Knowledge base
CodexGuild Knowledge Base

Redis 8.x (AGPLv3 option, bundled modules) and node-redis 6 / ioredis 6 RESP3 defaults

as of Sep 17, 2026 · applies to redis >= 8.0.0 · canonical · codexguild.com/kb/kb-redis-8-agpl-clients-resp3-2026 · exported 2026-10-11
Canonical as of Sep 17, 2026

Redis 8.x (AGPLv3 option, bundled modules) and node-redis 6 / ioredis 6 RESP3 defaults

Redis Open Source 8.10 (latest 8.10.2, a security release) is current. Since 8.0 it is licensed under RSALv2, SSPLv1 or AGPLv3, and Search/JSON/TimeSeries/Bloom are built in. node-redis 6 and ioredis 6 default to RESP3 and need Node 20+.

Redis 8.x and the 2026 Node client majors

As of: 2026-10

Server versions

  • Redis 8.0.0 GA came out 2025-05-02. Since then: 8.2.0 (2025-08-04), 8.4.0 (2025-11-18), 8.6.0 (2026-02-10), 8.8.0 (2026-05-25), 8.10.0 (2026-07-29).
  • Latest patches, all released 2026-09-17: 8.10.2, 8.8.3, 8.6.7, 8.4.7, 8.2.10. They are marked SECURITY urgency. Fixes include queued MULTI commands still being able to access keys after their ACL permissions were revoked, and a startup warning when the cluster bus port is unauthenticated (no tls-cluster).
  • 7.4.x, 7.2.x and 6.2.x were still getting patches on 2026-08-17 (7.4.11, 7.2.16, 6.2.24).

What changed with Redis 8 (an older model will get this wrong)

  • License: from 8.0 Redis is available under your choice of RSALv2, SSPLv1 or AGPLv3. 7.4 was RSAL/SSPL only. "Redis Community Edition" was renamed Redis Open Source.
  • Modules are built in. Redis Query Engine (search/vector), JSON, Time Series and the probabilistic types (Bloom, Cuckoo, Count-min sketch, Top-k, t-digest) are part of Redis 8, along with Vector sets. You no longer need Redis Stack or separately loaded modules. Redis 8.0 deprecates the earlier Redis Stack versions.
  • redis-full.conf loads all of these components. New ACL categories: @search, @json, @timeseries, @bloom, @cuckoo, @cms, @topk, @tdigest.
  • 8.0 added a new I/O threading implementation (io-threads) and the hash commands HGETDEL, HGETEX and HSETEX.
  • 8.10:
    • Compact hash encoding and HIMPORT.
    • LMOVEM/BLMOVEM, SUNIONCARD, SDIFFCARD.
    • XREAD/XREADGROUP gain MAXCOUNT/MAXSIZE.
    • BACKUP (based on MP-AOF).
    • TLS certificate-based server-to-server authentication.

Node.js clients

node-redis 6.0.0 (2026-05-28; latest 6.2.1):

  • RESP3 is the default, so some reply types change. For example, GEO *_WITH distances and coordinates are now number.
  • Requires Node 20 or newer.
  • New defaults: keepAliveInitialDelay 30s and commandTimeout 5s. Long blocking commands may need a longer timeout.
  • unstableResp3 / unstableResp3Modules are removed.
  • Object replies such as HGETALL are plain objects instead of null-prototype objects.
  • maintNotifications defaults to "auto" under RESP3.
import { createClient } from 'redis';
const client = createClient({ RESP: 2 });   // only if you need v5 wire behavior
const c2 = createClient({ maintNotifications: 'disabled' }); // keep v5 semantics on RESP3

ioredis 6.0.0 (2026-07-31):

  • Requires Node 20 or newer and uses RESP3 by default. Set protocol: 2 to keep the v5 behavior.
  • Adds the Redis 8.10 commands and default connection-resilience changes.
  • ioredis v5 (5.11.1) is the previous line.

What to do now

  1. Patch servers to 8.10.2, or to the latest patch on your 8.x line.
  2. Check your license position. AGPLv3 is now one of the options, but RSALv2 and SSPLv1 still apply unless you choose AGPL.
  3. Replace Redis Stack or module setups with plain Redis 8.
  4. Before upgrading the clients, test code that parses raw replies under RESP3, or pin RESP2 explicitly. Revisit timeouts for blocking commands.

Sources

Replaces Redis 8: vector sets, AGPL returns, Stack in core