Releases: Integrity-Ltd/BoronDNS
Release list
BoronDNS 1.0.1
BoronDNS 1.0.1
This maintenance release adds native Linux packages, improves durable IXFR
publication, and fixes DNS answer and installation behavior present in 1.0.0.
The 1.0 public-beta support posture is unchanged.
Highlights
- New Debian/Ubuntu
.deband Fedora/Rocky Linux.rpmpackages, including
service integration and version-checked builds. - Bounded journals for durable IXFR updates, avoiding a full checkpoint rewrite
for each small update. Restart recovery validates and replays the journal. - Corrected repeated RRsets in CNAME/DNAME answers, delegation lookup below
zone cuts, and NSEC3 hashing of names with escaped bytes. - More portable archive installation, Docker containerd image verification,
and accurate AF_XDP artifact metadata. - Rust 1.98.1 builds and reorganized operator/developer documentation.
See CHANGELOG.md
for the complete user-facing change summary and measured IXFR workload limits.
Before upgrading or downgrading
Release verification now uses one authenticated release-handoff.sha256
manifest and its release-handoff.sha256.sigstore.json bundle. Verify the
manifest against the exact release tag, then check the downloaded payloads.
Version 1.0.0 cannot replay the new .bdj IXFR journals. Before downgrading,
stop the service and preserve the complete cache. Use a separate empty cache
and obtain fresh full transfers from reachable primaries before returning the
downgraded server to service.
Installation and verification instructions are in the
operator guide.
The security policy
and implemented scope
define the supported product boundary.
Artifacts and verification
Support posture: initial public beta. The DNS wire behavior and
documented operator interfaces are supported; internal Rust crate
APIs and ABI are not stable. BoronDNS is a secondary-only
authoritative server: primary service, dynamic update, recursive
resolution, and encrypted client-query listeners are out of scope.
Detailed RFC dispositions and future full-acceptance evidence gaps
remain in docs/rfc-compliance-assertions.md and
docs/release-acceptance-gap-register.md at this tag.
Assets:
- Installer archive: borondns-1.0.1-x86_64-unknown-linux-musl.tar.xz
- Static BoronDNS binary: borondns-1.0.1-x86_64-unknown-linux-musl.bin
- Static XDP-enabled BoronGun binary: borondns-1.0.1-x86_64-unknown-linux-musl-boron-gun.bin
- Debian/Ubuntu amd64 package: borondns_1.0.1-1_amd64.deb
- Fedora/RHEL-compatible x86_64 package: borondns-1.0.1-1.x86_64.rpm
- Docker image archive: borondns-1.0.1-x86_64-unknown-linux-musl-docker-image.tar.xz
- CycloneDX SBOMs: borondns-1.0.1-x86_64-unknown-linux-musl-borondns.cdx.json, borondns-1.0.1-x86_64-unknown-linux-musl-boron-gun.cdx.json, borondns-1.0.1-x86_64-unknown-linux-musl-docker-image.cdx.json
- The authenticated checksum manifest is release-handoff.sha256.
- Its keyless Sigstore bundle is release-handoff.sha256.sigstore.json.
- SBOM evidence manifest: borondns-1.0.1-x86_64-unknown-linux-musl-sbom-manifest.tsv
Target: x86_64-unknown-linux-musl
Docker image use (after verifying the files below):
xz -dc borondns-1.0.1-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm borondns:1.0.1 --version
Verify the manifest, then verify downloaded files:
cosign verify-blob \
--bundle release-handoff.sha256.sigstore.json \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity "https://github.com/Integrity-Ltd/BoronDNS/.github/workflows/release-installer.yml@refs/tags/v1.0.1" \
release-handoff.sha256
sha256sum --ignore-missing -c release-handoff.sha256
BoronDNS 1.0.0
BoronDNS 1.0.0
Support posture: initial public beta. The DNS wire behavior and
documented operator interfaces are supported; internal Rust crate
APIs and ABI are not stable. BoronDNS is a secondary-only
authoritative server: primary service, dynamic update, recursive
resolution, and encrypted client-query listeners are out of scope.
Detailed RFC dispositions and future full-acceptance evidence gaps
remain in docs/rfc-compliance-assertions.md and
docs/release-acceptance-gap-register.md at this tag.
Assets:
- Installer archive: borondns-1.0.0-x86_64-unknown-linux-musl.tar.xz
- Static BoronDNS binary: borondns-1.0.0-x86_64-unknown-linux-musl.bin
- Static XDP-enabled BoronGun binary: borondns-1.0.0-x86_64-unknown-linux-musl-boron-gun.bin
- Docker image archive: borondns-1.0.0-x86_64-unknown-linux-musl-docker-image.tar.xz
- CycloneDX SBOMs: borondns-1.0.0-x86_64-unknown-linux-musl-borondns.cdx.json, borondns-1.0.0-x86_64-unknown-linux-musl-boron-gun.cdx.json, borondns-1.0.0-x86_64-unknown-linux-musl-docker-image.cdx.json
- SHA256 files are attached for the installer, binaries, Docker image archive, and SBOMs.
- The authenticated handoff manifest is release-handoff.sha256.
- Each published asset has a keyless Sigstore bundle named
<asset>.sigstore.json. - SBOM evidence manifest: borondns-1.0.0-x86_64-unknown-linux-musl-sbom-manifest.tsv
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc borondns-1.0.0-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm borondns:1.0.0 --version
Verify any asset after installing Cosign:
cosign verify-blob
--bundle .sigstore.json
--certificate-oidc-issuer https://token.actions.githubusercontent.com
--certificate-identity "https://github.com/Integrity-Ltd/BoronDNS/.github/workflows/release-installer.yml@refs/tags/v1.0.0"
BoronDNS 0.9.1
BoronDNS 0.9.1
Assets:
- Installer archive: borondns-0.9.1-x86_64-unknown-linux-musl.tar.xz
- Static BoronDNS binary: borondns-0.9.1-x86_64-unknown-linux-musl.bin
- Static XDP-enabled BoronGun binary: borondns-0.9.1-x86_64-unknown-linux-musl-boron-gun.bin
- Docker image archive: borondns-0.9.1-x86_64-unknown-linux-musl-docker-image.tar.xz
- CycloneDX SBOMs: borondns-0.9.1-x86_64-unknown-linux-musl-borondns.cdx.json, borondns-0.9.1-x86_64-unknown-linux-musl-boron-gun.cdx.json, borondns-0.9.1-x86_64-unknown-linux-musl-docker-image.cdx.json
- SHA256 files are attached for the installer, binaries, Docker image archive, and SBOMs.
- The authenticated handoff manifest is release-handoff.sha256.
- Each published asset has a keyless Sigstore bundle named
<asset>.sigstore.json. - SBOM evidence manifest: borondns-0.9.1-x86_64-unknown-linux-musl-sbom-manifest.tsv
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc borondns-0.9.1-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm borondns:0.9.1 --version
Verify any asset after installing Cosign:
cosign verify-blob
--bundle .sigstore.json
--certificate-oidc-issuer https://token.actions.githubusercontent.com
--certificate-identity "https://github.com/Integrity-Ltd/BoronDNS/.github/workflows/release-installer.yml@refs/tags/v0.9.1"
BoronDNS 0.9.0
BoronDNS 0.9.0 is the first complete public release under the BoronDNS name.
Release contents include static musl binaries for BoronDNS and BoronGun, the installer archive, a Docker image archive, CycloneDX SBOMs, checksums, and the authenticated handoff manifest.
This release was built and validated locally because the GitHub Actions allocation was unavailable. The artifacts are reproducible and checksum-verified, but this manual release does not include GitHub Actions OIDC Sigstore bundles. Verify the asset set with sha256sum -c release-handoff.sha256.
See CHANGELOG.md for the full 0.9.0 changes.
OxideDNS 0.2.0
OxideDNS 0.2.0
Assets:
- Installer archive: oxidedns-0.2.0-x86_64-unknown-linux-musl.tar.xz
- Static OxideDNS binary: oxidedns-0.2.0-x86_64-unknown-linux-musl.bin
- Static XDP-enabled OxideGun binary: oxidedns-0.2.0-x86_64-unknown-linux-musl-oxide-gun.bin
- Docker image archive: oxidedns-0.2.0-x86_64-unknown-linux-musl-docker-image.tar.xz
- SHA256 files are attached for the installer, binaries, and Docker image archive.
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc oxidedns-0.2.0-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm oxidedns:0.2.0 --version
OxideDNS 0.1.5
OxideDNS 0.1.5
Assets:
- Installer archive: oxidedns-0.1.5-x86_64-unknown-linux-musl.tar.xz
- Static OxideDNS binary: oxidedns-0.1.5-x86_64-unknown-linux-musl.bin
- Static XDP-enabled OxideGun binary: oxidedns-0.1.5-x86_64-unknown-linux-musl-oxide-gun.bin
- Docker image archive: oxidedns-0.1.5-x86_64-unknown-linux-musl-docker-image.tar.xz
- SHA256 files are attached for the installer, binaries, and Docker image archive.
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc oxidedns-0.1.5-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm oxidedns:0.1.5 --version
OxideDNS 0.1.4
OxideDNS 0.1.4
Assets:
- Installer archive: oxidedns-0.1.4-x86_64-unknown-linux-musl.tar.xz
- Static OxideDNS binary: oxidedns-0.1.4-x86_64-unknown-linux-musl.bin
- Static XDP-enabled OxideGun binary: oxidedns-0.1.4-x86_64-unknown-linux-musl-oxide-gun.bin
- Docker image archive: oxidedns-0.1.4-x86_64-unknown-linux-musl-docker-image.tar.xz
- SHA256 files are attached for the installer, binaries, and Docker image archive.
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc oxidedns-0.1.4-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm oxidedns:0.1.4 --version
OxideDNS 0.1.3
OxideDNS 0.1.3
Assets:
- Installer archive: oxidedns-0.1.3-x86_64-unknown-linux-musl.tar.xz
- Static OxideDNS binary: oxidedns-0.1.3-x86_64-unknown-linux-musl.bin
- Static XDP-enabled OxideGun binary: oxidedns-0.1.3-x86_64-unknown-linux-musl-oxide-gun.bin
- Docker image archive: oxidedns-0.1.3-x86_64-unknown-linux-musl-docker-image.tar.xz
- SHA256 files are attached for the installer, binaries, and Docker image archive.
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc oxidedns-0.1.3-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm oxidedns:0.1.3 --version
OxideDNS 0.1.2
OxideDNS 0.1.2
Assets:
- Installer archive: oxidedns-0.1.2-x86_64-unknown-linux-musl.tar.xz
- Static binary: oxidedns-0.1.2-x86_64-unknown-linux-musl.bin
- Docker image archive: oxidedns-0.1.2-x86_64-unknown-linux-musl-docker-image.tar.xz
- SHA256 files are attached for the installer, binary, and Docker image archive.
Target: x86_64-unknown-linux-musl
Docker image use:
xz -dc oxidedns-0.1.2-x86_64-unknown-linux-musl-docker-image.tar.xz | docker load
docker run --rm oxidedns:0.1.2 --version
OxideDNS 0.1.1
OxideDNS 0.1.1
Assets:
- Installer archive: oxidedns-0.1.1-x86_64-unknown-linux-musl.tar.xz
- Static binary: oxidedns-0.1.1-x86_64-unknown-linux-musl.bin
- SHA256 files are attached for both assets.
Target: x86_64-unknown-linux-musl