sing-box
io.nekohasekai.sfa
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 24, 2026 1.14.2## :memo: Release Notes * Fixes and improvements
- Sep 15, 2026 1.14.1## :memo: Release Notes * Fixes and improvements
- Aug 31, 2026 1.14.0## :memo: Release Notes Important changes since 1.13: * iOS and tvOS clients are back on the [App Store](https://apps.apple.com/us/app/sing-box-mt/id6785326793) **1** * Add OpenVPN client and server support **2** * Add OpenConnect client support **3** * Add Snell protocol support **4** * Add L3 forwarding support and bridge outbound **5** * Add network namespace support **6**
More…
* Introducing sing-box API service, Dashboard and remote control **7** * Add `api` command **8** * Add USB/IP services **9** * Add Hysteria Realm service and Hysteria2 NAT traversal support **10** * Add Chrome QUIC fingerprint parroting, BBR profile, hop interval randomization and gecko obfs for Hysteria2 **11** * Add `evaluate` DNS rule action, Response Match Fields and parallel DNS response evaluation **12** * `ip_version` and `query_type` now also take effect on internal DNS lookups **13** * Correct undefined rule-set matching semantics **14** * Add optimistic DNS cache **15** * Add DNS query timeout options **16** * Add mDNS DNS server, `preferred_by` DNS rule item and search domain rule items **17** * Add `source_mac_address` and `source_hostname` rule items **18** * Allow customizing TUN DNS mode and hijack interface DNS by default **19** * Add new UDP NAT options **20** * Add `sniff` support for pre-match **21** * Unify HTTP client **22** * Unify HTTP/2 and QUIC parameters **23** * Refactor ACME support to certificate provider system **24** * Add Cloudflare Origin CA and Tailscale certificate providers **25** * Add TLS spoof **26** * Add Windows and Apple TLS engines and Apple HTTP engine **27** * Add Tailscale SSH server and Taildrop support **28** * Add JSON Schema support **29** * Add multiple tags and `initial_path` support to rule-sets **30** * Add `package_name_regex` route, DNS and headless rule item * Add `query_client_subnet` and `query_dnssec` DNS rule items and `remove_client_subnet` DNS rule action option * Add cipher, MAC, and key exchange algorithm options for SSH outbound * Add cloudflared inbound * Add `include_mac_address` and `exclude_mac_address` TUN options * Add `handshake_timeout` TLS option * Add `listen_port`, `accept_search_domain` options for Tailscale * Preserve comments between formatting * Remove [Deprecated Features](https://sing-box.sagernet.org/deprecated/) by agreement * Introducing [sing-box for Desktop](https://sing-box.sagernet.org/clients/desktop/) for Windows and Linux **31** * Add iOS jailbreak release **32** * Apple/Android/Desktop: Add JSON editor completion, power report, report export encryption and updater improvements * Add beta, testing and oldstable release tracks for Linux packages and Docker **33** * Drop support for go1.24 **34** * Update quic-go to v0.61.0 * Update gVisor to 20260727.0 * Update Tailscale to v1.102.1 * Update uTLS to v1.8.7 * Update NaiveProxy to v150.0.7871.63-2 **1**: Apple platform clients migrated to a new Apple developer account, and the iOS and tvOS clients are available on the App Store again as sing-box MT. Users of the previous App Store version (sing-box VT) need to install the new application. Due to entitlement restrictions, SFM is no longer offered on the macOS App Store; use the [standalone version](https://sing-box.sagernet.org/clients/apple/#download-macos-standalone-version) instead. Its profiles and settings are not inherited from the previous application, see [Migration](https://sing-box.sagernet.org/migration/#migrate-the-macos-standalone-client-data). **2**: The new [OpenVPN Client](https://sing-box.sagernet.org/configuration/endpoint/openvpn-client/) and [OpenVPN Server](https://sing-box.sagernet.org/configuration/endpoint/openvpn-server/) endpoints are compatible with standard OpenVPN clients and servers, including static-key mode, legacy ciphers and digests, OpenVPN-compatible certificate checks, and options for tunnel addressing, MSS calculation, replay windows, timers, and TLS renegotiation. The new [OpenVPN DNS server](https://sing-box.sagernet.org/configuration/dns/server/openvpn/) uses DNS options pushed by OpenVPN servers. Interactive client authentication is available through the sing-box graphical clients and [Dashboard](https://github.com/SagerNet/sing-box-dashboard). **3**: The new [OpenConnect Client](https://sing-box.sagernet.org/configuration/endpoint/openconnect/) endpoint supports Cisco AnyConnect, GlobalProtect, Fortinet, F5, Pulse Connect Secure, and Juniper Network Connect VPN servers, with SSO (single sign-on) for AnyConnect, existing authentication sessions, OIDC Bearer authentication, AnyConnect compression, and Fortinet host check via [`fortinet_host_check`](https://sing-box.sagernet.org/configuration/endpoint/openconnect/#fortinet_host_check). The new [OpenConnect DNS server](https://sing-box.sagernet.org/configuration/dns/server/openconnect/) uses pushed split-DNS resolvers. Interactive authentication is available through the sing-box graphical clients and [Dashboard](https://github.com/SagerNet/sing-box-dashboard). **4**: Surge believes that being closed-source and not proliferated can keep [Snell](https://kb.nssurge.com/surge-knowledge-base/release-notes/snell) covert, but this is already impossible in 2026; considering that Snell still has advantages that other random-traffic protocols do not possess, such as multiplexing support with complete TCP semantics and traffic-characteristic diversity, we [implemented it in Go](https://github.com/SagerNet/sing-snell) instead of reinventing the wheel, with all features except the v5 QUIC proxy, behavior as consistent with the official implementation as possible, and performance at least on par with it. See [Snell Inbound](https://sing-box.sagernet.org/configuration/inbound/snell/) and [Snell Outbound](https://sing-box.sagernet.org/configuration/outbound/snell/). **5**: Building on the ICMP proxy support introduced in sing-box 1.13.0, TCP and UDP traffic from L3 inbounds (TUN, WireGuard, and Tailscale) can now be forwarded directly to WireGuard and Tailscale endpoints at L3, without going through L3 to L4 translation. The new [`bridge`](https://sing-box.sagernet.org/configuration/outbound/bridge/) outbound is the L3 counterpart of `direct`: it forwards L3 traffic (TCP, UDP and ICMP) from a TUN or other L3 endpoints directly out of a network interface. It requires privileges and is supported on Linux, macOS, Windows (via WinDivert), rooted Android, and jailbroken iOS. It also works with the [`preferred_by`](https://sing-box.sagernet.org/configuration/route/rule/#preferred_by) route rule item. See [Pre-match](https://sing-box.sagernet.org/configuration/shared/pre-match/). **6**: The new [`network_namespaces`](https://sing-box.sagernet.org/configuration/network-namespace/) option defines Linux network namespaces for inbounds and outbounds, referenced by tag from the new tun [`netns`](https://sing-box.sagernet.org/configuration/inbound/tun/#netns) field and the existing [Listen](https://sing-box.sagernet.org/configuration/shared/listen/#netns) and [Dial](https://sing-box.sagernet.org/configuration/shared/dial/#netns) `netns` fields. The [`unshare`](https://sing-box.sagernet.org/configuration/network-namespace/unshare/) type creates the namespace at startup without requiring root privileges: a rootless sing-box can provide a tun (including `auto_route` and `auto_redirect`) inside a namespace, which can be entered with `nsenter`. **7**: The new [sing-box API service](https://sing-box.sagernet.org/configuration/service/api/) is a gRPC server for observing and controlling the running sing-box instance, exposing the same interface the graphical clients use locally: service status, logs, outbound groups (selection and URL tests), Clash mode, connection tracking, and tools such as network quality tests, STUN tests, and Tailscale operations. It can also download, update and serve [sing-box-dashboard](https://github.com/SagerNet/sing-box-dashboard) directly over its listener via the [`dashboard`](https://sing-box.sagernet.org/configuration/service/api/#dashboard) option. The graphical clients can control remote sing-box instances running the API service. [sing-box Dashboard](https://github.com/SagerNet/sing-box-dashboard) is a new web client for the API service, providing almost the same experience as the graphical clients. A public instance is available at http://sing-box-dashboard.sagernet.org (shortcut: dash.sing-box.app). **8**: The new `sing-box api` command is a CLI client for the [API service](https://sing-box.sagernet.org/configuration/service/api/), providing the same operations available in graphical clients and the Dashboard. **9**: New [USB/IP Server](https://sing-box.sagernet.org/configuration/service/usbip-server/) and [USB/IP Client](https://sing-box.sagernet.org/configuration/service/usbip-client/) services export and import USB devices over the [USB/IP](https://usbip.sourceforge.net/) protocol, built on [sing-usbip](https://github.com/SagerNet/sing-usbip), which adds hotplug while staying interoperable with standard USB/IP. Exporting config-selected local devices (`provider: default`) runs via the CLI on Linux, Windows, and macOS and requires elevated privileges (macOS additionally needs a CGO build and disabled System Integrity Protection). With `provider: dynamic`, devices are instead supplied at runtime through the API service by the graphical clients or the [sing-box Dashboard](https://github.com/SagerNet/sing-box-dashboard). **10**: The new [Hysteria Realm service](https://sing-box.sagernet.org/configuration/service/hysteria-realm/) is a rendezvous service for Hysteria2 NAT traversal. A Hysteria2 server behind NAT registers its STUN-discovered public addresses on a stable realm endpoint via the new [`realm`](https://sing-box.sagernet.org/configuration/inbound/hysteria2/#realm) inbound field; clients query the realm via the new [`realm`](https://sing-box.sagernet.org/configuration/outbound/hysteria2/#realm) outbound field to learn the server's current addresses and perform UDP hole-punching to establish a direct QUIC connection. [`realm.ip_version`](https://sing-box.sagernet.org/configuration/outbound/hysteria2/#realmip_version) restricts realm connections to a single IP version, and [`realm.port_mapping`](https://sing-box.sagernet.org/configuration/outbound/hysteria2/#realmport_mapping) maintains a UDP port mapping on the local gateway via UPnP or NAT-PMP. **11**: Hysteria2 client connections now parrot Chrome's QUIC handshake by default, making the traffic harder to identify by handshake fingerprinting. Since Chrome does not declare support for Ed25519, servers using Ed25519 certificates will fail the handshake; see [disable_chrome_parrot](https://sing-box.sagernet.org/configuration/outbound/hysteria2/#disable_chrome_parrot). Also adds [`bbr_profile`](https://sing-box.sagernet.org/configuration/outbound/hysteria2/#bbr_profile), [`hop_interval_max`](https://sing-box.sagernet.org/configuration/outbound/hysteria2/#hop_interval_max), and `gecko` as a new QUIC traffic obfuscation type alongside `salamander`, with configurable [`min_packet_size`](https://sing-box.sagernet.org/configuration/inbound/hysteria2/#obfsmin_packet_size) and [`max_packet_size`](https://sing-box.sagernet.org/configuration/inbound/hysteria2/#obfsmax_packet_size). **12**: Response Match Fields ([`response_rcode`](https://sing-box.sagernet.org/configuration/dns/rule/#response_rcode), [`response_answer`](https://sing-box.sagernet.org/configuration/dns/rule/#response_answer), [`response_ns`](https://sing-box.sagernet.org/configuration/dns/rule/#response_ns), and [`response_extra`](https://sing-box.sagernet.org/configuration/dns/rule/#response_extra)) match the evaluated DNS response. They are gated by the new [`match_response`](https://sing-box.sagernet.org/configuration/dns/rule/#match_response) field and populated by a preceding [`evaluate`](https://sing-box.sagernet.org/configuration/dns/rule_action/#evaluate) DNS rule action; the evaluated response can also be returned directly by a [`respond`](https://sing-box.sagernet.org/configuration/dns/rule_action/#respond) action. `evaluate` can assign a `tag` to each response, allowing multiple evaluated responses to coexist and be selected through tagged `match_response` rules. The new [`race`](https://sing-box.sagernet.org/configuration/dns/rule_action/#race) field allows response-dependent rules to compete in parallel, with the first matching rule taking effect and the remaining queries canceled; the `speculative` option can start `evaluate` and `route` queries while race rules are still pending. This deprecates the Legacy Address Filter Fields (`ip_cidr`, `ip_is_private` without `match_response`) in DNS rules, the Legacy `strategy` DNS rule action option, and the Legacy `rule_set_ip_cidr_accept_empty` DNS rule item; all three will be removed in sing-box 1.16.0. See [Migration](https://sing-box.sagernet.org/migration/#migrate-address-filter-fields-to-response-matching). **13**: `ip_version` and `query_type` in DNS rules, together with `query_type` in referenced rule-sets, now take effect on every DNS rule evaluation, including matches from internal domain resolutions that do not target a specific DNS server (for example a `resolve` route rule action without `server` set). In earlier versions they were silently ignored in that path. Combining these fields with any of the legacy DNS fields deprecated in **12** in the same DNS configuration is no longer supported and is rejected at startup. See [Migration](https://sing-box.sagernet.org/migration/#ip_version-and-query_type-behavior-changes-in-dns-rules). **14**: Rule-set matching has always been described as merged matching: fields of rule-set rules are considered merged into the referencing rule. However, this description is only intuitive when a rule-set contains only a single `default` rule without `invert`. Merged matching is now limited to exactly this case; any other referenced rule-set is matched as an `other field`, which matches when any of its rules matches on its own. Since the previous behavior in the corrected cases was effectively undefined, counterintuitive, and hard to understand, we do not consider this a breaking change — except for configurations that worked without their author understanding why. **15**: Optimistic DNS cache returns an expired cached response immediately while refreshing it in the background, reducing tail latency for repeated queries. Enabled via [`optimistic`](https://sing-box.sagernet.org/configuration/dns/#optimistic) in DNS options, and can be persisted across restarts with the new [`store_dns`](https://sing-box.sagernet.org/configuration/experimental/cache-file/#store_dns) cache file option. A per-query [`disable_optimistic_cache`](https://sing-box.sagernet.org/configuration/dns/rule_action/#disable_optimistic_cache) field is also available on DNS rule actions and the `resolve` route rule action. This deprecates the `independent_cache` DNS option (the DNS cache now always keys by transport) and the `store_rdrc` cache file option (replaced by `store_dns`); both will be removed in sing-box 1.16.0. See [Migration](https://sing-box.sagernet.org/migration/#migrate-independent-dns-cache). **16**: Adds [`dns.timeout`](https://sing-box.sagernet.org/configuration/dns/#timeout), with per-query overrides via [DNS rule action](https://sing-box.sagernet.org/configuration/dns/rule_action/#timeout) and [`resolve` route rule action](https://sing-box.sagernet.org/configuration/route/rule_action/#timeout), and a `timeout` field on [`domain_resolver`](https://sing-box.sagernet.org/configuration/shared/dial/#domain_resolver). **17**: The new [mDNS DNS server](https://sing-box.sagernet.org/configuration/dns/server/mdns/) sends queries via multicast on the local network. The default [local DNS server](https://sing-box.sagernet.org/configuration/dns/server/local/) also routes queries for `*.local.` and IPv4/IPv6 link-local reverse zones via mDNS on non-Apple platforms (and via the system resolver on Apple), and the new [`neighbor_domain`](https://sing-box.sagernet.org/configuration/dns/server/local/#neighbor_domain) option answers single-label hosts from the [neighbor resolver](https://sing-box.sagernet.org/configuration/shared/neighbor/). The new [`preferred_by`](https://sing-box.sagernet.org/configuration/dns/rule/#preferred_by) DNS rule item matches domains that the listed DNS servers consider their preferred names, including search domain suffixes. Supported server types are `hosts`, `local`, `dhcp`, `mdns`, `tailscale`, and `resolved`. The new DNS rule items [`domain_label_count`](https://sing-box.sagernet.org/configuration/dns/rule/#domain_label_count) and [`search_domain_available`](https://sing-box.sagernet.org/configuration/dns/rule/#search_domain_available) match the number of labels in the query name and whether a DNS server currently holds search domains; combined with `race`, they allow unqualified name queries to race a server that can expand them against a public resolver. **18**: New rule items for matching LAN devices by MAC address and hostname via [neighbor resolution](https://sing-box.sagernet.org/configuration/shared/neighbor/). Supported on Linux, macOS, or in graphical clients on Android and macOS. See [Route Rule](https://sing-box.sagernet.org/configuration/route/rule/#source_mac_address) and [DNS Rule](https://sing-box.sagernet.org/configuration/dns/rule/#source_mac_address). **19**: Adds [`dns_mode`](https://sing-box.sagernet.org/configuration/inbound/tun/#dns_mode) and [`dns_address`](https://sing-box.sagernet.org/configuration/inbound/tun/#dns_address) on the TUN inbound. The default `hijack` mode now sets the platform's native interface DNS (`systemd-resolved` on Linux, per-interface DNS on Windows and Apple) and installs platform-level DNS hijacking (an `iproute2` rule on Linux, nftables DNAT when `auto_redirect` is enabled, WFP filters on Windows when `strict_route` is enabled). Earlier versions did not touch the interface DNS or the platform firewall. **20**: The new [UDP NAT](https://sing-box.sagernet.org/configuration/shared/udp-nat/) fields [`udp_mapping`](https://sing-box.sagernet.org/configuration/shared/udp-nat/#udp_mapping), [`udp_filtering`](https://sing-box.sagernet.org/configuration/shared/udp-nat/#udp_filtering) and [`udp_nat_max`](https://sing-box.sagernet.org/configuration/shared/udp-nat/#udp_nat_max) configure the NAT mapping and filtering behaviors and the maximum number of UDP NAT sessions for TUN and TProxy inbounds and the WireGuard endpoint. **21**: For UDP connections, the first packet is available in pre-match, so protocol sniffing runs on it directly and rule matching continues with the sniffed metadata. See [Pre-match](https://sing-box.sagernet.org/configuration/shared/pre-match/#sniff). **22**: The new top-level [`http_clients`](https://sing-box.sagernet.org/configuration/shared/http-client/) option defines reusable HTTP clients (engine, version, dialer, TLS, HTTP/2 and QUIC parameters). Components that make outbound HTTP requests — remote rule-sets, ACME and Cloudflare Origin CA certificate providers, and DERP `verify_client_url` — now accept an inline HTTP client object or the tag of an `http_clients` entry, replacing the dial and TLS fields previously inlined in each component. [`route.default_http_client`](https://sing-box.sagernet.org/configuration/route/#default_http_client) selects the default client for remote rule-sets. The legacy fallback (use the default outbound when `http_clients` is empty altogether) is preserved with a deprecation warning and will be removed in sing-box 1.16.0, together with the legacy `download_detour` remote rule-set option. **23**: [HTTP/2](https://sing-box.sagernet.org/configuration/shared/http2/) and [QUIC](https://sing-box.sagernet.org/configuration/shared/quic/) parameters are now shared across QUIC-based outbounds ([Hysteria](https://sing-box.sagernet.org/configuration/outbound/hysteria/), [Hysteria2](https://sing-box.sagernet.org/configuration/outbound/hysteria2/), [TUIC](https://sing-box.sagernet.org/configuration/outbound/tuic/)) and HTTP clients running HTTP/2 or HTTP/3. This deprecates the Hysteria v1 tuning fields `recv_window_conn`, `recv_window`, `recv_window_client`, `max_conn_client` and `disable_mtu_discovery`; they will be removed in sing-box 1.16.0. **24**: Inline ACME options in TLS are deprecated and replaced by the [certificate provider](https://sing-box.sagernet.org/configuration/shared/certificate-provider/) system, referenced via the new [`certificate_provider`](https://sing-box.sagernet.org/configuration/shared/tls/#certificate_provider) TLS field. The [ACME](https://sing-box.sagernet.org/configuration/shared/certificate-provider/acme/) provider adds `account_key`, `key_type`, `profile` (including IP address certificates) and `http_client` options, and [DNS-01 challenge](https://sing-box.sagernet.org/configuration/shared/dns01_challenge/) providers gain `ttl`, `propagation_delay`, `propagation_timeout`, `resolvers` and `override_domain` options. See [Migration](https://sing-box.sagernet.org/migration/#migrate-inline-acme-to-certificate-provider). **25**: See [Cloudflare Origin CA](https://sing-box.sagernet.org/configuration/shared/certificate-provider/cloudflare-origin-ca/) and [Tailscale](https://sing-box.sagernet.org/configuration/shared/certificate-provider/tailscale/). **26**: Added outbound TLS [`spoof`](https://sing-box.sagernet.org/configuration/shared/tls/#spoof) and [`spoof_method`](https://sing-box.sagernet.org/configuration/shared/tls/#spoof_method) fields, and [`tls_spoof`](https://sing-box.sagernet.org/configuration/route/rule_action/#tls_spoof) / [`tls_spoof_method`](https://sing-box.sagernet.org/configuration/route/rule_action/#tls_spoof_method) route rule action fields. When enabled, a forged ClientHello carrying a whitelisted SNI is sent before the real handshake to fool SNI-filtering middleboxes. Requires `CAP_NET_RAW` + `CAP_NET_ADMIN` or root on Linux and macOS, and Administrator privileges on Windows (ARM64 is not supported). **27**: The new `windows` value for outbound TLS [`engine`](https://sing-box.sagernet.org/configuration/shared/tls/#engine) routes the TLS handshake through Schannel via SSPI on Windows build 17763 or later. The new `apple` value for outbound TLS `engine` routes the TLS handshake through `Network.framework`, and the new `apple` [HTTP client `engine`](https://sing-box.sagernet.org/configuration/shared/http-client/#engine) routes HTTP requests through `NSURLSession`. The default remains `go`. **28**: The new [`ssh_server`](https://sing-box.sagernet.org/configuration/endpoint/tailscale/#ssh_server) field runs a Tailscale SSH server on tailnet port 22, with access controlled by the SSH ACL in the Tailscale admin console. [Tailscale](https://sing-box.sagernet.org/configuration/endpoint/tailscale/) endpoints now also support [Taildrop](https://tailscale.com/kb/1106/taildrop). Received files are stored in the directory configured by [`taildrop_directory`](https://sing-box.sagernet.org/configuration/endpoint/tailscale/#taildrop_directory); files can be sent and managed through the graphical clients, the Dashboard, or the `sing-box api` command. **29**: sing-box now provides a [JSON Schema](https://sing-box.sagernet.org/configuration/schema/) for its configuration, enabling completion and validation in compatible editors. The schema published with the documentation can be selected with the new top-level `$schema` field, while the new `sing-box schema` command generates a schema matching the current binary and its build tags. **30**: The rule-set [`tag`](https://sing-box.sagernet.org/configuration/rule-set/#tag) field now accepts a list of tags to define multiple rule-sets sharing other options at once, with the `{tag}` placeholder in `path` or `url` replaced by each tag. The new [`initial_path`](https://sing-box.sagernet.org/configuration/rule-set/#initial_path) option provides initial content for remote rule-sets so startup is not blocked by the initial download. **31**: The new [sing-box for Desktop](https://sing-box.sagernet.org/clients/desktop/) client provides an experience equal to other standard sing-box graphical clients, is available for Windows 10+ (x64 / x86 / arm64) and Linux (x64 / arm64 / armv7l), and is distributed from [GitHub Releases](https://github.com/SagerNet/sing-box/releases). **32**: A new jailbreak build of the iOS [sing-box for Apple](https://sing-box.sagernet.org/clients/apple/) client is available, distributed as a `.deb` for rootless iOS 15.0+ from [GitHub Releases](https://github.com/SagerNet/sing-box/releases) (`SFI-iphoneos-arm64.deb`). Unlike the App Store and TestFlight builds, it can run a [Tailscale SSH server](https://sing-box.sagernet.org/configuration/endpoint/tailscale/#ssh_server) on the device and supports [process matching](https://sing-box.sagernet.org/configuration/route/rule/#process_name) in route and DNS rules. **33**: Linux packages and Docker images are now published in four tracks: `sing-box` / `latest` (stable release), `sing-box-beta` / `latest-beta` (stable pre-release), `sing-box-testing` / `latest-testing` (testing branch), and `sing-box-oldstable` / `latest-oldstable` (previous stable branch). **34**: Due to maintenance difficulties, sing-box 1.14.0 requires at least Go 1.25 to compile. - Aug 30, 2026 1.13.21## :memo: Release Notes * Fixes and improvements
- Aug 29, 2026 1.13.20## :memo: Release Notes * Fixes and improvements
- Aug 17, 2026 1.13.19## :memo: Release Notes * Fixes and improvements
- Aug 9, 2026 1.13.18## :memo: Release Notes * Update naiveproxy to v150.0.7871.63-1 * Fixes and improvements
- Aug 3, 2026 1.13.16## :memo: Release Notes * Remove client metadata from AnyTLS requests by default **1** * Fixes and improvements **1**: We found that the AnyTLS client implementation uploads metadata that is **not used by the open-source server**, and there are reports of vendors using it to profile and discriminate against users. We now leave it empty by default and allow you to customize it, see [AnyTLS client metadata](https://sing-box.sagernet.org/manual/misc/anytls-client-metadata/).
- Jul 29, 2026 1.13.15## :memo: Release Notes * Fixes and improvements
- Jun 25, 2026 1.13.14## :memo: Release Notes * Fixes and improvements
- Apr 23, 2026 1.13.11## :memo: Release Notes * Fix process searcher failure introduced in 1.13.9 * Fixes and improvements
- Apr 22, 2026 1.13.10## :memo: Release Notes * Fix process searcher failure introduced in 1.13.9
- Apr 14, 2026 1.13.8## :memo: Release Notes * Update naiveproxy to v147.0.7727.49-1 * Fix fake-ip DNS server should return SUCCESS when address type is not configured * Fixes and improvements
- Apr 10, 2026 1.13.7## :memo: Release Notes * Fixes and improvements
- Apr 6, 2026 1.13.6## :memo: Release Notes * Fixes and improvements
- Mar 30, 2026 1.13.5## :memo: Release Notes * Fixes and improvements
- Mar 26, 2026 1.13.4## :memo: Release Notes * Fixes and improvements
- Mar 15, 2026 1.13.3## :memo: Release Notes * Add OpenWrt and Alpine APK packages to release **1** * Backport to macOS 10.13 High Sierra **2** * OCM service: Add WebSocket support for Responses API **3** * Fixes and improvements **1**: Alpine APK files use `linux` in the filename to distinguish from OpenWrt APKs which use the `openwrt` prefix:
More…
- OpenWrt: `sing-box_{version}_openwrt_{architecture}.apk` - Alpine: `sing-box_{version}_linux_{architecture}.apk` **2**: Legacy macOS binaries (with `-legacy-macos-10.13` suffix) now support macOS 10.13 High Sierra, built using Go 1.25 with patches from [SagerNet/go](https://github.com/SagerNet/go). **3**: See [OCM](https://sing-box.sagernet.org/configuration/service/ocm). - Mar 7, 2026 1.13.2## :memo: Release Notes * Fixes and improvements
- Mar 5, 2026 1.13.1## :memo: Release Notes * Fixes and improvements
- Feb 28, 2026 1.13.0## :memo: Release Notes Important changes since 1.12: * Add NaiveProxy outbound **1** * Add pre-match support for `auto_redirect` **2** * Improve `auto_redirect` **3** * Add Chrome Root Store certificate option **4** * Add new options for ACME DNS-01 challenge providers **5** * Add Wi-Fi state support for Linux and Windows **6**
More…
* Add curve preferences, pinned public key SHA256, mTLS and ECH `query_server_name` for TLS options **7** * Add kTLS support **8** * Add ICMP echo (ping) proxy support **9** * Add `interface_address`, `network_interface_address` and `default_interface_address` rule items **10** * Add `preferred_by` route rule item **11** * Improve `local` DNS server **12** * Add `disable_tcp_keep_alive`, `tcp_keep_alive` and `tcp_keep_alive_interval` options for listen and dial fields **13** * Add `bind_address_no_port` option for dial fields **14** * Add system interface and relay server options for Tailscale endpoint **15** * Add Claude Code Multiplexer service **16** * Add OpenAI Codex Multiplexer service **17** * Apple/Android: Refactor GUI * Apple/Android: Add support for sharing configurations via [QRS](https://github.com/qifi-dev/qrs) * Android: Add support for resisting VPN detection via Xposed * Drop support for go1.23 **18** * Drop support for Android 5.0 **19** * Update uTLS to v1.8.2 **20** * Update quic-go to v0.59.0 * Update gVisor to v20250811 * Update Tailscale to v1.92.4 **1**: NaiveProxy outbound now supports QUIC, ECH, UDP over TCP, and configurable QUIC congestion control. Only available on Apple platforms, Android, Windows and some Linux architectures. Each Windows release includes `libcronet.dll` — ensure this file is in the same directory as `sing-box.exe` or in a directory listed in `PATH`. See [NaiveProxy outbound](https://sing-box.sagernet.org/configuration/outbound/naive/). **2**: `auto_redirect` now allows you to bypass sing-box for connections based on routing rules. A new rule action `bypass` is introduced to support this feature. When matched during pre-match, the connection will bypass sing-box and connect directly. This feature requires Linux with `auto_redirect` enabled. See [Pre-match](https://sing-box.sagernet.org/configuration/shared/pre-match/) and [Rule Action](https://sing-box.sagernet.org/configuration/route/rule_action/#bypass). **3**: `auto_redirect` now rejects MPTCP connections by default to fix compatibility issues. You can change it to bypass sing-box via the new `exclude_mptcp` option. Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default), ensuring traffic is routed to the sing-box table when no route is found in system tables. The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768). See [TUN](https://sing-box.sagernet.org/configuration/inbound/tun/#exclude_mptcp). **4**: Adds `chrome` as a new certificate store option alongside `mozilla`. Both stores filter out China-based CA certificates. See [Certificate](https://sing-box.sagernet.org/configuration/certificate/#store). **5**: See [DNS-01 Challenge](https://sing-box.sagernet.org/configuration/shared/dns01_challenge/). **6**: sing-box can now monitor Wi-Fi state on Linux and Windows to enable routing rules based on `wifi_ssid` and `wifi_bssid`. See [Wi-Fi State](https://sing-box.sagernet.org/configuration/shared/wifi-state/). **7**: See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **8**: Adds `kernel_tx` and `kernel_rx` options for TLS inbound. Enables kernel-level TLS offloading via `splice(2)` on Linux 5.1+ with TLS 1.3. See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **9**: sing-box can now proxy ICMP echo (ping) requests. A new `icmp` network type is available for route rules. Supported from TUN, WireGuard and Tailscale inbounds to Direct, WireGuard and Tailscale outbounds. The `reject` action can also reply to ICMP echo requests. **10**: New rule items for matching based on interface IP addresses, available in route rules, DNS rules and rule-sets. **11**: Matches outbounds' preferred routes. For Tailscale: MagicDNS domains and peers' allowed IPs. For WireGuard: peers' allowed IPs. **12**: The `local` DNS server now uses platform-native resolution: `getaddrinfo`/libresolv on Apple platforms, systemd-resolved DBus on Linux. A new `prefer_go` option is available to opt out. See [Local DNS](https://sing-box.sagernet.org/configuration/dns/server/local/). **13**: The default TCP keep-alive initial period has been updated from 10 minutes to 5 minutes. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#tcp_keep_alive). **14**: Adds the Linux socket option `IP_BIND_ADDRESS_NO_PORT` support when explicitly binding to a source address. This allows reusing the same source port for multiple connections, improving scalability for high-concurrency proxy scenarios. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#bind_address_no_port). **15**: Tailscale endpoint can now create a system TUN interface to handle traffic directly. New `relay_server_port` and `relay_server_static_endpoints` options for incoming relay connections. See [Tailscale endpoint](https://sing-box.sagernet.org/configuration/endpoint/tailscale/). **16**: CCM (Claude Code Multiplexer) service allows you to access your local Claude Code subscription remotely through custom tokens, eliminating the need for OAuth authentication on remote clients. See [CCM](https://sing-box.sagernet.org/configuration/service/ccm). **17**: See [OCM](https://sing-box.sagernet.org/configuration/service/ocm). **18**: Due to maintenance difficulties, sing-box 1.13.0 requires at least Go 1.24 to compile. **19**: Due to maintenance difficulties, sing-box 1.13.0 will be the last version to support Android 5.0, and only through a separate legacy build (with `-legacy-android-5` suffix). For standalone binaries, the minimum Android version has been raised to Android 6.0, since Termux requires Android 7.0 or later. **20**: This update fixes missing padding extension for Chrome 120+ fingerprints. Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities. uTLS is not recommended for censorship circumvention due to fundamental architectural limitations; use NaiveProxy instead for TLS fingerprint resistance. - Feb 27, 2026 1.12.23## :memo: Release Notes * Fixes and improvements
- Feb 23, 2026 1.13.0-rc.6## :memo: Release Notes * Fixes and improvements Important changes since 1.12: * Add NaiveProxy outbound **1** * Add pre-match support for `auto_redirect` **2** * Improve `auto_redirect` **3** * Add Chrome Root Store certificate option **4**
More…
* Add new options for ACME DNS-01 challenge providers **5** * Add Wi-Fi state support for Linux and Windows **6** * Add curve preferences, pinned public key SHA256, mTLS and ECH `query_server_name` for TLS options **7** * Add kTLS support **8** * Add ICMP echo (ping) proxy support **9** * Add `interface_address`, `network_interface_address` and `default_interface_address` rule items **10** * Add `preferred_by` route rule item **11** * Improve `local` DNS server **12** * Add `disable_tcp_keep_alive`, `tcp_keep_alive` and `tcp_keep_alive_interval` options for listen and dial fields **13** * Add `bind_address_no_port` option for dial fields **14** * Add system interface and relay server options for Tailscale endpoint **15** * Add Claude Code Multiplexer service **16** * Add OpenAI Codex Multiplexer service **17** * Apple/Android: Refactor GUI * Apple/Android: Add support for sharing configurations via [QRS](https://github.com/qifi-dev/qrs) * Android: Add support for resisting VPN detection via Xposed * Drop support for go1.23 **18** * Drop support for Android 5.0 **19** * Update uTLS to v1.8.2 **20** * Update quic-go to v0.59.0 * Update gVisor to v20250811 * Update Tailscale to v1.92.4 **1**: NaiveProxy outbound now supports QUIC, ECH, UDP over TCP, and configurable QUIC congestion control. Only available on Apple platforms, Android, Windows and some Linux architectures. Each Windows release includes `libcronet.dll` — ensure this file is in the same directory as `sing-box.exe` or in a directory listed in `PATH`. See [NaiveProxy outbound](https://sing-box.sagernet.org/configuration/outbound/naive/). **2**: `auto_redirect` now allows you to bypass sing-box for connections based on routing rules. A new rule action `bypass` is introduced to support this feature. When matched during pre-match, the connection will bypass sing-box and connect directly. This feature requires Linux with `auto_redirect` enabled. See [Pre-match](https://sing-box.sagernet.org/configuration/shared/pre-match/) and [Rule Action](https://sing-box.sagernet.org/configuration/route/rule_action/#bypass). **3**: `auto_redirect` now rejects MPTCP connections by default to fix compatibility issues. You can change it to bypass sing-box via the new `exclude_mptcp` option. Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default), ensuring traffic is routed to the sing-box table when no route is found in system tables. The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768). See [TUN](https://sing-box.sagernet.org/configuration/inbound/tun/#exclude_mptcp). **4**: Adds `chrome` as a new certificate store option alongside `mozilla`. Both stores filter out China-based CA certificates. See [Certificate](https://sing-box.sagernet.org/configuration/certificate/#store). **5**: See [DNS-01 Challenge](https://sing-box.sagernet.org/configuration/shared/dns01_challenge/). **6**: sing-box can now monitor Wi-Fi state on Linux and Windows to enable routing rules based on `wifi_ssid` and `wifi_bssid`. See [Wi-Fi State](https://sing-box.sagernet.org/configuration/shared/wifi-state/). **7**: See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **8**: Adds `kernel_tx` and `kernel_rx` options for TLS inbound. Enables kernel-level TLS offloading via `splice(2)` on Linux 5.1+ with TLS 1.3. See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **9**: sing-box can now proxy ICMP echo (ping) requests. A new `icmp` network type is available for route rules. Supported from TUN, WireGuard and Tailscale inbounds to Direct, WireGuard and Tailscale outbounds. The `reject` action can also reply to ICMP echo requests. **10**: New rule items for matching based on interface IP addresses, available in route rules, DNS rules and rule-sets. **11**: Matches outbounds' preferred routes. For Tailscale: MagicDNS domains and peers' allowed IPs. For WireGuard: peers' allowed IPs. **12**: The `local` DNS server now uses platform-native resolution: `getaddrinfo`/libresolv on Apple platforms, systemd-resolved DBus on Linux. A new `prefer_go` option is available to opt out. See [Local DNS](https://sing-box.sagernet.org/configuration/dns/server/local/). **13**: The default TCP keep-alive initial period has been updated from 10 minutes to 5 minutes. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#tcp_keep_alive). **14**: Adds the Linux socket option `IP_BIND_ADDRESS_NO_PORT` support when explicitly binding to a source address. This allows reusing the same source port for multiple connections, improving scalability for high-concurrency proxy scenarios. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#bind_address_no_port). **15**: Tailscale endpoint can now create a system TUN interface to handle traffic directly. New `relay_server_port` and `relay_server_static_endpoints` options for incoming relay connections. See [Tailscale endpoint](https://sing-box.sagernet.org/configuration/endpoint/tailscale/). **16**: CCM (Claude Code Multiplexer) service allows you to access your local Claude Code subscription remotely through custom tokens, eliminating the need for OAuth authentication on remote clients. See [CCM](https://sing-box.sagernet.org/configuration/service/ccm). **17**: See [OCM](https://sing-box.sagernet.org/configuration/service/ocm). **18**: Due to maintenance difficulties, sing-box 1.13.0 requires at least Go 1.24 to compile. **19**: Due to maintenance difficulties, sing-box 1.13.0 will be the last version to support Android 5.0, and only through a separate legacy build (with `-legacy-android-5` suffix). For standalone binaries, the minimum Android version has been raised to Android 6.0, since Termux requires Android 7.0 or later. **20**: This update fixes missing padding extension for Chrome 120+ fingerprints. Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities. uTLS is not recommended for censorship circumvention due to fundamental architectural limitations; use NaiveProxy instead for TLS fingerprint resistance. - Feb 21, 2026 1.13.0-rc.5## :memo: Release Notes * Add `mipsle`, `mips64le`, `riscv64` and `loong64` support for NaiveProxy outbound Important changes since 1.12: * Add NaiveProxy outbound **1** * Add pre-match support for `auto_redirect` **2** * Improve `auto_redirect` **3** * Add Chrome Root Store certificate option **4**
More…
* Add new options for ACME DNS-01 challenge providers **5** * Add Wi-Fi state support for Linux and Windows **6** * Add curve preferences, pinned public key SHA256, mTLS and ECH `query_server_name` for TLS options **7** * Add kTLS support **8** * Add ICMP echo (ping) proxy support **9** * Add `interface_address`, `network_interface_address` and `default_interface_address` rule items **10** * Add `preferred_by` route rule item **11** * Improve `local` DNS server **12** * Add `disable_tcp_keep_alive`, `tcp_keep_alive` and `tcp_keep_alive_interval` options for listen and dial fields **13** * Add `bind_address_no_port` option for dial fields **14** * Add system interface and relay server options for Tailscale endpoint **15** * Add Claude Code Multiplexer service **16** * Add OpenAI Codex Multiplexer service **17** * Apple/Android: Refactor GUI * Apple/Android: Add support for sharing configurations via [QRS](https://github.com/qifi-dev/qrs) * Android: Add support for resisting VPN detection via Xposed * Drop support for go1.23 **18** * Drop support for Android 5.0 **19** * Update uTLS to v1.8.2 **20** * Update quic-go to v0.59.0 * Update gVisor to v20250811 * Update Tailscale to v1.92.4 **1**: NaiveProxy outbound now supports QUIC, ECH, UDP over TCP, and configurable QUIC congestion control. Only available on Apple platforms, Android, Windows and some Linux architectures. Each Windows release includes `libcronet.dll` — ensure this file is in the same directory as `sing-box.exe` or in a directory listed in `PATH`. See [NaiveProxy outbound](https://sing-box.sagernet.org/configuration/outbound/naive/). **2**: `auto_redirect` now allows you to bypass sing-box for connections based on routing rules. A new rule action `bypass` is introduced to support this feature. When matched during pre-match, the connection will bypass sing-box and connect directly. This feature requires Linux with `auto_redirect` enabled. See [Pre-match](https://sing-box.sagernet.org/configuration/shared/pre-match/) and [Rule Action](https://sing-box.sagernet.org/configuration/route/rule_action/#bypass). **3**: `auto_redirect` now rejects MPTCP connections by default to fix compatibility issues. You can change it to bypass sing-box via the new `exclude_mptcp` option. Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default), ensuring traffic is routed to the sing-box table when no route is found in system tables. The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768). See [TUN](https://sing-box.sagernet.org/configuration/inbound/tun/#exclude_mptcp). **4**: Adds `chrome` as a new certificate store option alongside `mozilla`. Both stores filter out China-based CA certificates. See [Certificate](https://sing-box.sagernet.org/configuration/certificate/#store). **5**: See [DNS-01 Challenge](https://sing-box.sagernet.org/configuration/shared/dns01_challenge/). **6**: sing-box can now monitor Wi-Fi state on Linux and Windows to enable routing rules based on `wifi_ssid` and `wifi_bssid`. See [Wi-Fi State](https://sing-box.sagernet.org/configuration/shared/wifi-state/). **7**: See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **8**: Adds `kernel_tx` and `kernel_rx` options for TLS inbound. Enables kernel-level TLS offloading via `splice(2)` on Linux 5.1+ with TLS 1.3. See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **9**: sing-box can now proxy ICMP echo (ping) requests. A new `icmp` network type is available for route rules. Supported from TUN, WireGuard and Tailscale inbounds to Direct, WireGuard and Tailscale outbounds. The `reject` action can also reply to ICMP echo requests. **10**: New rule items for matching based on interface IP addresses, available in route rules, DNS rules and rule-sets. **11**: Matches outbounds' preferred routes. For Tailscale: MagicDNS domains and peers' allowed IPs. For WireGuard: peers' allowed IPs. **12**: The `local` DNS server now uses platform-native resolution: `getaddrinfo`/libresolv on Apple platforms, systemd-resolved DBus on Linux. A new `prefer_go` option is available to opt out. See [Local DNS](https://sing-box.sagernet.org/configuration/dns/server/local/). **13**: The default TCP keep-alive initial period has been updated from 10 minutes to 5 minutes. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#tcp_keep_alive). **14**: Adds the Linux socket option `IP_BIND_ADDRESS_NO_PORT` support when explicitly binding to a source address. This allows reusing the same source port for multiple connections, improving scalability for high-concurrency proxy scenarios. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#bind_address_no_port). **15**: Tailscale endpoint can now create a system TUN interface to handle traffic directly. New `relay_server_port` and `relay_server_static_endpoints` options for incoming relay connections. See [Tailscale endpoint](https://sing-box.sagernet.org/configuration/endpoint/tailscale/). **16**: CCM (Claude Code Multiplexer) service allows you to access your local Claude Code subscription remotely through custom tokens, eliminating the need for OAuth authentication on remote clients. See [CCM](https://sing-box.sagernet.org/configuration/service/ccm). **17**: See [OCM](https://sing-box.sagernet.org/configuration/service/ocm). **18**: Due to maintenance difficulties, sing-box 1.13.0 requires at least Go 1.24 to compile. **19**: Due to maintenance difficulties, sing-box 1.13.0 will be the last version to support Android 5.0, and only through a separate legacy build (with `-legacy-android-5` suffix). For standalone binaries, the minimum Android version has been raised to Android 6.0, since Termux requires Android 7.0 or later. **20**: This update fixes missing padding extension for Chrome 120+ fingerprints. Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities. uTLS is not recommended for censorship circumvention due to fundamental architectural limitations; use NaiveProxy instead for TLS fingerprint resistance. - Feb 15, 2026 1.12.22## :memo: Release Notes * Fixes and improvements
- Feb 9, 2026 1.13.0-rc.3## :memo: Release Notes * Fixes and improvements Important changes since 1.12: * Add NaiveProxy outbound **1** * Add pre-match support for `auto_redirect` **2** * Improve `auto_redirect` **3** * Add Chrome Root Store certificate option **4**
More…
* Add new options for ACME DNS-01 challenge providers **5** * Add Wi-Fi state support for Linux and Windows **6** * Add curve preferences, pinned public key SHA256, mTLS and ECH `query_server_name` for TLS options **7** * Add kTLS support **8** * Add ICMP echo (ping) proxy support **9** * Add `interface_address`, `network_interface_address` and `default_interface_address` rule items **10** * Add `preferred_by` route rule item **11** * Improve `local` DNS server **12** * Add `disable_tcp_keep_alive`, `tcp_keep_alive` and `tcp_keep_alive_interval` options for listen and dial fields **13** * Add `bind_address_no_port` option for dial fields **14** * Add system interface and relay server options for Tailscale endpoint **15** * Add Claude Code Multiplexer service **16** * Add OpenAI Codex Multiplexer service **17** * Apple/Android: Refactor GUI * Apple/Android: Add support for sharing configurations via [QRS](https://github.com/qifi-dev/qrs) * Android: Add support for resisting VPN detection via Xposed * Drop support for go1.23 **18** * Drop support for Android 5.0 **19** * Update uTLS to v1.8.2 **20** * Update quic-go to v0.59.0 * Update gVisor to v20250811 * Update Tailscale to v1.92.4 **1**: NaiveProxy outbound now supports QUIC, ECH, UDP over TCP, and configurable QUIC congestion control. Only available on Apple platforms, Android, Windows and some Linux architectures. Each Windows release includes `libcronet.dll` — ensure this file is in the same directory as `sing-box.exe` or in a directory listed in `PATH`. See [NaiveProxy outbound](https://sing-box.sagernet.org/configuration/outbound/naive/). **2**: `auto_redirect` now allows you to bypass sing-box for connections based on routing rules. A new rule action `bypass` is introduced to support this feature. When matched during pre-match, the connection will bypass sing-box and connect directly. This feature requires Linux with `auto_redirect` enabled. See [Pre-match](https://sing-box.sagernet.org/configuration/shared/pre-match/) and [Rule Action](https://sing-box.sagernet.org/configuration/route/rule_action/#bypass). **3**: `auto_redirect` now rejects MPTCP connections by default to fix compatibility issues. You can change it to bypass sing-box via the new `exclude_mptcp` option. Adds a fallback iproute2 rule checked after system default rules (32766: main, 32767: default), ensuring traffic is routed to the sing-box table when no route is found in system tables. The rule index can be customized via `auto_redirect_iproute2_fallback_rule_index` (default: 32768). See [TUN](https://sing-box.sagernet.org/configuration/inbound/tun/#exclude_mptcp). **4**: Adds `chrome` as a new certificate store option alongside `mozilla`. Both stores filter out China-based CA certificates. See [Certificate](https://sing-box.sagernet.org/configuration/certificate/#store). **5**: See [DNS-01 Challenge](https://sing-box.sagernet.org/configuration/shared/dns01_challenge/). **6**: sing-box can now monitor Wi-Fi state on Linux and Windows to enable routing rules based on `wifi_ssid` and `wifi_bssid`. See [Wi-Fi State](https://sing-box.sagernet.org/configuration/shared/wifi-state/). **7**: See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **8**: Adds `kernel_tx` and `kernel_rx` options for TLS inbound. Enables kernel-level TLS offloading via `splice(2)` on Linux 5.1+ with TLS 1.3. See [TLS](https://sing-box.sagernet.org/configuration/shared/tls/). **9**: sing-box can now proxy ICMP echo (ping) requests. A new `icmp` network type is available for route rules. Supported from TUN, WireGuard and Tailscale inbounds to Direct, WireGuard and Tailscale outbounds. The `reject` action can also reply to ICMP echo requests. **10**: New rule items for matching based on interface IP addresses, available in route rules, DNS rules and rule-sets. **11**: Matches outbounds' preferred routes. For Tailscale: MagicDNS domains and peers' allowed IPs. For WireGuard: peers' allowed IPs. **12**: The `local` DNS server now uses platform-native resolution: `getaddrinfo`/libresolv on Apple platforms, systemd-resolved DBus on Linux. A new `prefer_go` option is available to opt out. See [Local DNS](https://sing-box.sagernet.org/configuration/dns/server/local/). **13**: The default TCP keep-alive initial period has been updated from 10 minutes to 5 minutes. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#tcp_keep_alive). **14**: Adds the Linux socket option `IP_BIND_ADDRESS_NO_PORT` support when explicitly binding to a source address. This allows reusing the same source port for multiple connections, improving scalability for high-concurrency proxy scenarios. See [Dial Fields](https://sing-box.sagernet.org/configuration/shared/dial/#bind_address_no_port). **15**: Tailscale endpoint can now create a system TUN interface to handle traffic directly. New `relay_server_port` and `relay_server_static_endpoints` options for incoming relay connections. See [Tailscale endpoint](https://sing-box.sagernet.org/configuration/endpoint/tailscale/). **16**: CCM (Claude Code Multiplexer) service allows you to access your local Claude Code subscription remotely through custom tokens, eliminating the need for OAuth authentication on remote clients. See [CCM](https://sing-box.sagernet.org/configuration/service/ccm). **17**: See [OCM](https://sing-box.sagernet.org/configuration/service/ocm). **18**: Due to maintenance difficulties, sing-box 1.13.0 requires at least Go 1.24 to compile. **19**: Due to maintenance difficulties, sing-box 1.13.0 will be the last version to support Android 5.0, and only through a separate legacy build (with `-legacy-android-5` suffix). For standalone binaries, the minimum Android version has been raised to Android 6.0, since Termux requires Android 7.0 or later. **20**: This update fixes missing padding extension for Chrome 120+ fingerprints. Also, documentation has been updated with a warning about uTLS fingerprinting vulnerabilities. uTLS is not recommended for censorship circumvention due to fundamental architectural limitations; use NaiveProxy instead for TLS fingerprint resistance.