSet and creates per-pod claims (data-<fullname>-N); the old shared<fullname>-dataclaim is kept (annotatedhelm.sh/resource-policy: keep) but no longer mounted, so copy any recordings you need out of it, then delete it. The Kubernetes test workflow’s Chaos Engineering job, which never ran, now runs on manual dispatch and weekly.
Fixed
-
[Reality]
bench-chunkedsends a valid JSON body when the request’s Content-Type is JSON (application/jsonor any+jsontype, from--headeror a targets-fileheadersentry). The body is the spec-generated request body plus a_paddingstring field, sized to exactly--total-size-bytesand streamed in the same chunks. Previously every body wasXfiller, so WAFs flagged each request as malformed JSON. Other content types still get filler. (#79) -
[DevX] Registry audit email hashing compiles under strict unused-qualification lints in both PostgreSQL and SQLite builds. Hashing behavior is unchanged.
-
[Cloud] Flow creation sends the registry-required configuration across all five editors. Federation details have a labeled Back button; portal dialogs, placeholders and disabled controls use readable theme colors and wrapping action rows, and service route counters retain their spacing.
-
[Cloud] Authenticated portal workflows recover from deleted workspace selections and page errors; resilience and snapshot comparisons load, deletion dialogs work, fixture lists refresh after writes, and fitness authoring sends supported evaluator settings. Cookie reloads restore tokens before loading protected pages. Theme toggles, deployment slugs, actor labels and action accessibility are corrected. (#1144)
-
[DevX]
cargo install --locked mockforge-clino longer warns about yanked dependencies (chacha200.10.0 andspin0.9.8/0.10.0 bumped to their patched releases). -
[DevX] GDPR erase on the SQLite backend did nothing (
delete_user_data_cascadereturned 0). It now matches the Postgres store. (#1087)
[0.3.229] - 2026-10-01
Changed
- [Cloud] Tenant isolation is now also enforced in the database for every org-scoped table (36 tables under Postgres row-level security, up from 5). Request-path queries run bound to the caller’s org; background workers, webhooks and platform-admin paths run on the owner role. Requires the owner role (
DATABASE_URL) to haveBYPASSRLS; the migration refuses to apply otherwise. Startup now logs which roles back each pool and flags a misconfigured one at ERROR. (#1087) - [Cloud]
PUT /api/v1/organizations/{org_id}/quotais now platform-admin only. Org owners can no longer set their own quota overrides, because overrides are merged over plan limits.GETnow requires membership in the org. (#1087) - [Cloud] Row-level security now also covers 38 tenant tables that have no
org_idcolumn of their own (workspace, hosted-mock and other child tables). Each is isolated through its parent’s org, and per-user tables are scoped with a newapp.current_user_idsetting. (#1087, #1120) - [Cloud] Requests without an organization header now resolve to an org the user belongs to even when they own none (SSO-provisioned members, or users who deleted their personal org). Previously every such request returned 404. (#1087, #1117)
- [DevX] Kubernetes manifests and the Helm chart now meet the “restricted” Pod Security Standard (non-root uid 999, no privilege escalation, all capabilities dropped), and liveness/readiness probes use the HTTP port instead of the auth-protected admin port. (#1118)
- [DevX] Dependency refresh: 33 patch and minor updates, including tokio 1.53.1 and hyper 1.11. (#1104)
Fixed
- [Cloud] The registry API no longer occasionally drops a request mid-flight (clients saw a closed connection or 502). The request-logging middleware held a tracing span open across an
await, which could panic once a request moved between worker threads. - [Cloud] Security: any authenticated user could read or overwrite any org’s quota overrides. (#1087)
- [Cloud][AI] Security:
POST /api/v1/organizations/{org_id}/mockai/generate-openapi-from-trafficdid not check that the caller belongs to the org. (#1087) - [Cloud] Security: the GDPR data export included pending invitation payloads, which let a plain member redeem an invite meant for someone else. (#1087)
- [Cloud]
GET /api/v1/organizations/{org_id}/incidents/statsno longer returns 500 once the org has a resolved incident. (#1087) - [Cloud] Security: a workspace could aim a chaos campaign at another org’s hosted mock and inject faults into it. Campaign targets are now checked against the caller’s org at create, trigger and snapshot restore, and the internal chaos toggle requires the run that owns it. (#1124)
- [Cloud] Security: adding a capture to a capture session did not check who owned the capture, so a replay could read another org’s captured request bodies. (#1124)
- [Cloud] Capture sessions, clone models, monitored services, diff runs and fitness functions belonging to another org now return exactly the same “not found” response as missing ones. (#1087, #1128)
- [Reality][AI] MockAI no longer stores a session for every write request that arrives without a session ID. Those sessions were never read again and every write waited on one shared lock, so throughput fell steadily under sustained load (about 2x faster writes, flat memory). Per-request fixture-matching logs are now at debug level instead of warning. (#1125)
- [Cloud] Returning visitors no longer see “Something went wrong” after a cloud UI deploy: the app’s entry JS and CSS are content-hashed so browsers can’t keep a stale copy. (#1116)
[0.3.228] - 2026-09-30
Added
- [Reality] The mock Kafka broker can filter messages so it counts or verifies them without keeping every payload in memory. (#992)
Fixed
- [Cloud] Hosted mocks now require a per-deployment management token for writes to MockForge’s control routes (
/__mockforge/*,/api/chaos,/api/recorder, and the other management APIs). Previously anyone who knew a hosted mock’s URL could change it. Reads and your mocked API are unaffected, and self-hosted servers don’t use a token. Owners can reveal the token on the Hosted Mocks page. (#1105) - [DevX] Windows release binaries build again (a Unix-only socket option in
bench-qosbroke every Windows build since 0.3.223). (#1101)
[0.3.227] - 2026-09-30
Added
- [Reality]
mockforge bench-chunkedgains--rps N(per-target cap on request starts per second),--cps(new TCP/TLS connection per request), and campaign mode:--rounds N/--repeat-until <duration>re-run the whole pass into<output>/round_N/, with per-round stats incampaign.jsonlandround-summaries/, and--keep-rounds Nrotating old round dirs, matchingmockforge bench. (#79) - [Cloud] Redesigned app shell for the logged-in portal: new sidebar, top bar, search and menus, refreshed shared UI primitives, and a new dashboard; every page moved onto the new frame. (#1086)
Fixed
- [Cloud] GDPR account erasure no longer fails for users who have audit-log rows. (#1093)
- [Reality]
bench-chunked --chunk-interval-msnow sends the first chunk immediately and waits only between chunks. Previously it waited before the first chunk and sent the last two back to back. (#79)
[0.3.226] - 2026-09-29
Added
- [DevX] Response overrides now work in
mockforge serve. Rules come from a newoverrides:list inmockforge.yaml,MOCKFORGE_HTTP_OVERRIDES_GLOBfiles, and a newMOCKFORGE_HTTP_OVERRIDESJSON array. With--admin,GET/PUT /__mockforge/overridesreads and replaces the live rules without a restart; an invalid set returns 400 and keeps the previous rules. Rules gainnameandenabled. (#1088) - [DevX] Admin UI Overrides page to toggle, reorder, edit, and save override rules for the running mock (self-hosted) or a hosted mock (cloud). (#1095)
- [Cloud] Per-hosted-mock override rules:
GET/PUT /api/v1/hosted-mocks/{id}/overridesstores rules on the deployment, passes them to new machines, and pushes them live to running ones over the private network. (#1094)
Fixed
- [DevX]
tag:override targets match the operation’s real OpenAPI tags, andwhen:conditions see request headers, query, and body. Invalid JSON pointers are rejected instead of silently patching the whole body, and regex targets work in rule sets loaded from config (including gRPC). (#1088) - [Cloud] Redeployed hosted mocks now start their admin server, so the resilience dashboard and override push can reach them. (#1094)
- [Cloud] Plugin registry search no longer returns 500 for the default “popular” sort and the “security” sort. (#1082)
- [DevX] The admin UI top-bar search suggests pages and navigates on Enter. (#1082)
- [Cloud] Bump wasmtime and wasmtime-wasi to 36.0.16 for RUSTSEC-2026-0316 and RUSTSEC-2026-0314. (#1092)
[0.3.225] - 2026-09-27
Added
- [Reality]
mockforge bench-chunked --targets-file <file>sends realTransfer-Encoding: chunkedtraffic to every target in a multi-target file in parallel (--max-concurrency, default 10). It uses the same file format asbench --targets-file, including per-targetauth/headers/spec. Per-target artifacts go to<output>/target_N/, with a roll-up inchunked-multi-target-summary.json. (#79)
[0.3.224] - 2026-09-24
Added
- [Reality] Campaign mode now supports
--no-k6-logs(skipsk6-output.logand conformance debug sidecars; k6 output is drained instead of buffered) plus per-round aggregate artifacts:round_N/round_summary.json,round_N/all_targets.csv, durablecampaign.jsonl, andround-summaries/copies. New--keep-rounds Nprunes old round directories during a campaign while preserving campaign-level stats, and k6 scripts are generated once per target and reused across rounds. (#79)
[0.3.223] - 2026-09-18
Added
- [Reality] Multi-target
--repeat-until <duration>and--rounds Ncycle the full targets list so low concurrency can still stress every server over a longevity window without manual restarts. Pair with a short--duration(per-batch k6 lifetime). (#79)
[0.3.222] - 2026-09-16
Fixed
- [Reality] Longevity / huge-spec k6 runs no longer emit a Trend+Rate pair per OpenAPI operation by default when ops >= 500 or duration >= 1h (
--per-op-metrics/--no-per-op-metricsto force).--max-concurrencyauto-caps to 3 for huge specs, and SIGKILL gets an OOM hint. (#79)
[0.3.221] - 2026-09-12
Fixed
- [Contracts] OpenAPI 3.1 schema
typearrays (["string", "null"]) are coerced to OAS 3.0type+nullableso the spec loads. LLM-generated specs failed withinvalid type: sequence, expected a stringand never extracted operations. (#79)
[0.3.220] - 2026-09-12
Fixed
- [Reality]
traffic-breakdown.jsonno longer repeatsunique/total/expected_requestsnext tounique_cases/projected_*. Those aliases were a one-release bridge and got read as k6 wire counts.unique_casesis still the YAML case count (not traffic on the wire).projected_per_second/projected_over_runstay the plan. (#79)
[0.3.219] - 2026-09-10
Fixed
-
[Reality] HTTPS + ALPN HTTP/2 was rejecting WAF
Connectionheaders (http2: invalid Connection request header). The header stays on the wire (it is the hop-by-hop test); k6 is forced onto HTTP/1.1 viaGODEBUG=http2client=0when--wafbench-verbatimis set or any request has aConnectionheader. generate-only prints the same prefix for a manualk6 run. (#79) -
[Reality]
traffic-breakdown.jsonfields are the plan, not k6 counters:unique_cases(YAML case count),projected_per_second(unique_cases * rps),projected_over_run(unique_cases * rps * duration).unique/total/expected_requestsstay as aliases for one release.expected_requests_unitis dropped. (#79)
Added
- [Reality] Multi-target runs print estimated wall clock:
ceil(targets / max-concurrency) * duration.--vusand--rpsare per target, not shared. (#79)
[0.3.218] - 2026-09-07
Fixed
-
[Reality] Static k6 paths are JSON-encoded and concatenated onto
BASE_URL, so WAF URIs containing\x(Werkzeug UNC/static/\\attacker.com\share\x) no longer land in a JS template literal. k6/goja treated\xas a hex escape and exited before sending any request (invalid escape: \x: len("") != 2). The wire URI is unchanged.validate_scriptnow rejects a bare\xhex escape in-process. (#79) -
[Reality]
traffic-breakdown.jsonfieldexpected_over_durationis nowexpected_requests(HTTP count over the run, not seconds). When--rpsis unset the value isnullinstead of inventing rps=1, which made a 60s run look like a duration of 300. (#79)
[0.3.217] - 2026-09-04
Fixed
-
[Reality] OpenAPI header parameters named
Content-Length,Host, orTransfer-Encodingare no longer invented from the schema (#79). Srikanth’s Amazon S3 spec listedContent-Lengthas an integer header; generation filled42on empty-body POSTs and k6 dropped every request (Content-Length header \"42\" doesn't match actual body length of 0). k6 now owns those headers. Verbatim / user-overridden values are kept. -
[Reality] Colliding WAFBench case titles no longer emit duplicate k6
constnames (#79). A 32-target--wafbench-verbatimrun with 31 YAML files sharing titles likenormal request allowedfailed every target with k6 exit 107 (ScriptException) and 0 requests. Identifiers and metric names now get a_2,_3, … suffix.
Added
- [Reality] Traffic-file breakdown reprints at end of run with unique vs total (
unique * RPS) and writestraffic-breakdown.jsonunder the output dir for automation (#79).
[0.3.216] - 2026-08-31
Fixed
- [Reality] A missing
--wafbench-dirpath is now a hard error instead of a warning plus an empty payload pool (#79). On 0.3.215,mockforge bench --wafbench-dir missing.yaml --spec ... --targets-file ...still generated a k6 script;getNextSecurityPayload()then returnedundefinedand goja threwCannot convert undefined or null to object. The command now exits withWAFBench path does not exist. Defense in depth: an empty pool returns[]rather thanundefined.
Added
- [Reality] After a traffic file loads, print per-file
sent/attack(expected 403)/normal(expected 200)/omittedcounts so a multi-YAML run has a checklist for proxy-log review (#79).
Security
- [Security] RUSTSEC-2026-0269: bumped
wasmtime36.0.13 to 36.0.14 (filesystem sandbox escape on trailing slashes). Same 36.x line as the rest of the plugin-loader pin.
[0.3.215] - 2026-08-30
Fixed
- [Reality]
--wafbench-verbatimnow works with--targets-file(#79). The single-target path already sent traffic-file requests as written and made--specoptional, but--targets-filedispatched intoParallelExecutorfirst. That path still required a spec and built templates from spec operations, so the same command either died withNo spec files providedor fuzzed spec URLs.ParallelExecutornow loads verbatim templates, keeps--specoptional, and callssecurity_testing_enabled()instead of recomputing the injection flag inline.--base-path /no longer prefixes a second slash onto paths that already start with/.
[0.3.214] - 2026-08-23
Added
-
[Reality] New
mockforge bench --wafbench-verbatimsends each traffic case exactly as written instead of extracting an attack payload from it (#994, #79 round 66 / Srikanth on 0.3.213). His WAF rule chained onARGS:redirect_uriandARGS:response_typenever fired, and the run still went green, which for a security tool is worse than an error. The cause: by default a case’suriis treated as a CRS attack string hidden in a query parameter, soextract_uri_payloadkeeps only the FIRST parameter’s value, discards the path, and re-attaches the survivor to a spec-derived endpoint as?test=<payload>./oauth/authorize?response_type=totally-unsupported&redirect_uri=https%3A%2F%2Fevil...&state=s1therefore went out as roughlyGET <spec-endpoint>?test=totally-unsupported, withredirect_uriabsent entirely. That behaviour is correct for CRS/WAFBench files, where one attack string is the whole test, so this adds a mode rather than changing the default. With the flag, method, full URI, headers and body are sent as given: no extraction, no path substitution, notest=injection, no spec-endpoint cycling, and--specno longer supplies the endpoints. The URI is preserved byte for byte (query params are deliberately not parsed and rejoined, because for charset and traversal cases the encoding IS the payload). Real-binary verified against his own case and his 8-case file. Also documents that--wafbench-cycle-allaffects payload selection only and does not change targeting. -
[Reality]
--wafbench-verbatimnow genuinely sends requests untouched (#997). Found by capturing what the flag actually put on the wire rather than by reading the generated k6 script:--wafbench-dirfeeds two consumers, and while verbatim mode stopped the template from extracting payloads, the security layer still read the same file as a payload POOL and appended&test=<payload>to every request at a later stage. That corrupted the exact cases the user asked to be sent literally, and it attached attack payloads toexpected: 200cases, so a correctly-behaving WAF would block them and the run would report failures the user never wrote. Inventing failures is as damaging as the false passes #994 fixed. The gating flag had been recomputed inline at four render sites, the #79 drift shape, and is now a singlesecurity_testing_enabled()method guarded by a test that fails if inline copies return.--security-testcombined with verbatim now warns and is ignored rather than silently mutating traffic.--specis optional in verbatim mode, since the traffic file supplies every request. -
[Reality] Traffic cases marked
omit_rule: trueare skipped with an explanation instead of being parsed and silently dropped (#997). The field marks a baseline to be sent with the rule under test disabled; mockforge cannot toggle a WAF rule, so the case previously went out byte-identical to its non-omitted twin while asserting the opposite status. Exactly one of the pair always failed regardless of whether the rule worked, which defeats the only purpose of a baseline.
Fixed
- [DevX] Documented the 41
MOCKFORGE_*environment variables that were read in code but absent from user-facing docs, which had left the docs/code drift gate red on every PR regardless of content. Covers the previously undocumented operator surface: plugin host, plugin egress proxy, test runner, platform LLM, capture forwarding, contract-diff and drift body limits, Kafka offset persistence, OTLP port, hosted overage ceiling, PagerDuty endpoint override. Defaults were read from the code rather than guessed, and three easy-to-miss behaviours are called out:MOCKFORGE_PLUGIN_HOST_SIGNATURE_MODEsilently falls back tooptionalon an unrecognised value, andMOCKFORGE_SSRF_ALLOW_LOOPBACK/MOCKFORGE_SSO_ALLOW_INSECURE_ISSUERSrelax SSRF protection and are test-only. - [DevX] Added a WAF Testing page to the book (#79).
--wafbench-dirhad no documentation at all, which is why targeting had to be explained by hand on the issue. Covers the two accepted file shapes, the payload-extraction vs verbatim distinction that decides whether a rule fires, a targeting matrix for the flag combinations, that--wafbench-cycle-allaffects payload selection only, and whyomit_rulecases are skipped.
[0.3.213] - 2026-08-20
Fixed
- [Contracts] OpenAPI specs whose operations omit
responsesnow load instead of aborting the run (#79 round 65 / Srikanth on 0.3.212). His proxy-generated spec failed outright withmissing field \responses`, and the error named no path or method. The spec is genuinely non-conformant (OpenAPI 3.x marksresponsesrequired, and 63 of its 70 operations omit it), but refusing it is the wrong trade: request generation, load testing and conformance probing all derive from paths, parameters andrequestBodyand never readresponses`, so the missing field costs nothing we use while rejecting the document costs the whole run. Proxies and API-discovery tools emit specs like this routinely, because they observe requests and have nothing to say about responses. A narrow repair pass fills in only the mandatory field, never invents response content, and warns with the count of affected operations and what is lost (response-schema validation has nothing to check for them). Real-binary verified against his attachment: the run now loads and finds all 70 operations.
Added
- [Reality]
--wafbench-dirnow accepts a simple{title, request, expected}YAML list in addition to the WAFBench document shape (#987, #79 round 65 / Srikanth). His LLM-generated traffic file was rejected withinvalid type: sequence, expected struct WafBenchFile, which was accurate about what failed but silent about what would have worked. The WAFBench shape exists to carry CRS rule IDs and provenance that a generated file has no reason to contain. The simple form maps 1:1 onto the internal representation (bodybecomesdata, titles are synthesised when absent), so the rest of the security-test pipeline is untouched.expectedaccepts403,[403, 406], or{status: ...}, and an unparsable expectation yields no status rather than dropping the case, since the request is still valid traffic. When both shapes fail, the error now names both with the parse error for each. Real-binary verified against his unmodified file: 8 cases, 24 payloads.
Security
- [Security] RUSTSEC-2026-0258 (
h2unbounded empty DATA frames): bumpedh20.4.15 to 0.4.17, which is the instance that serves HTTP here via hyper 1.x / axum. The remainingh20.3.27 is reached only through the AWS SDK client path and is ignored with reasoning recorded inaudit.toml: 0.3.27 is the latest 0.3.x and upstream patched only the 0.4 line, and the flaw concerns queueing empty frames from a peer, where on that path we are the client talking to AWS KMS/STS over TLS. Advisory is rated low severity.
[0.3.212] - 2026-08-03
Fixed
- [Reality]
--conformance-basic-auth(and--conformance-headers, where--auth-bearerlands) now reach the wire on multi-target runs (#79 round 64 / Srikanth on 0.3.210). Hismockforge bench --use-k6 --targets-file vs_list3.json --conformance-basic-auth user:pass ...sent no credentials at all, absent from both his PCAP and his proxy, while the identical single-target invocation worked. Round 47 taughtparse_headers()to fold those auth shortcuts into the shared header map so the same flags work for a plain load run without--conformance, and both ends of the chain were already correct (ParallelExecutorcallsparse_headers(); the k6 generator mergescustom_headersinto every endpoint). The break was between them:execute_multi_targethand-copiesBenchCommandfield by field and setconformance_basic_auth: None/conformance_headers: vec![], nulling the fields beforeparse_headers()ran, so the fold had nothing to fold. Real-binary verified across two targets:grep -c Authorizationon the generated k6 scripts goes 0,0 to 3,3, carryingBasic dXNlcm5hbWU6cGFzc3dvcmQ=. Adds a drift guard asserting every fieldparse_headers()folds survives that clone, because field-by-field struct literals drop fields silently. Note that--validate-requestsand--export-requestsare conformance-run features (read only insideexecute_conformance_test); they no-op on a plain load run in single- and multi-target alike, and need--conformance. - [Security] RUSTSEC-2026-0222:
wasmtime36.0.12 to 36.0.13, reached viawasmtime-wasi->wiggle->mockforge-plugin-loader. Lockfile only, a patch bump inside the existing 36.x line. - [Contracts]
mockforge-registry-coreno longer fails to compile for default-feature consumers. An associated const added in 0.3.211’s audit fix sat inside a#[cfg(feature = "postgres")]impl while its ungated caller and tests still referenced it, socargo install mockforge-clicould not build. Nothing in CI covered that combination: the workspace test job runs--all-featuresand the registry server always builds withpostgres. Moved to a module-level const. - [Contracts] Repaired the release pipeline itself. A stale doctest in
mockforge-intelligence(broken since May) was failingcargo test --workspace --releasein the Create Release job, which skipped everything after it, including the GitHub Release and the Fly deploy, which hasneeds: release. Production had therefore been serving 0.3.183 since 2026-06-19. Also aligned every Dockerfile builder withrust-toolchain.toml(1.75/1.90/1.91 to 1.96) afteraws-smithy-typesraised its MSRV past the pinned builder and broke container builds outright, and cleared theunused_qualificationserrors that were reddening the Test job on every PR regardless of content.
[0.3.211] - 2026-07-27
Fixed
- [Reality] Target-side HTTP protocol violations classify as
"kind": "protocol"inconformance-network-events.jsoninstead of generic"other"(#79 round 63 / Srikanth on 0.3.210). A WAF answering blocked security probes with a body that disagreed with its declaredContent-Lengthtrips Go’sserver replied with more than declared Content-Length; truncated; those events previously mixed in with unclassifiable failures. Also coversmalformed,protocol error,invalid header. Evaluated last, so eof/timeout/tls/connect keep their meaning and onlyotheris re-labelled. Applied to all three k6 render paths with a regression test guarding both presence and ordering.
[0.3.210] - 2026-07-24
Added
- [Reality] New
mockforge bench --no-abort-on-error/--abort-on-error-rate <rate>flags to control the round-60 k6 memory safety valve (#79 round 62 / Srikanth on 0.3.209). The round-60 valve aborts a k6 run whosehttp_req_failedrate crosses 0.95 for 60s (OOM guard on dead targets), but that also stopped legitimate stress tests: Srikanth’s WAF/proxy targets legitimately reject ~95.2% of the probe traffic (fast non-2xx, zero transport failures), crossing 0.95 and aborting every run at ~2min.--no-abort-on-errordrops theabortOnFailthreshold so the run goes its full duration regardless of error rate;--abort-on-error-rateretunes the threshold (default 0.95). Wired through single- and multi-target k6 paths; default behaviour unchanged. Real-binary verified: the generated k6 script omitsabortOnFailunder--no-abort-on-errorand rendersrate<0.99under--abort-on-error-rate 0.99.
[0.3.209] - 2026-07-22
Added
- [Reality] New
mockforge bench --dns-policy <policy>flag → k6--dns "policy=<value>"(#79 round 61 / Srikanth on 0.3.208). Values:preferIPv4(default),preferIPv6,onlyIPv4,onlyIPv6,any. Unblocks GEODB IPv6 tests where the target must stay a hostname (proxy routes by Host/SNI) but must be dialed over its AAAA record; k6/Go default to IPv4, which can’t be dialed from an IPv6--source-ip(no suitable address found).preferIPv6picks the AAAA record while keeping the hostname on the wire. Wired through single- and multi-target k6 paths; real-binary verified the launched k6 runs with--dns policy=preferIPv6.
[0.3.208] - 2026-07-21
Fixed
- [Reality] k6 no longer OOM-kills (
signal: 9) when a load target rejects/times-out ~every request (#79 round 60 / Srikanth on 0.3.207). The generated k6 load scripts now carry anabortOnFailsafety valve onhttp_req_failed: a target failing>=95%of requests after a 60s grace period aborts (exit 99) instead of hammering a dead endpoint for the full duration and accumulating per-request memory. Legitimate runs under 95% failure are unaffected. Real-binary verified against a dead target: k6 stops at ~60s instead of running the full scenario. Applies to the standard-load and CRUD-flow templates.
[0.3.207] - 2026-07-19
Added
- [Contracts] New “Security probes (owasp injection)” view in the self-test (#79 round 59 / Srikanth on 0.3.206 was WAF-testing and saw
owasp: 0 caught / 8127 missedbutDefinite issues: none). The self-test now prints a per-injection-family breakdown of how many OWASP payloads the target accepted (status < 400) vs blocked (4xx), plus aconformance-owasp-accepted.jsonsidecar listing every accepted payload with method + URL. For a WAF each accepted payload is one it did NOT block; for a plain API it is expected (a string field accepts any string). Kept out of “Definite issues” (spec violations only) but surfaced on its own line. Verified against Srikanth’s capture (all 8127 payloads across 7 families accepted) and real-binary againstmockforge serve.
[0.3.206] - 2026-07-16
Fixed
- [Reality] Multi-target load no longer fails to start with
exit status: 106(k6CannotStartRESTAPI) and zero requests (#79 round 58 / Srikanth on 0.3.205). Each parallel k6 was pinned to a fixed REST API port (6565 + index) that collides when already taken (orphaned k6 from a prior OOM-killed run, a second bench, a local service). k6 now binds an ephemeral port (--address localhost:0) instead; MockForge reads results fromsummary.jsonon disk, never the API. Real-binary verified with ports 6566/6567 occupied: a load that used to exit 106 on every target now runs.
Added
- [Contracts] New “Definite issues” view in the self-test (#79 round 58 / Srikanth on 0.3.205 asked for a “for sure this is an issue” filter). A
Definite issues (N)console section plus aconformance-definite-issues.jsonsidecar surface only unambiguous problems: a spec-valid request the target rejected, or any probe that drew a 5xx. Spec-valid “missed” negatives are excluded. Clarified that a “caught” 4xx is the target correctly rejecting a bad request, not a violation.
[0.3.205] - 2026-07-14
Added
- [DevX] New
mockforge bench --discard-response-bodiesflag exposesK6_DISCARD_RESPONSE_BODIES=trueas a first-class option (#79 round 57 / Srikanth on 0.3.204 asked for a flag instead of the env var for scale/stress runs). Opts a single-target load run into discarding response bodies (multi-target load already discards by default); no-op on conformance / self-test / extraction runs, which need the body. Real-binary verified: the launched k6 child carries the env var anddata_receivedstays at header-only levels.
Changed
- [DevX] The self-test console summary prints a one-line legend under the
Negatives [...]lines explaining “caught” (target rejected a deliberately-bad request with a 4xx) vs “missed” (target accepted it), and that a high “missed” is not automatically a bug because many probes are spec-valid by construction (#79 round 57 / Srikanth on 0.3.204 asked how to read caught vs missed). The self-test-probes and capacity-sizing reference pages gain the same nuance and document the new flag.
[0.3.204] - 2026-07-13
Fixed
- [Contracts]
parameters:*negative probes are now recorded inconformance-request-violations.json, and the single-target self-test writes that file at all (#79 round 56 / Srikanth on 0.3.203: parameter violations were still absent from the logs). For his Apigee spec the parameter probes are all spec-VALID by construction (dropping the OPTIONAL$.xgafvquery, adding an oversized/undeclared query param, or an unconstrained{instance}path value violate no schema), so the emitted-request validator found nothing to flag and stayed silent. Eachparameters:*negative that produces no hard breach is now recorded as a typedparameter_negative_proberow explaining why it is not a schema violation; the single-target self-test calls the validator too (previously only the multi-target--targets-filepath did); and--validate-requestsnow implies request capture. Real-binary verified againstmockforge servewith a custom-verb Apigee spec: the violations file carries all three parameter probes (uri-too-long,bad-path-param,missing-query) alongside the genuinebody_schema_violation/query_value_mismatchrows, in both single-target and--targets-filemodes. - [Reality] k6 no longer gets OOM-killed (
signal: 9 (SIGKILL)) during long, high-concurrency multi-target load runs (#79 round 56 / Srikanth on 0.3.203). The plain-load k6 only checks status codes but was buffering every response body in memory; over a multi-hour run at 10 VUs across 10+ targets the buffered bodies plus k6’s metric accumulation exhausted RAM and the kernel OOM-killer sent SIGKILL. The multi-target plain-load path now runs k6 withK6_DISCARD_RESPONSE_BODIES=true(safe there because bodies are never inspected). Real-binary verified: the launched k6 child process carriesK6_DISCARD_RESPONSE_BODIES=truein its environment anddata_receivedstays at header-only levels. The flag defaults off and is opt-in per executor; body-inspecting paths (conformance, extraction) are untouched.
[0.3.198] - 2026-07-02
Fixed
- [Contracts] Self-test baseline probe filler is now spec-VALID (enum -> first member, boolean ->
true, string body enums -> a valid member), so arequest-body:*probe no longer trips spuriousquery_value_mismatchviolations onalt/prettyPrintand body probes no longer showtest-stringenum noise (#79 round 51 / Srikanth on 0.3.196). Verified againstmockforge serve: by-probe violations dropped 32 -> 12,request-body:*query violations now 0. - [Contracts] Multipart
wirebyte count now prefers k6’sContent-Length(the exact wire body size a proxy sees) over the reconstructed envelope, closing the 264-byte gap Srikanth reported on 0.3.196 (#79 round 51).
Added
- [AI][DevX] New “Agent / LLM / MCP Traffic (Packet-Level)” reference page documenting Agent<->LLM, Agent<->Agent, and MCP interactions at the HTTP-packet level with real captures and PCAP-recording recipes (#79 / Srikanth on 0.3.196).
[0.3.197] - 2026-07-01
Added
- [AI] Mock LLM endpoint real-model modes via
--llm-mock-mode(#915):proxy(forward to--llm-mock-upstream),record(forward on cassette miss + save, replay on hit),replay(cassette only, offline; canned fallback). Default stays pure offlinemock. New flags--llm-mock-upstream/--llm-mock-api-key/--llm-mock-cassette. Verified againstmockforge serveby pointing one--llm-mockinstance at another (no API key).
[0.3.196] - 2026-06-30
Added
- [AI] Mock LLM endpoint:
mockforge serve --llm-mockmounts OpenAI-compatiblePOST /v1/chat/completions+GET /v1/modelsand Anthropic-compatiblePOST /v1/messageswith SSE streaming, so an agent can point its base URL at MockForge for scale/offline/failure testing (#912 / #79 Srikanth). - [AI] Mock MCP server:
mockforge serve --mcp-mockmounts a JSON-RPC 2.0 endpoint atPOST /mcpansweringinitialize/tools/list/tools/call/resources/list/prompts/list, so an agent acting as an MCP client can talk to MockForge (#913 / #79 Srikanth).
[0.3.195] - 2026-06-30
Fixed
- [Contracts] Multipart
wirebyte count no longer comes out smaller thantotal; computed as disk-sum payload + ASCII multipart envelope instead of the UTF-8-undercountingraw.length(#79 round 50 / Srikanth on 0.3.194). - [Contracts]
conformance-request-violations-by-request.jsonemits one row per URL with the deduped union of all violations and contributing checks, so a URL’s owasp/query checks no longer hide in a separate row from its body checks (#79 round 50 / Srikanth on 0.3.194). - [Contracts] Repeated self-test iterations no longer duplicate the same violation N times in the flat and grouped violation files (#79 round 50 / Srikanth on 0.3.194).
Added
- [Contracts][AI] New
--security-categoriesvaluesllm-prompt-injection(OWASP LLM01 prompt-injection/jailbreak) anddlp(synthetic PII canaries) for agent-driven AI-attack and data-loss-prevention testing (#79 round 50 / Srikanth on 0.3.194).
[0.3.181] - 2026-06-17
Fixed
- [DevX] Capture-viewer HTML status badge colour now follows the probe’s
expected_status_range; a variant-b 400 reads green to match theexp 2xx-4xxbadge (#79 round 36 / #875 / Srikanth).
[0.3.180] - 2026-06-16
Fixed
- [Contracts] Embedded-content variant-b probes no longer flag 4xx responses as mismatches; only 5xx counts as failure (#79 round 35 / #859 / Srikanth).
[0.3.179] - 2026-06-15
Fixed
- [DevX]
response_schema_errorstrips description/example fields from the focused schema before truncation sotypesurvives (#79 round 34 / #827 / Srikanth). - [Contracts] Per-endpoint summary
pathcolumn matches the URL user sent:base_pathprefixed (#79 round 34 / #828 / Srikanth). - [Contracts] Embedded-content variant-b probes skip when positive sample has no string field, instead of synthesizing a non-conforming envelope (#79 round 34 / #829 / Srikanth).
[0.3.178] - 2026-06-14
Added
- [Contracts] Per-endpoint summary groups by spec path template, with a
speclabel for multi-spec runs (#79 round 33 / #823 / Srikanth). - [Contracts]
MOCKFORGE_INJECT_RESPONSE_VIOLATIONS=true(+--inject-response-violations) intentionally drops one required field from 2xx response bodies for negative-testing downstream proxies (#79 round 33 / #822 / Srikanth).
[0.3.177] - 2026-06-14
Fixed
- [Contracts] Server-side conformance buffer now records
content-types(415) violations from the MockAI router path too (#79 round 32 / Srikanth). - [Install]
cargo install mockforge-clino longer requiresprotobuf-compileron Ubuntu 16.04 / RHEL 7;mockforge-grpcbuild uses a vendoredprotocwhenPROTOCis unset (#79 round 32 / Srikanth).
Added
- [Contracts] Per-endpoint traffic summary (sent count, status-class breakdown, request/response/query length p95) in
bench-results/conformance-per-endpoint.jsonand a new section inconformance-report.html(#79 round 32 / Srikanth).
[0.3.176] - 2026-06-10
Fixed
- [Contracts] Write requests (POST / PUT / PATCH / DELETE) now return spec-shape response bodies instead of MockAI’s hardcoded
{id, status, data}envelope (#79 round 31 follow-up / Srikanth).
[0.3.175] - 2026-06-10
Fixed
- [DevX] For
required field missingerrors, the printed schema is now the missing property’s own sub-schema, not the entire parent object (#79 round 31 / Srikanth). - [Install]
cargo install mockforge-clino longer requires OpenSSL 1.1+; the workspace is fully rustls-only (#79 round 31).
Added
- [Server]
mockforge serve --conformance-buffer-size Nand--conformance-buffer-uniqueCLI flags mirror the round-29/round-30 env vars (#79 round 31 / Srikanth).
[0.3.174] - 2026-06-09
Fixed
- [DevX]
response_schema_errornow prints only the sub-schema at the offending JSON Pointer instead of the full top-level schema (#79 round 30 / Srikanth).
Added
- [Contracts]
MOCKFORGE_CONFORMANCE_BUFFER_UNIQUE=trueswitches the violation buffer from FIFO to dedup-by-signature; every duplicate bumps a newoccurrencesfield on the entry instead of consuming a new buffer slot (#79 round 30 / Srikanth).
[0.3.173] - 2026-06-08
Fixed
- [DevX]
response_schema_errormessage readsresponse body root: .../response body at /<path>: ...instead of the ambiguousat /: ...(#79 round 29 / Srikanth).
Added
- [Contracts]
MOCKFORGE_CONFORMANCE_BUFFER_SIZEenv var raises the server-side violation ring buffer above the default 256, capped at 64k (#79 round 29 / Srikanth). - [Contracts] Bench capacity advisory at run start when
targets × VUs ≥ 150; estimates RAM / CPU and links to the new sizing doc. - [DevX] New book page
reference/bench-capacity-sizing.mdwith sizing table, formulas, and sharding guide.
[0.3.172] - 2026-06-07
Fixed
- [Contracts] Content-type-swap probes now send only ONE Content-Type (the reqwest header-append bug let axum’s JSON extractor accept). Smoke test: same 4 probes that returned 204 on 0.3.171 now return 415 (#79 round 28).
- [Contracts] Server-side
check_request_content_typeflags Content-Type mismatches againstrequestBody.contentkeys; records acontent-typescategory violation. (#79 round 28) - [DevX]
response_schema_errorembeds the expected schema JSON:at /: expected type string; expected schema {"type":"string"}. (#79 round 28)
Added
- [Contracts]
expected_status_rangefield on everyCaseCapture;exp 4xx/exp 2xx-3xxbadge on every card. (#79 round 28) - [DevX] “Only show mismatches” checkbox + per-cat clickable counts in the per-op
By categorycolumn. (#79 round 28)
[0.3.171] - 2026-06-06
Fixed
- [DevX] Capture HTML viewer paginates with cross-page filters; the round-25 + round-26 1000-card cap that hid 4xx/5xx probes is gone (#79 round 27 / Srikanth d3).
Added
- [Contracts] Content-type swap variant (b): four
request-body:embedded-content:*probes per JSON operation send a valid JSON envelope with an XML/YAML/multipart/urlencoded snippet stuffed into a string field. Flags servers that crash on the embedded content (#79 round 27 / Srikanth k variant b).
[0.3.170] - 2026-06-06
Fixed
- [Contracts] TUI Conformance tab: detail modal now snapshots the violation’s text at Enter time (#79 round 26 / Srikanth re-test of 0.3.169). The round-25 identity-key re-anchor only worked when the clicked violation survived the 256-cap buffer; under heavy traffic it got evicted and
selectedstayed at a stale index. Snapshot + Esc-clear fixes it; regression tests cover both the index-shift and the on_data refresh path. - [DevX]
response_schema_erroris now human-readable (“at /: expected type string”) instead of broken Rust debug syntax (#79 round 26 / Srikanth). Falls back tojsonschema’sDisplayimpl for the long-tail kinds. - [DevX] HTML report
Negatives by categoryis now a single grouped table with a Family column prepended (#79 round 26 / Srikanth d2). The standalone family rollup section is gone; one table carries both axes.
[0.3.169] - 2026-06-05
Fixed
- [Contracts] TUI Conformance tab: selecting a row no longer jumps to a different request when new traffic arrives on the next refresh tick (#79 round 25 / Srikanth follow-up).
- [DevX] Capture HTML viewer no longer hangs the browser at 9000+ probes:
content-visibility: autoper card, 200 ms debounced filter, hard cap at 1000 rendered cards withShowing N of Mbanner (#79 round 25 / Srikanth d follow-up).
Added
- [Contracts] Content-type swap probe family
request-body:content-type-mismatch:<variant>(#79 round 25 / Srikanth k). Four probes per JSON operation: xml / yaml / multipart / urlencoded. - [Contracts]
--validate-response-schemasflag (#79 round 25 / closes round 21.3 / Srikanth a2 + a3). Validates every probe’s response body against the spec’s response schema for the actual status returned. Mismatches surface asresponse_schema_errorin the JSONL and a red “Response schema mismatch” section in the per-probe HTML viewer card. Opt-in. - [DevX] HTML report:
Negatives by category familyrollup (Request body / Parameters / Security family) and a per-operationBy categorycolumn showing mismatch breakdown (#79 round 25 / Srikanth d remainder).
[0.3.168] - 2026-06-04
Fixed
- [Contracts] Geo-source-IP headers now ride on every self-test probe, not just the positive case (#79 round 24 / Srikanth f). Four negative-probe call sites and the security-probe path were dropping the geo IP. Regression test (
geo_headers_present_on_every_probe_with_capture) added. - [DevX] Clickable count cells in the HTML report no longer dead-end when
--report-missed-capcrops the drill-down (#79 round 24 / Srikanth e). Counts only link when their target row actually survives the truncation.
Added
- [DevX]
--conformance-self-test-capturenow also emits a browser-viewableconformance-self-test-requests.htmlalongside the JSONL (#79 round 24 / Srikanth d). Self-contained, includes a filter toolbar and expandable per-probe cards.
[0.3.167] - 2026-06-03
Fixed
- [Contracts][DevX]
--source-ipnow actually works with the k6 path (#79 round 23 / Srikanth correction on round-22 g1). The round-22 warning that said “k6 cannot bind a VU to a source IP from the script side” was wrong: k6 supports--local-ipsnatively (CIDR, ranges, and comma-separated single IPs). The k6 executor now forwards the CLI’s--source-ipstraight tok6 run --local-ips, and the misleading warning is removed. Only the--conformance-self-test --use-k6combo still fires a warning, because self-test returns before k6 launches and--use-k6is a no-op there. - [DevX] Docs site is rebuilding again (
docs.mockforge.devhad been stuck since the 2025-11-10 build because mdbook-toc 0.15.x stopped parsing mdbook’s preprocessor input). The TOC preprocessor was disabled (no page uses the<!-- toc -->marker anyway) and itscargo installstep was removed from the deploy workflow, so the round-21 probe-label reference page resolves athttps://docs.mockforge.dev/reference/conformance-self-test-probes.html.
Added
- [Contracts][DevX]
--conformance-self-test-captureflag (#79 round 23 / Srikanth c-iii deferred from round 22.5). When set alongside--conformance-self-test, every probe records method, URL, request headers/body and response status/headers/body toconformance-self-test-requests.jsonl(one JSON object per line) next to the JSON/HTML report. Bodies cap at 16 KiB per direction withrequest_body_truncated/response_body_truncatedflags. - [DevX] HTML conformance report: count-cells in the “Negatives by category” and “Per-operation results” tables are now clickable links into the drill-down table below (#79 round 23 / Srikanth d).
#miss-cat-<category>jumps to the first row of that category;#miss-op-<method>_<path-slug>jumps to the first row for that operation. - [DevX] HTML conformance report wording: “missed/caught” renamed to “Mismatched (non-4xx) / Matched (4xx)” across the cards, category table, per-operation table, and drill-down heading; the category status badge is now a plain
PASS/FAIL(replacing “all caught” / “rejection gaps”) since the count column already conveys magnitude (#79 round 23 / Srikanth d wording).
[0.3.166] - 2026-06-02
Fixed
- TUI Conformance: Enter in the Unknown view (
u) opens Unknown Path Detail instead of the (wrong) Violation Detail (#79 round 22.1). --source-ip/--geo-source-ipemit a warning when used with--use-k6since k6 can’t bind a VU to a source IP (#79 round 22.2).
Added
--geo-source-ipheaders wired into the k6 template; the rendered script rotates X-Forwarded-For / True-Client-IP / CF-Connecting-IP per iteration (#79 round 22.3).--source-ip/--geo-source-ipacceptstart-endIPv4 ranges (e.g.10.0.0.5-10.0.0.27) alongside CIDR and comma-separated lists (#79 round 22.4).- HTML report header links to the probe-label reference; “gaps” badge wording clarified to “rejection gaps” (#79 round 22.6).
[0.3.165] - 2026-06-01
Added
--report-missed-cap Nflag for the HTML drill-down (#79 round 21.1). Default 200;0= no cap.- HTML missed-negative table gains an Expected column (#79 round 21.1). Addresses Srikanth’s (a1).
- New book page: Conformance Self-Test Probes (#79 round 21.2). Canonical reference for every probe label.
Notes
- Response-body shape validation alongside the response-code check (a2 / a3) is queued for a separate release.
[0.3.164] - 2026-06-01
Fixed
- Shadow mode now gates
200on the configured--base-path(#79 round 20). Paths outside the configured prefix (e.g./api123/...when server is/api) return404even with--shadowenabled, matching pre-shadow semantics.path_in_basechecks at the segment boundary, so/api123is not under/api.
[0.3.163] - 2026-06-01
Fixed
- Live-server route handler now resolves nested
$refpointers against the spec’s components (#79 round 19) — third schema-validator call site, missed by round 18.3. Dotted-name vCenter schemas resolve.
Added
--source-ipand--geo-source-ipaccept CIDR ranges (10.0.0.0/28,2001:db8::/126) capped at 256 hosts per range. IPv4 + IPv6 supported (#79 round 19).
[0.3.162] - 2026-05-31
Issue #79 rounds 17.1–18.5 consolidated into a single release. Intermediate version numbers (0.3.153–0.3.161) were never published.
Added
- TUI Conformance:
ccopies the selected violation to clipboard (round 17.1);total_okcounter alongsidetotal_seenfor accurate pass/fail ratio (round 17.1). --conformance-self-testschema-driven body mutator (round 17.2), security probes (round 17.3), spec-level audit (round 17.4), OWASP/WAF unification (round 17.5), self-contained HTML report (round 17.6).- GEODB multi-source-IP testing (round 18.5):
--source-ip(real bind) +--geo-source-ip(forwarded-IP headers).
Changed
- OWASP coverage table now explains the “-” rows with actionable category hints (round 18.4).
Fixed
--conformance-self-testhonours--base-path(round 18.1); hard warning when every positive returns the same status (round 18.1); accurate bench header before spec parse (round 18.2).- Request-body validator resolves nested
$refpointers against the spec’s components map (round 18.3) — fixes theVcenter.VM.DiskCloneSpec“Pointer does not exist” class of failures.
[0.3.152] - 2026-05-28
Changed
- [Contracts][DevX] TUI Conformance export (
e) now deduplicates by(method, path, category, reason)with acount+first_seen/last_seenwindow (#79 round 16). - [DevX]
--conformance-self-testproduces negatives for two previously-zero-coverage shapes: operations with a required body but no synthesised sample, and operations whose only spec input is a path parameter (parameters:bad-path-paramprobe).
[0.3.151] - 2026-05-27
Added
- [Reality]
mockforge serve --shadowCLI flag (#79 round 15) — first-class flag for shadow mode (alias forMOCKFORGE_SHADOW_MODE=true) so it can’t be forgotten. - [Contracts][DevX] Lifetime “seen total” counters for conformance violations + unknown paths — admin API
total_seenfield and TUI titles now show the true lifetime count alongside the 256-cap buffered count.
Changed
- [DevX] Per-violation server log under target
mockforge::conformance(enable withRUST_LOG=mockforge::conformance=debug) showing method/path/status/category/reason. - [DevX] TUI Conformance detail view + Top Offending Endpoints panel now wrap long lines so big paths/reasons are fully readable.
[0.3.150] - 2026-05-26
Fixed
- [Reality] Server no longer OOM-killed at startup on large specs (#79 round 14) — router construction cloned the entire routes Vec into every per-route handler (O(N²) memory; ~260 GB for an 11,422-op spec). Fixed by sharing one validator via
Arcacross all handlers. Reproduced + verified with a 22,000-operation synthetic spec.
Added
- [Reality][Contracts] Server-side shadow mode (
MOCKFORGE_SHADOW_MODE=true) (#79 round 14) — returns 200 for unknown paths and spec violations while still recording them to the conformance + unknown-paths buffers (report-only / monitor mode for proxy-replay traffic). Startup prints a👻 SHADOW MODE ONbanner. - [Contracts][DevX] Status column on the TUI unknown-paths view — surfaces the HTTP status the server returned (404 normally, 200 in shadow mode).
[0.3.149] - 2026-05-25
Added
- [Contracts][DevX]
mockforge bench --conformance --conformance-self-test(#79 round 13 (4)) — positive + per-category negative driver. Sends one valid request and per-category negatives (empty body / wrong-type body / missing required query / missing required header) per spec operation; reports how many the server correctly rejected with 4xx. Writesconformance-self-test.jsonand emits a warning when any negative slipped through.
[0.3.148] - 2026-05-25
Fixed
- [Contracts][DevX] Conformance buffer now actually fires on the default-flow handlers (#79 round 13) — the MockAI and AI handlers bypassed validation entirely, so violations never populated for default-flow routes. Extracted
OpenApiRouteRegistry::run_validation_with_recordingand called it at the entry of each handler.
Added
- [Contracts] New
response-shapeviolation category — surfaces when a requested status code isn’t defined in the spec for that operation. - [Contracts][DevX] New
unknown-pathsfeed + admin endpoint + TUI view — separate ring buffer tracks requests whose path didn’t match any spec route.GET /__mockforge/api/conformance/unknown-paths; TUIutoggles between violations and unknown-paths views.
[0.3.147] - 2026-05-25
Changed
- [DevX] TUI
Conformancetab moved beforeVerification(#79 round 12 follow-up) — Verification’sTabcycles internal fields so it acts as a dead-end for plain Tab nav. Putting Conformance earlier in the strip keeps it reachable.
[0.3.146] - 2026-05-25
Fixed
- [DevX] TUI
Conformancetab now appears + admin server exposes the violations endpoint (#79 round 12 hotfix) — v0.3.145 had two bugs: (1)ScreenId::Conformancewas added to the enum butConformanceScreen::new()was missing fromApp::new’s screens vec, so the tab silently dropped from the header; (2) the endpoint was only wired intomockforge-http’s management router (mock-traffic port), not the admin server the TUI polls. Fixed both, plus added anapp_screens_match_screen_id_allregression test.
[0.3.145] - 2026-05-24
Added
- [Contracts][DevX] New
ConformanceTUI screen +/__mockforge/api/conformance/violationsendpoint (#79 round 12) — server-side counterpart to the bench-side conformance suite; every incoming request the OpenAPI router rejects for a spec violation (400/422) is captured to a bounded ring buffer and rendered in a new TUI tab.
Fixed
- [DevX]
mockforge bench --conformance --operations 'METHOD,…'now actually filters (#79 round 12) —execute_conformance_testwas silently ignoringself.operations/self.exclude_operations. Also relaxedSpecParser::filter_operationsto accept method-only form ("GET") without requiring"GET /path". - [Reality] Multi-target bench summary now includes connection + iteration counts (#79 round 12).
- [Cloud]
pillar_trackingno longer drivessqlx::pool::acquire“slow acquire” spam under load (#79 round 12) — added a 20-task in-flight cap at the recorder entry so over-pressure events are dropped immediately instead of queuing on the analytics-DB pool’s 30s acquire timeout.
[0.3.144] - 2026-05-24
Fixed
- [Reality] OpenAPI router accepts request bodies up to 50 MiB by default (was 2 MiB axum default) — closes the “200 OK before all chunk requests arrived” PCAP behaviour Srikanth reported on Issue #79
- Root cause: axum 0.8’s
BytesandOption<Json<Value>>extractors enforce a 2 MiBDefaultBodyLimit. Above that, the body gets truncated and the handler runs without consuming the rest of the request — hyper sends the response and TLS Close Notify while the client is still uploading the body. Reproduced locally with a 3 MiB JSON body to the demo spec. - Fix: every
OpenApiRouteRegistry::build_router_*variant now mountsaxum::extract::DefaultBodyLimit::max(...)with a 50 MiB default, configurable viaMOCKFORGE_HTTP_BODY_LIMIT_MB.
- Root cause: axum 0.8’s
- [Cloud]
pillar_trackingno longer floods logs with one WARN per dropped event under load (#79 round 11)- Per-event failures are now DEBUG; a single aggregated
pillar_tracking: dropped X events in the last 60s due to analytics-DB pressureWARN fires at most every 60 seconds.
- Per-event failures are now DEBUG; a single aggregated
[0.3.143] - 2026-05-23
Fixed
- [DevX] Republish of 0.3.142 — fixes broken
[email protected]install (#79 round 10 hotfix)cargo install [email protected]failed witherror[E0432]: unresolved import \crate::database::Database`inmockforge-http/src/handlers/threat_modeling.rs:29andlib.rs:2387. Thedatabasemodule was moved tomockforge-intelligencein #611, but twouse crate::database::Database;statements weren't gated behind#[cfg(feature = “database”)], so default-feature builds (which is whatcargo installuses) failed to compile. Fix landed onmain` in #616/#618 but was not in the 0.3.142 tag.- 0.3.142 of the broken crates (cli, http, import, pipelines, proxy, workspace, core, bench, chaos, collab, recorder, registry-server, k8s-operator, vbr, sdk, test, reporting, ui) yanked from crates.io. 0.3.143 republishes the same #79 round-10 changes from a known-good main commit.
[0.3.142] - 2026-05-21
Changed
- [DevX] Pre-flight
--vusrecommendation caps at 1000 for huge specs (#79 round 10)- Srikanth’s 11,422-operation spec at
--rps 100(9.4ms baseline) produced a recommendation of ~10,740 VUs — mathematically correct but practically absurd. The right answer for that workload isn’t “spin up 10K VUs”, it’s “shrink the workload.” 0.3.142 caps the printed recommendation at 1000 and, above the cap, steers users toward--operations/--exclude-operationsfilters or dropping--rpsfor closed-model loading.
- Srikanth’s 11,422-operation spec at
Added
- [DevX] Iteration coverage in bench summary (#79 round 10)
- New
Iterations: X complete × N ops = Y ops fully exercisedline appears whenever k6’siterations.values.countis non-zero. When the run ends mid-iteration (large spec, undersized VUs), a follow-up line surfaces the extra requests from the partial pass so users know the last iteration didn’t cover every operation in the spec.
- New
Fixed
- [DevX]
scripts/check-changelog.shnow uses the PR-wide diff in CI instead ofgit diff-tree -r HEAD(which returns the empty combined diff on the syntheticrefs/pull/<N>/mergecommitactions/checkoutuses). Previously every PR whose CHANGELOG.md edit landed in a commit that the merge didn’t have to reconcile would fail the “Changelog Validation” gate even though the workflow’s own outer condition correctly detected the edit (caught on #595’s release PR). Now switches modes on$GITHUB_BASE_REF: PR-widegit diff --name-only origin/$GITHUB_BASE_REF...HEADin CI, single-commitdiff-tree -r HEADlocally for the cargo-release flow.
[0.3.141] - 2026-05-20
Fixed
- [DevX]
mockforge-foundation::pillarsdoctests now reference the actual crate path (release-gate fix)- All 9 doctests imported
use mockforge_core::pillars::..., but thePillarenum lives inmockforge-foundationitself. The mismatch causedcargo test --doc -p mockforge-foundationto fail withcannot find module or crate `mockforge_core`, which gates the Release workflow’scargo test --workspace --releasestep — so the v0.3.140 tag’sCreate Releasejob failed and Publish-to-crates.io was skipped. Replacedmockforge_core::pillars→mockforge_foundation::pillarsacross all 9 doctests. 11 doctests now pass. - 0.3.140 was never published to crates.io; this release ships the round-9 bench fix originally intended for that version, plus this doctest fix on top.
- All 9 doctests imported
[0.3.140] - 2026-05-20
Fixed
- [DevX] Pre-flight
--vusprobe now factors in operations-per-iteration (#79 round 9)- The round-8 probe assumed 1 iteration = 1 request, but k6’s
constant-arrival-ratecounts iterations and every iteration calls every operation in the spec. Srikanth’s 12-op spec at--rps 100with 15ms latency reported “–vus 5 is sufficient” and then k6 still emitted “Insufficient VUs, reached 5 active VUs” mid-run because real iteration time was 15ms × 12 ops, not 15ms. - Fix:
ProbeResult::required_vus(rps, num_operations)now multiplies by spec operation count. Same call site change incommand.rs. New testsrequired_vus_scales_with_operation_countandrequired_vus_treats_zero_operations_as_one. The pre-flight progress / warning lines now print the operation count so users see what the math used.
- The round-8 probe assumed 1 iteration = 1 request, but k6’s
[0.3.139] - 2026-05-19
Added
- [DevX] Adaptive pre-flight latency probe for
--vussizing (#79 round 8)mockforge bench --rps N --vus Mnow does a 3-request HEAD/GET probe of the target before launch to measure baseline latency, then recommends--vusbased onceil(rps × measured_latency_secs) + 1instead of the static “100ms / 10 req-per-VU” heuristic. Fixes a false-positive on Srikanth’s fast targets (~2ms response time) where the old heuristic warned “bump to –vus 100” when –vus 5 was actually plenty.- If the probe can’t reach the target (auth-gated, strict WAF, etc.), falls back to the previous 100ms heuristic so the warning still fires when warranted. When the probe succeeds AND
--vusis sufficient, prints a confirmation line so users know the size check passed.
- [Reality] “Connection reuse NOT detected” diagnostic in bench summary (#79 round 8)
- When
tcp_connect_samples > 5 × vus_maxin pooled-reuse mode (no--cps), the bench reporter now prints a yellow warning explaining the target is closing sockets between requests. Addresses Srikanth’s 0.3.137 question: “I expected 5 connections with –vus 5 but see 7425” — the counter is correct, the proxy isn’t pooling. The new line makes that interpretation explicit so users don’t have to guess.
- When
[0.3.138] - 2026-05-19
Added
- [Cloud][Reality] Cloud-mode Time Travel — controllable virtual clock on hosted-mock deployments (#466, #527)
- [Cloud][AI] Cloud-mode Test Generator — async LLM jobs over runtime_captures (#469, #529)
- [Cloud][Reality] Real-time runtime-logs SSE via Fly NATS subscription (#556, #559)
- [Cloud][Reality] OTLP gRPC trace receiver alongside HTTP/JSON (#548, #566)
- [Cloud][Reality] Per-capture cloud forwarder with backpressure + retry (#553, #564)
- [Cloud][Reality] Trust-root boot — plugin host fetches + refreshes active trust roots from registry (#549, #565)
- [Cloud][Reality] HSM-backed platform signing-root rotation via AWS KMS (#550, #567)
- [Cloud][Reality] Email notification channel via EmailService (#551, #557)
- [Cloud][Reality] PagerDuty notification channel via Events API v2 (#552, #558)
- [CI][Reality] Nightly hosted-mocks smoke workflow (#554, #563)
Changed
- [DevX]
pr_generationmoved out ofmockforge-coreintomockforge-intelligence; intelligence → core dep cycle broken (#562 phase 1, #571) - [DevX] ADR auditing
mockforge-httpfor intelligence/proxy extraction (#555, #561)
Fixed
- [DevX] CI rust-cache no longer poisons builds with dangling
target/*.dpaths (#446, #570) - [UI][Cloud] CloudTestGeneratorView import path corrected (#547)
Note: Time Travel (#527) and Test Generator (#529) were initially attributed to 0.3.137 in the historical changelog block below. Both PRs landed after the v0.3.137 tag (efa43d20) had already been published, so they actually ship in 0.3.138.
[0.3.137] - 2026-05-18
Added
- [Cloud][Reality] Cloud-mode World State — per-deployment graph + snapshot + layers + slice-query surface (#464, #528)
- Registry proxies 5 HTTP endpoints (
snapshot,snapshot/{id},graph?layers=…,layers,query) over Fly 6PN to{fly-app}.internal:3000/api/world-state/*. Wire format mirrors cloudResilience and cloudTimeTravel:{ runtime_state: "live" | "unreachable", data }.unreachablecarriesdata: nullso the UI renders an honest empty state. - New
CloudWorldStateViewreuses the existingStateLayerPanel,WorldStateGraph, andStateNodeInspectorcomponents so the visualization is identical to local mode. Deployment selector auto-picks the first active hosted-mock; multi-deployment orgs get a dropdown. 5-second polling matches the local TanStack QueryrefetchInterval. 'world-state'added tocloudNavItemIds. WebSocket/streamupstream is intentionally not proxied — polling parity is functionally equivalent for the cadence the local UI uses, and ws-tunneling through 6PN is a follow-up.
- Registry proxies 5 HTTP endpoints (
- [Cloud][Reality] Cloud-mode Time Travel — controllable virtual clock on hosted-mock deployments (#466, #527)
- 7 clock-control endpoints proxied (
status,enable,disable,advance,set,scale,reset). Targets the hosted mock’s main HTTP port (3000) — not the admin port — because the time-travel router mounts there for reachability when admin isn’t publicly exposed. - New
CloudTimeTravelViewwith a runtime-unreachable banner that disables the control fieldset so users don’t fire mutations that’ll bounce back. Cron jobs + mutation rules stay local-only — they manage scenario state, not a hosted mock’s single-process clock. 'time-travel'added tocloudNavItemIds.
- 7 clock-control endpoints proxied (
- [Cloud][AI] Cloud-mode Test Generator — async LLM jobs over runtime_captures (#469, #529)
- New
cloud_test_generation_jobstable + 4 CRUD endpoints + SSE stream (GET .../jobs/{id}/stream) for live progress. - Background tokio worker drains the queue with
FOR UPDATE SKIP LOCKEDclaims, processes up toTEST_GENERATION_WORKER_CONCURRENCY(default 4) jobs in parallel per tick, and dispatches via the sameai::client+ai::quotapipelineai_studiouses — so quota and billing semantics stay consistent. BYOK skips the platform token quota; paid plans without BYOK succeed via the platform key (MOCKFORGE_PLATFORM_LLM_API_KEY+ provider/model/endpoint env vars). - Worker is forgiving: best-effort JSON parse strips
```jsonfences, recovers from prose wrappers, falls back to a{ raw_content }wrapper. Cancellation race is safe — terminal writes are gated onWHERE status = 'running'so a user-cancel mid-flight wins. - New
CloudTestGeneratorViewwith job timeline + create form + expandable detail rows + SSE-driven sub-second updates on expanded non-terminal rows.'test-generator'added tocloudNavItemIds.
- New
- [DevX] Pre-flight warning when
--vusis too low for--rps(#79 round 6 follow-up, #543)mockforge bench --rps N --vus Mnow warns before launch whenM × 10 < N(rule of thumb: 1 VU at ~100ms latency sustains ~10 req/s). The warning suggests a higher--vusvalue (ceil(rps / 10)), so users hit by k6’s “Insufficient VUs, reached M active VUs and cannot initialize more” message know what to change.
Changed
- [CI][Reality]
release.ymlgates Fly deploy + crates.io publish + Helm chart push on thereleasejob’scargo test --workspace --release(#447, #526)- All three downstream jobs (
deploy-registry,publish,helm) nowneeds: release. A tag with red tests no longer ships to Fly / crates.io / the Helm repo.
- All three downstream jobs (
- [DevX]
pr_generationmoved out ofmockforge-coreintomockforge-intelligenceand the intelligence → core cycle was broken (#562 phase 1, #571)mockforge-intelligencedropped itsmockforge-coredep, freeingmockforge-coreto take amockforge-intelligencedep.mockforge_core::pr_generationis preserved as apub usere-export for backwards compat.
Fixed
-
[DevX] CI rust-cache no longer poisons builds with dangling
target/*.dpaths (#446, #570)CARGO_HOMEswitched from per-run to per-runner-name so cached dep-info paths remain valid across runs on the same runner.Swatinem/rust-cache@v2invocations now partition the cache key by runner.
-
[Reality] Client-side “Connections opened” counter now appears for
--rps-only runs (#79 round 6 follow-up, #543)- Root cause: the parser was reading
http_req_connecting.values.countfrom k6’ssummary.json, but k6’s Trend metric never emits acountfield — onlyavg/min/med/max/p(90)/p(95). The field was always absent, sotcp_connect_sampleswas always 0 and the connection-count line never printed for non---cpsruns. - Fix: the generated k6 script now declares a dedicated
mockforge_connections_openedCounter and increments it wheneverres.timings.connecting > 0(i.e. a fresh TCP socket was opened). The Rust parser reads this Counter’scountdirectly. Works for both--cpsruns (≈ total requests) and pooled-reuse runs (≈vus_max). - Also: TCP-connect / TLS-handshake timing lines now print whenever the Trend has a non-zero
avg, not whencount > 0(which was unreliable). Newtest_connections_opened_counter_presentregression test guards both the Counter declaration and the per-request increment.
- Root cause: the parser was reading
-
[Reality]
--scenario constantnow runs at full VU concurrency from t=0 (#79 round 6 follow-up, #543)- Root cause: Srikanth reported that
--vus 5 -d 600stook until the ~6-minute mark to reach 5 VUs and then ramped DOWN. The k6 template always wrotestartVUs: 0, so even--scenario constant’s single{duration: '600s', target: 5}stage maderamping-vuslinearly interpolate from 0 → 5 across the whole window. - Fix: for
Constant,startVUsis seeded atmax_vusso concurrency is at full from the start. Ramping scenarios (RampUp/Spike/Stress/Soak) still start at 0 and let their stages drive the curve. Guarded bytest_constant_scenario_starts_at_target_vus.
- Root cause: Srikanth reported that
-
[Cloud][Reality] Cloud Resilience dashboard could not reach hosted mocks over Fly 6PN (#468 follow-up, #542, #544)
mockforge serve --adminwas binding the admin port to127.0.0.1, so the registry proxy’s{fly-app}.internal:9080reach failed silently (#542 — bind dual-stack). UI’s/api/resilience/*paths also sat behind auth middleware that doesn’t run in proxied cloud mode, so the proxy’s outbound calls 401’d (#544 — explicit exempt prefix). Both fixes were needed for the cloud Resilience tab to render live state instead of perpetualruntime_state: unreachable.
-
[UI][Build] Allow
esbuild/vue-demibuild scripts under pnpm 11’s managed-builds policy (#525, #533)pnpm-workspace.yamldeclares the two packages inonlyBuiltDependenciesso production docker builds succeed.
-
[UI][Build] Pin pnpm to 10.15.0 in the docker stages (#525 follow-up, #536)
- 10.15.0 predates the managed-builds policy that triggered #525 in the first place.
-
[UI][Cloud] Hide
api-explorerfrom cloud sidebar (#459 follow-up, #537) -
[CI][Docker] Explicit cosign login so signature push to GHCR succeeds (#546)
Cloud-parity meta tracker
This release closes #459 — the cloud-parity meta tracker for the 14 “Local only” nav items. 14 / 14 addressed: 8 shipped end-to-end across prior releases (Graph #460, Virtual Backends #461, Logs #462, Metrics-folded #463, World State #464, Observability #465, Performance-folded #467, Resilience #468), 4 explicitly kept local-only (Proxy Inspector #470, SMTP Mailbox #471, MQTT Broker #472, Kafka Broker #473), 2 land in this release (Time Travel #466, Test Generator #469).
[0.3.132] - 2026-05-12
Added
- [Reality] Full chaos fault-category coverage in stats and
/metrics(#79 round-4)connection_errorfault now records at the HTTP layer whenconnection_error_kind: http_503(previously only TCP-level kinds had counters). Newjitterandbandwidth_throttlecounters + matching Prometheus histograms (mockforge_chaos_jitter_ms,mockforge_chaos_bandwidth_throttle_ms{direction}).ChaosStatsSnapshotgains mean latency, jitter samples + mean offset, and bandwidth-throttle totals. TUI ChaosFault Statspanel renders all of them.
- [Reality] Bench client surfaces server-injected chaos signals (#79 item 7)
- HTTP chaos middleware stamps
X-Mockforge-Injected-Latency-Ms,-Injected-Jitter-Ms, and-Faultresponse headers. Generated k6 script reads them into custom trends (mockforge_server_injected_latency_ms,mockforge_server_injected_jitter_ms) and a counter (mockforge_server_fault_total). Bench summary prints a newServer-Injected (chaos)block alongside client-observed latency.
- HTTP chaos middleware stamps
- [DevX] New bench CLI flags
--rpsand--cps(#79 item 8)--rps Nswitches the k6 executor fromramping-vustoconstant-arrival-rateatNrequests/sec (and drops the per-iterationsleep(1)that previously capped throughput at ~2 RPS).--cpssetsnoConnectionReuse: trueso each request opens a fresh TCP/TLS connection — useful for stressing connection-limit chaos and TCP-level fault injection.
- [Reality] Opt-in
MOCKFORGE_HTTP_KEEPALIVE_HINT=1advertisesConnection: keep-alive+Keep-Alive: timeout=N, max=Mon every response (#79 item 2 workaround)- For proxies (F5/Avi/HAProxy/nginx) that read those headers when deciding to pool upstream sockets. Best-effort signal; the actual fix for the FIN-after-response pattern is upstream HTTP/1.1 negotiation in the proxy itself.
[0.3.131] - 2026-05-10
Added
- [Reality] TUI Chaos screen now surfaces live fault-injection counts (#79 follow-up)
- New
ChaosStatsSnapshotandGET /api/chaos/stats(+ admin passthrough at/__mockforge/chaos/stats). - Fault Stats panel below Settings shows totals + per-fault-type counts. Older servers without the endpoint fall back to the 2-panel layout.
- New
[0.3.130] - 2026-05-10
Fixed
- [Reality]
mockforge_chaos_*counters silently absent from/metrics(#79 follow-up)- Chaos counters register against the global
prometheus::default_registry();/metricswas exporting only the localMetricsRegistry. The two were disjoint, so chaos counters never surfaced.metrics_handlernow gathers from both. No format change for scrapers.
- Chaos counters register against the global
- [Reality]
LatencyInjectionConfig/RateLimitingConfig/NetworkShapingConfigrejected partial YAML- Missing fields broke the whole config load (e.g.
traffic_shaping:withoutmax_connections). AddingDefault+#[serde(default)]makes partial YAML parse cleanly.
- Missing fields broke the whole config load (e.g.
[0.3.129] - 2026-05-09
Added
- [Reality] YAML config now exposes every chaos
fault_injectionfield (#79 follow-up)mockforge_core::config::FaultConfiggainsconnection_error_kind,partial_responses+partial_response_probability,payload_corruption+payload_corruption_probability,corruption_type,error_pattern(Burst / Random / Sequential),mockai_enabled, andrequest_matcher. All#[serde(default)]so existing chaos.yaml files keep parsing.- The bridge in
serve.rsnow maps every field through tomockforge_chaos::config::FaultInjectionConfig; previously these were silently defaulted at YAML load time and only thePUT /api/chaos/config/faultsREST API could set them.
[0.3.128] - 2026-05-09
Fixed
- [DevX] k6 metric-name validation failure on deeply nested OpenAPI specs (Microsoft Graph etc.) (#436, #79)
- Root cause:
operationIds likedrives.drive.items.driveItem.workbook.worksheets.workbookWorksheet.charts.workbookChart.axes.categoryAxis.format.line.clear, after dot-to-underscore sanitization plus_latency/_errorssuffix, exceeded k6’s 128-char metric-name cap.validate_scriptcorrectly rejected the script before k6 ran. - New
K6ScriptGenerator::sanitize_k6_metric_namecaps the base at 112 chars (128 − 16 for_step99_latency) and appends an 8-hex-char hash of the original name when truncating, so distinct long names produce distinct metric names. JS variable identifiers keep the full readable form; only the metric string is truncated. - Wired into both render paths:
k6_script.hbs(per-operation) andk6_crud_flow.hbs. Tests cover passthrough, truncation, prefix-collision uniqueness, the “starts with letter or _” rule after truncation, and end-to-end script validation on a microsoft-graph-style operationId.
- Root cause:
- [Reality] Chaos prometheus counters were registered but never incremented (#436, #79)
mockforge_chaos_faults_total{fault_type, endpoint},mockforge_chaos_latency_ms, andmockforge_chaos_rate_limit_violations_totalall existed in the registry, but no caller invoked the correspondingrecord_*methods./metricsreported zero faults regardless of how many were actually firing — masking the effect of configured chaos rules from operators.- Wired
record_fault(...)at every fault decision point in the HTTP middleware (http_error,timeout,rate_limit,connection_limit,packet_loss,partial_response,payload_corruption) and the TCP chaos listener (tcp_reset,tcp_close). Latency injection also now records to the histogram viarecord_latency. - The TUI Chaos screen still renders config-only; surfacing these counters as a stats panel is tracked as a follow-up.
[0.3.127] - 2026-05-08
Fixed
- [Reality] TPS / RPS200 dashboard counters stuck at 0 under load (#351, #79)
- Metrics middleware (
collect_http_metrics) was never.layer()d on the production router built inserve.rs. CPS still advanced becauseCountingMakeServicewraps the make-service at a different layer. - Layer
collect_http_metricsas the outermost wrapper onhttp_appso every response — including chaos-mutated ones — bumps the rate counters the dashboard sampler reads.
- Metrics middleware (
Added
- [DevX]
bench-chunkedaccepts--base-path, humantime--duration,--validate-requests,--export-requests(#352, #79)--base-path <PATH>prepends to every spec-derived operation path before URL construction. CLI > spec.servers > none.-d 600s/--duration <DURATION>switched from bare seconds (u64) to humantime parsing.--validate-requestsand--export-requestsmirror the flags already onmockforge bench.
- [DevX] Supervisor wrappers for unattended runs under heavy traffic (#350, #79)
deploy/systemd/mockforge.service— systemd unit withRestart=always.deploy/scripts/run-forever.sh— bash supervisor that restarts the binary after any non-clean exit.
[0.3.73] - 2026-03-05
Fixed
- [UI] Fix
cargo publishfailure formockforge-uicaused bybuild.rsmodifying source directory- Removed code that copied
pwa-manifest.jsonandsw.jsintoui/dist/during build (violates cargo’s source-dir-immutability rule) serve_service_workernow readssw.jsfromui/public/(same pattern asserve_manifest)- Added
sw.jsto the crate’sincludelist so it’s packaged correctly
- Removed code that copied
- [Core] Mock server now supports
X-Mockforge-Response-Statusheader to return non-default status codes (#79)- Conformance checks for
response:404andresponse:400previously always failed because the server returned the first declared status (usually 200) - New
has_response_for_status()validates the requested code exists in the spec before overriding - Both OpenAPI handler paths extract and pass the header through
- Conformance checks for
- [Core] Response generation no longer replaces object-typed properties with string examples (#79)
- When a property schema declares
type: object, the fallback now preserves an empty{}instead of generating a name-based string like"example config" - Fixes
response:schema:validationfailures where JSON schema validation rejected string values for object properties - Added
is_object_typed_property()helper for type-aware fallback decisions
- When a property schema declares
- [Data]
generate_by_type("object")now returns{}instead of"unknown_type_object"(#79)- Also added
"array"handler returning[]
- Also added
Changed
- [Bench] Spec-driven conformance generator now sends
X-Mockforge-Response-Statusheader forresponse:400andresponse:404checks (#79)- Tells the mock server which status code to return, enabling accurate status-code conformance testing
[0.3.72] - 2026-03-04
Fixed
- [UI]
mockforge serve --adminno longer panics when no production auth is configured (#79)validate_auth_config_on_startup()now logs a warning instead of returning an error- Auto-generated JWT secret fallback so the admin UI works out of the box
- Default users are seeded even without
ENVIRONMENT=development, so login works immediately
- [Bench] Fix duplicate session ID in conformance Cookie headers (#79)
- Removed invalid
noCookies: truefrom k6 options (not a real k6 option; k6 silently ignores it) - Added
http.cookieJar().clear(BASE_URL)before and after each request when custom Cookie headers are present - Prevents k6’s internal cookie jar from re-sending server
Set-Cookievalues alongside custom headers - Applied to both reference-mode (
generator.rs) and spec-driven (spec_driven.rs) generators
- Removed invalid
- [Bench] Fix missing single-quote escaping in spec-driven
format_headers()(#79)- Header values containing single quotes are now properly escaped, matching
generator.rsbehavior
- Header values containing single quotes are now properly escaped, matching
Added
- [Bench] Conformance report now shows individual failed checks with pass/fail counts (#79)
- New “Failed Checks” section after the category summary table lists each check that failed
- When not using
--conformance-all-operations, prints a tip suggesting it for endpoint-level detail
[0.3.70] - 2026-02-27
Fixed
- [Bench] Remove dead
CUSTOM_HEADERSJS const from conformance generators (#79)- Custom header values are now inlined directly into each request instead of referencing an unused JS constant
- Eliminates confusing dead code in generated k6 scripts
- [Bench] Add
noCookies: trueto k6 options when Cookie header is in custom headers (#79)- Prevents k6’s automatic cookie jar from duplicating cookies on subsequent requests
- Fixes duplicate session ID / authentication failures reported by @srikr
- [Bench] Fix conformance report file not found after k6 execution (#79)
handleSummarynow writesconformance-report.jsonto an absolute path matching the output directory- Previously wrote to a relative path based on k6’s CWD, causing the CLI to report “Conformance report not generated”
Added
- [Bench]
--conformance-all-operationsflag for full-endpoint conformance testing (#79)- Default mode tests one representative operation per feature check (fast feature-coverage)
- New flag tests ALL operations with path-qualified check names (e.g.,
method:GET:/api/users) - Addresses user confusion about “only 5 endpoints tested”
- [Bench] Conformance coverage summary output (#79)
- After generating conformance tests, prints “Conformance: N operations analyzed, M unique checks generated”
- When using default mode with fewer checks than operations, shows tip about
--conformance-all-operations
[0.3.69] - 2026-02-24
Fixed
- [Multi] Replace 36+
assert!(true)placeholder tests with meaningful assertions across 16 files- CLI command tests (MQTT, SMTP, governance) now construct and verify command variants
- Registry server tests use compile-time type checks instead of no-op assertions
- Integration tests (voice workspace, drift GitOps, behavioral cloning, WebSocket, cross-platform sync) use proper verification patterns
- [gRPC] Add
use super::*to 13 emptytest_module_compiles()tests so they actually verify module compilation - [HTTP] Fix misleading “placeholder” doc comment on fully-implemented
get_proxy_inspecthandler
[0.3.57] - 2026-02-14
Fixed
- [Bench] Spec-driven conformance: global security requirement detection (#79)
annotate_security()now falls back tospec.security(root-level) when an operation has no operation-level security defined- APIs that only define security globally are now correctly detected
- [Bench] Spec-driven conformance: SecurityScheme type resolution (#79)
- Security schemes are now resolved from
components.securitySchemesto detect actual type (HTTP/bearer,APIKey,HTTP/basic) instead of relying on name heuristics alone - A scheme named “myAuth” that is actually an
apiKeytype is now correctly identified - Name-based heuristic retained as fallback for unresolvable schemes
- Security schemes are now resolved from
- [Bench] Spec-driven conformance: ContentNegotiation detection (#79)
ContentNegotiationfeature is now detected when a response defines multiple content types (e.g., bothapplication/jsonandapplication/xml)- Previously only worked in reference mode
- [Bench] CLI help text for
--conformance-categoriesnow includesresponse-validation(#79)
Added
- [Bench] 5 new conformance tests: ResponseValidation with schema check, global security, SecurityScheme resolution, ContentNegotiation detection, single-type negative case (#79)
[0.3.56] - 2026-02-14
Added
- [Bench] Conformance category filtering (#79)
- New
--conformance-categoriesflag to run only specific conformance categories (e.g.,--conformance-categories "parameters,security") - Case-insensitive category matching with validation against known categories
- New
- [Bench] Spec-driven conformance testing (#79)
- When
--conformance --spec my-api.jsonis provided, analyzes the user’s actual OpenAPI spec to detect which features their API exercises - Generates conformance tests against real endpoints instead of reference
/conformance/paths - Full
$refresolution with cycle detection for parameters, schemas, request bodies, and responses - Detects: parameter types, request body formats, schema types/composition/formats/constraints, response codes, security schemes
- When
- [Bench] Response schema validation (#79)
- In spec-driven mode, validates response bodies against OpenAPI response schemas
SchemaValidatorGeneratorproduces JavaScript validation expressions from OpenAPI schemas- Supports object (required fields, property types), array, string (format regex, enum, length), integer/number (range), boolean validation
- Wrapped in try-catch for resilient k6 execution
- [Bench] SARIF 2.1.0 report output (#79)
- New
--conformance-report-format sarifflag outputs conformance results in SARIF 2.1.0 format - Compatible with GitHub Code Scanning, VS Code SARIF Viewer, and CI/CD pipelines
- Maps each conformance feature to a SARIF rule with OpenAPI spec section links
- Passed features emit
level: "note", failed features emitlevel: "error"
- New
[0.3.55] - 2026-02-14
Added
- [Bench] Per-server stats in multi-target mode (#79)
K6Resultsnow parses RPS, VUs, and full latency breakdown (min/med/p90/p95/p99/max) from k6summary.jsonAggregatedMetricsincludestotal_rps,avg_rps,total_vus_max- Multi-target reporter shows per-target RPS, VUs, and full latency breakdown
aggregated_summary.jsonincludes all new metrics in both aggregated and per-target sections
- [Bench] Per-target spec support for multi-target mode (#79)
- Targets file JSON format now supports
"spec"field for per-target OpenAPI specs - Each target can use a different spec file for heterogeneous fan-out
- Example:
[{"url": "https://server1", "spec": "spec_a.json"}, {"url": "https://server2", "spec": "spec_b.json"}]
- Targets file JSON format now supports
- [Bench] OpenAPI 3.0.0 conformance testing (#79)
- New
--conformanceflag generates and runs comprehensive k6 scripts exercising 47 OpenAPI 3.0.0 features across 10 categories (Parameters, Request Bodies, Schema Types, Composition, String Formats, Constraints, Response Codes, HTTP Methods, Content Negotiation, Security) - Reports per-category pass/fail rates with colored terminal output
- Supports
--conformance-api-key,--conformance-basic-auth,--conformance-reportfor security scheme testing - Example:
mockforge bench --conformance --target http://localhost:3000
- New
[0.3.54] - 2026-02-13
Fixed
- [Bench] fix(bench): deliver CRS payloads as path injection + form-encoded body (#79)
- Added
inject_as_pathfield toSecurityPayload— URI payloads without query params (e.g., CRS 942101:POST /1234%20OR%201=1) now replace the request path viaencodeURI()so WAFs inspectREQUEST_FILENAMEinstead ofARGS - Added
form_encoded_bodyfield toSecurityPayload— body payloads from CRS tests (e.g., 942432:var=;;dd foo bar) now sent asapplication/x-www-form-urlencodedso WAFs parse form data intoARGSfor character counting - Updated
k6_script.hbsandk6_crud_flow.hbstemplates to handle both new delivery mechanisms - Replaced unreliable
startsWith('/')URI heuristic in CRUD flow template with explicitinjectAsPathflag - Expected SQLi detection: 46/46 rules (100%), up from 45/46 (97.8%)
- Added
[0.3.53] - 2026-02-13
Fixed
- [Bench] fix(bench): URL-encode URI payloads + strip form keys from body payloads (#79)
- URI security payloads now wrapped in
encodeURIComponent()for valid HTTP transport — WAFs decode before inspection (fixes 942101) - Form-encoded body payloads now have form key prefix stripped (
var=;;dd foo bar→;;dd foo bar) so WAF ARGS parsing sees the attack payload directly (fixes 942432) - Confirmed SQLi detection: 45/46 rules (97.8%), up from 43/46 (93.5%)
- URI security payloads now wrapped in
[0.3.52] - 2026-02-12
Fixed
- [Bench] fix(bench): Group multi-part WAFBench payloads + decode body payloads + fix Cookie/CookieJar conflict (#79)
- Multi-part CRS test cases (URI + headers + body) now grouped by
group_idand sent together in one HTTP request instead of being split across separate requests (fixes 942290) - Body payloads from CRS YAML files are now form-URL-decoded before injection (
%22+WAITFOR+DELAY+%27→" WAITFOR DELAY ') so WAFs see actual SQL patterns in JSON bodies (fixes 942240, 942320, 942432) - URI payloads from path-only CRS tests are now URL-decoded and stripped of leading
/artifact (fixes 942101) - Cookie header payloads no longer overridden by empty CookieJar —
secRequestOptsconditionally skipsjar: new http.CookieJar()when a security Cookie header is present (fixes 942420, 942421) - Added
groupedPayloadsarray-of-arrays in generated k6 scripts;getNextSecurityPayload()returns arrays of related payloads - Template loop applies URI/header/body parts simultaneously per request via
secPayloadGroup - Expected SQLi detection improvement: 37/46 → 44/46 (80.4% → 95.7%)
- Multi-part CRS test cases (URI + headers + body) now grouped by
[0.3.51] - 2026-02-11
Fixed
- [Bench] fix(bench): Accept all WAFBench CRS payloads without attack-pattern filter (#79)
- Removed overly strict
attack-patterncategory filter that was silently dropping valid CRS test cases - All CRS YAML test cases now loaded regardless of their
attack_typemetadata
- Removed overly strict
[0.3.50] - 2026-02-10
Fixed
- [Bench] fix(bench): Use per-request CookieJar instead of shared EMPTY_JAR (#79)
- Each HTTP request now creates its own
new http.CookieJar()instead of sharing a global empty jar - Prevents cookie cross-contamination between requests in security testing
- Each HTTP request now creates its own
[0.3.49] - 2026-02-09
Fixed
- [Bench] fix(bench): Send raw security payloads + use dedicated empty cookie jar (#79)
- Security payloads now sent as raw strings without additional encoding
- Dedicated empty CookieJar per request prevents k6’s default cookie accumulation
[0.3.48] - 2026-02-08
Fixed
- [Bench] fix(bench): Cycle security payloads per-operation + clear cookies in API2 tests (#79)
- Security payloads now cycle per-operation block (each API endpoint gets a different payload)
- Previously all operations in one VU iteration used the same payload
- OWASP API2 (Broken Auth) tests now properly clear cookies between requests
[0.3.47] - 2026-02-06
Added
- [DevX] chore: Add Claude Code setup (CLAUDE.md, agents, skills, hooks, hookify)
- Project-specific Claude Code configuration with rules, agents, and skills
- Custom skills for verification, template checking, code review, and bench review
- Hookify rules engine for behavioral guardrails
Fixed
-
[Bench] fix(bench): Security payloads now injected + cookie dedup in all templates (#79)
- Security payloads now properly injected in both k6_script.hbs and k6_crud_flow.hbs templates
- Cookie deduplication applied to all HTTP request paths in both templates
- Comprehensive test suite added for issue #79 security pipeline
-
[Registry] fix(registry): Add RBAC permission system with Display, AdminAll bypass, and PermissionChecker
- New RBAC permission model with role-based access control
- AdminAll role bypasses all permission checks
- PermissionChecker trait for consistent authorization across endpoints
[0.3.46] - 2026-01-30
Fixed
-
[Bench] fix(bench): WAFBench payloads now distributed across VUs for better coverage (#79)
- Changed payload cycling to use VU-based offset:
(__VU - 1) % payloads.length - Previously all 50 VUs started at index 0 and cycled through same sequence
- Now each VU starts at a different payload, maximizing attack coverage in shorter test runs
- With 50 VUs and 30 payloads, all payloads are tested from the start
- Changed payload cycling to use VU-based offset:
-
[Bench] fix(bench): OWASP API tests now include custom headers in all requests (#79)
- Added
CUSTOM_HEADERSto API8 verbose error test (malformed JSON body test) - Added
CUSTOM_HEADERSto API9 discovery paths test - Added
CUSTOM_HEADERSto API9 API versions test - Fixes auth failures when using
--headers "Cookie:..."with OWASP testing
- Added
[0.3.43] - 2026-01-16
Fixed
- [Bench] fix(bench): Security payloads now actually applied to requests in k6 scripts (#79)
- Updated k6_script.hbs template to call
getNextSecurityPayload()andapplySecurityPayload() - Previously, security payload functions were defined but never called in generated scripts
- Security payloads now properly injected into request bodies for POST/PUT/PATCH
- Header-based payloads now properly injected into request headers
- Updated k6_script.hbs template to call
[0.3.42] - 2026-01-15
Fixed
- [Bench] fix(bench): XSS payloads now inject into ALL string fields, not just the first one (#79)
- Removed
breakstatement fromapplySecurityPayload()loop in security_payloads.rs - Ensures WAF can detect payloads regardless of which field it scans
- Removed
- [Bench] fix(bench): Added
jar: nullto remaining OWASP HTTP calls to prevent cookie duplication (#79)- Fixed testBrokenAuth empty token test
- Fixed testMisconfiguration verbose error test
- Fixed testInventory discovery paths and API versions checks
- [CLI] fix(cli): Fixed format string compilation error in plugin_commands.rs (#79)
- Escaped all braces (
{→{{,}→}}) insideformat!macro for auth plugin template - Fixes “invalid format string: expected
}, foundr” compilation error
- Escaped all braces (
[0.3.39] - 2026-01-14
Fixed
- [Bench] fix(bench): WAFBench XSS attacks now properly injected into request body (#79)
- Removed location check from
applySecurityPayload()- ALL payloads now injected into body for POST/PUT - WAFBench payloads correctly pass location info (uri/header/body) to k6 scripts
- Header payloads include header name for proper injection into specified headers
- Removed location check from
- [Bench] fix(bench): Cookie header duplication in OWASP and security tests (#79)
- Added
jar: nullto all HTTP request params to disable k6’s automatic cookie jar - Prevents duplicate cookies when user provides Cookie header via
--headersflag - Applied to k6_script.hbs, k6_crud_flow.hbs, and OWASP generator
- Added
[0.3.38] - 2026-01-13
Fixed
- [Bench] fix(bench): pass custom headers from
--headersflag to OWASP tests (#79)- Cookie and other custom headers are now included in all OWASP request helpers
- Fixes issue where
avi-sessionid=Nonewas being sent instead of actual cookie values
- [Bench] fix(bench): WAFBench loader now handles single YAML file paths (#79)
- Previously only directories or glob patterns were supported
- Single file paths like
/path/to/941100.yamlnow work correctly
- [Bench] Verified CRS v3.3 format compatibility with full CoreRuleSet test suite
- Tested with 175 files, 1512 payloads (692 XSS, 505 SQLi, 304 Command Injection, 11 Path Traversal)
[0.3.37] - 2026-01-12
Added
- [Bench] feat(bench): add WAFBench cycle-all mode (
--wafbench-cycle-all) to test all payloads sequentially (#79) - [Bench] feat(bench): add
--owasp-iterationsparameter to control OWASP test iterations per VU (#79) - [Bench] feat(bench): OWASP tests now respect
--vusparameter for concurrent testing (#79)
Fixed
- [Bench] fix(bench): WAFBench payloads now properly injected in standard bench mode (not just CRUD flow)
- [Bench] fix(bench): OWASP APIs now use random UUIDs per request instead of static IDs for BOLA testing (#79)
- [Bench] fix(bench): OWASP auth tokens with special characters (quotes, backslashes) now properly escaped (#79)
- [Bench] fix(bench): prevent Handlebars double-escaping of pre-escaped JavaScript values
- [Bench] fix(bench): WAFBench security payloads now integrated into CRUD flow requests (#79)
- [Bench] fix(owasp): use
http.del()instead ofhttp.delete()for k6 compatibility (#79) - [Bench] fix(owasp): add
--base-pathsupport for OWASP API testing (#79) - [Bench] fix(bench): remove undefined
totalRequestCountvariable reference - [Bench] fix(bench): support CRS v3.3 WAFBench format and pass
--insecureto OWASP tests
[0.3.33] - 2026-01-10
Fixed
- [Bench] fix(bench): multiple fixes for OWASP and WAFBench testing
- Support CRS v3.3 format in WAFBench parser
- Pass
--insecureflag to OWASP tests for self-signed certificates
[0.3.31] - 2026-01-08
Fixed
- [Bench] fix(bench): fix extracted value substitution in CRUD flows
- [Bench] fix(bench): OWASP k6 configuration improvements
[0.3.30] - 2026-01-07
Added
- [Bench] feat(bench): add
merge_bodysupport for CRUD flows - merge extracted values with request body - [Bench] feat(bench): add
inject_attacksdata model for security testing in CRUD flows
[0.3.28] - 2026-01-06
Added
- [Bench] feat(bench): add nested path extraction for CRUD flows (e.g.,
results[0].id) - [Bench] feat(bench): add filter extraction for CRUD flows (e.g.,
results[?name=='test'].id)
[0.3.27] - 2026-01-05
Added
- [Bench] feat(bench): add full body extraction for CRUD flows
- [Bench] feat(bench): add key filtering for extracted values
[0.3.26] - 2026-01-04
Added
- [Bench] feat(bench): add aliased extraction for CRUD flow value chaining
- Extract values with aliases (e.g.,
id as poolId) for use in subsequent requests
- Extract values with aliases (e.g.,
[0.3.24] - 2026-01-03
Fixed
- [Bench] fix(bench): use correct variable name in CRUD flow extracted value replacement
[0.3.22] - 2026-01-02
Added
- [Bench] feat(bench): add OWASP API Security Top 10 testing mode (#79)
- Test for BOLA (API1), Broken Auth (API2), Mass Assignment (API3), Resource Consumption (API4)
- Test for Function Auth (API5), SSRF (API7), Misconfiguration (API8), Inventory (API9), Unsafe Consumption (API10)
- Configurable test categories with
--owasp-categories - Support for auth tokens with
--owasp-auth-token - SARIF and JSON report formats
Changed
- [DevX] chore: include UI dist files for publishing to crates.io
[0.3.21] - 2025-12-31
Fixed
- [DevX] fix(bench): use custom flow config and fix sequential mode path matching - enables cross-resource dependency chains
- [DevX] fix(bench): process dynamic placeholders in CRUD flow params file bodies (#79)
- chore: update benchmark baseline [skip ci]
- chore: enable publishing for previously internal crates
- chore: update benchmark baseline [skip ci]
- fix(release): disable sccache for crates.io publish
- chore: update benchmark baseline [skip ci]
- fix(release): publish all crates in dependency order
- fix(release): add mockforge-core to crates.io publish order
- chore: update benchmark baseline [skip ci]
- feat(bench): add –base-path option for API base path support (#79)
- chore: update benchmark baseline [skip ci]
- fix(collab): include SQLx query cache for crates.io installation (#79)
- chore: update benchmark baseline [skip ci]
- feat: implement optional enhancements from improvement plan
- fix: update doc tests to use rust,ignore for external dependencies
- chore: update benchmark baseline [skip ci]
- chore: add missing crates to workspace and restore path dependencies
- chore: restore path dependencies after publishing remaining v0.3.17 crates
- fix: restore all crates to workspace members list
- chore: restore path dependencies after publishing v0.3.17
- docs: update CHANGELOG for v0.3.17 release
- feat(bench): add WAFBench YAML integration for security testing
- Bump version to 0.3.17
- feat: comprehensive improvements across AMQP, MQTT, gRPC, registry server, and UI
- feat(ui): add type safety, mobile layout fixes, and search/filter to frontend
- Restore path dependencies after publishing v0.3.16
- Bump version to 0.3.16
- fix: resolve flaky tests and race conditions across test suite
- fix: replace panic-prone unwrap calls with safe error handling
- fix: resolve UUID storage format mismatch in collab crate tests
- Add multi-spec support and cross-spec dependency detection for bench command
- feat: add multi-spec support and cross-spec dependency handling to bench command
- fix: add validation to CRUD flow script generation
- fix: sanitize k6 CRUD flow metric names (#79 follow-up)
- Bump version to 0.3.13 and improve changelog
- Bump version to 0.3.12 and publish to crates.io
- Bump version to 0.3.11 and publish to crates.io
- chore: update benchmark baseline [skip ci]
- feat: add –params-file option for custom parameter values in bench
- Bump version to 0.3.10 and publish to crates.io
- chore: update benchmark baseline [skip ci]
- fix: move insecureSkipTLSVerify to global k6 options (fixes –insecure)
- chore: update benchmark baseline [skip ci]
- fix: resolve k6 bench issues with –insecure flag, textSummary, and query params
- chore: update benchmark baseline [skip ci]
- chore: bump version to 0.3.9 and update changelog
- feat: implement comprehensive mock server functionality across all crates
- chore: commit remaining version updates
- fix: enable publishing for mockforge-ui
- fix: enable publishing for mockforge-tunnel
- fix: update all 0.3.7 dependencies to 0.3.8 with path dependencies
- fix: add path dependencies for all workspace crates
- chore: update CHANGELOG date for 0.3.8
- chore: bump version to 0.3.8
- Fix cargo publish issues: add version requirements to dependencies
- chore: update benchmark baseline [skip ci]
- Apply formatting and additional code changes
- Fix compilation errors: update dependencies and adapt to API changes
- fix: remove path from mockforge-pipelines dep in mockforge-collab
- Add mockforge-sdk, mockforge-ui, mockforge-cli to workspace
- fix: add mockforge to restore function targets list
- fix: convert mockforge dev-dependencies to path dependencies
- fix: add mockforge-core to restore list and manually fix dependency
- fix: include mockforge-core in restore list
- fix: restore function now properly handles table-form dependencies without path
- fix: automatically restore dependencies at start of publish
- fix: restore all crate dependencies, not just a few
- fix: only convert dependencies for already-published crates
- fix: correct publish order - publish mockforge-data before mockforge-core
- fix: add mockforge-data as optional dependency in mockforge-core
- chore: bump version to 0.3.6 and update changelog
- chore: update benchmark baseline [skip ci]
- Fix k6 script generation and UI icon embedding issues
- chore: update benchmark baseline [skip ci]
- Add comprehensive test suite and fix build issues
- chore: update benchmark baseline [skip ci]
- docs: add comprehensive performance benchmarks documentation
- chore: update benchmark baseline [skip ci]
- fix: implement real functionality in benchmark tests and fix k8s-operator
- chore: update benchmark baseline [skip ci]
- fix: filter out ‘change’ directories from benchmark baseline parsing
- chore: update benchmark baseline [skip ci]
- chore: update benchmark baseline [skip ci]
- fix: GitHub Actions workflow cleanup and fixes (#81)
- chore: restore dependencies after publishing all crates
- fix: add mockforge-cli to workspace and add metadata to mockforge-k8s-operator
- fix: add missing crates to workspace (mockforge-sdk, mockforge-http, mockforge-ui, mockforge-k8s-operator)
- fix: add mockforge-world-state to workspace and publishing order before mockforge-http
- fix: add mockforge-route-chaos publishing step before mockforge-http
- fix: add mockforge-route-chaos to dependency targets and publishing order
- fix: add mockforge-route-chaos to workspace and publishing script
- fix: add mockforge-route-chaos to publishing order before mockforge-http
- fix: reduce keywords from 6 to 5 for mockforge-performance
- fix: reduce keywords to 5 for mockforge-performance (crates.io limit)
- fix: add mockforge-performance to publishing order before mockforge-http
- fix: add mockforge-collab to workspace members list
- fix: add mockforge-collab to workspace members
- fix: add missing README.md for mockforge-pipelines
- fix: add mockforge-pipelines to publishing order and dependency targets
- fix: add mockforge-pipelines to workspace and publishing script
- fix: add all missing crates to workspace members
- fix: handle short form dependencies when converting to path
- fix: publish mockforge-template-expansion before mockforge-core
- fix: add mockforge-template-expansion to publishing script
- fix: temporarily convert dependent crates’ dependencies to path before publishing
- fix: remove argon2 from mockforge-core during MSRV checks
- fix: exclude mockforge-collab from MSRV checks and remove patch section
- fix: use awk instead of sed for multi-line patch section insertion
- fix: use Cargo patch section to pin base64ct for MSRV
- fix: improve base64ct pinning order in MSRV workflow
- fix: use exact version constraint for base64ct in MSRV workflow
- fix: improve base64ct pinning in MSRV workflow
- fix: pin base64ct to 1.7 for MSRV compatibility
- fix: exclude mockforge-ui from MSRV checks
- fix: add abd and existant to typos config
- fix: exclude FontAwesome and all minified files from spell check
- fix: also remove sysinfo from mockforge-ui during MSRV checks
- fix: exclude elasticlunr.min.js from spell check
- fix: exclude highlight.js from spell check
- fix: disable sysinfo feature during MSRV checks
- fix: sync sysinfo to 0.37, fix resolvable typo, exclude ace.js from spell check
- fix: pin sysinfo to 0.36, fix typos, improve MSRV workaround
- fix: update MSRV to 1.80 and add GraphQL exclusion workaround
- fix: update MSRV from 1.82 to 1.75
- fix: fix GitHub Actions workflow failures
- fix: standardize dependencies and fix all test failures
- Skip CRDs in kubectl validation to avoid server connection
- Fix kubectl validation to prevent server connection attempts
- Fix kubectl validation to skip server connection
- Fix all test failures and resolve dependency conflicts
- Fix k6 metric name validation error (issue #79) (#80)
- Optimize workflows: update deprecated actions and add path filters
- Fix mockforge-smtp version constraint from 0.2.0 to 0.3.3
- Fix Docker build, k8s validation, and spell check issues
- fix: update all mockforge dependency versions to 0.3.3 in mockforge-http
- chore: fix formatting (pre-commit hooks)
- deps(deps): bump opentelemetry_sdk from 0.21.2 to 0.31.0 (#67)
- chore: update benchmark baseline [skip ci]
- deps(deps): bump opentelemetry-semantic-conventions (#66)
- chore: update benchmark baseline [skip ci]
- deps(deps): bump sysinfo from 0.32.1 to 0.37.2 (#60)
- deps(deps): bump wasmparser from 0.239.0 to 0.240.0 (#64)
- deps(deps): bump governor from 0.6.3 to 0.8.1 (#61)
- chore: update benchmark baseline [skip ci]
- deps(deps): bump mail-parser from 0.9.4 to 0.11.1 (#63)
- deps(deps): bump rumqttc from 0.24.0 to 0.25.0 (#65)
- deps(deps): bump ndarray from 0.16.1 to 0.17.1 (#76)
- chore: update benchmark baseline [skip ci]
- ci(deps): bump azure/setup-helm from 3 to 4 (#72)
- ci(deps): bump actions/upload-artifact from 4 to 5 (#71)
- deps(deps): bump image from 0.24.9 to 0.25.9 (#77)
- deps(deps): bump rustls from 0.21.12 to 0.23.35 (#78)
- chore: update benchmark baseline [skip ci]
- Bump all crates to version 0.3.3
- Format code with rustfmt
- Fix k6 script generation with operation IDs containing dots/hyphens
- chore: update benchmark baseline [skip ci]
- perf: optimize template rendering by avoiding unnecessary operations
- chore: update benchmark baseline [skip ci]
- docs: update benchmark documentation with final optimizations
- perf: fix benchmark regressions and optimize measurements
- chore: update benchmark baseline [skip ci]
- Fix Kafka compilation errors and borrow checker issues
- feat: Implement cross-pillar enhancements - World State Engine, MOD, and Performance Mode
- feat(ai-studio): Add API Critique, System Generator, and Behavioral Simulator
- chore: rework UI/UX to be more AI native
- fix: Address pre-commit security vulnerabilities
- feat: Implement Invisible Mock Server experience (DevX Pillar)
- feat(security): implement email, Slack, and webhook notification services
- Refactor template expansion for Send safety
- chore: Restore path dependencies after 0.3.2 publish
- Fix: Complete SQLx query cache for mockforge-collab 0.3.2
- chore: update mockforge dependencies to version 0.3.1 across multiple crates
- fix: improve dependency conversion for optional dependencies and fix publishing order
- fix: update publish script to handle Phase 1 crate dependencies correctly
- feat: add comprehensive integration tests for 0.3.0 features and update changelog
- feat: Complete pillar enhancement gaps - VS Code extension and docs
- feat: Implement pillar tagging system and documentation enhancements
- feat: Implement MockForge AI Studio - Unified AI Copilot
- feat(cloud): Complete Cloud pillar implementation and fix compilation issues
- [DevX] Add JSON Schema support for config validation and IDE autocompletion
- feat: Implement Contract Fitness Functions, Consumer Impact Analysis, and Multi-Protocol Contracts
- feat: Enhance Reality feature with observability, cross-protocol consistency, and time-aware lifecycles
- fix: use proper vosk API by matching on CompleteResult enum
- fix: resolve all compilation errors
- chore: prepare release 0.3.0
- feat: Implement LLM Studio - Natural Language Workspace Creation (0.3.4)
- feat: Complete Behavioral Cloning v1 implementation and refactor architecture
- feat: Implement Drift Budget & GitOps for API Sync + AI Contract Diff
- feat: implement Scenario Studio Visual Editor with React Flow
- feat: implement AI-Native Interface Deepening features
- feat: Implement Time Travel & Snapshots and Frontend X-Ray Mode
- feat(sdk): Add Contract-Backed Types and Scenario-First SDKs to Vue, Svelte, and Angular
- Format code: Apply rustfmt and whitespace cleanup
- Release v0.2.9: Update version, CHANGELOG, and publish all crates to crates.io
- Add registry server improvements, password reset, metrics, and marketplace enhancements
- security: Upgrade wasmtime to 36.0.3 to fix RUSTSEC-2025-0118
- feat: Fix compilation errors and implement comprehensive E2E test suite
- fix: implement custom routes, template expansion, latency injection, and init improvements
- feat: Smart Personas with array generation and relationship inference
- feat: Complete Java and .NET SDK implementations with builder patterns
- fix: update all test files for new function signatures
- fix: resolve all compilation errors across workspace
- Complete Phase 3 security controls implementation
- Add cloud monetization infrastructure and features
- Implement organization management endpoints
- Fix Axum 0.8 route syntax in state_machine_api.rs
- Fix file server route syntax for Axum 0.8 compatibility
- Release v0.2.8: Publish all crates to crates.io
- chore: bump version to 0.2.8
- feat: Complete Generative Schema Mode and achieve 100% roadmap completion
- Implement Smart Personas feature for consistent cross-endpoint data generation
- Add Reality Continuum feature for blending mock and real data sources
- Implement Voice + LLM Interface with STT backends
- Implement complete Deceptive Deploy feature
- Add GraphQL + REST Playground with workspace filtering
- Implement ForgeConnect SDK with full feature set
- Add enhanced scenario marketplace features
- Configure SQLx and integrate mockforge-collab with mockforge-core
- Fix test compilation errors in reality integration and hot-reload tests
- Implement Reality Slider feature with hot-reload support
- Complete latency recording integration and fix WorkspaceConfig reality_level field
- style: Apply rustfmt formatting to Chaos Lab code
- feat: Add Chaos Lab interactive network condition simulation
- Fix test compilation errors in openapi_generator_tests
- Fix all compilation errors for AI Contract Diff feature
- Add WireMock-inspired features: browser proxy mode, git sync, data sources, template library, managed hosting docs, and user management
- Add comprehensive ecosystem and use cases documentation
- Complete configuration and extensibility implementation
- Add advanced behavior and simulation features
- Fix test and benchmark compilation errors
- Complete Scenario State Machines 2.0 with sub-scenario execution
- Implement VBR Engine enhancements: OpenAPI integration, M2M relationships, seeding, ID generation, snapshots
- Add mock-to-real migration pipeline with per-route toggling
- Add Data Scenarios Marketplace feature
- feat: Implement ForgeConnect - Front-End Integrated Mode for browser-based mock creation
- Add MockForge Cloud Graph visualization with real-time updates and export
- Add data personality profiles system for consistent mock data generation
- Add realistic network conditions and chaos lab with interactive UI controls
- Add temporal simulation with CLI commands and scenario support
- Complete MockAI implementation with query params and session recording
- Add Virtual Backend Reality (VBR) engine
- Add multipart form data support and file generation/serving for API mocks
- fix: update mockforge-plugin-sdk to use workspace version
- fix: enable publishing for mockforge-tunnel and add to publish script
[0.3.20] - 2025-12-31
Fixed
- [Bench] Dynamic placeholder expansion in CRUD flow params file bodies (#79): Fixed
${__VU},${__ITER}, and other dynamic placeholders not being expanded when used in request body content from params files- Previously, placeholders like
"name": "HTTP-WAAP-vsvip-${__VU}-${__ITER}"were sent literally to the API - Now properly converted to k6 template literals for runtime evaluation
- Supports all dynamic placeholders:
${__VU},${__ITER},${__TIMESTAMP},${__UUID},${__RANDOM},${__COUNTER},${__DATE},${__VU_ITER}
- Previously, placeholders like
[0.3.19] - 2025-12-30
Added
- [DevX] API base path support for bench command (#79): New
--base-pathoption to prepend a path prefix to all API endpoints in generated load tests- Automatically extracts base path from OpenAPI spec’s
serversURL (e.g.,https://api.example.com/api/v1→/api/v1) - CLI option takes priority over spec’s base path for explicit control
- Use
--base-path ""to disable base path even if spec defines one - Works with both standard k6 scripts and CRUD flow mode
- Example usage:
# Auto-detect from spec's servers URL mockforge bench --spec api.yaml --target http://localhost:8080 --crud-flow # Explicitly set base path mockforge bench --spec api.yaml --target http://localhost:8080 --base-path /api # Disable base path mockforge bench --spec api.yaml --target http://localhost:8080 --base-path ""
- Automatically extracts base path from OpenAPI spec’s
[0.3.18] - 2025-12-29
Fixed
- [Collab] SQLx offline mode for crates.io installation (#79): Fixed compilation errors when installing
mockforge-collabfrom crates.io- Added
.sqlxquery cache directory with 51 precompiled query metadata files - The
build.rsnow automatically enablesSQLX_OFFLINE=truewhen query cache is present - Users no longer need
DATABASE_URLor to runcargo sqlx prepareto install the crate - Resolves “set DATABASE_URL to use query macros online” compilation errors
- Added
[0.3.17] - 2025-12-28
Added
-
[DevX] WAFBench YAML integration for security testing: New
--wafbench-dirflag to import Microsoft WAFBench CRS (Core Rule Set) attack patterns- Parse WAFBench YAML test files from the WAFBench project
- Support glob patterns for loading specific rule categories (e.g.,
REQUEST-941-*for XSS,REQUEST-942-*for SQLi) - Extract attack payloads from URI parameters, headers, and request bodies
- Automatic CRS rule ID parsing from test metadata (e.g.,
941100for XSS attacks) - Integrate WAFBench payloads with existing security testing framework
- Example usage:
mockforge bench spec.yaml --wafbench-dir ./wafbench/REQUEST-941-* # XSS rules mockforge bench spec.yaml --wafbench-dir ./wafbench/**/*.yaml # All rules
-
[DevX] Per-URI control mode for data-driven testing (#79): New
--per-uri-controlflag for CSV/JSON data files that allows each row to specify HTTP method, URI, body, query params, headers, attack type, and expected status code- Enables fine-grained control over test requests directly from data files
- Supports security testing per-URI with
attack_typecolumn - Automatic status validation with
expected_statuscolumn - Example CSV format:
method,uri,body,query_params,headers,attack_type,expected_status GET,/virtualservice,,include_name=true,,,200 POST,/virtualservice,"{""name"":""test""}",,,sqli,201
-
[Protocol] AMQP TLS support: Full TLS/SSL support for AMQP broker with configurable certificates
-
[Protocol] MQTT protocol improvements: Enhanced MQTT server with TLS, session management, and metrics
-
[Protocol] gRPC dynamic service improvements: Better dynamic proto loading and error handling
-
[Registry] Security enhancements: CSRF protection, request ID middleware, trusted proxy support, token revocation
-
[UI] Frontend improvements: Type safety fixes, mobile layout improvements, search/filter functionality
Changed
- Comprehensive dependency updates across workspace crates
Fixed
- [DevX] CRUD flow params file integration (#79): Fixed
--params-filenot being applied in CRUD flow mode- Body configurations from params file are now correctly applied to POST/PUT/PATCH operations in
--crud-flowmode - Fixed body serialization issue that caused “ReferenceError: object is not defined” error in generated k6 scripts
- Body is now properly serialized as a JSON string for the Handlebars template
- Body configurations from params file are now correctly applied to POST/PUT/PATCH operations in
- [Core] Race conditions and flaky tests: Resolved timing issues across test suite
- [Core] Panic-prone unwrap calls: Replaced with safe error handling throughout codebase
[0.3.16] - 2025-12-27
Added
- Version bump with dependency updates
Fixed
- [Test] Flaky test fixes: Resolved race conditions and timing issues in integration tests
- [Core] Safe error handling: Replaced panic-prone
.unwrap()calls with proper error handling
[0.3.15] - 2025-12-26
Added
- [DevX] Multi-spec support for bench command: The
mockforge benchcommand now supports loading and merging multiple OpenAPI specifications- Multiple
--specflags:mockforge bench --spec pools.yaml --spec vs.yaml --target https://api.com - Directory discovery with
--spec-dir:mockforge bench --spec-dir ./specs/ --target https://api.com - Conflict resolution strategies with
--merge-conflicts:error(default),first,last - Spec mode selection with
--spec-mode:merge(default) combines all specs,sequentialruns specs in dependency order - Sequential execution mode with per-spec output directories and results
- Leverages existing multi-spec infrastructure from mockforge-core
- Multiple
- [DevX] Cross-spec dependency detection: New
spec_dependenciesmodule for handling dependencies between specs- Automatic detection of dependencies from field naming patterns (
pool_ref,pool_id,poolId, etc.) - Schema registry for cross-referencing schemas across multiple specs
- Topological sorting for correct execution order
- Manual dependency configuration via
--dependency-config(YAML/JSON) - Support for value extraction and injection between spec groups
- Automatic detection of dependencies from field naming patterns (
Changed
BenchCommand.specfield changed fromPathBuftoVec<PathBuf>to support multiple specsSpecParsernow includesfrom_spec()method for pre-loaded OpenAPI specs- Added
dependency_configfield toBenchCommandfor cross-spec value passing configuration
Fixed
- Nothing yet.
[0.3.14] - 2025-12-26
Added
- Version bump to 0.3.14
Changed
- Nothing yet.
Fixed
- Nothing yet.
[0.3.13] - 2025-12-24
Fixed
- [DevX] k6 CRUD flow metric name sanitization (#79 follow-up): Fixed invalid k6 metric names in CRUD flow scripts when flow names contain dots or special characters
- CRUD flow names are now sanitized for use as k6 metric names (e.g.,
plans.list→plans_list) - Original flow names preserved in comments and group names for readability
- Made
sanitize_js_identifierfunction public for reuse across k6 generators - Added script validation to CRUD flow generation for defense in depth
- CRUD flow names are now sanitized for use as k6 metric names (e.g.,
[0.3.12] - 2025-12-23
Changed
- [DevX] Dependency updates: Version alignment and dependency updates across all workspace crates
[0.3.11] - 2025-12-19
Added
-
[DevX] Custom benchmark parameters: Added
--params-fileoption tomockforge benchcommand for loading custom parameter values from a fileWhy it matters: Allows users to define reusable parameter configurations for benchmark runs, making it easier to test different scenarios without modifying command-line arguments each time.
[0.3.10] - 2025-12-18
Fixed
- [DevX] k6 benchmark script generation fixes: Resolved multiple issues with generated k6 scripts
- Fixed
--insecureflag handling by movinginsecureSkipTLSVerifyto global k6 options - Fixed
textSummaryimport and usage in generated scripts - Fixed query parameter encoding in benchmark requests
- Fixed
[0.3.9] - 2025-12-17
Added
-
[Reality] Comprehensive Mock Server Implementation: Full implementation across all protocol crates
- mockforge-amqp: Complete AMQP 0-9-1 broker with exchanges, queues, bindings, messages, protocol handling, fixtures, and spec registry
- mockforge-kafka: Full Kafka broker with consumer groups, partitions, topics, metrics, and protocol handling
- mockforge-mqtt: Complete MQTT broker with QoS levels, topic subscriptions, and retained messages
- mockforge-ftp: Virtual filesystem, spec registry, and fixture support
- mockforge-smtp: Email server with fixtures and spec registry
- mockforge-tcp: TCP server with fixtures and protocol support
- mockforge-grpc: Dynamic proto parser, service generator, reflection, and metrics
- mockforge-graphql: Full handler implementations
-
[DevX] Enhanced CLI Commands: New commands for all protocols and features
- AMQP, Kafka, MQTT, FTP, SMTP protocol commands
- Blueprint, cloud, deploy, dev-setup, governance commands
- Logs, progress, recorder, scenario, snapshot commands
- Time manipulation, VBR, voice, wizard, and workspace commands
- AI-powered mock generation commands
-
[Reality] Virtual Backend Repository (VBR): Complete data management system
- API generator, entity management, constraints, and validation
- Database integration with migrations and schema management
- Session handling, snapshots, and mutation rules
- ID generation strategies and scheduling
-
[Reality] World State Engine: Coherent world simulation
- State engine with model and query support
- Entity relationships and lifecycle management
-
[AI] Enhanced AI Capabilities: AI-powered mock generation
- RAG-based AI response generator
- AI event generator for WebSocket scenarios
- Behavioral cloning with scenario types
-
[Cloud] Collaboration Features: Team collaboration support
- Backup, merge, and promotion workflows
- Multi-environment configuration
- Client SDK improvements
-
[DevX] Observability & Analytics: Enhanced monitoring
- Pillar usage tracking and analytics queries
- Metrics middleware and coverage tracking
- Latency metrics and performance monitoring
-
[Contracts] Chaos Engineering: Resilience testing capabilities
- Failure designer and incident replay
- Chaos API with configurable fault injection
- Route-level chaos with latency distributions
-
[DevX] Plugin System Enhancements: Extended plugin capabilities
- Backend generator and datasource support
- Runtime adapter improvements
- SDK builders and testing utilities
-
[Cloud] Registry Server: Complete registry implementation
- Authentication, authorization, and RBAC
- Redis caching, email notifications
- Organization and subscription models
- API token management and audit logging
-
[DevX] UI Server: Dashboard and admin features
- Admin handlers for workspace management
- Chain visualization and coverage metrics
- Failure analysis and promotion workflows
- Graph visualization and health monitoring
[0.3.8] - 2025-01-27
Fixed
-
[DevX] Compilation errors resolved: Fixed all compilation errors across the workspace
- Updated
axum-serverfrom 0.6 to 0.8 withtls-rustls-no-providerfeature - Updated
rustlsfrom 0.21 to 0.23,rustls-pemfilefrom 1.0 to 2.0,tokio-rustlsfrom 0.24 to 0.26 - Adapted TLS code to rustls 0.23 API (CertificateDer, PrivateKeyDer, WebPkiClientVerifier)
- Fixed multi_spec module: properly exported and resolved compilation errors
- Fixed handle_serve function calls: added missing parameters and fixed type mismatches
- Fixed borrow checker issues in multi_spec merging logic
- Added missing documentation for enum variants and struct fields
- Fixed various type mismatches and iteration patterns
- Updated
-
[DevX] Cargo publish readiness: Fixed all dependency version requirements for crates.io publishing
- Added version requirements to all path dependencies in mockforge-cli, mockforge-chaos, mockforge-http, mockforge-route-chaos, mockforge-vbr
- Set
publish = falsefor desktop-app and tests packages (not meant for crates.io) - All crates now pass
cargo publish --dry-runvalidation
[0.3.6] - 2025-11-25
Fixed
-
[DevX] k6 script generation with operation IDs containing dots/hyphens (#79)
- Fixed “Unexpected token .” error when OpenAPI operation IDs contain dots (e.g.,
plans.create) or hyphens (e.g.,plans.update-pricing-schemes) - Changed
is_alphanumeric()tois_ascii_alphanumeric()in JavaScript identifier sanitization to ensure ASCII-only identifiers - All operations are now properly included in generated k6 scripts with valid JavaScript identifiers
- Added comprehensive tests including integration test with full billing subscriptions spec
- Fixed “Unexpected token .” error when OpenAPI operation IDs contain dots (e.g.,
-
[DevX] UI icon embedding for published crates
- Fixed build failures when installing
mockforge-clifrom crates.io due to missing icon files - Updated
build.rsto read icon files at build time and embed them as byte array literals - Replaced
include_bytes!withCARGO_MANIFEST_DIRapproach that failed in published crates - Icons are now properly embedded and work both in development and when installing from crates.io
- Fixed build failures when installing
[0.3.0] - 2025-11-17
Added
-
[DevX] Pillars & Tagged Changelog: Complete pillar system implementation with documentation and tooling
- Defined five foundational pillars: [Reality], [Contracts], [DevX], [Cloud], [AI]
- Added comprehensive PILLARS.md documentation with feature mappings
- Implemented CI validation for pillar tags in changelog entries
- Added pillar tagging instructions to release tooling
- Updated README and getting-started guide with pillars section
Why it matters: Clear product story spine that makes it obvious what each release invests in. Pillar tags help users understand product direction and find features relevant to their needs.
-
[Reality] Smart Personas & Reality Continuum v2: Complete persona graph and lifecycle system
- Persona graphs with relationship linking across entities
- Lifecycle states (NewSignup, Active, PowerUser, ChurnRisk, Churned, etc.)
- Reality Continuum integration with field-level and entity-level mixing
- Fidelity score calculation and API endpoint
- Comprehensive PERSONAS.md documentation
Why it matters: Upgrade from “random-but-consistent fake data” to “coherent world simulation.” Personas maintain relationships across endpoints, and fidelity scores quantify how real your mock environment is.
-
[Contracts] Drift Budget & GitOps for API Sync: Complete drift management system
- Hierarchical drift budget configuration (global, workspace, service, endpoint)
- Breaking change detection and classification
- Incident management with webhook integration
- GitOps PR generation for contract updates
- Comprehensive DRIFT_BUDGETS.md documentation
Why it matters: Make MockForge the “drift nerve center” for contracts. Define acceptable drift, get alerts when budgets are exceeded, and automatically generate PRs to update contracts and fixtures.
-
[Reality] Behavioral Cloning v1: Multi-step flow recording and replay
- Flow recording with request/response capture and timing
- Flow viewer with timeline visualization
- Scenario replay engine with strict/flex modes
- Scenario storage and export/import (YAML/JSON)
- Comprehensive BEHAVIORAL_CLONING.md documentation
Why it matters: Move from endpoint-level mocks to journey-level simulations. Record realistic flows from real systems and replay them as named scenarios for comprehensive testing.
-
[AI][DevX] LLM/Voice Interface for Workspace Creation: Natural language to complete workspace
- Natural language workspace creation from descriptions
- Automatic persona and relationship generation
- Behavioral scenario generation (happy path, failure, slow path)
- Reality continuum and drift budget configuration from NL
- Voice and text input support
- Comprehensive LLM Studio documentation
Why it matters: The golden path: “Describe the system in natural language → MockForge builds a realistic mock backend with personas, behaviors, and reality level config.” No manual configuration required.
-
[DevX] Comprehensive Integration Test Coverage: Complete test suite for all 0.3.0 features
- Smart Personas v2 integration tests (15 tests covering persona graphs, lifecycle states, fidelity scores)
- Drift Budget integration tests (14 tests covering budget hierarchy, breaking change detection, incident management)
- Drift GitOps integration tests (16 tests covering PR generation, OpenAPI/fixture updates, GitOps configuration)
- Behavioral Cloning integration tests (15 tests covering flow recording, scenario replay, strict/flex modes)
- Voice/LLM Workspace Creation integration tests (16 tests covering command parsing, workspace building, NL to workspace flow)
- All tests passing with 100% success rate (76 total integration tests)
Why it matters: Production-ready features require production-ready tests. Comprehensive integration test coverage ensures reliability, prevents regressions, and provides confidence for users adopting these features.
Changed
- Changelog entries now require pillar tags for all major features
- Release process includes automated pillar tag validation
- Documentation structure updated to highlight pillars
Fixed
- Nothing yet.
Security
- Nothing yet.
[0.2.9] - 2025-11-14
Added
-
[Cloud] Registry server improvements with password reset functionality
Why it matters: Enable seamless team collaboration with secure registry access—teams can share and discover mock scenarios without friction, and password reset keeps workflows moving when credentials are lost.
-
[Cloud] Enhanced metrics and marketplace features
-
[DevX] Comprehensive E2E test suite
-
[DevX] Custom routes implementation
-
[Reality] Template expansion improvements
-
[Reality] Latency injection enhancements
-
[Reality] Smart Personas with array generation and relationship inference
Why it matters: Generate realistic, interconnected mock data automatically—arrays that make sense, relationships that stay consistent across endpoints, and personas that feel like real users without manual configuration.
-
[DevX] Complete Java and .NET SDK implementations with builder patterns
Why it matters: Bring MockForge to enterprise teams using Java and .NET—no more language barriers, no more custom integration work. Your entire stack can use the same mock infrastructure.
-
[Cloud] Cloud monetization infrastructure and features
Why it matters: Enable sustainable platform growth with flexible pricing models—teams can scale from free tier to enterprise without friction, and the platform can grow while serving developers.
-
[Cloud] Organization management endpoints
Why it matters: Scale from solo developer to enterprise team—manage users, permissions, and resources at the org level, not just individual accounts. Real teams need real organization tools.
-
[Cloud] Security controls implementation (Phase 3)
Why it matters: Protect production deployments with enterprise-grade security—fine-grained access controls, audit trails, and compliance features that let you trust MockForge with sensitive data and critical workflows.
Changed
- [DevX] Upgraded wasmtime to 36.0.3 to fix RUSTSEC-2025-0118
- [DevX] Fixed Axum 0.8 route syntax compatibility across multiple modules
- [DevX] Updated all test files for new function signatures
Fixed
- [DevX] Fixed compilation errors across workspace
- [DevX] Fixed Axum 0.8 route syntax in state_machine_api.rs
- [DevX] Fixed file server route syntax for Axum 0.8 compatibility
- [DevX] Resolved all compilation errors for comprehensive test coverage
Security
- [DevX] Upgraded wasmtime to 36.0.3 to address RUSTSEC-2025-0118
- [Cloud] Completed Phase 3 security controls implementation
[0.2.8] - 2025-11-10
Added
-
[Reality] Generative Schema Mode: Complete implementation of generative schema mode for dynamic mock data generation
Why it matters: Spin up a believable API even when the backend doesn’t exist yet—no sample DB or seed data required.
-
[Reality] Smart Personas: Feature for consistent cross-endpoint data generation using persona-based templates
-
[Reality] Reality Continuum: Feature for blending mock and real data sources with configurable reality levels
Why it matters: Turn the dial between deterministic mock and noisy production-like chaos without changing your client code.
-
[Reality] Reality Slider: Hot-reload support for reality level adjustments
Why it matters: Adjust reality levels on the fly during development and testing without restarting the server.
-
[Reality] Chaos Lab: Interactive network condition simulation tool
Why it matters: Test how your application handles real-world network conditions like latency spikes, packet loss, and connection failures.
-
[Contracts] AI Contract Diff: Feature for comparing and diffing API contracts
Why it matters: Automatically detect and visualize API contract changes to catch breaking changes before they reach production.
-
[DevX] Voice + LLM Interface: Voice interface implementation with Speech-to-Text (STT) backend support
-
[Reality] Deceptive Deploy: Complete deceptive deploy feature for advanced testing scenarios
-
[DevX] GraphQL + REST Playground: Interactive playground with workspace filtering capabilities
-
[DevX] ForgeConnect SDK: Complete SDK implementation with full feature set
-
[Cloud] Enhanced Scenario Marketplace: Improved scenario marketplace with additional features
-
[DevX] WireMock-Inspired Features: Browser proxy mode, git sync, data sources, template library, managed hosting documentation, and user management
-
[DevX] Ecosystem Documentation: Comprehensive ecosystem and use cases documentation
-
[DevX] Configuration Extensibility: Complete configuration and extensibility implementation
-
[Reality] Advanced Behavior Simulation: Enhanced behavior and simulation features
Changed
- [DevX] SQLx Integration: Configured SQLx and integrated mockforge-collab with mockforge-core
- [Reality] Latency Recording: Completed latency recording integration with WorkspaceConfig reality_level field support
Fixed
- [DevX] Fixed test compilation errors in reality integration and hot-reload tests
- [DevX] Fixed test compilation errors in openapi_generator_tests
- [Contracts][DevX] Fixed all compilation errors for AI Contract Diff feature
- [DevX] Applied rustfmt formatting to Chaos Lab code
Security
- Nothing yet.
[0.2.7] - 2025-11-05
Added
-
[Contracts] Automatic API Sync & Change Detection: Implemented periodic polling and automatic sync for detecting upstream API changes
Why it matters: Keep your mocks in sync with real APIs automatically—catch breaking changes before they break your tests.
- Periodic sync service with configurable intervals (default: 1 hour)
- Automatic change detection using deep response comparison (status, headers, body)
- Optional automatic fixture updates when changes detected
- Manual sync trigger via API (
POST /api/recorder/sync/now) - Sync status tracking and change history
- Configurable sync settings: upstream URL, interval, headers, timeout, max requests
- Support for GET-only or all-methods sync
- Detailed change reports with before/after comparisons
- Database update method for refreshing recorded responses
- API endpoints:
/api/recorder/sync/status,/api/recorder/sync/config,/api/recorder/sync/changes
-
[Reality] TCP Protocol Support: Added raw TCP server mocking support via new
mockforge-tcpcrateWhy it matters: Mock any protocol that runs over TCP—not just HTTP. Perfect for testing database clients, custom protocols, and legacy systems.
- Raw TCP connection handling with fixture-based matching
- Echo mode for testing TCP clients
- TLS/SSL support for encrypted connections
- Delimiter-based message framing (optional)
- Configurable buffer sizes and connection limits
- CLI flag
--tcp-portfor custom TCP server port - Configuration via
config.tcpin YAML/JSON config files
-
[Reality] Response Selection Modes: Added support for sequential (round-robin) and random response selection when multiple examples are available
- Sequential mode: Cycles through available examples in order (round-robin)
- Random mode: Randomly selects from available examples
- Weighted random mode: Random selection with custom weights per example
- Configuration via
x-mockforge-response-selectionOpenAPI extension - Environment variable support:
MOCKFORGE_RESPONSE_SELECTION_MODE(global) andMOCKFORGE_RESPONSE_SELECTION_<OPERATION_ID>(per-operation) - State tracking for sequential mode ensures round-robin behavior across requests
-
[Reality] Webhook HTTP Execution: Implemented actual HTTP request execution in chaos orchestration hooks
HookAction::HttpRequestnow executes real outbound HTTP requests (previously only logged)- Supports GET, POST, PUT, DELETE, PATCH methods
- Configurable request body and headers
- Error handling and logging for webhook failures
- Fire-and-forget execution (failures don’t block orchestration)
-
[DevX] CRUD & Webhook Documentation: Added comprehensive documentation guides
docs/CRUD_SIMULATION.md: Complete guide for simulating CRUD operations with stateful data storedocs/WEBHOOKS_CALLBACKS.md: Full documentation of webhook capabilities via hooks, chains, and scripts- Examples demonstrating realistic workflows and integrations
Changed
- Nothing yet.
Deprecated
- Nothing yet.
Removed
- Nothing yet.
Fixed
- Nothing yet.
Security
- Nothing yet.
[0.2.6] - 2025-11-04
Added
-
[DevX] TLS/HTTPS and mTLS Support: Added TLS/HTTPS and mutual TLS (mTLS) support for HTTP server
- Configurable TLS certificate and key paths
- Client certificate authentication support
- Secure connection handling for production deployments
-
[DevX] Built-in Tunneling Service: Added built-in tunneling service for exposing local servers via public URLs
- Automatic tunnel creation for local development
- Public URL generation for testing and demos
- Integration with popular tunneling services
-
[DevX] SDK Implementation: Completed Phase 1 & 2 of SDK implementation
- Comprehensive documentation and examples
- Production-ready client generators
Changed
-
[DevX] Version Bumps: Updated all workspace crates from 0.2.5 to 0.2.6
- Updated all dependency versions across the workspace
- Fixed version mismatches in mockforge-ui and mockforge-plugin-loader
-
[DevX] Publishing Improvements: Enhanced crate publishing process
- Added mockforge-tcp and mockforge-test to publish script
- Enabled publishing for mockforge-test crate
- Fixed mockforge-tcp to remove README requirement
Fixed
-
[DevX] Documentation: Fixed missing module-level documentation in test files
- Added comprehensive module documentation to all test modules
- Improved code documentation consistency
-
[DevX] Axum Compatibility: Fixed Axum 0.8 compatibility issues in proxy server module
- Updated proxy server to work with latest Axum version
- Resolved breaking changes from Axum upgrade
-
[Reality] MQTT Error Types: Fixed MQTT publish handlers error types to be Send + Sync
- Updated error types for proper async/await compatibility
- Ensured thread-safety in MQTT handlers
[0.2.5] - 2025-01-27
Added
-
[DevX] OAuth2 Flow Support: Complete OAuth2 implementation with all standard flows
- Authorization Code flow with PKCE (RFC 7636 compliant, SHA256 hash)
- Client Credentials flow for server-side applications
- Password flow for trusted clients
- Implicit flow support
- Automatic token refresh and expiration management
- State parameter for CSRF protection
- PKCE code verifier/challenge generation helpers
- Token storage with expiration tracking (localStorage)
-
[DevX] Enterprise Error Handling: Structured error handling for generated clients
ApiErrorclass with status codes, statusText, and error bodyRequiredErrorclass for missing required fields- Helper methods:
isClientError(),isServerError(),getErrorDetails(),getVerboseMessage() - Optional verbose error messages with detailed validation information
-
[Contracts] Request/Response Validation: Built-in validation support
- Required field validation before sending requests
- Basic response structure validation (type checking, object validation)
- Configurable via
validateRequestsflag - Detailed validation error messages
-
[DevX] Request/Response Interceptors: Custom request/response/error transformation
- Request interceptor: Modify requests before sending
- Response interceptor: Transform responses after receiving
- Error interceptor: Global error handling
- Support for async interceptors
-
[DevX] Enhanced Authentication: Multiple authentication methods
- Bearer token (static or dynamic function)
- API key authentication (static or dynamic)
- Basic authentication (username/password)
- OAuth2 (all flows, takes priority over other methods)
-
[DevX] PKCE Helper Functions: Exported utilities for PKCE implementation
generatePKCECodeVerifier(): Generate cryptographically random code verifiergeneratePKCECodeChallenge(): Generate SHA256 code challenge from verifier
-
[DevX] Security Best Practices: Comprehensive security warnings and guidance
- Client secret warnings for browser-based applications
- XSS vulnerability warnings for localStorage token storage
- CSRF protection via state parameter validation
- Token expiration checking
- Security documentation in generated README
-
[DevX] Request Timeout Handling: Configurable request timeouts
- Default 30-second timeout (configurable)
- AbortController-based timeout implementation
- Proper timeout error handling
-
[DevX] React Query Integration Documentation: Comprehensive examples for @tanstack/react-query integration
Changed
-
[DevX] React Client Generator: Major enhancements to generated React client code
- Replaced placeholder PKCE implementation with full SHA256-based solution
- Implemented proper response validation (previously placeholder)
- Enhanced README with comprehensive feature documentation
- Improved error messages and validation details
- Better security documentation and best practices
-
[DevX] Operation ID Sanitization: Improved identifier generation
- Enhanced
sanitize_identifierfunction to handle complex operation IDs - Better handling of parentheses, slashes, hyphens in operation IDs
- Proper camelCase conversion with word boundary detection
- Enhanced
Fixed
-
[DevX] TypeScript Empty Object Types: Fixed formatting issue where empty object schemas generated invalid TypeScript
- Empty objects now correctly generate as
[key: string]: any;instead of malformedRecord<string, any>}
- Empty objects now correctly generate as
-
[DevX] DELETE Operations with Query Params: Fixed missing query parameter support in DELETE operations
-
[DevX] Duplicate Operation IDs: Fixed duplicate operation ID handling by appending numeric suffixes
-
[DevX] PKCE Code Challenge: Fixed PKCE implementation to use proper SHA256 hash instead of plain encoding
-
[Contracts][DevX] Response Validation: Replaced placeholder with actual implementation (type checking, structure validation)
Security
- [DevX] Added comprehensive security warnings for OAuth2 client secrets in browser code
- [DevX] Added XSS vulnerability warnings for localStorage token storage
- [DevX] Implemented CSRF protection via state parameter validation
- [DevX] Added token expiration checking to prevent use of expired tokens
- [DevX] Documented security best practices in generated client README
[0.2.4] - 2025-01-27
Fixed
- [DevX] Fix request body parameter generation in React/Vue/Svelte client generators - request bodies now correctly generate
dataparameter andbody: JSON.stringify(data)in API client methods - [DevX] Fix required vs optional field handling in generated TypeScript interfaces - required fields no longer incorrectly marked with optional marker (
?) - [DevX] Fix OpenAPI serde deserialization by adding
#[serde(rename)]attributes foroperationIdandrequestBodyfields - [DevX] Apply required fields processing consistently across all client generators (React, Vue, Svelte)
Added
- [DevX] Comprehensive test coverage for request body parameter scenarios (POST, PUT, PATCH, DELETE)
- [DevX] Test cases for
$refschemas in request bodies - [DevX] Test cases for YAML spec support verification
[0.2.3] - 2025-01-27
Fixed
- [DevX] Fix OpenAPI example extraction to prioritize explicit examples from schema and properties
- [DevX] Fix request body parameter generation in React client generator for POST, PUT, PATCH, DELETE methods
- [DevX] Fix Handlebars template logic for request body type generation in client code
- [DevX] Fix useCallback dependency array formatting in React hooks template
- [DevX] Add comprehensive test coverage for request body parameter scenarios
[0.2.0] - 2025-10-29
Added
- [DevX] Output control features for MockForge generator with comprehensive configuration options
- [DevX] Unified spec parser with enhanced validation and error reporting
- [DevX] Multi-framework client generation with Angular and Svelte support
- [Reality] Enhanced mock data generation with OpenAPI support
- [DevX] Configuration file support for mock generation
- [DevX] Browser mobile proxy mode implementation
- [DevX] Comprehensive documentation and example workflows
Changed
- [DevX] Enhanced CLI with progress indicators, error handling, and code quality improvements
- [DevX] Comprehensive plugin architecture documentation
Fixed
- [DevX] Remove tests that access private fields in mock data tests
- [DevX] Fix compilation issues in mockforge-collab and mockforge-ui
- [DevX] Update mockforge-plugin-core version to 0.1.6 in plugin-sdk
- [DevX] Enable SQLx offline mode for mockforge-collab publishing
- [DevX] Add description field to mockforge-analytics
- [DevX] Add version requirements to all mockforge path dependencies
- [DevX] Fix publish order dependencies (mockforge-chaos before mockforge-reporting)
- [DevX] Update Cargo.lock and format client generator tests
[0.1.3] - 2025-10-22
Changes
- [DevX] docs: prepare release 0.1.3
- [DevX] docs: update CHANGELOG for 0.1.3 release
- [DevX] docs: add roadmap completion summary
- [DevX] feat: add Kubernetes-style health endpoint aliases and dashboard shortcut
- [DevX] feat: add unified config & profiles with multi-format support
- [Reality] feat: add capture scrubbing and deterministic replay
- [DevX] feat: add native GraphQL operation handlers with advanced features
- [Reality] feat: add programmable WebSocket handlers
- [Reality] feat: add HTTP scenario switching for OpenAPI response examples
- [DevX] feat: add mockforge-test crate and integration testing examples
- [DevX] build: enable publishing for mockforge-ui and mockforge-cli
- [DevX] build: extend publish script for internal crates
- [DevX] build: parameterize publish script with workspace version
[0.1.2] - 2025-10-17
Changes
- [DevX] build: make version update tolerant
- [DevX] build: manage version references via wrapper
- [DevX] build: mark example crates as non-publishable
- [DevX] build: drop publish-order for cargo-release 0.25
- [DevX] build: centralize release metadata in release.toml
- [DevX] build: remove per-crate release metadata
- [DevX] build: fix release metadata field name
- [DevX] build: move workspace release metadata into Cargo.toml
- [DevX] build: require execute flag for release wrapper
- [DevX] build: automate changelog generation during release
- [DevX] build: add release wrapper with changelog guard
- [DevX] build: align release tooling with cargo-release 0.25
[0.1.1] - 2025-10-17
Added
- [Contracts] OpenAPI request validation (path/query/header/cookie/body) with deep $ref resolution and composite schemas (oneOf/anyOf/allOf).
- [Contracts] Validation modes:
disabled,warn,enforce, with aggregate error reporting and detailed error objects. - [DevX] Runtime Admin UI panel to view/toggle validation mode and per-route overrides; Admin API endpoint
/__mockforge/validation. - [DevX] CLI flags and config options to control validation (including
skip_admin_validationand per-routevalidation_overrides). - [DevX] New e2e tests for 2xx/422 request validation and response example expansion across HTTP routes.
- [DevX] Templating reference docs and examples; WS templating tests and demo update.
- [Reality] Initial release of MockForge - Multi-protocol mocking framework
- [Reality] HTTP API mocking with OpenAPI support
- [Reality] gRPC service mocking with Protocol Buffers
- [Reality] WebSocket connection mocking with replay functionality
- [DevX] CLI tool for easy local development
- [DevX] Admin UI for managing mock servers
- [DevX] Comprehensive documentation with mdBook
- [DevX] GitHub Actions CI/CD pipeline
- [DevX] Security audit integration
- [DevX] Pre-commit hooks for code quality
Changed
- [Contracts] HTTP handlers now perform request validation before routing; invalid requests return 400 with structured details (when
enforce). - [Contracts] Bump
jsonschemato 0.33 and adapt validator API; enable draft selection and format checks internally. - [Contracts] Improve route registry and OpenAPI parameter parsing, including styles/explode and array coercion for query/header/cookie parameters.
Deprecated
- N/A
Removed
- N/A
Fixed
- [DevX] Resolve admin mount prefix from config and exclude admin routes from validation when configured.
- [Contracts] Various small correctness fixes in OpenAPI schema mapping and parameter handling; clearer error messages.
Security
- N/A
Release Process
This project uses cargo-release for automated releases.
Creating a Release
-
Patch Release (bug fixes):
make release-patch -
Minor Release (new features):
make release-minor -
Major Release (breaking changes):
make release-major
Manual Release Process
If you need to do a manual release:
- Update version in
Cargo.tomlfiles - Update
CHANGELOG.mdwith release notes - Commit changes:
git commit -m "chore: release vX.Y.Z" - Tag:
git tag vX.Y.Z - Push:
git push && git push --tags - Publish to crates.io:
cargo publish
Pre-release Checklist
-
All tests pass (
make test) -
Code formatted (
make fmt) -
Lints pass (
make clippy) -
Security audit passes (
make audit) - Documentation updated
- Changelog updated
-
Version bumped in all
Cargo.tomlfiles - Breaking changes documented (if any)
- CI passes on all branches