Release notes
Last updated Edit this page View as Markdown
mod_pagespeed 2.1 release notes: the current release, the notes of every line, every release in one list, security updates and what changed since upstream.
On this page
mod_pagespeed 2.1 is released as two parts: the module, which runs inside Apache or nginx and applies the classic rewriting filters in the request itself, and the optimizer worker, a separate process introduced by the 2.0 re-architecture that does the heavy optimization work off the request path. Since 2.1.0 the two are released together; the native packages of the current release carry the package version 1.17.0, the product as a whole is 2.2.0, and that is the version the container images, the NuGet packages and the Helm chart’s application version carry. This page lists the current release, the release notes of each line, and every release in one list, newest first, followed by the security updates we have published and what has changed since the last upstream release. We recommend running the latest release: it always carries the most recent performance and security work.
The current release
mod_pagespeed 2.2.0 2026-10-06 module + optimizer worker
mod_pagespeed 2.2.0 is a security and reliability update for the module and the optimizer worker, released together and installed as a matching pair. In the signed apt and yum repositories both parts carry the package version 1.17.0; 2.2.0 is the version of the container images and the NuGet packages and the application version of the Helm chart (chart 0.3.6). It fixes eleven security issues across the nginx and Apache modules, the admin console, the optimizer worker and the Windows NuGet packages, and it updates the bundled curl; see Security below. It stops a server process that dies or starts at the wrong moment from hanging others or itself, and it stops optimized copies from being lost from a shared cache. The nginx module can now use the optimizer worker, and prioritize_critical_css loads stylesheets so that content is not shown without its styles. Container images and the Helm chart are published with this release.
Update recommended.
Read the full 2.2.0 release notes: the security fixes, the behavior changes, what to do before you upgrade and the notes for embedders.
Release notes by line
Each line has its own page with the full entry for every release, collapsed and newest first.
- mod_pagespeed 2.2 — 2.2.0, 2026-10-06 (packages 1.17.0). The current release: the module and the optimizer worker together.
- mod_pagespeed 2.1 — 2.1.0, 2026-09-17 (packages 1.16.0). The first release of the two parts as one product.
- The 2.0 optimizer worker — 2.0.0-beta.1 to 2.0.42 (2026-08-10). The out-of-process optimizer before the converged line.
- The 1.15 module — 1.15.0 (2026-06-01) to 1.15.0+r22 (2026-08-08). The module after the renumber.
- The 1.1 module — 1.1.0-beta.1 (2026-02-25) to 1.1.0+r23–r24 (2026-06-01). The first releases of the maintained module, before the renumber.
All releases
Every release, grouped into four periods and newest first inside each. Each line says which part the release belongs to, the module or the optimizer worker, and links to the full entry on that line’s page. Where the module shipped several package revisions within a few days they are grouped into one entry, listed under the lowest revision in the group.
The converged line — September to October 2026
mod_pagespeed 2.1.0 and 2.2.0 are the module and the optimizer worker released together. 2.1.0 carries package version 1.16.0 in the apt and yum repositories and 2.1.0 on the NuGet package; no container images or Helm chart were published for it. 2.2.0 carries package version 1.17.0, and 2.2.0 on the container images, the NuGet packages and as the Helm chart’s application version. See the current release above and the 2.2 and 2.1 pages for the full entries.
2.2.0 2026-10-06 module + optimizer worker Security and reliability update for the module and the optimizer worker, released together. Update recommended.
2.1.0 2026-09-17 module + optimizer worker Security update: the module and the optimizer worker as one product, with hardened defaults, an image-decoding fix and a web console dependency update. Update recommended.
Two parts, shipping in parallel — late May to August 2026
2.0.42 2026-08-10 optimizer worker Security: web console dependency update (GHSA-29g2-3rmr-qm68). Update recommended.
2.0.41 2026-08-08 optimizer worker Security: base-image update, plus above-the-fold CSS accuracy and stylesheet-deferral correctness fixes.
1.15.0+r22 2026-08-08 module In-place optimization now serves one cacheable variant per image, dropping per-client Vary headers.
2.0.40 2026-08-01 optimizer worker Cache-staleness, EXIF orientation and a batch of CSS/JS minifier correctness fixes.
1.15.0+r21 2026-08-01 module Apache optimization thread counts now size correctly from the machine; plus minifier and parser fixes.
1.15.0+r20 2026-07-24 module Security update: output-escaping, input-validation and rewrite-correctness fixes. Update recommended.
2.0.39 2026-07-23 optimizer worker Security: nginx and SQLite updates, cache-sharing rules, image-decode crash. Update recommended.
2.0.38 2026-07-17 optimizer worker Cache performance and upgrade safety: a lock-free read path, and one cold start on upgrade.
1.15.0+r19 2026-07-17 module Cache upgrade-safety release, plus zero-copy serving corrections.
2.0.37 2026-07-11 optimizer worker Security: runtime-image rebuild and admin-console hardening, plus cache fixes. Update recommended.
1.15.0+r18 2026-07-11 module Security update: performance, caching and correctness fixes, with input-validation hardening.
2.0.36 2026-07-05 optimizer worker Experimental verified-crawler controls, an async-CSS fix and unified metrics output.
1.15.0+r17 2026-07-05 module Security update: bundled nginx CVE fixes and an nginx memory-safety fix; cache now persists across restarts.
2.0.35 2026-07-03 optimizer worker The Web Bot Auth verdict counters now appear in the metrics output.
2.0.34 2026-07-03 optimizer worker Web Bot Auth crawler verification: observe-only and off by default.
2.0.33 2026-07-01 optimizer worker Security maintenance release: the runtime image is rebuilt. Update recommended.
1.15.0+r16 2026-06-30 module Security update: bundled third-party dependency hardening; fixed an Apache exit crash.
2.0.32 2026-06-24 optimizer worker Security: hardened native-library build and image-codec updates. Update recommended.
1.15.0+r15 2026-06-24 module Security-hardening release.
1.15.0+r11–r14 2026-06-21 – 2026-06-22 module Feature, security, and packaging roll-up (r12–r14 contain no additional product changes).
2.0.30 2026-06-21 optimizer worker Security: a content-integrity fix in agent markdown; Content Credentials survive optimization.
2.0.29 2026-06-18 optimizer worker The console URL list and the cache-URL API no longer time out.
2.0.28 2026-06-16 optimizer worker A cold-cache flash-of-unstyled-content fix, and one lockstep image tag in the Helm chart.
2.0.27 2026-06-15 optimizer worker A full-page cache-churn fix, a three-band critical-CSS budget, and modern JS minification.
2.0.26 2026-06-15 optimizer worker CSP-safe async CSS loading, and honest bandwidth-savings reporting in the console.
2.0.25 2026-06-14 optimizer worker The agent markdown variant no longer fails to render on larger pages.
2.0.24 2026-06-14 optimizer worker A degraded analysis pass can no longer overwrite a good optimization profile.
2.0.23 2026-06-12 optimizer worker Cached pages are no longer served past expiry, plus four optimizer correctness fixes.
1.15.0+r10 2026-06-11 module Admin console maintenance release; optimization is unchanged.
2.0.22 2026-06-11 optimizer worker Security: container images rebuilt against current distribution security updates. Update recommended.
1.15.0+r9 2026-06-10 module Security update: IIS memory-safety defect and resource leak fixed on module unload.
1.15.0+r7–r8 2026-06-08 – 2026-06-09 module nginx packaging quality.
2.0.21 2026-06-05 optimizer worker Packaging release.
1.15.0+r3–r6 2026-06-04 – 2026-06-08 module Packaging expansion (r5–r6 contain no additional product changes).
2.0.20 2026-06-01 optimizer worker The live console dashboard no longer shows zeros for stats the Metrics page reports.
1.15.0+r2 2026-06-01 module cPanel/EasyApache 4 packaging fix: ea-apache24-mod_pagespeed now reliably wins package precedence.
1.15.0 2026-06-01 module The renumber release.
2.0.18 2026-05-31 optimizer worker Maintenance release.
The first releases — May to early June 2026
1.1.0+r23–r24 2026-05-31 – 2026-06-01 module Admin console copy and notices updated.
1.1.0+r22 2026-05-29 module Security and reliability hardening release, the result of a dedicated audit pass.
1.1.0+r18–r21 2026-05-25 – 2026-05-27 module Security update: 13 admin-console dependency advisories cleared (4 high, 9 medium).
2.0.15 2026-05-23 optimizer worker Bandwidth-savings statistics now populate for the ASP.NET Core middleware, matching nginx.
1.1.0+r9–r17 2026-05-21 – 2026-05-22 module IIS quality wave (r12–r17 contain no product changes).
1.1.0+r1–r8 2026-05-19 – 2026-05-21 module Packaging and distribution (most of these revisions contain no product changes).
2.0.4 2026-05-18 optimizer worker The web console is now served by the ASP.NET Core package on the app’s own port.
2.0.3 2026-05-17 optimizer worker Hotfix: the linux-x64 native binary loads again on all supported distributions.
2.0.2 2026-05-17 optimizer worker Packaging correctness: the native binaries are now self-contained.
2.0.1 2026-05-17 optimizer worker Packaging and metadata fixes on top of 2.0.0.
2.0.0 2026-05-17 optimizer worker First general release of the optimizer worker, on NuGet and as container images.
1.1.0 2026-05-15 module Security update: general availability, clearing a six-year CVE backlog including CVE-2023-4863.
Before the first releases — February to May 2026
2.0.0-beta.1 optimizer worker The 2.0 re-architecture: an asynchronous optimizer worker behind a variant-aware cache.
1.1.0-beta.1 2026-02-25 module First public beta of the maintained module line, on Apache, nginx and IIS.
Security updates
Every security fix we have published for either part is listed here with the release that carried it. Where a fix repairs a defect inherited from the open-source line — code that shipped in 1.14.36.1 and was never fixed upstream — the release entry says so.
| # | Advisory | Impact | Affected | Fixed in | Update |
|---|---|---|---|---|---|
| 1 | — | denial of service — nginx module | the nginx module, all releases up to and including 1.16.0 | mod_pagespeed 2.2.0 | Recommended |
| 2 | — | denial of service — Apache module | the Apache module, all releases up to and including 1.16.0 | mod_pagespeed 2.2.0 | Recommended |
| 3 | — | denial of service — HTML rewriter | releases 1.15.0+r20 through 1.16.0 | mod_pagespeed 2.2.0 | Recommended |
| 4 | — | access-restriction bypass — nginx admin, statistics, console and message pages | the nginx module, all releases up to and including 1.16.0, where access to these pages is restricted in the nginx configuration | mod_pagespeed 2.2.0 | Recommended; then replace the access rules for these pages with the updated example in every server block |
| 5 | — | information disclosure — per-host admin console | module 1.16.0 with the optimizer worker in use | mod_pagespeed 2.2.0 | Recommended |
| 6 | — | cache integrity — nginx in-place optimization | the nginx module, all releases up to and including 1.16.0, with in-place optimization enabled (the default) | mod_pagespeed 2.2.0 | Recommended |
| 7 | — | information disclosure — nginx in-place optimization | the nginx module, all releases up to and including 1.16.0, with in-place optimization enabled (the default) | mod_pagespeed 2.2.0 | Recommended; flush the PageSpeed cache once after updating |
| 8 | — | request forgery — admin console | all releases up to and including 1.16.0, where the admin console is reachable beyond loopback | mod_pagespeed 2.2.0 | Recommended; scripted purges and some monitoring probes need a change |
| 9 | — | denial of service — optimizer management API | optimizer worker 2.0.0 through 2.1.0 and optimizer packages through 1.16.0, with the management API enabled | mod_pagespeed 2.2.0 | Recommended |
| 10 | — | information disclosure — optimizer management API with --api-read-open | optimizer worker 2.0.0 through 2.1.0 and optimizer packages through 1.16.0, started with --api-read-open | mod_pagespeed 2.2.0 | Recommended; read-only clients that relied on it beyond the documented read endpoints need the API token |
| 11 | — | local privilege escalation — Windows | WeAmp.PageSpeed.AspNetCore and WeAmp.PageSpeed.NativeAssets.Windows 2.0.0 through 2.1.0, and the Windows optimizer worker built from them | mod_pagespeed 2.2.0 | Recommended |
| 12 | CVE-2026-19931, CVE-2026-18924, CVE-2026-82209, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-13608 | dependency update — bundled HTTPS fetch library (curl 8.22.0) | module releases 1.1.0-beta.2 through 1.16.0 | mod_pagespeed 2.2.0 | Recommended |
| 13 | CVE-2026-32327, CVE-2026-34191, CVE-2025-49506, CVE-2026-34501, CVE-2026-34502 | dependency update — bundled apr-util | apr-util 1.6.3 and earlier in the bundle; the affected components are not built into or called by any mod_pagespeed release | module 1.16.0 | Recommended (no earlier release believed exposed) |
| 14 | GHSA-29g2-3rmr-qm68 | dependency update — web console | ASP.NET Core packages before 2.0.42; container and Helm deployments before 2.2.0 | optimizer worker 2.0.42 · mod_pagespeed 2.2.0 | Recommended |
| 15 | — | denial of service — image decoding | optimizer worker before 2.1.0 | mod_pagespeed 2.1.0 | Recommended |
| 16 | — | hardening — privilege separation for the optimizer worker | — | mod_pagespeed 2.1.0 | Recommended (new default in 2.1) |
| 17 | — | hardening — management API authentication | — | mod_pagespeed 2.1.0 | Recommended (new default in 2.1) |
| 18 | — | hardening — browser-analysis sandbox | — | mod_pagespeed 2.1.0 | Recommended (new default in 2.1) |
| 19 | — | hardening — system-call allow-list enforcement | — | mod_pagespeed 2.1.0 | Recommended (new default in 2.1) |
| 20 | — | hardening — container and Helm defaults | — | mod_pagespeed 2.1.0 | Recommended (new default in 2.1) |
| 21 | — | dependency update — base image | worker and nginx images before 2.0.41 | optimizer worker 2.0.41 | Recommended |
| 22 | — | cache disclosure — authenticated responses | optimizer worker before 2.0.40 | optimizer worker 2.0.40 | Recommended |
| 23 | — | cache disclosure — responses the origin later marks non-shareable | optimizer worker before 2.0.40 | optimizer worker 2.0.40 | Recommended |
| 24 | CVE-2026-42533 | memory safety — bundled nginx | the sidecar package, the container images and the worker and nginx images, before module 1.15.0+r20 / worker 2.0.39 (bundled nginx before 1.30.4) | module 1.15.0+r20 · optimizer worker 2.0.39 | Recommended |
| 25 | — | cross-site scripting — CSS inlining | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 26 | — | cross-site scripting — local-storage cache inlining | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 27 | — | cross-site scripting — inline-image deduplication | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 28 | — | cross-site scripting — inline image preview | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 29 | — | denial of service — image resolution limit | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 30 | — | denial of service — image spriting | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 31 | — | denial of service — JavaScript minifier | all 1.15 releases up to and including r19 | module 1.15.0+r20 | Recommended |
| 32 | — | denial of service — HTML parser | all 1.15 releases up to and including r19 | module 1.15.0+r20 | Recommended |
| 33 | — | content integrity — CSS dependency parsing | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 34 | — | content integrity — HTML character references | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 35 | — | thread safety — HTML parsing (startup race) | all releases up to and including 1.15.0+r19; long-standing defects inherited from the open-source line | module 1.15.0+r20 | Recommended |
| 36 | CVE-2026-50812, CVE-2026-50813 | memory safety — bundled SQLite | worker and nginx images before 2.0.39 | optimizer worker 2.0.39 | Recommended |
| 37 | — | denial of service — image dimension reading | optimizer worker before 2.0.39 | optimizer worker 2.0.39 | Recommended |
| 38 | — | dependency update — runtime images | 2.0.x container images before 2.0.37 | optimizer worker 2.0.37 | Recommended |
| 39 | — | hardening — admin console | — | optimizer worker 2.0.37 | Recommended |
| 40 | — | dependency update — bundled HTTPS fetch library | all releases up to and including 1.15.0+r17 | module 1.15.0+r18 | Recommended |
| 41 | — | hardening — input validation and output escaping | all releases up to and including 1.15.0+r17; the underlying gaps date back to 1.14.36.1 and earlier | module 1.15.0+r18 | Recommended |
| 42 | CVE-2026-42055, CVE-2026-48142 | dependency update — bundled nginx | the ASP.NET Core sidecar, all 1.15 releases up to and including r16 (bundled nginx before 1.30.3) | module 1.15.0+r17 | Recommended |
| 43 | — | memory safety — nginx request handling | all releases up to and including 1.15.0+r16; a defect inherited from the open-source line | module 1.15.0+r17 | Recommended |
| 44 | — | dependency update — runtime image | 2.0.x container images before 2.0.33 | optimizer worker 2.0.33 | Recommended |
| 45 | — | hardening — bundled third-party code (defense in depth) | — | module 1.15.0+r16 | Recommended |
| 46 | — | dependency update — bundled image codecs | optimizer worker before 2.0.32 | optimizer worker 2.0.32 | Recommended |
| 47 | — | hardening — binary hardening of the shipped native library | — | optimizer worker 2.0.32 | Recommended |
| 48 | — | hardening — binary hardening and reduced attack surface | — | module 1.15.0+r15 | Recommended |
| 49 | — | hardening — parser bounds and IIS sub-resource TLS | all releases up to and including 1.15.0+r10 | module 1.15.0+r11–r14 | Recommended; particularly for IIS deployments |
| 50 | — | dependency update — admin console | all 1.15 releases up to and including r10 | module 1.15.0+r11–r14 | Recommended |
| 51 | — | content integrity — agent-optimized markdown output | optimizer worker before 2.0.30 | optimizer worker 2.0.30 | Recommended |
| 52 | — | dependency update — container images | 2.0.x container images before 2.0.22 | optimizer worker 2.0.22 | Recommended |
| 53 | — | memory safety — IIS module unload | IIS deployments, all releases up to and including 1.15.0+r8 | module 1.15.0+r9 | Recommended for IIS deployments |
| 54 | — | availability — prebuilt nginx module | prebuilt Ubuntu nginx module packages, 1.15.0+r3–r6 | module 1.15.0+r7–r8 | Recommended |
| 55 | — | denial of service — nginx request handling | all 1.1.0 releases up to and including r21; a defect inherited from the open-source line | module 1.1.0+r22 | Recommended |
| 56 | — | hardening — admin-surface access control and sidecar defaults | — | module 1.1.0+r22 | Recommended |
| 57 | — | dependency update — admin console (13 published advisories) | all 1.1.0 releases up to and including r17 | module 1.1.0+r18–r21 | Recommended |
| 58 | CVE-2023-4863 | memory safety — bundled libwebp | the open-source line, 1.14.36.1 and earlier | module 1.1.0 | Recommended |
| 59 | — | memory safety — image processing | the open-source line, 1.14.36.1 and earlier | module 1.1.0 | Recommended |
| 60 | — | denial of service — untrusted input handling | the open-source line, 1.14.36.1 and earlier | module 1.1.0 | Recommended |
| 61 | — | dependency update — bundled image codecs and HTTPS fetch library | the open-source line, 1.14.36.1 and earlier | module 1.1.0 | Recommended |
| 62 | — | hardening — admin surface | the open-source line, 1.14.36.1 and earlier | module 1.1.0 | Recommended |
No container images or Helm chart were published for 2.1.0; for those deployments, the fixes listed as fixed in 2.1.0 arrive with 2.2.0.
Beyond the individual fixes listed above, both parts carry continuing security work.
At a high level, that work spans:
- Memory-safety hardening across the engine and request-handling paths, backed by continuous sanitizer testing on every platform.
- Robustness against malformed or oversized input — untrusted content and abnormal conditions are handled gracefully instead of crashing or exhausting resources.
- Admin-surface hardening — stricter authentication, safer defaults, and improved resilience of administrative and reporting endpoints to malformed or unauthorized external requests.
- Binary hardening of the shipped modules (RELRO, BIND_NOW, stack-protector, FORTIFY_SOURCE) and a reduced attack surface.
- Ongoing dependency updates, including image codecs, the bundled HTTPS fetch library, and tracking upstream nginx security releases, gated by continuous CVE scanning.
We keep these descriptions general by design: security entries state the impact class and the recommendation, not the mechanism. If your servers run an older open-source mod_pagespeed build, moving to mod_pagespeed 2.1 is the supported way to get all of the above.
The security page sets out how to report a problem and how we handle reports.
Since the last upstream release
The last upstream release was 1.14.36.1, published in August 2020 — the one release made under the Apache incubator. The last Google-era stable release before it was 1.13.35.2, February 2018. If the build you run today came from either of those, this section is the short version of what is different in what we ship now.
We-Amp helped build ngx_pagespeed, maintained mod_pagespeed and helped drive the Apache incubation throughout the Google era, and has carried the line forward since. The module alone carries 765 first-parent merges since 1.13.35.2. Very little of that is visible from a configuration file, which is what the three lists below are for.
Carried over unchanged
- Every existing
pagespeedconfiguration directive and filter name from the open-source release continues to work, with a small set of long-obsolete filter names now accepted with a warning. - The
ModPagespeed*directive spelling still parses, and the admin console is still at/pagespeed_admin/. - The module still runs in process, inside Apache and nginx, on the server you already operate.
- The Debian and Ubuntu package name is unchanged —
mod-pagespeed-stable— so the.debpaths in your configuration management carry over.
Changed
- The dependency graph was rebased off its 2018-vintage pins. libwebp moved from 1.1.0 to 1.5.0, which clears CVE-2023-4863; libpng, giflib and libjpeg-turbo were brought to current upstream versions; curl moved to the 8.x line, with the HTTP fetcher rewritten on top of it; and zlib was replaced by zlib-ng.
- The file-based cache was replaced by Cyclone Cache — a fixed-size,
lock-free, memory-mapped backend shared with the rest of the converged line.
There are no more periodic pruning scans across millions of small files. Old
FileCachedirectories are not read, andFileCacheInodeLimitparses as a no-op so Apache configurations keep loading. - The build moved off the 2012-era gyp and Python 2 toolchain to Bazel,
and packages are prebuilt, reproducible and signed —
.deb,.rpmand.msi— so there is nothing to compile. - The nginx module is dynamic. It loads as a module rather than being recompiled against the nginx source tree, and the prebuilt packages are built per distribution with a runtime compatibility guard, so a distribution’s own nginx patch does not leave you with a module that will not load.
- Apache 2.4 and later, and one
X-Page-Speedheader. The_ap24suffix is gone from the package name, and theX-Page-Speedresponse header is now the same across every port — no port-specific override and no special expired-state header to special-case in monitoring. - The admin console was rebuilt as a single-page application, bundled into one file so it ships inside the module itself with no extra static-asset deployment step. It is the operator UI for cache configuration and filter configuration, and it is stamped with the release tag at build time, so the running build is unambiguous from the UI.
- The whole line is licensed under the Apache License 2.0 — the same license the original codebase carried — and the relicensing is retroactive. The source is published at github.com/We-Amp/mod_pagespeed.
New since 1.14.36.1
- AVIF joined WebP as an opt-in image format, alongside ongoing filter-stack modernization: modern JavaScript and CSS syntax support, Core Web Vitals reporting, Subresource Integrity and CSP awareness.
- IIS became a first-class platform alongside Apache and nginx, and an
ASP.NET Core sidecar package (
WeAmp.PageSpeed.Sidecar) joined as an additional integration option — see ASP.NET Core Getting Started for both ASP.NET Core options. - Linux on arm64. The upstream tree had no aarch64 build at all; Apache and nginx now ship arm64 builds alongside x86_64.
- The optimizer worker joined as the second part of the product. The heavy work — image transcoding, critical CSS, variant-aware caching — runs in a separate process, and with the Apache module or the reverse-proxy deployment the module serves the results from the shared cache. On the deb and rpm channels the two install and upgrade together from the same signed repository; the current release covers the pair.
Everything published after 1.14.36.1 is on this page, release by release. The upstream history up to and including it is archived here, unchanged:
Release notes for the upstream line, up to 1.14.36.1 →
Install and upgrade
mod_pagespeed 2.1 ships as native packages for Apache and nginx — the module
and the pagespeed-optimizer worker from the same signed repository — as
Docker images, and as a Helm chart. See
Getting started to install, the
installation guide for Docker, the
Helm deployment guide for Kubernetes, and
Deployment for production rollouts.
The Apache packages install the configuration that points the module at the optimizer worker. The native nginx module runs on its own; to use the optimizer worker with nginx, run the reverse-proxy deployment.
The IIS package ships from the 1.15 packaging channel.
Reporting a security issue
Found a security problem? Please email security@we-amp.com so we can investigate and ship a fix. We publish security-relevant changes here as part of the regular release notes. Our disclosure policy is on the security page.