Repository navigation
Releases: projectdiscovery/subfinder
Releases · projectdiscovery/subfinder
Release list
v2.17.0
What's Changed
🎉 New Features
- Added bounded concurrent domain enumeration by @dwisiswant0 in #1870
- Added crtname passive source by @melvinsh in #1838
- Added subdomaincenter passive source by @g147 in #1865
- Added Options
-match-regexand-filter-regexto filter results with regular expressions by @root-Manas in #1956
🐞 Bug Fixes
- Fixed HIGH CVEs by bumping golang.org/x/net and golang.org/x/text by @dwisiswant0 in #1942
- Fixed response body leaks on error responses and unbounded GitHub rate-limit retries by @CalvinTjoaquinn in #1957
- Fixed dropped subdomains reported with uppercase letters or a trailing dot by @krishna28238-arch in #1863
- Fixed ZoomEye source by switching to the v2 search API by @dwisiswant0 in #1944
- Fixed data races between concurrent source runs by @dwisiswant0 in #1953
- Fixed scanmalware statistics races between concurrent runs by @dwisiswant0 in #1949
- Fixed HTTP connection reuse by @dwisiswant0 in #1873
Other Changes
- Moved Docker image publishing into the GoReleaser release workflow by @dwisiswant0 in #1965
- Fixed processItems helper name in GitHub source by @daixiheguu in #1841
New Contributors
- @daixiheguu made their first contribution in #1841
- @melvinsh made their first contribution in #1838
- @krishna28238-arch made their first contribution in #1863
- @CalvinTjoaquinn made their first contribution in #1957
- @root-Manas made their first contribution in #1956
- @g147 made their first contribution in #1865
Full Changelog: v2.16.0...v2.17.0
v2.16.0
What's Changed
- feat(sources): honor -max-results across paginating sources by @Gerijacki in #1810
- fix(extractor): match the target domain literally and reject partial hosts by @Gerijacki in #1811
- fix(subscraping): cap untrusted source response bodies with a size limit by @adamsjack711-ux in #1809
- fix(subscraping): use DialContext instead of the deprecated Dial by @jonaslejon in #1835
- feat: add scanmalware passive source by @jonaslejon in #1834
- fix(crtsh): set statement_timeout via SQL query to avoid PgBouncer handshake rejection (#1828) by @gcoinstash-cmd in #1832
New Contributors
- @J12934 made their first contribution in #1823
- @adamsjack711-ux made their first contribution in #1809
- @gcoinstash-cmd made their first contribution in #1832
Full Changelog: v2.15.0...v2.16.0
v2.15.0
What's Changed
🎉 New Features
- Added shodanct passive source by @dogancanbakir in #1796
- Added Option
-vR,-virustotal-resfor VirusTotal source by @Bundy01 in #1719 - Added machine-readable source listing with
-ls -oJby @Gerijacki in #1812
🐞 Bug Fixes
- Fixed source leaks by @Mzack9999 in #1801
- Fixed drain source channels on cancel so source goroutines exit instead of leaking on a blocked send by @Mzack9999 in #1799
- Fixed crtsh's query by dropping unused certificate metadata from SQL query by @ChrisJr404 in #1787
- Fixed VirusTotal source by capping pagination and providing clearer 429 message by @ChrisJr404 in #1788
- Fixed Anubis source by switching subdomain API to anubisdb.com by @jatinder14 in #1815
Other Changes
- Fixed lint issues by @dogancanbakir in #1820
- Refactored loadFromFile to use bufio.Scanner by @nandaanomi in #1791
New Contributors
- @ChrisJr404 made their first contribution in #1787
- @Bundy01 made their first contribution in #1719
- @nandaanomi made their first contribution in #1791
- @jatinder14 made their first contribution in #1815
- @Gerijacki made their first contribution in #1812
Full Changelog: v2.14.0...v2.15.0
v2.14.0
What's Changed
Warning
The Facebook source (Meta CT) has been removed in this release after Meta discontinued the upstream API.
If you reference this source in automation, CI jobs, or saved source lists, remove it from those configurations.
For most users, the practical impact should be low, since the integration was already non-functional, and this change mainly removes related errors and confusion.
✨ Features
- Added the new Sub.md passive source, plus follow-up hardening for non-200 responses and context-aware error delivery, by @x-stp in PR #1771 (ae1c9a6, 9ea2b18, d6282b0).
🐞 Bug Fixes
- Fixed Netlas community-tier downloads by capping bulk size to 200 and tightening non-200 and body-close handling, by @x-stp in PR #1776 (7fc6da4, 3206a8b).
- Fixed control-flow bugs across Hackertarget, IntelX, Shodan, C99, and Chinaz, including better transport error reporting and safer response validation, by @x-stp in PR #1777 (14103b5, 75f3c28, 9760a96, 01569ae, b9ef679, c61d1e9).
- Fixed rate-limit handling so global and per-source limits work as expected, preserved per-source durations, and prevented nil map panics, by @CharlesWong in PR #1764 (c1ce78e, cca10d8, 240305b, cf0b801, 6f0e11e).
❌ Removed
- Removed the dead Facebook source after Meta discontinued the backing API, by @PontusLindblom in PR #1732 (4d9e078).
🧹 Chores
- Updated workflow dependencies, switched to org actions, and cleaned up workflow configuration, by @PontusLindblom in PRs #1733 and #1768 (0dfd80a, 7bd72ff, e6ed1e1).
- Refreshed Go dependencies, including grouped module bumps plus utls, circl, and grouped ProjectDiscovery dependency updates, by @dependabot in PRs #1716, #1746, #1751, #1769, #1774, #1783 (bb5a68a, 2636330, 8aa8653, 4de1dde, 2d58630, 0ed1b0b).
New Contributors
- @CharlesWong made their first contribution in #1764
Full Changelog: v2.13.0...v2.14.0
v2.13.0
What's Changed
🎉 New Features
- Added URLScan.io as passive subdomain source by @Jigardjain in #1710
🐞 Bug Fixes
- Fixed timeout issue for Crtsh source by @recepgunes1 in #1723
Other Changes
- Changed working directory path for Dependabot by @mikelolasagasti in #1708
- Added PR template by @dogancanbakir in #1729
- Sorted sources alphabetically by @PontusLindblom in #1720
- Marked LeakIX as requiring an API key by @spameier in #1709
New Contributors
- @Jigardjain made their first contribution in #1710
- @PontusLindblom made their first contribution in #1720
- @spameier made their first contribution in #1709
- @recepgunes1 made their first contribution in #1723
Full Changelog: v2.12.0...v2.13.0
v2.12.0
What's Changed
🎉 New Features
- Added API key support for HackerTarget by @dogancanbakir in #1622
- Added Reconeer by @dogancanbakir in #1694
- Added optional API key support for sources by @dogancanbakir in #1700
- Added request tracking to -stats flag by @dogancanbakir in #1699
Full Changelog: v2.11.0...v2.12.0
v2.11.0
What's Changed
🎉 New Features
- Added Profundis source by @dogancanbakir in #1682
- Added MerkleMap source by @nohehf in #1683
- Added THC source by @dogancanbakir in #1685
Other Changes
- Improved context cancellation sources by @knakul853 in #1680
- Updated Censys to adapt recent changes in the API by @knakul853 in #1654
New Contributors
- @knakul853 made their first contribution in #1680
- @nohehf made their first contribution in #1683
Full Changelog: v2.10.1...v2.11.0
v2.10.1
v2.10.0
What's Changed
🎉 New Features
- Added Windvane source by @dogancanbakir in #1657
- Added OnHype by @dogancanbakir in #1647
- Added API key support by @dogancanbakir in #1660
- Added DomainsProject source by @tb0hdan in #1663
- Added wildcard certificate detection in JSON output by @tarunKoyalwar in #1665
Other Changes
- Added real-time result support to ResultCallback for enumerated subdomains by @mukesh-dream11 in #1652
- Removed hunter by @dogancanbakir in #1662
- Refactored to use strings.Builder for string manipulation to improve performance by @sunnyraindy in #1666
New Contributors
- @mukesh-dream11 made their first contribution in #1652
- @tb0hdan made their first contribution in #1663
- @sunnyraindy made their first contribution in #1666
Full Changelog: v2.9.0...v2.10.0
v2.9.0
What's Changed
🎉 New Features
- Added environment variable support for config files by @dogancanbakir in #1650
- Added the driftnet source. by @0x4500 in #1612
Other Changes
- Moved v2 module to root directory for cleaner structure by @mikelolasagasti in #1613
- Corrected typo in README by @emmanuel-ferdman in #1621
- Corrected the working directory in the
build-testaction by @tekkamanendless in #1631 - Renamed variables to prevent potential nil pointer dereference in netlas source by @tekkamanendless in #1630
New Contributors
- @0x4500 made their first contribution in #1612
- @tekkamanendless made their first contribution in #1631
Full Changelog: v2.8.0...v2.9.0