restic/restic
68.9
Adequate · 24 September 2026
41.5k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a command-line backup tool that creates encrypted, deduplicated snapshots of data and stores them across various local and cloud storage backends. It supports multiple cloud providers including Azure, Google Cloud, S3, and SFTP, while offering features like compression, rate limiting, and resumable operations. The tool provides comprehensive management capabilities for snapshots, including retention policies, integrity checking, and repair of corrupted data.
How it got here
2014–2017 — Backend expansion and architectural modernization
33 changes.
This period focused on significantly expanding cloud storage support by adding native backends for Azure, Google Cloud, and Backblaze B2, while refactoring the core archiver and repository layers for better modularity and performance. The codebase underwent extensive structural improvements, including the introduction of a new FUSE implementation, a unified file system abstraction, and a standardized migration framework, alongside comprehensive updates to developer tooling and documentation.
2018–2021 — Backend expansion and UI modernization
27 changes.
This period focused on significantly expanding storage capabilities by introducing rclone backend support and enhancing existing cloud integrations, alongside a major overhaul of the user interface with new terminal status, progress reporting, and table rendering components. The codebase also saw substantial internal refactoring, including a multithreaded restorer, a new tree walker for snapshot modification, and improved release automation tools. These changes were accompanied by numerous bug fixes and performance optimizations across backup, restore, and check operations.
2022–2024 — Backend architecture and performance overhaul
25 changes.
This period focused on a comprehensive restructuring of the backend layer, introducing concurrency limits, rate limiting, retry mechanisms, and a local metadata cache to improve reliability and performance. Significant architectural changes included the adoption of repository format v2 with compression, a rewrite of index data structures for memory efficiency, and the extraction of layout logic into dedicated packages. The work also involved stabilizing the codebase through extensive bug fixes, platform-specific improvements for Windows and macOS, and the introduction of feature flags to manage deprecations and new capabilities.
2025–2026 — internal refactoring and crypto integration
7 changes.
This period focused on restructuring the codebase by introducing dedicated internal packages for data structures, cryptographic operations, and backend registries to centralize core logic. It also involved improving terminal interaction robustness, enforcing strict validation for configuration environment variables, and isolating progress reporting for specific commands. The work concluded with bug fixes addressing regressions in stats, snapshots, and mount commands.
Features
Add Azure Blob Storage backend
Users can now store backups in Azure Blob Storage by using the \azure:\ URL scheme. This new backend supports authentication via account keys, Shared Access Signatures (SAS/SAT tokens), and Azure CLI/Default credentials, and allows configuration of the storage account container, access tier (Hot, Cool, Cold, Archive), and connection limits.
internal/backend/azure · high confidence
Add Backblaze B2 backend support
Users can now store backups on Backblaze B2 cloud storage. This change introduces a new backend implementation using the official Backblaze Go library (Backblaze/blazer), supporting configuration via the \b2:\ URI scheme and environment variables for account credentials. It includes features such as configurable connection limits, bucket name validation, and proper handling of file deletion and existence checks.
internal/backend/b2 · high confidence
Add Google Cloud Storage backend
Users can now store backups in Google Cloud Storage (GCS). This change introduces a new backend implementation that supports configuration via the \gs:\ URI scheme, allowing specification of the bucket name, prefix, region, and connection limits. Authentication is handled automatically using Google's default application credentials or an explicit access token provided via the \GOOGLE\_ACCESS\_TOKEN\ environment variable, eliminating the need for manual credential management in most cases.
internal/backend/gs · high confidence
Add changelog generation templates for Markdown and GitHub releases
The changelog tooling now includes three new template files to structure release notes. The \CHANGELOG.tmpl\ generates a Markdown changelog with a table of contents, summary, and detailed entries including issue and PR links. The \TEMPLATE\ file provides a style guide for contributors on how to write changelog entries, specifying formatting rules for bugfixes, enhancements, and breaking changes. The \changelog-github.tmpl\ generates a GitHub release note format with similar structure but adapted for GitHub's markdown rendering, including hyperlinked issue and PR references.
changelog · high confidence
Add configurable rate limiting for backend I/O operations
The backend now supports rate limiting for uploads and downloads via a new \internal/backend/limiter\ package. This introduces a \Limiter\ interface and a \staticLimiter\ implementation that uses \golang.org/x/time/rate\ to cap throughput based on configurable KB/s limits for upstream (upload) and downstream (download) traffic. The limiter wraps the backend's \Save\ and \Load\ methods to throttle data streams and provides an HTTP \Transport\ wrapper to limit network requests, allowing users to control bandwidth usage during backup and restore operations.
internal/backend/limiter · high confidence
Add dry-run mode to backup command
Users can now use the --dry-run/-n flag with the backup command to preview what changes would be made without actually modifying the repository. This is implemented via a new dryrun backend that passes through read operations (List, Load, Stat) to the underlying storage while silently ignoring write operations (Save, Remove, Delete), allowing the system to validate logic and report actions without persisting data.
internal/backend/dryrun · high confidence
Add in-memory backend for testing
A new in-memory backend implementation has been added to the internal backend suite, allowing tests to run against a mock storage layer that keeps all data in RAM rather than on disk. This backend supports standard operations like Save, Load, Stat, Remove, and List, and is registered via a factory for use in the generic backend test suite.
internal/backend/mem · high confidence
Add internal table rendering component
Introduces a new internal \table\ package that provides a structured way to render tabular data in the CLI. The component supports defining columns with Go template formatting, adding rows of arbitrary data, and appending footers. It handles complex layout requirements such as multi-line cell content, variable column widths based on display width, and customizable separators for headers, data, and footers.
internal/ui/table · high confidence
Add rclone backend support
Users can now use rclone as a backend for restic, enabling access to any storage system supported by rclone (such as B2, S3, or local filesystems) via a stdio connection. This new backend allows configuration of the rclone program path, command-line arguments, connection limits, and timeouts, and includes robust error handling for subprocess lifecycle events.
internal/backend/rclone · high confidence
Added RPM spec file for restic
A new \restic.spec\ file has been added to the \contrib\ directory to enable building RPM packages for restic. The spec file defines the build process, dependencies (such as Go and bash), and installation paths for binaries, man pages, and shell completions (zsh, fish, bash). It also includes a changelog noting a compatibility fix for RHEL 6 by replacing the \%license\ macro with \%doc\.
contrib · high confidence
Debug logging added to backend operations
A new logger backend wrapper has been introduced in the internal/backend/logger package that intercepts all backend operations (such as Save, Load, Remove, List, and Close) to emit debug logs for each call and its result. This change allows users to enable detailed debug tracing for backend interactions without modifying the underlying backend implementations.
internal/backend/logger · high confidence
Introduce feature flag system for controlled deprecations and new capabilities
A new internal feature flag system has been added to manage the lifecycle of repository formats and backend behaviors. This allows users to control specific changes through configuration flags, such as enabling the new S3 restore capability (cold storage support) or explicitly requesting the new S3 anonymous authentication behavior. The system also enforces the deprecation of legacy index formats and S3 legacy layouts, ensuring they are disabled by default while providing a mechanism for users to opt-in if necessary during migration.
internal/feature · high confidence
Introduce internal repository crypto package
The repository now includes a new internal package at internal/repository/crypto that provides the core cryptographic operations for restic. This package implements AES-256 encryption with Poly1305 authentication, manages key structures (including JSON serialization for storage), and handles key derivation using scrypt with hardware-calibrated parameters. It also includes utilities for buffer management and nonce generation, along with comprehensive tests verifying encryption/decryption integrity and authentication.
internal/repository/crypto · high confidence
Introduce internal/fs package with cross-platform file system abstraction
The internal/fs package provides a unified, OS-independent abstraction for file system operations, replacing direct stdlib usage in the backup and restore workflows. It introduces a local file system implementation that handles long paths on Windows via the \\\?\\\ prefix and supports Volume Shadow Copy (VSS) snapshots for reading locked files, configurable via \vss.timeout\, \vss.provider\, and \vss.exclude-volumes\ options. The package also implements a dedicated \fileio\ sub-package for platform-specific temporary file creation (using delete-on-close flags on Windows) and file pre-allocation (using \fallocate\ on Linux and \F\_PREALLOCATE\ on macOS). Additionally, it includes a \Reader\ implementation for in-memory testing and a \CommandReader\ for streaming data from external commands, ensuring consistent error handling and metadata access across all supported platforms.
internal/fs · high confidence
Introduce local backend cache for snapshots, indexes, and metadata packs
A new local caching layer has been added to the backend system to automatically store and serve snapshot, index, and metadata pack files from a local directory. This reduces network round-trips by keeping frequently accessed data locally, with the cache location configurable via the RESTIC\_CACHE\_DIR environment variable or falling back to the OS default. The implementation includes automatic cache management, concurrent download coordination to avoid redundant network requests, and safe file operations for multi-process environments.
internal/backend/cache · high confidence
Introduce official Docker images with integrated nice/ionice support
Adds official Docker build files (Dockerfile, Dockerfile.release) and an entrypoint script that allows users to run restic in containers with integrated nice and ionice options. The entrypoint script handles busybox-specific quirks by conditionally applying ionice and nice commands based on environment variables, ensuring proper I/O and CPU scheduling within the containerized environment.
docker · high confidence
Introduce self-update command with secure GitHub release handling
Users can now update restic to the latest stable version directly via a new self-update command. The implementation fetches the latest release from GitHub, verifies the SHA256SUMS file using GPG signatures (via ProtonMail/go-crypto), and validates the downloaded binary's hash before installation. On Windows, the update process handles locked binaries by renaming the current executable to a backup file before replacing it, while Unix systems remove the old binary atomically. The update process also supports private repositories or rate-limit avoidance by reading a personal access token from the GITHUB\_ACCESS\_TOKEN environment variable.
internal/selfupdate · high confidence
Introduce termstatus for interactive terminal status updates
Added a new internal/ui/termstatus package that manages interactive status lines and progress output. It detects whether the output is a terminal to enable in-place status updates (clearing and redrawing lines) or falls back to standard sequential printing when output is redirected. The implementation includes a background goroutine to handle screen updates, thread-safe output via a line-buffered writer, and specific handling for password input and error reporting, ensuring status messages are suppressed or formatted correctly in non-interactive or quiet modes.
internal/ui/termstatus · high confidence
Introduce tree walker and rewriter for snapshot modification
The internal/walker package now provides a new tree walker and a tree rewriter. The walker traverses repository trees, passing the parent tree ID to the visitor callback and supporting a callback for when a directory is left. The rewriter allows nodes to be modified or removed during traversal, with options to keep or discard empty directories and to handle failed tree loads. Tests verify the correct traversal order, parent ID propagation, skipping behavior, and node modification.
internal/walker · high confidence
New UI formatting and terminal abstraction layer
The internal/ui package now provides a centralized set of formatting utilities (FormatBytes, FormatPercent, FormatDuration, ParseBytes) and terminal-aware string helpers (DisplayWidth, Quote, Truncate) that correctly handle multi-byte Unicode characters for accurate table padding and text truncation. Additionally, a new Terminal interface and MockTerminal implementation have been introduced to standardize how the application interacts with the terminal for printing, error reporting, status updates, and password input, replacing previous ad-hoc output mechanisms.
internal/ui · high confidence
New archiver implementation for backup operations
The internal/archiver package has been replaced with a new implementation that handles reading files, splitting them into chunks, and saving data to the repository. This new archiver introduces a worker-based architecture with separate fileSaver, blobSaver, and treeSaver components to manage concurrent saving of data structures. It includes a new Scanner for traversing backup targets, improved exclusion logic via RejectFunc and RejectByNameFunc, and a buffer pool for memory-efficient file reading. The new system also adds support for tracking change detection flags (ctime and inode), storing device IDs for hardlinks, and providing detailed item statistics during backup.
internal/archiver · high confidence
New backend utility helpers for default operations and file permissions
The internal/backend/util package now provides reusable helper functions for backend implementations. DefaultLoad standardizes the logic for loading data by handling reader lifecycle and error propagation, while DefaultDelete simplifies repository cleanup by removing all standard file types (packs, keys, locks, snapshots, indexes, and config). Additionally, LimitReadCloser wraps io.LimitedReader to support closing underlying resources, and DeriveModesFromFileInfo calculates appropriate file and directory permissions based on existing file modes, defaulting to 0700/0600 if information is unavailable.
internal/backend/util · high confidence
New data package for core backup structures and snapshot management
The internal/data package has been introduced to centralize core data structures and logic previously scattered in the restic package. This includes definitions for Node (file metadata), Snapshot (backup state), and ExpirePolicy (retention rules), along with utilities for parsing durations, finding used blobs, and grouping snapshots. The package also provides a HardlinkIndex for tracking hard links and implements snapshot filtering and policy application, forming the foundational data layer for the backup system.
internal/data · high confidence
New internal LRU blob cache with race-free concurrent computation
The dump command now uses a new internal LRU cache (internal/bloblru) backed by hashicorp/golang-lru/v2 to store blob contents in memory. This cache enforces a byte-size limit by checking buffer capacity rather than length, and provides a GetOrCompute method that ensures the underlying data is fetched only once even when multiple goroutines request the same blob concurrently, preventing redundant work and race conditions.
internal/bloblru · high confidence
New internal debug logging infrastructure with HTTP request tracing and credential redaction
The internal/debug package has been introduced to provide a centralized infrastructure for debug logging and HTTP request tracing. This change adds an HTTP RoundTripper that logs outgoing requests and responses, automatically redacting sensitive headers such as Authorization, X-Auth-Token, and X-Auth-Key to prevent credential leakage in logs. The system supports configurable logging via the DEBUG\_LOG environment variable, allows filtering by function or file patterns using DEBUG\_FUNCS and DEBUG\_FILES, and includes a mechanism to print stacktraces on SIGINT when RESTIC\_DEBUG\_STACKTRACE\_SIGINT is set. Additionally, it provides utilities for testing, such as directing debug output to stderr, and ensures that debug logging overhead is minimized when the feature is disabled.
internal/debug · high confidence
New internal options parsing and secret redaction utilities
The internal/options package now provides a structured way to define, parse, and apply configuration options via reflection, supporting namespaces, key-value parsing, and automatic application to struct fields (including strings, integers, and booleans). It also introduces a SecretString type that safely redacts sensitive values in debug logs and string representations to prevent accidental exposure.
internal/options · high confidence
New release binary build helper tool
A new Go-based helper script (helpers/build-release-binaries) has been introduced to automate the cross-compilation and packaging of release binaries. This tool supports building for multiple operating systems and architectures, including Linux (riscv64, s390x, ARMv5/6), Darwin (ARM64 for Apple M1), Windows, DragonflyBSD, and others. It incorporates build tags to disable GRPC modules, reducing binary size, and handles compression (zip for Windows, bzip2 for others) and versioning of the output files.
helpers/build-release-binaries · high confidence
New release preparation helper script
A new Go-based helper script at helpers/prepare-release has been added to streamline the release process. It provides command-line flags to validate the release environment, including checks for the current branch (defaulting to master), uncommitted changes, existing version tags, and changelog status. The script also handles generating the CHANGELOG.md, creating versioned changelog subdirectories, and removing old changelog files, ensuring a consistent and verified state before a release is finalized.
helpers/prepare-release · high confidence
New release verification helper script
Added a new helper script (verify-release-binaries.sh) that automates the verification of release binaries by checking SHA256 sums, validating GPG signatures, reproducing binaries from source, and verifying Docker container contents.
helpers · high confidence
New textfile package for encoding-aware file reading
Added a new internal textfile package that provides a Read function to load file contents as UTF-8 text. This utility automatically detects and strips Byte Order Marks (BOM) from UTF-8, UTF-16 Big Endian, and UTF-16 Little Endian files, ensuring consistent text output regardless of the source file's encoding. Tests confirm correct handling of plain ASCII, UTF-8 with BOM, and UTF-16 encoded content.
internal/textfile · high confidence
REST backend implements API v2 and supports Unix sockets
The REST backend has been updated to implement the REST API v2 protocol, which changes the HTTP content type negotiation and response format (e.g., listing files now returns JSON objects with name and size instead of just hashes, reducing HTTP requests). Additionally, the backend now supports connecting to REST servers via Unix domain sockets using the \http+unix://\ scheme, and configuration values for username and password can now be read from environment variables (\RESTIC\_REST\_USERNAME\, \RESTIC\_REST\_PASSWORD\) if not explicitly provided in the URL.
internal/backend/rest · high confidence
Restic 0.13.0 release notes
This entry documents the changelog for version 0.13.0, which includes a \--dry-run\ option for the \backup\ command, upload checksums for Azure, GS, S3, and Swift backends, support for negative include/exclude patterns, and a crash-resistant cache. It also fixes repository locking behavior for \list locks\ and \copy\, improves error handling for S3 credentials and B2 SSL errors, and adds JSON output and quiet mode to the \diff\ command. Additional changes include atomic uploads for SFTP, xattr support for Solaris, and a requirement for Go 1.14 or newer.
_changelog/0.13.0\2022-03-26 · high confidence
Structured JSON progress output for restore operations
The restore command now supports a machine-readable JSON output format for progress tracking. This new feature introduces a dedicated JSON printer that emits structured status updates, including elapsed time, file/byte counts (total, restored, skipped, deleted), and per-item actions (restored, updated, unchanged, deleted) at high verbosity levels. A corresponding summary is printed upon completion. This structured output is designed for integration with external monitoring tools or scripts, complementing the existing human-readable text progress bar.
internal/ui/restore · high confidence
Removals
Removal of hashing package
The hashing package, which previously provided Reader and Writer wrappers to compute hashes (MD5, SHA1) while streaming data, has been removed from the codebase. This change eliminates the ability to use these specific streaming hash utilities for data ingestion and output.
hashing · high confidence
Architecture
Checker logic moved to internal/checker package
The repository checking functionality has been reorganized by moving the core checker implementation into a new \internal/checker\ package. This change introduces a dedicated \Checker\ struct that encapsulates the logic for validating repository structure, pack integrity, and unused blobs, separating it from the main repository package. The update includes corresponding test coverage in \checker\_test.go\ and a helper utility in \testing.go\ to facilitate testing of the checker against repository fixtures.
internal/checker · high confidence
Layout logic extracted into a dedicated subpackage
The code responsible for computing file storage paths has been moved from the backend package into a new \internal/backend/layout\ subpackage. This change introduces a \Layout\ interface and concrete implementations (\DefaultLayout\ for local/SFTP backends and \RESTLayout\ for the REST protocol) that determine how files like packs, snapshots, and indexes are organized on disk or in URLs. The \DefaultLayout\ continues to use two-character subdirectories for pack files, while \RESTLayout\ maps file types to specific URL paths. Comprehensive tests have been added to verify path generation for both layouts.
internal/backend/layout · high confidence
Repository package refactored into modular sub-packages
The internal/repository package has been reorganized into distinct sub-packages (checker, chunker, crypto, debug, filetype, hashing, index, lock, pack) to improve code structure and maintainability. This change introduces a new Checker component for validating repository integrity, a dedicated ChunkerFactory for managing data chunking, and a new hashing utility package for transparent data hashing. Additionally, lock management and debug inspection tools have been moved into their own focused modules, separating core repository logic from auxiliary capabilities.
internal/repository · high confidence
Restructure cmd/restic into modular command files
The cmd/restic package has been reorganized from a monolithic structure into distinct, modular files (e.g., cleanup.go, cmd\_backup.go). This change introduces a dedicated cleanup handler for signal management (SIGINT/SIGTERM) and implements the backup command using a structured options pattern with Cobra, improving code maintainability and separation of concerns without altering user-facing behavior.
cmd/restic · high confidence
Behavioural changes
Azure CLI credential override and dependency updates
Users can now force the use of Azure CLI credentials by setting the environment variable AZURE\_FORCE\_CLI\_CREDENTIAL=true, which ignores other credential sources like managed identity. Additionally, several potentially vulnerable dependencies have been updated to address security concerns.
_changelog/0.16.5\2024-07-01 · high confidence
Backend HTTP transport enhancements and interface restructuring
The backend package has been restructured with the \Backend\ interface moved to \internal/backend/backend.go\, introducing \Warmup\ and \WarmupWait\ methods for cold-storage optimization and a \Properties\ struct to expose backend capabilities like atomic replace support. HTTP transport now supports custom User-Agent headers, TLS client certificate authentication, and configurable root CA certificates. A new watchdog round-tripper cancels stuck HTTP requests after a configurable timeout (defaulting to 5 minutes), and HTTP/2 connection health checks are enabled when the \backend-error-redesign\ feature flag is active.
internal/backend · high confidence
Backend operations are now limited by concurrency and can be frozen
The backend layer now enforces a limit on concurrent operations (Save, Load, Stat, Remove) based on the backend's configured connection count, ensuring that only a specific number of requests run simultaneously. Lock file operations are exempt from this limit to guarantee that lock refreshes can always proceed. Additionally, a new freeze mechanism allows all non-lock backend operations to be temporarily paused, which is used to prevent interference while stale locks are being refreshed.
internal/backend/sema · high confidence
Bug fixes for Windows file handling, rclone reliability, and restore accuracy
This release addresses several stability and correctness issues. On Windows, error messages for irregular files (reparse points) are now more descriptive, and support for backing up deduplicated files has been restored by updating the Go version. The rclone backend now handles listing errors more robustly to prevent potential data loss during pruning. Additionally, the restore command provides more accurate progress information when errors occur and includes special handling for large files with repeated chunks to prevent network timeouts and incomplete restores.
_changelog/0.16.3\2024-01-14 · high confidence
Bug fixes for rclone bandwidth limits, Azure large file uploads, find command accuracy, and caching/deadlock issues
This release includes several bug fixes: the rclone backend now respects --limit-upload and --limit-download flags; large file uploads to MS Azure are supported by chunking uploads into 100MiB blocks to comply with API limits; the find command no longer skips snapshots containing unmodified directories and now supports glob patterns like \\; file caching errors during check are handled correctly across threads; and a deadlock in the scanning process that could halt backups is resolved.
_changelog/0.9.1\2018-06-10 · high confidence
Bug fixes for restic 0.19.1
This release addresses several regressions introduced in 0.19.0: the \stats\ command no longer displays a progress bar in JSON mode; \snapshots --latest\ restores its default grouping by host and paths when \--group-by\ is not specified; the SFTP backend on Windows now clears the read-only flag before removing files; \backup\ correctly respects exclude patterns for duplicate directory entries and skips inaccessible source paths; the \mount\ command prevents deadlocks by refusing to mount over the repository directory, updates the \latest\ symlink after snapshot reloads, and handles inaccessible mountpoints gracefully without crashing; and \snapshots\ output now uses a consistent timezone label.
_changelog/0.19.1\2026-07-05 · high confidence
Data integrity enhancements and zstd downgrade
Restic now performs extra verification of data integrity before uploading files to detect corruption caused by hardware issues or software bugs, a feature that increases CPU usage during backups but can be disabled with the \--no-extra-verify\ option. Additionally, the zstd library has been downgraded to the version used in 0.16.2 to fix rare data corruption that could occur when using maximum compression (\--compression max\), while the default \auto\ compression level remains unaffected.
_changelog/0.16.4\2024-02-04 · high confidence
Documentation restructured into Sphinx format
The documentation has been reorganized into a new Sphinx-based structure, replacing the previous layout. This change introduces a new set of reStructuredText source files (010\_introduction.rst through 050\_restore.rst) and a .gitignore file to manage build artifacts, providing a more modular and maintainable documentation foundation for users.
doc · high confidence
Enhancements and bug fixes for version 0.7.1
This release introduces several enhancements and fixes for the restic backup tool. The local and SFTP backends now automatically create subdirectories below the data directory upon initialization to ensure they exist. S3 backend users can now load credentials from an IAM instance profile when environment variables are not specified. The \migrate\ command for converting S3 repositories from the \s3legacy\ layout to the \default\ layout has been improved with restart capability and automatic error retries. Additionally, the \forget\ command's \--tag\ semantic has been clarified, chmod errors are ignored on unsupported filesystems, and statistics are printed on SIGINFO (Ctrl+T) for Darwin and FreeBSD. A bug in the \prune\ command that caused indexes to include non-existent blobs has been fixed.
_changelog/0.7.1\2017-07-22 · high confidence
Extracted OS-specific signal handling into a dedicated internal package
The codebase now includes a new \internal/ui/signals\ package that centralizes the management of process signals for UI progress reporting. This package provides a \GetProgressChannel\ function that returns a channel for receiving signals, ensuring that only a single listener receives each incoming signal via a global singleton pattern. The implementation is platform-aware: BSD systems (Darwin, FreeBSD, etc.) listen for \SIGINFO\ and \SIGUSR1\, System V systems (Linux, AIX, Solaris) listen for \SIGUSR1\, and Windows provides an empty implementation. This refactoring isolates the signal-handling logic from the rest of the UI code, making the signal reception mechanism explicit and maintainable.
internal/ui/signals · high confidence
Fail fast on invalid RESTIC\_PACK\_SIZE and RESTIC\_COMPRESSION environment variables
Restic now immediately aborts if the RESTIC\_PACK\_SIZE or RESTIC\_COMPRESSION environment variables contain invalid values, rather than proceeding with incorrect settings. This prevents backups from running for extended periods with misconfigured pack sizes or compression modes, ensuring users are notified of configuration errors early.
internal/global · high confidence
Improved terminal interaction and background process handling
The terminal package now provides robust support for running backend commands in the foreground, ensuring that interactive prompts (like password entry) work correctly even when the main process is backgrounded. This includes new logic to detect if the process is running in the background, manage terminal process groups to prevent suspension, and securely strip RESTIC\\ environment variables from child processes. Additionally, status line updates and cursor movements are now handled with platform-specific optimizations for both Unix and Windows (including Cygwin/Mintty detection), ensuring reliable output in various terminal environments.
internal/terminal · high confidence
Introduce structured repository migration framework
The internal/migrations package now provides a standardized interface for applying data migrations to repositories. This includes a new UpgradeRepoV2 migration that automatically upgrades repositories from version 1 to version 2, ensuring compatibility with the latest repository format. The migration system supports pre-checks to verify applicability and reports reasons when migrations cannot be applied, improving reliability and user feedback during repository upgrades.
internal/migrations · high confidence
Mock backend now supports warmup and property inspection
The mock backend implementation in internal/backend/mock has been updated to include support for warmup operations and property inspection. Users can now configure mock backends to simulate warmup and warmup-wait behaviors via the new WarmupFn and WarmupWaitFn callbacks, and can inspect backend properties (such as connection count and atomic replace support) through the PropertiesFn callback. This aligns the mock backend with the updated backend interface that exposes these capabilities.
internal/backend/mock · high confidence
Modernize error handling with Go 1.13 semantics and fatal error support
The internal errors package now adopts Go 1.13-style error handling by exposing standard library functions \Is\, \As\, \Unwrap\, and \Join\, while retaining compatibility wrappers for \New\, \Errorf\, \Wrap\, \Wrapf\, and \WithStack\ from the \github.com/pkg/errors\ library. A new fatal error mechanism has been introduced via the \Fatal\ and \Fatalf\ functions, which create errors marked with a "Fatal" prefix and support underlying error preservation; users can detect these using the new \IsFatal\ helper to trigger appropriate program exits.
internal/errors · high confidence
Multiple enhancements and bug fixes in version 0.12.0
This release introduces several key improvements and fixes across the backup, check, and prune commands. Users can now back up files with special characters more safely using the new \--files-from-verbatim\ and \--files-from-raw\ options, and the \backup\ command offers a new \--ignore-ctime\ flag to skip unnecessary content reads when only metadata changes. The \prune\ command is significantly faster and more customizable, featuring parallelized snapshot scanning, a \--dry-run\ mode, and reduced memory usage. Additionally, the \check\ command now validates index integrity against pack files and supports percentage-based data subset checks. Backend support has been expanded with Alibaba Cloud OSS compatibility for S3, legacy ListObjects fallback for broken S3 implementations, and improved error handling for Google Cloud Storage and rclone connections. Other notable changes include fixing tag parsing to correctly handle comma-separated lists, allowing progress reports on non-interactive terminals, and ensuring mount points are backed up as empty directories.
_changelog/0.12.0\2021-02-14 · high confidence
Multiple enhancements and fixes for backup, repair, and security
This release introduces several improvements and fixes: \restic backup -vv\ now shows excluded files and directories in both text and JSON output; \restic repair snapshots --forget\ allows removal of broken snapshots found by \restic check\; \restic repair packs\ and \restic find --pack\ now handle missing or corrupted packfiles more robustly; the \prune\ command supports \--json\ for statistics; S3 backend \check\ command gains warmup support; the \list packs snapshotID\ command lists packfiles for a snapshot; in-memory index memory usage is reduced by \~12%; a crash on truncated key/config files is fixed to report an error instead; Swift backend passwords are redacted in debug logs; and the self-update GPG verification library is replaced with ProtonMail/go-crypto to address security weaknesses.
changelog/unreleased · high confidence
New memory-efficient index data structures and parallel loading
The repository index has been rewritten with new internal data structures to reduce memory usage and improve performance. A new \AssociatedSet\ type allows storing small data items for each blob handle using a compact array-based approach with an overflow map, supporting set operations like intersection and subtraction. The core \Index\ and \MasterIndex\ now use a custom \indexMap\ backed by a hashed array tree and a bloom filter to speed up unknown blob checks and reduce cache misses. Index files are now loaded in parallel via \ForAllIndexes\, and the system supports incremental index loading, automatic saving of full indexes during pack storage, and handling of oversized indexes.
internal/repository/index · high confidence
New multithreaded file restorer with sparse file and overwrite support
The internal restorer has been replaced with a new, optimized multithreaded implementation that significantly reduces restore times and memory usage. This change introduces support for sparse file restoration on both Unix and Windows, allowing large files with zero-filled regions to consume less disk space. It also adds configurable overwrite behavior (e.g., \--overwrite=if-changed\ to skip files with matching size and mtime) and the ability to recursively delete existing directories or files to replace them with restored content. The new restorer processes packs concurrently and tracks progress more accurately, including handling of hardlinks and deletions.
internal/restorer · high confidence
New retry backend with configurable backoff and error handling
A new \internal/backend/retry\ package provides a wrapper that automatically retries backend operations using exponential backoff. This change introduces a new retry strategy that ensures at least one retry attempt, limits retries based on elapsed time rather than just count, and avoids retrying permanent errors or operations on non-existent files. The implementation also respects context cancellation to prevent unnecessary retries and includes a feature flag (\BackendErrorRedesign\) to control the new behavior, which differs from the previous fixed-retry-count approach.
internal/backend/retry · high confidence
Prepare changelog for 0.17.0
This entry documents the addition of the changelog files for version 0.17.0, which records a wide range of enhancements, bug fixes, and behavioral changes. Key updates include support for repositories with empty passwords via \--insecure-no-password\, a new \--delete\ option for the \restore\ command to remove extraneous files, and resumable \prune\ operations with reduced memory usage. The release also introduces \--stdin-from-command\ for the \backup\ command, FUSE-T support for macOS mounts, and AWS Assume Role capabilities for the S3 backend. Significant backend improvements include redesigned error handling with chunked downloads and retries, while deprecated features include the legacy index format and \s3legacy\ layout. Other notable changes involve Windows-specific enhancements (Shadow Copy configuration, SecurityDescriptor and Extended Attribute support), a new \--overwrite\ option for \restore\, and stricter safety checks for the \forget\ command.
_changelog/0.17.0\2024-07-26 · high confidence
Prepopulated backend registry for unified backend access
The internal/backend/all package now provides a Backends() function that returns a registry pre-registered with all supported storage backends (Azure, B2, Google Cloud Storage, local, rclone, REST, S3, SFTP, and Swift). This allows consumers to easily access a complete set of backend factories without manually registering each one individually.
internal/backend/all · high confidence
Project hygiene and developer tooling configuration
This change introduces foundational configuration files to standardize code quality and development workflows. It adds a \.golangci.yml\ file to configure the \golangci-lint\ static analysis tool, including rules to prevent backend packages from importing internal repository packages and to enforce consistent import aliases. A \.codespellrc\ file is added to configure automated spelling checks, with specific exceptions for technical identifiers and test data. Additionally, a \.dockerignore\ file is introduced to ensure clean Docker builds by excluding unnecessary files, and a \.gitattributes\ file is added to enforce line-ending consistency for fuzz test data, addressing a known Go issue.
(repo-wide) · high confidence
Refactor pack file handling into the internal/repository/pack package
The pack file creation and parsing logic has been moved into a new \internal/repository/pack\ package, introducing dedicated types like \Blob\, \Blobs\, and \PackedBlob\ to manage pack layout information. This change adds a \Sort\ method to \Blobs\ for ordering by offset and implements a \Merge\ capability for the \Packer\ to combine small pack files before flushing. Additionally, the \Packer\ now strictly prevents usage after a write error by returning \ErrBroken\, and new methods like \UncompressedCiphertextLength\ are available on blob types to expose precise size metadata.
internal/repository/pack · high confidence
Refactored backup progress reporting with improved ETA and JSON output
The backup command's progress reporting has been consolidated into the \internal/ui/backup\ package, introducing a new \ProgressPrinter\ interface and dedicated implementations for text and JSON output. This change improves the accuracy of the estimated time of arrival (ETA) by replacing the previous channel-based concurrency model with a mutex-protected state and a new rate estimator that tracks byte transfer speeds over a sliding time window. For users relying on machine-readable output, the JSON summary now includes the full snapshot ID, start and end times, and a renamed \data\_added\_packed\ statistic, while verbose text output now displays the compressed size of added files.
internal/ui/backup · high confidence
Refactored local backend with atomic saves and configurable concurrency
The local repository backend has been restructured to improve reliability and performance. File writes now use atomic operations (writing to a temporary file and renaming) to prevent data corruption, and directory changes are synced to ensure durability. A new configuration option allows users to set the number of concurrent backend operations via the \Connections\ parameter (defaulting to 2). The implementation also includes platform-specific handling for file permissions and directory syncing, such as ignoring unsupported fsync errors on macOS and adjusting read-only behavior on Windows.
internal/backend/local · high confidence
Refactored path filtering with case-insensitive and file-based patterns
The internal filter package has been restructured to support case-insensitive matching and pattern loading from files. Users can now use the --iexclude and --iinclude flags (and their file-based counterparts --iexclude-file and --iinclude-file) to apply filters that ignore filename casing. The filter logic also now supports negative patterns (prefixed with '!') and recursive wildcards ('\\'), with improved validation and optimized matching for complex path structures.
internal/filter · high confidence
Refactored progress reporting with decoupled Counter and Updater components
The internal progress reporting system has been restructured to improve modularity and concurrency safety. A new \Counter\ type now manages atomic value tracking and supports dynamic updates to the maximum expected value via \SetMax\, decoupling the counting logic from the UI display layer. The periodic reporting mechanism has been extracted into a standalone \Updater\ struct, which handles ticker-based updates and signal handling (SIGUSR1/SIGINFO) independently. Additionally, the terminal printer logic has been consolidated into \terminal.go\, ensuring that progress bars are only displayed on interactive terminals and respecting the \RESTIC\_PROGRESS\_FPS\ environment variable for update frequency.
internal/ui/progress · high confidence
Refactored repository location parsing and backend registration
The repository location parsing logic has been restructured to use a centralized registry of backend factories. The new \location\ package introduces a \Registry\ that manages backend-specific factories, allowing \Parse\ and \StripPassword\ operations to be delegated to the appropriate backend implementation based on the scheme. This change decouples the location parsing logic from specific backend implementations, making it easier to add new backends by simply registering their factory with the registry. The \StripPassword\ function now correctly handles password masking for registered backends, while falling back to the original string for unknown schemes.
internal/backend/location · high confidence
Refactored stats command progress reporting into a dedicated module
The progress reporting logic for the stats command has been moved from the general UI package into a new, dedicated internal/ui/stats module. This change introduces a specific Progress type that handles the display of snapshot processing status, file counts, blob counts, and processed size, ensuring that the stats command now uses its own isolated implementation for terminal updates rather than sharing the generic progress infrastructure.
internal/ui/stats · high confidence
Repository format v2 with compression and multiple performance and usability improvements
This release introduces repository format version 2, which adds data compression (configurable via --compression or RESTIC\_COMPRESSION) and requires initialization with init --repository-version 2; note that v2 repositories cannot be read by restic versions prior to 0.14.0. Several performance and usability enhancements are included: adaptive IO concurrency now scales with the configured number of backend connections (controlled via -o \<backend-name\>.connections=N), improving speed on high-latency backends and allowing concurrency limits for local and SFTP backends; the backup pipeline continues reading files while uploads are busy to improve performance with many small files; the copy command is faster and now shows a progress bar; prune and check --read-data stream data to avoid large temporary files; prune handles duplicate blobs more efficiently; snapshot ID resolution lists snapshots only once; and memory usage for directories with many files is reduced by up to 30%. Usability and reliability changes include: an --unsafe-recover-no-free-space option for prune to recover when the disk is full; debug log creation in release builds via the DEBUG\_LOG environment variable; customizable mount snapshot directory structure via --snapshot-template and --time-template; Azure authentication now supports SAS tokens (AZURE\_ACCOUNT\_SAS) alongside account keys; self-update works on Windows by renaming the running file; temporary file handling on Windows is improved; the diff command no longer incorrectly lists files in removed directories as added; the stats command correctly calculates restore size for multiple snapshots; the forget command yields an error on invalid policy units; the check command deprecates --check-unused, warns about legacy S3 layout and mixed pack files, and now displays full IDs; the init and copy commands replace --repo2 with --from-repo; the rebuild-index command correctly handles legacy mixed pack files; the number of key files tested when opening a repository is limited to 20 (with --key-hint as an alternative); and invalid include/exclude patterns are validated before backup and restore. Additionally, repository file group access is now controlled by the config file's permissions, and the wrong-password error is printed to stderr.
_changelog/0.14.0\2022-08-25 · high confidence
Restic 0.16.0 changelog entry
This location contains the changelog entries for the 0.16.0 release, documenting a wide range of enhancements, bug fixes, and behavioral changes. Key updates include new repair commands for damaged snapshots, support for non-global Azure clouds and Managed Identity, and the ability to select specific subfolders within snapshots using the \\<snapshot\>:\<subfolder\>\ syntax. The release also introduces \--group-by\ for backup parent selection, \--human-readable\ output for \ls\ and \find\, and a progress bar for restores. Bug fixes address issues with non-UTF8 symlink targets, lock refresh failures on slow networks or after standby, and the \forget\ command's handling of unlimited retention. Additionally, the release improves ETA accuracy during backups, reduces memory usage, and adds support for extended attributes on symlinks.
_changelog/0.16.0\2023-07-31 · high confidence
Restic 0.19.0 release notes
This changelog entry documents the comprehensive set of changes in Restic version 0.19.0, including bug fixes, enhancements, and behavioral changes. Key updates include: correcting handling of duplicate index entries and missing pack files (issue-21820, pull-21827); limiting the \check\ command to filtered snapshots (issue-3326); supporting ownership restoration by name on UNIX systems (issue-3572); allowing optional GitHub tokens for \self-update\ to avoid rate limits (issue-3738); adding include filters to the \rewrite\ command (issue-4278); enforcing 0700 permissions for SFTP repository directories (issue-4447); returning exit code 3 for missing backup source paths (issue-4467) and failed snapshot removals (issue-5233); supporting zstd \fastest\ and \better\ compression levels (issue-4728); failing on invalid environment variables (issue-4759); including repository ID in \mount\ filesystem names (issue-4868); returning exit code 130 on SIGINT (issue-5258); rejecting impossible \find\ time bounds (issue-5280); pruning small packfiles more aggressively by default (issue-5293); excluding cloud-backed files on macOS (issue-5352); fixing background execution with rclone/sftp backends (issue-5354); reducing progress bar refresh rates to 10 FPS (issue-5383); allowing \--host\ to override \RESTIC\_HOST\ (issue-5440); copying multiple snapshots in batches (issue-5453); fixing password prompt visibility with \backup -v\ (issue-5477); marking SFTP files read-only (issue-5487); optimizing Azure uploads to reduce costs (issue-5531); rewriting only changed status lines (issue-5562); fixing \snapshots --group-by\ with \--latest\ (issue-5586); avoiding spurious chmod errors (issue-5595); preventing hangs with \backup --stdin-from-command\ (issue-5683); showing detailed \stats\ progress (issue-5689); respecting \--user\/\--host\ in \key passwd\ (issue-5757); preventing exclusion of explicitly backed-up paths (issue-5767); serving Windows backups via Samba (pull-21784); requiring Go 1.25+ (pull-21796); adding status counters to \copy\ (pull-5319); enabling Windows privileges earlier (pull-5424); configuring nice/ionice in Docker (pull-5448); restoring ACL inheritance on Windows (pull-5465); adding OCI labels to Docker images (pull-5523); showing timezone in \snapshots\ output (pull-5588); reducing memory usage for check/copy/diff/stats (pull-5610); fixing \find --pack\ for tree packs (pull-5664); validating mount points earlier (pull-5718); and speeding up index loading (pull-5720).
(repo-wide) · high confidence
Restic repository layer refactored with new blob and index abstractions
The internal restic package has been restructured to improve performance and modularity. The repository interface now uses BlobHandle and PackBlob types to identify and access data, replacing previous ID-based lookups. A new MasterIndex interface manages index operations, and the repository supports asynchronous blob uploading via WithBlobUploader. The Find function now returns specific errors for ambiguous or missing prefixes, and a MemorizeList helper caches file listings to speed up repeated index loads. Progress tracking is decoupled via a Counter interface, and repository initialization defaults to version 2 with compression enabled.
internal/restic · high confidence
Rewritten FUSE mount implementation with customizable snapshot directories
The FUSE mount logic in internal/fuse has been completely rewritten to improve performance and flexibility. The new implementation switches to the anacrolix/fuse library, introduces a global LRU blob cache, and adds a generation-based tree cache to prevent stale entries when snapshots reload. Users can now customize the directory structure of the mount point using path and time templates (e.g., hosts/%h/%T), which automatically generate 'latest' symlinks. The rewrite also ensures correct reporting of file attributes such as block counts and hard link numbers, and adds support for extended attributes on symlinks.
internal/fuse · high confidence
Rewritten dump module with new ZIP support and improved ACL handling
The internal dump module has been refactored to support both TAR and ZIP archive formats, with ZIP archives now compressing regular files by default. The dump logic has been restructured to use a TreeNodeIterator and concurrent blob loading for better performance. Linux POSIX.1e ACLs are now properly converted to text format and included in TAR archives via SCHILY extended attributes. The dump also includes username and group name in TAR headers, uses relative paths, and handles special file modes (setuid, setgid, sticky) correctly. Error handling has been improved throughout, including proper reporting of filenames when tar.ErrFieldTooLong occurs.
internal/dump · high confidence
S3 backend refactored with new configuration options and credential handling
The S3 backend has been restructured to support a more robust configuration model and improved credential management. Users can now explicitly configure storage classes, enable Glacier/Deep Archive restores (behind a feature flag), and control bucket lookup styles (DNS or path). The credential chain has been standardized to prioritize environment variables and AWS session tokens, and AWS Assume Role support has been added via environment variables. Additionally, the backend now supports anonymous authentication only when explicitly requested via a new unsafe flag, and HTTP concurrency limits are enforced to prevent resource exhaustion.
internal/backend/s3 · high confidence
SFTP backend refactored with improved configuration parsing and security hardening
The SFTP backend has been restructured to support more robust connection configuration and stricter security defaults. Users can now specify SSH arguments via the new 'sftp.args' option (mutually exclusive with 'sftp.command') and connect using IPv6 addresses. The configuration parser now rejects paths starting with a tilde (\~) to prevent server-specific interpretation issues. Additionally, repository directories are now created with restrictive 0700 permissions to enhance security, and the backend includes better error handling for broken connections and disk space issues.
internal/backend/sftp · high confidence
Swift backend upgraded to v2 library with expanded authentication and security fixes
The Swift backend has been upgraded to use the ncw/swift v2 library, which introduces support for Keystone v3 authentication parameters (such as UserID, Domain, and Application Credentials) and allows explicit passing of upload sizes. To improve security, the APIKey is now stored as a SecretString to prevent accidental leakage in debug logs, and the backend now calculates MD5 content hashes for uploads. Additionally, the implementation enforces HTTP concurrency limits on operations like Save, Stat, and List, and exposes a configurable connection limit (defaulting to 5) to manage resource usage.
internal/backend/swift · high confidence
Updated documentation styling and layout
The documentation now uses a custom CSS file that imports the default theme while overriding the sidebar background color to blue, resizing the logo to 50% of its container, and allowing table cells to wrap text instead of truncating it.
_doc/\static · high confidence
Updated manual pages for restic commands
The manual pages in doc/man have been regenerated and updated to reflect current command-line options and descriptions. This includes corrections such as removing the broken --allow-root flag from restic mount, adding a note about rescanning when using the hostname flag, and clarifying the behavior of the --exclude-caches option with respect to the Cache Directory Tagging Standard.
doc/man · high confidence
Windows backup fixes, JSON error improvements, and cache cleanup
This release addresses several Windows-specific issues, including correct handling of volume names without trailing slashes in backup targets, support for long paths on older Windows versions, skipping extended attribute processing on unsupported volumes, and fixing spurious privilege errors. It also improves the \--json\ output by including actual error text during backups and formatting restore errors as JSON. Additionally, the \restore --verify\ command now shows a progress bar, removed snapshots are automatically cleared from local caches across hosts, and the timeout for stuck backend requests is now customizable via \--stuck-request-timeout\. Other fixes include better cancellation response for commands like \diff\ and \find\, preventing panics with \--stdin-from-command\, and improving HTTP/2 support for the REST backend.
_changelog/0.17.1\2024-09-05 · high confidence
Fixes
Bug fixes for Azure SAS tokens, Windows VSS metadata, and irregular file handling
This release addresses several issues affecting backup reliability and compatibility. Users on Windows with the --use-fs-snapshot option will now correctly read extended metadata from the snapshot rather than the original filesystem path, preventing errors if files are removed during the backup process. The tool now supports both account-level and container-level SAS/SAT tokens for initializing Azure repositories, resolving previous initialization failures with container-level tokens. Additionally, the tag command now properly returns an error if it fails to lock the repository, and concurrent cache cleanup operations no longer trigger 'no such file or directory' errors. A fix also prevents irregular files from being included in snapshots, which previously caused check command errors; affected snapshots can be repaired by running 'restic repair snapshots --forget'.
_changelog/0.17.2\2024-10-27 · high confidence
Restore ARMv5 support and fix documentation build
This release corrects the official binaries to restore support for ARMv5 architecture, which was accidentally restricted to ARMv7 in version 0.16.1, and repairs the documentation build process on Read the Docs to ensure documentation is available again.
_changelog/0.16.2\2023-10-29 · high confidence
Test coverage
New backend test suite and benchmarks; New internal test helper package.
Dependencies
Updated Go dependencies and raised minimum Go version to 1.25
The project has updated its Go module dependencies, including upgrades to the Azure SDK (azcore, azidentity, azblob), Google Cloud Storage, Minio, and various golang.org/x packages. The minimum required Go version has been raised to 1.25.8, and the documentation build requirements now include Sphinx and the RTD theme.
(dependencies) · high confidence
Housekeeping
Changelog for version 0.17.3; Prepare changelog for 0.15.1; Release 0.12.1 changelog entry; Restic 0.8.2 release notes; Restic 0.9.6 changelog entries; Update changelog for new version of calens; Version 0.9.5 release notes.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 68 → 69 (+0.7)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 75 → 84 (+9.0)
- Architecture 99 → 84 (-15.1)
- Maturity 64 → 64 (+0.0)
- Readiness 69 → 71 (+1.9)
- Security 66 → 67 (+1.4)
- Domain Modelling 100 → 100 (+0.0)
Resolved (55)
- Change coupling: cmd_repair_index.go ↔ cmd_repair_packs.go (cmd/restic/cmd_repair_index.go)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (cmd/restic/cmd_diff.go)
- Duplicated block (10 lines × 2) (cmd/restic/cmd_find.go)
- Duplicated block (10 lines × 3) (cmd/restic/cmd_forget.go)
- Duplicated block (11 lines × 2) (cmd/restic/cmd_snapshots.go)
- Duplicated block (11 lines × 2) (internal/fs/node_windows.go)
- Duplicated block (12 lines × 3) (cmd/restic/cmd_find.go)
- Duplicated block (13 lines × 2) (cmd/restic/cmd_diff.go)
- Duplicated block (14 lines × 2) (cmd/restic/cmd_dump.go)
- Duplicated block (16 lines × 2) (internal/ui/restore/json.go)
- Duplicated block (18 lines × 2) (cmd/restic/cmd_repair_snapshots.go)
- Duplicated block (7 lines × 2) (internal/repository/repository.go)
- Duplicated block (8 lines × 2) (internal/repository/testing.go)
- Duplicated block (9 lines × 2) (cmd/restic/cmd_key_add.go)
- Duplicated block (9 lines × 3) (internal/fuse/dir.go)
- Hotspot: internal/repository/prune.go (internal/repository/prune.go)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- …and 35 more
New (199)
- CI installs an unverified third-party binary (.github/workflows/tests.yml)
- CI installs an unverified third-party binary (.github/workflows/tests.yml)
- ClassTooLong: Archiver (internal/archiver/archiver.go)
- ClassTooLong: Repository (internal/repository/repository.go)
- Documentation: no architecture or design documentation (README.md)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (10 lines × 2) (cmd/restic/cmd_find.go)
- Duplicated block (10 lines × 2) (internal/data/snapshot.go)
- Duplicated block (10 lines × 2) (internal/fs/node_windows.go)
- Duplicated block (10 lines × 2) (internal/restic/blob_set.go)
- Duplicated block (10 lines × 3) (cmd/restic/cmd_forget.go)
- Duplicated block (11 lines × 2) (cmd/restic/cmd_snapshots.go)
- Duplicated block (12 lines × 2) (internal/fuse/link.go)
- Duplicated block (12 lines × 2) (internal/ui/backup/json.go)
- Duplicated block (12 lines × 3) (cmd/restic/cmd_cat.go)
- Duplicated block (12–13 lines × 2) (cmd/restic/cmd_diff.go)
- Duplicated block (13–14 lines × 2) (cmd/restic/cmd_diff.go)
- Duplicated block (13–14 lines × 3) (cmd/restic/cmd_find.go)
- Duplicated block (17 lines × 2) (internal/ui/restore/json.go)
- Duplicated block (19 lines × 2) (internal/backend/file.go)
- …and 179 more
Changes since last survey
- 20 commits — 18 feature/other, 2 fixes
By area
- (root) — 7 commits
- .github/workflows — 2 commits
- doc/040_backup.rst — 2 commits
- (repo) — 1 commit
- doc/030_preparing_a_new_repo.rst — 1 commit
- doc/060_forget.rst — 1 commit
- doc/075_scripting.rst — 1 commit
- doc/110_talks.rst — 1 commit
- doc/design.rst — 1 commit
- internal/backend — 1 commit
- internal/data — 1 commit
- internal/repository — 1 commit
Notable commits
- fix: documentation: Fix incorrect snapshot ID (#22017)
- fix: fix(swift): store APIKey as SecretString to prevent debug log leak (#22007)
- change: Apply go fix ./... (#22037)
- change: CI: add size labels to PRs (#22036)
- change: Merge pull request #22054 from user01010111/docs/env-option-precedence
- change: Update 110_talks.rst (#21989)
- change: Update documentation for environment variable syntax (#22026)
- change: [Documentation] A few minor improvements (#21998)
- change: backend/s3: switch tests from minio to seaweedfs (#22067)
- change: build(deps): bump cloud.google.com/go/storage from 1.63.0 to 1.64.0 (#21996)
- change: build(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.14.0 to 1.14.1 (#22043)
- change: build(deps): bump github.com/klauspost/compress from 1.19.2 to 1.20.0 (#22044)
- change: build(deps): bump github.com/minio/minio-go/v7 from 7.2.1 to 7.3.0 (#22046)
- change: build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.2 (#22068)
- change: build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 (#22047)
- change: doc: clarify environment variable precedence
- change: docs: fix contradiction about which files are encrypted (#22029)
- change: docs: fix two dead links (PGP key URL, MinIO docs URL) (#22028)
- change: repository: use synctest for lock tests (#22038)
- change: selfupdate: replace deprecated golang.org/x/crypto/openpgp with ProtonMail/go-crypto (#21997)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
restic/restic was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6adedec6b48ae9ff0ffbc37bd675ccebd02c728f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.