New: Restrict recommended and automatically selected exit nodes using the new AllowedSuggestedExitNodessystem policy. Applies only to platforms that support system policies.
Changed: Improved NAT traversal for some uncommon scenarios.
Fixed: Taildrive share paths configured through the CLI resolve relative to where you run the tailscale command.
Linux
Fixed: Switching from unstable to stable tracks using the tailscale update command now works correctly.
Windows
New: Use the value auto:any to automatically select an exit node for the existing ExitNodeIDsystem policy. Available for Enterprise plan users only.
New: The new AllowedSuggestedExitNodessystem policy restricts which exit nodes Tailscale recommends or automatically selects.
Fixed: DNS leak issue.
Fixed: Switching from unstable to stable tracks using the tailscale update command now works correctly.
Fixed: Taildrive server no longer starts unnecessarily when no drives are configured.
macOS
Note: As previously announced, Tailscale v1.70 is the last version to support macOS 10.15 Catalina. macOS 10.15 is no longer supported by Apple and no longer receives security updates. Users still running macOS 10.15 should update to a newer version of macOS to continue receiving security updates and new features.
New: Toggle Tailscale DNS from Siri or the Shortcuts app.
New: Receive health notifications in the client menu on macOS to inform you about lack of internet connectivity, firewalls blocking Tailscale, misconfiguration issues, and other issues. Health issues that affect connectivity also change the Tailscale icon in the system menubar to show an exclamation mark.
New: On MacBooks with a notch in the display, a notification window will now appear if the Tailscale icon is hidden behind the notch due to too many menubar items.
New: The Tailscale client now warns you when the built-in macOS content filter (Screen Time) prevents Tailscale from connecting.
New: Use the value auto:any to automatically select an exit node for the existing ExitNodeIDsystem policy. Available for Enterprise plan users only.
Changed: The exit node picker no longer presents exit node suggestions if the organization enforces always using the suggested exit node using the ExitNodeIDsystem policy.
Fixed: Disconnect shortcut no longer connects to the VPN tunnel if executed when Tailscale is disconnected.
Fixed: Taildrive server no longer starts unnecessarily when no drives are configured.
Fixed: Increased the reliability of the Install Updates Automatically setting.
iOS
New: Toggle Tailscale DNS from Siri or the Shortcuts app.
New: Use the value auto:any to automatically select an exit node for the existing ExitNodeIDsystem policy. Available for Enterprise plan users only.
Fixed: wireguard-go memory pool deadlock issue is resolved.
Fixed: Disconnect shortcut no longer connects to the VPN tunnel if executed when Tailscale is disconnected.
Fixed: User interface no longer flickers when selecting an exit node.
tvOS
New: Use the value auto:any to automatically select an exit node for the existing ExitNodeIDsystem policy. Available for Enterprise plan users only.
Fixed: wireguard-go memory pool deadlock issue is resolved.
Fixed: User interface no longer flickers when selecting an exit node.
Android
New: Access ping information and connection status by long-pressing on a device in the devices list and selecting Ping.
New: Use split tunneling to force or exclude app traffic through your tailnet.
Fixed: wireguard-go memory pool deadlock issue is resolved.
Configuration
📅Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [tailscale.com](https://github.com/tailscale/tailscale) | require | minor | `v1.68.2` -> `v1.72.1` |
---
### Release Notes
<details>
<summary>tailscale/tailscale (tailscale.com)</summary>
### [`v1.72.1`](https://github.com/tailscale/tailscale/releases/tag/v1.72.1)
[Compare Source](https://github.com/tailscale/tailscale/compare/v1.72.0...v1.72.1)
Please refer to the changelog available at <https://tailscale.com/changelog#2024-08-22>.
### [`v1.72.0`](https://github.com/tailscale/tailscale/releases/tag/v1.72.0)
[Compare Source](https://github.com/tailscale/tailscale/compare/v1.70.0...v1.72.0)
Please refer to the changelog available at <https://tailscale.com/changelog#2024-08-19>.
### [`v1.70.0`](https://github.com/tailscale/tailscale/releases/tag/v1.70.0)
[Compare Source](https://github.com/tailscale/tailscale/compare/v1.68.2...v1.70.0)
#### All platforms
- New: Restrict [recommended][kb-recommended-exit-nodes] and automatically selected exit nodes using the new `AllowedSuggestedExitNodes` [system policy][kb-mdm-keys]. Applies only to platforms that support [system policies][kb-mdm-keys].
- Changed: Improved [NAT traversal][bl-nat-traversal] for some uncommon scenarios.
- Changed: Optimized [sending firewall rules to clients][kb-acls] more efficiently.
- Fixed: [Exit node suggestion][kb-recommended-exit-nodes] CLI command now prints the hostname (which you can use with the [`tailscale set`][kb-cli-tailscale-set] command).
- Fixed: [Taildrive][kb-taildrive] share paths configured through the CLI resolve relative to where you run the `tailscale` command.
#### Linux
- Fixed: Switching from unstable to stable tracks using the [`tailscale update`][kb-cli-tailscale-update] command now works correctly.
#### Windows
- New: Use the value `auto:any` to automatically select an [exit node][kb-exit-nodes] for the existing `ExitNodeID` [system policy][kb-mdm-keys]. Available for [Enterprise plan][co-pricing] users only.
- New: The new `AllowedSuggestedExitNodes` [system policy][kb-mdm-keys] restricts which exit nodes Tailscale [recommends][kb-recommended-exit-nodes] or automatically selects.
- Fixed: DNS leak issue.
- Fixed: Switching from unstable to stable tracks using the [`tailscale update`][kb-cli-tailscale-update] command now works correctly.
- Fixed: [Taildrive][kb-taildrive] server no longer starts unnecessarily when no drives are configured.
#### macOS
**Note**: As previously announced, Tailscale v1.70 is the last version to support macOS 10.15 Catalina. macOS 10.15 is no longer supported by Apple and no longer receives security updates. Users still running macOS 10.15 should update to a newer version of macOS to continue receiving security updates and new features.
- New: Toggle Tailscale DNS from Siri or the Shortcuts app.
- New: Receive health notifications in the client menu on macOS to inform you about lack of internet connectivity, firewalls blocking Tailscale, misconfiguration issues, and other issues. Health issues that affect [connectivity][kb-device-connectivity] also change the Tailscale icon in the system menubar to show an exclamation mark.
- New: On MacBooks with a notch in the display, a notification window will now appear if the Tailscale icon is hidden behind the notch due to too many menubar items.
- New: The Tailscale client now warns you when the built-in macOS [content filter (Screen Time)][kb-macos-screen-time] prevents Tailscale from connecting.
- New: Use the value `auto:any` to automatically select an exit node for the existing `ExitNodeID` [system policy][kb-mdm-keys]. Available for [Enterprise plan][co-pricing] users only.
- Changed: The exit node picker no longer presents exit node suggestions if the organization enforces always using the suggested exit node using the `ExitNodeID` [system policy][kb-mdm-keys].
- Fixed: Disconnect shortcut no longer connects to the VPN tunnel if executed when Tailscale is disconnected.
- Fixed: [Taildrive][kb-taildrive] server no longer starts unnecessarily when no drives are configured.
- Fixed: Increased the reliability of the **Install Updates Automatically** setting.
#### iOS
- New: Toggle Tailscale DNS from Siri or the Shortcuts app.
- New: Use the value `auto:any` to automatically select an exit node for the existing `ExitNodeID` [system policy][kb-mdm-keys]. Available for [Enterprise plan][co-pricing] users only.
- Fixed: [`wireguard-go`][xt-wireguard-go] memory pool deadlock issue is resolved.
- Fixed: Disconnect shortcut no longer connects to the VPN tunnel if executed when Tailscale is disconnected.
- Fixed: User interface no longer flickers when selecting an exit node.
#### tvOS
- New: Use the value `auto:any` to automatically select an exit node for the existing `ExitNodeID` [system policy][kb-mdm-keys]. Available for [Enterprise plan][co-pricing] users only.
- Fixed: [`wireguard-go`][xt-wireguard-go] memory pool deadlock issue is resolved.
- Fixed: User interface no longer flickers when selecting an exit node.
#### Android
- New: Access ping information and connection status by long-pressing on a device in the devices list and selecting **Ping**.
- New: Use [split tunneling][kb-android-split-tunneling] to force or exclude app traffic through your tailnet.
- Fixed: [`wireguard-go`][xt-wireguard-go] memory pool deadlock issue is resolved.
[bl-nat-traversal]: https://tailscale.com/blog/how-nat-traversal-works
[co-pricing]: https://tailscale.com/pricing
[kb-acls]: https://tailscale.com/kb/1018/acls
[kb-android-split-tunneling]: https://tailscale.com/kb/1444/android-app-split-tunneling
[kb-cli-tailscale-set]: https://tailscale.com/kb/1080/cli#set
[kb-cli-tailscale-update]: https:/tailscale.com/kb/1080/cli#update
[kb-device-connectivity]: https:/tailscale.com/kb/1411/device-connectivity
[kb-exit-nodes]: https://tailscale.com/kb/1103/exit-nodes
[kb-macos-screen-time]: https://tailscale.com/kb/1420/macos-webfilterproxyd
[kb-mdm-keys]: https://tailscale.com/kb/1315/mdm-keys
[kb-recommended-exit-nodes]: https://tailscale.com/kb/1392/auto-exit-nodes
[kb-taildrive]: https://tailscale.com/kb/1369/taildrive
[xt-wireguard-go]: https://github.com/WireGuard/wireguard-go/pull/106
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC42My4wIiwidXBkYXRlZEluVmVyIjoiMzguNjMuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6W119-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v1.68.2->v1.72.1Release Notes
tailscale/tailscale (tailscale.com)
v1.72.1Compare Source
Please refer to the changelog available at https://tailscale.com/changelog#2024-08-22.
v1.72.0Compare Source
Please refer to the changelog available at https://tailscale.com/changelog#2024-08-19.
v1.70.0Compare Source
All platforms
AllowedSuggestedExitNodessystem policy. Applies only to platforms that support system policies.tailscale setcommand).tailscalecommand.Linux
tailscale updatecommand now works correctly.Windows
auto:anyto automatically select an exit node for the existingExitNodeIDsystem policy. Available for Enterprise plan users only.AllowedSuggestedExitNodessystem policy restricts which exit nodes Tailscale recommends or automatically selects.tailscale updatecommand now works correctly.macOS
Note: As previously announced, Tailscale v1.70 is the last version to support macOS 10.15 Catalina. macOS 10.15 is no longer supported by Apple and no longer receives security updates. Users still running macOS 10.15 should update to a newer version of macOS to continue receiving security updates and new features.
auto:anyto automatically select an exit node for the existingExitNodeIDsystem policy. Available for Enterprise plan users only.ExitNodeIDsystem policy.iOS
auto:anyto automatically select an exit node for the existingExitNodeIDsystem policy. Available for Enterprise plan users only.wireguard-gomemory pool deadlock issue is resolved.tvOS
auto:anyto automatically select an exit node for the existingExitNodeIDsystem policy. Available for Enterprise plan users only.wireguard-gomemory pool deadlock issue is resolved.Android
wireguard-gomemory pool deadlock issue is resolved.Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
ℹ Artifact update notice
File name: go.mod
In order to perform the update(s) described in the table above, Renovate ran the
go getcommand, which resulted in the following additional change(s):Details:
github.com/fxamacker/cbor/v2v2.5.0->v2.6.0github.com/gaissmai/bartv0.4.1->v0.11.1github.com/tailscale/wireguard-gov0.0.0-20240429185444-03c5a0ccf754->v0.0.0-20240731203015-71393c576b98golang.org/x/cryptov0.21.0->v0.25.0golang.org/x/modv0.16.0->v0.19.0golang.org/x/netv0.23.0->v0.27.0golang.org/x/sysv0.19.0->v0.22.0golang.org/x/termv0.18.0->v0.22.0golang.org/x/textv0.14.0->v0.16.0golang.org/x/toolsv0.19.0->v0.23.0gvisor.dev/gvisorv0.0.0-20240306221502-ee1e1f6070e3->v0.0.0-20240722211153-64c016c92987