Update Note 1:vmsingle, vmstorage, vmselect and vminsert in VictoriaMetrics cluster, and vmagent: builds without CGO (pure Go) may fail to read valid data blocks with the window size exceeded error. This can break queries, background merges and native import, and can make vmsingle and vmstorage crash. Affected official builds: darwin, windows, freebsd, openbsd, linux/arm, linux/ppc64le, linux/386, linux/s390x, and -pure builds. The linux/amd64 and linux/arm64 builds use CGO and are not affected. Users of affected builds should not upgrade to this release, or should roll back to v1.152.0. See #11683.
SECURITY: vminsert, vmagent and vmsingle: properly apply memory limits to the zstd encoded blocks ingested via native import. This prevents excessive memory allocation during ingestion when handling maliciously crafted requests. See GHSA-8g4f-32hw-vqf8.
FEATURE: vmalert: skip a redundant pending state when an alert can be restored directly to firing after restart. See #11401.
FEATURE: vmauth: log informative message when a JWT token has no vm_access claim and default_vm_access_claim is not configured, if -logInvalidAuthTokens is enabled. See JWT claim-based request templating or #11579.
FEATURE: dashboards/vmauth: update the dashboard to upstream Grafana version, fix typos and inconsistencies, improve resource usage panels. See #11587
FEATURE: vmauth: support printing HTTP headers in the Access Logs. Only headers listed in access_log.headers list will be printed in the logs. This feature should help troubleshooting pipelines that rely on HTTP headers. See #11598.
FEATURE: vmui: move auto-refresh controls from the header to the Execute button dropdown and display the selected interval in the button text. See #11343.
FEATURE: vmstorage in VictoriaMetrics cluster: support ingesting data directly via Prometheus Remote Write v1 protocol for vmstorage. This feature can be enabled by setting -enableIngestionAPI command-line flag and is disabled by default. See remote write directly to vmstorage and #11252.
FEATURE: vmauth: add Single sign-on (SSO) support via OpenID Connect (OIDC). vmauth redirects unauthenticated browser requests to the configured Identity Provider (IdP), verifies the IdP response, and sets a session cookie for subsequent requests. See #10278.
BUGFIX: all VictoriaMetrics components: create the Unix domain socket for -httpListenAddr=unix:/path/to/socket with permissions according to the umask of the process. Previously it was always created with 0600 permissions, so processes running under other users, such as a reverse proxy, couldn't connect to it. See these docs and #11615.
BUGFIX: stream aggregation: serially push samples to stream aggregation jobs. This helps reduce CPU overhead. 11f488d8ff introduced parallel processing for this stage, which introduced extra CPU overhead while only providing negligible sample lag reduction. See #9878.
BUGFIX: vmagent: add missing X-Influxdb-Version HTTP header to influxdb API responses. See #11570.
BUGFIX: vmagent: disable metrics metadata sending for MDX remote write destinations. See #11572.
BUGFIX: vmagent and vmsingle: properly discover *_sd_config targets. Previously scrape targets were preserved until the process restart if *_sd_config returned an empty targets response. See #11550 for details. Thanks to @evkuzin for contribution.
BUGFIX: vmalert: properly reload alert_relabel_configs from the notifier configuration file. Previously, this config was applied only at startup and was not updated on config reload. See #11635.
BUGFIX: vmselect, vminsert, vmagent and vmsingle: ignore empty extra_label, extra_filters and extra_filters[] query args instead of returning an error. This allows dropping client-provided values for these query args via url_prefix in vmauth as described in the security docs. See #11618.
BUGFIX: vmauth: respect the -enableTCP6 flag when discovering backend IPs via discover_backend_ips or -discoverBackendIPs. Previously, discovery included IPv6 addresses even when IPv6 support was disabled. See #11470.
BUGFIX: vmui: fix synchronization of the custom query step with URL changes on the predefined dashboards page. See #11137.
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [victoriametrics/vmagent](https://github.com/VictoriaMetrics/VictoriaMetrics) | minor | `v1.152.0` → `v1.153.0` |
---
### Release Notes
<details>
<summary>VictoriaMetrics/VictoriaMetrics (victoriametrics/vmagent)</summary>
### [`v1.153.0`](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.153.0)
[Compare Source](https://github.com/VictoriaMetrics/VictoriaMetrics/compare/v1.152.0...v1.153.0)
##### [v1.153.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.153.0)
Released at 2026-09-28
**Update Note 1:** [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/), `vmstorage`, `vmselect` and `vminsert` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/), and [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/): builds without CGO (pure Go) may fail to read valid data blocks with the `window size exceeded` error. This can break queries, background merges and [native import](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#how-to-import-data-in-native-format), and can make `vmsingle` and `vmstorage` crash. Affected official builds: `darwin`, `windows`, `freebsd`, `openbsd`, `linux/arm`, `linux/ppc64le`, `linux/386`, `linux/s390x`, and `-pure` builds. The `linux/amd64` and `linux/arm64` builds use CGO and are not affected. Users of affected builds should not upgrade to this release, or should roll back to [v1.152.0](https://docs.victoriametrics.com/victoriametrics/changelog/#v11520). See [#​11683](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11683).
- SECURITY: `vminsert`, [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/) and [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/): properly apply memory limits to the `zstd` encoded blocks ingested via [native import](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#how-to-import-data-in-native-format). This prevents excessive memory allocation during ingestion when handling maliciously crafted requests. See [GHSA-8g4f-32hw-vqf8](https://github.com/VictoriaMetrics/VictoriaMetrics/security/advisories/GHSA-8g4f-32hw-vqf8).
- SECURITY: [vmauth](https://docs.victoriametrics.com/victoriametrics/vmauth/): restrict redirects in the [OIDC Discovery](https://docs.victoriametrics.com/victoriametrics/vmauth/#oidc-discovery) HTTP client to stay within the original request host. See [GHSA-xxqh-2hcc-9fp6](https://github.com/VictoriaMetrics/VictoriaMetrics/security/advisories/GHSA-xxqh-2hcc-9fp6).
- SECURITY: upgrade base docker image (Alpine) from 3.24.1 to 3.24.2. See [Alpine 3.24.2 release notes](https://www.alpinelinux.org/posts/Alpine-3.24.2-released.html).
- FEATURE: [vmalert](https://docs.victoriametrics.com/victoriametrics/vmalert/): skip a redundant pending state when an alert can be [restored](https://docs.victoriametrics.com/victoriametrics/vmalert/#alerts-state-on-restarts) directly to firing after restart. See [#​11401](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11401).
- FEATURE: [vmauth](https://docs.victoriametrics.com/victoriametrics/vmauth/): log informative message when a JWT token has no `vm_access` claim and `default_vm_access_claim` is not configured, if `-logInvalidAuthTokens` is enabled. See [JWT claim-based request templating](https://docs.victoriametrics.com/victoriametrics/vmauth/#jwt-claim-based-request-templating) or [#​11579](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11579).
- FEATURE: [dashboards/vmauth](https://github.com/VictoriaMetrics/VictoriaMetrics/tree/master/dashboards/vmauth.json): update the dashboard to upstream Grafana version, fix typos and inconsistencies, improve resource usage panels. See [#​11587](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11587)
- FEATURE: [vmauth](https://docs.victoriametrics.com/victoriametrics/vmauth/): support printing HTTP headers in the [Access Logs](https://docs.victoriametrics.com/victoriametrics/vmauth/#access-log). Only headers listed in `access_log.headers` list will be printed in the logs. This feature should help troubleshooting pipelines that rely on HTTP headers. See [#​11598](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11598).
- FEATURE: [vmui](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#vmui): move auto-refresh controls from the header to the `Execute` button dropdown and display the selected interval in the button text. See [#​11343](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11343).
- FEATURE: `vmstorage` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): support ingesting data directly via Prometheus Remote Write v1 protocol for `vmstorage`. This feature can be enabled by setting `-enableIngestionAPI` command-line flag and is disabled by default. See [remote write directly to vmstorage](https://docs.victoriametrics.com/victoriametrics/data-ingestion/vmagent/#remote-write-directly-to-vmstorage) and [#​11252](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11252).
- FEATURE: [vmauth](https://docs.victoriametrics.com/victoriametrics/vmauth/): add [Single sign-on (SSO)](https://docs.victoriametrics.com/victoriametrics/vmauth/#single-sign-on-sso) support via OpenID Connect (OIDC). vmauth redirects unauthenticated browser requests to the configured Identity Provider (IdP), verifies the IdP response, and sets a session cookie for subsequent requests. See [#​10278](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/10278).
- FEATURE: [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/) and `vmstorage` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): add support for opt-in [fadvise(FADV_RANDOM)](https://man7.org/linux/man-pages/man2/posix_fadvise.2.html) and [madvise(MADV_RANDOM)](https://man7.org/linux/man-pages/man2/madvise.2.html) hints for data part files, which can reduce disk I/O and improve page cache efficiency. To enable, set `-fs.disableAdviseRandomRead=false`. If you experience issues after enabling this feature, please [leave a comment](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11461) with details. See [#​11461](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11461).
- BUGFIX: all VictoriaMetrics components: create the Unix domain socket for `-httpListenAddr=unix:/path/to/socket` with permissions according to the [umask](https://en.wikipedia.org/wiki/Umask) of the process. Previously it was always created with `0600` permissions, so processes running under other users, such as a reverse proxy, couldn't connect to it. See [these docs](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#security) and [#​11615](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11615).
- BUGFIX: [stream aggregation](https://docs.victoriametrics.com/victoriametrics/stream-aggregation/): serially push samples to [stream aggregation](https://docs.victoriametrics.com/victoriametrics/stream-aggregation/) jobs. This helps reduce CPU overhead. [11f488d8ff](https://github.com/VictoriaMetrics/VictoriaMetrics/commit/11f488d8ff) introduced parallel processing for this stage, which introduced extra CPU overhead while only providing negligible sample lag reduction. See [#​9878](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/9878#issuecomment-5692311649).
- BUGFIX: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/): add missing `X-Influxdb-Version` HTTP header to [influxdb](https://docs.victoriametrics.com/victoriametrics/integrations/influxdb/) API responses. See [#​11570](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11570).
- BUGFIX: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/): disable metrics metadata sending for [MDX](https://docs.victoriametrics.com/victoriametrics/vmagent/#monitoring-data-exchange) remote write destinations. See [#​11572](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11572).
- BUGFIX: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/) and [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/): properly discover `*_sd_config` targets. Previously scrape targets were preserved until the process restart if `*_sd_config` returned an empty targets response. See [#​11550](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11550) for details. Thanks to [@​evkuzin](https://github.com/evkuzin) for contribution.
- BUGFIX: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/): properly reload SSL certificate for [kafka producer and consumer](https://docs.victoriametrics.com/victoriametrics/integrations/kafka/). See [#​11577](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11577).
- BUGFIX: [vmalert](https://docs.victoriametrics.com/victoriametrics/vmalert/): properly reload `alert_relabel_configs` from the [notifier configuration file](https://docs.victoriametrics.com/victoriametrics/vmalert/#notifier-configuration-file). Previously, this config was applied only at startup and was not updated on config reload. See [#​11635](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11635).
- BUGFIX: `vmselect`, `vminsert`, [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/) and [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/): ignore empty `extra_label`, `extra_filters` and `extra_filters[]` query args instead of returning an error. This allows dropping client-provided values for these query args via `url_prefix` in vmauth as described in the [security](https://docs.victoriametrics.com/victoriametrics/vmauth/#security) docs. See [#​11618](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11618).
- BUGFIX: [vmauth](https://docs.victoriametrics.com/victoriametrics/vmauth/): respect the `-enableTCP6` flag when discovering backend IPs via [`discover_backend_ips`](https://docs.victoriametrics.com/victoriametrics/vmauth/#discovering-backend-ips) or `-discoverBackendIPs`. Previously, discovery included IPv6 addresses even when IPv6 support was disabled. See [#​11470](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11470).
- BUGFIX: [vmui](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#vmui): fix synchronization of the custom query step with URL changes on the predefined dashboards page. See [#​11137](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11137#issuecomment-5396835285).
- BUGFIX: [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/) and `vmselect` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): slightly reduce CPU usage during concurrent queries execution. See [#​11569](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11569).
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTcuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEzOC4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v1.152.0→v1.153.0Release Notes
VictoriaMetrics/VictoriaMetrics (victoriametrics/vmagent)
v1.153.0Compare Source
v1.153.0
Released at 2026-09-28
Update Note 1: vmsingle,
vmstorage,vmselectandvminsertin VictoriaMetrics cluster, and vmagent: builds without CGO (pure Go) may fail to read valid data blocks with thewindow size exceedederror. This can break queries, background merges and native import, and can makevmsingleandvmstoragecrash. Affected official builds:darwin,windows,freebsd,openbsd,linux/arm,linux/ppc64le,linux/386,linux/s390x, and-purebuilds. Thelinux/amd64andlinux/arm64builds use CGO and are not affected. Users of affected builds should not upgrade to this release, or should roll back to v1.152.0. See #11683.SECURITY:
vminsert, vmagent and vmsingle: properly apply memory limits to thezstdencoded blocks ingested via native import. This prevents excessive memory allocation during ingestion when handling maliciously crafted requests. See GHSA-8g4f-32hw-vqf8.SECURITY: vmauth: restrict redirects in the OIDC Discovery HTTP client to stay within the original request host. See GHSA-xxqh-2hcc-9fp6.
SECURITY: upgrade base docker image (Alpine) from 3.24.1 to 3.24.2. See Alpine 3.24.2 release notes.
FEATURE: vmalert: skip a redundant pending state when an alert can be restored directly to firing after restart. See #11401.
FEATURE: vmauth: log informative message when a JWT token has no
vm_accessclaim anddefault_vm_access_claimis not configured, if-logInvalidAuthTokensis enabled. See JWT claim-based request templating or #11579.FEATURE: dashboards/vmauth: update the dashboard to upstream Grafana version, fix typos and inconsistencies, improve resource usage panels. See #11587
FEATURE: vmauth: support printing HTTP headers in the Access Logs. Only headers listed in
access_log.headerslist will be printed in the logs. This feature should help troubleshooting pipelines that rely on HTTP headers. See #11598.FEATURE: vmui: move auto-refresh controls from the header to the
Executebutton dropdown and display the selected interval in the button text. See #11343.FEATURE:
vmstoragein VictoriaMetrics cluster: support ingesting data directly via Prometheus Remote Write v1 protocol forvmstorage. This feature can be enabled by setting-enableIngestionAPIcommand-line flag and is disabled by default. See remote write directly to vmstorage and #11252.FEATURE: vmauth: add Single sign-on (SSO) support via OpenID Connect (OIDC). vmauth redirects unauthenticated browser requests to the configured Identity Provider (IdP), verifies the IdP response, and sets a session cookie for subsequent requests. See #10278.
FEATURE: vmsingle and
vmstoragein VictoriaMetrics cluster: add support for opt-in fadvise(FADV_RANDOM) and madvise(MADV_RANDOM) hints for data part files, which can reduce disk I/O and improve page cache efficiency. To enable, set-fs.disableAdviseRandomRead=false. If you experience issues after enabling this feature, please leave a comment with details. See #11461.BUGFIX: all VictoriaMetrics components: create the Unix domain socket for
-httpListenAddr=unix:/path/to/socketwith permissions according to the umask of the process. Previously it was always created with0600permissions, so processes running under other users, such as a reverse proxy, couldn't connect to it. See these docs and #11615.BUGFIX: stream aggregation: serially push samples to stream aggregation jobs. This helps reduce CPU overhead. 11f488d8ff introduced parallel processing for this stage, which introduced extra CPU overhead while only providing negligible sample lag reduction. See #9878.
BUGFIX: vmagent: add missing
X-Influxdb-VersionHTTP header to influxdb API responses. See #11570.BUGFIX: vmagent: disable metrics metadata sending for MDX remote write destinations. See #11572.
BUGFIX: vmagent and vmsingle: properly discover
*_sd_configtargets. Previously scrape targets were preserved until the process restart if*_sd_configreturned an empty targets response. See #11550 for details. Thanks to @evkuzin for contribution.BUGFIX: vmagent: properly reload SSL certificate for kafka producer and consumer. See #11577.
BUGFIX: vmalert: properly reload
alert_relabel_configsfrom the notifier configuration file. Previously, this config was applied only at startup and was not updated on config reload. See #11635.BUGFIX:
vmselect,vminsert, vmagent and vmsingle: ignore emptyextra_label,extra_filtersandextra_filters[]query args instead of returning an error. This allows dropping client-provided values for these query args viaurl_prefixin vmauth as described in the security docs. See #11618.BUGFIX: vmauth: respect the
-enableTCP6flag when discovering backend IPs viadiscover_backend_ipsor-discoverBackendIPs. Previously, discovery included IPv6 addresses even when IPv6 support was disabled. See #11470.BUGFIX: vmui: fix synchronization of the custom query step with URL changes on the predefined dashboards page. See #11137.
BUGFIX: vmsingle and
vmselectin VictoriaMetrics cluster: slightly reduce CPU usage during concurrent queries execution. See #11569.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.