Releases: pgsty/silo
Release list
RELEASE.2026-09-16T00-00-00Z
SILO 20260916 is a security and correctness release following RELEASE.2026-09-03T13-18-01Z, built from 2a4d51406b7ed87af5fe6fe0f801f3290f96eb3c. The package version is 20260916000000.0.0.
Highlights
- Authentication and policies: reject unsigned
x-amz-*operation headers, verify header-bound presigned payloads, and align signature-age and payload-hash conditions with authenticated values. Shared policy fixes preserve distinct Deny statements and avoid exponential wildcard matching. See SN-2026-011 through SN-2026-014. - Durable IAM revocation: retain deletion revisions, membership grant times and parent revocation boundaries so stale replication events and old child credentials cannot cross retained revocations. Peer notifications reload committed state. Password self-service now checks
admin:ChangeMyPasswordseparately fromadmin:CreateUser. - Multi-pool consistency: evaluate conditional PUT and multipart completion against the logical current object; honor single-object conditional DELETE; reconcile addressed-version deletion and independently ordered tags/Object Lock metadata across pools. Rebalance and decommission preserve object tags and their revisions for ordinary and multipart objects (
fced86303). - Listing and delete-marker repairs: retain a quorate null version when a newer minority would hide it; require majority-confirmed absence for missing-version purge retries; preserve marker replication/purge metadata through healing; recheck queued marker creations under the replication lock; and report a purged data version without incorrectly identifying it as a delete marker (
8d06424b1,eb4f5e5b3,254b19ac0,358ab38fb). - Encrypted and federated copies: preserve raw SSE-C replicas, logical multipart sizes, lock/tag revisions and key-rotation checksums; prevent new compressed SSE-C writes; bind federated CopyObject checksums, version and timestamps to the actual destination write.
- Replication and configuration: repair ordered tag deletion, marker purge/MRF recovery, resync counters and cancellation, bucket metadata convergence and CORS export/import. Prevent transport-only
aws-chunkedfrom being stored as object encoding. - Multipart discovery: add durable, quorum-checked listing and preflight with global prefix, delimiter and pagination behavior. Legacy remains the default. Strict mode is enabled only through
MINIO_API_MULTIPART_LISTING=strictafter the documented upgrade and capacity checks (#198, #213). - TLS handshake defaults: remove eight explicit curve overrides so listeners, nodes, identity providers, replication and etcd follow Go 1.27 defaults and the
tlsmlkem/tlssecpmlkemGODEBUG controls, with certificate and hostname verification unchanged (#164). This changes what SILO offers and accepts on the wire. If an SSL-inspecting firewall, SASE gateway, IDS/IPS or a JA3/JA4 allow-list sits on an outbound path, read pinned TLS parameters and handshake compatibility before upgrading. - Runtime reliability: enforce the configured absolute HTTP/1 header deadline, synchronize CPU metrics reads during Prometheus scraping (#210), and correct quota/logger metrics.
Coordinated components
| Component | Selected version |
|---|---|
| Embedded Console | v2.4.1, source 1360e26d976d |
| MC module and image-bundled mcli | RELEASE.2026-09-16T00-00-00Z, source e952aa78f10a |
| Shared package | github.com/pgsty/silo-pkg/v3 v3.14.1 |
| Upstream S3 SDK | github.com/minio/minio-go/v7 v7.3.1-0.20260915093545-32e1f32cb176 |
| Go | 1.27.1 |
Console adds bounded object browsing, streaming ZIP downloads, restricted anonymous sharing, and session/UI recovery. mcli includes reliable failure exit codes, Object Lock/mirror/move fixes, and the SDK repair for CopyObject errors embedded in HTTP 200. Server and mcli images use Docker Hub: docker.io/pgsty/silo and docker.io/pgsty/mc. The standalone docker.io/pgsty/silo-console image is not currently available for anonymous pulls; use the embedded Console or the standalone release binary. The maintained four-component SILO stack is the supported integration target; upstream MinIO/MC compatibility is best effort.
Release verification
The exact tagged source passed Go CI, VulnCheck, and the complete release pipeline test, including package metadata, runtime shutdown and distroless health checks. The release build and signed-package finalization also passed.
All 36 downloadable assets were independently downloaded and checked against GitHub asset digests; the archive and package manifests, package sidecars, and both manifests' provenance identities were verified. Both RPM architectures carry the PGSTY GPG signature. A smoke test of the downloaded macOS ARM64 Server with the released mcli passed readiness, embedded Console HTTP, object write/read SHA-256 comparison, tags, versioning and delete-marker checks. These checks do not remove the known distributed-operation limitations below.
Container images
The Docker Hub publication workflow passed and published both linux/amd64 and linux/arm64:
- Classic:
docker.io/pgsty/silo:RELEASE.2026-09-16T00-00-00Zand:latest—sha256:635197cb9f36d01bee221d34d1c7d7960f6a95c48b0b6c01d99cd13bdae51a46. - Distroless:
docker.io/pgsty/silo:RELEASE.2026-09-16T00-00-00Z-distrolessand:distroless—sha256:32a8a777d90f3296294c9a57da5e8d397121187c4b868b2a7fc7874c726c0291.
Anonymous access, architecture coverage, source labels, rolling-tag equality and workflow provenance were independently verified. Runtime checks passed for the amd64 classic version and for both ARM64 variants' startup, readiness and S3 write/read checksums; the classic bundled mcli and distroless Docker health check also passed. Container write/read smoke tests used isolated temporary memory storage because the local Docker data disk was full; they are not persistence or distributed-cluster acceptance.
Upgrade requirements
- Coordinate all nodes and sites. Mixed old/new processes sharing an IAM backend and rolling downgrade are unsupported. Back up complete IAM storage and encryption material; live IAM exports omit deletion history. Follow the IAM upgrade and recovery guide.
- Review password policies. To retain an old combined password/user-administration restriction, deny both
admin:CreateUserandadmin:ChangeMyPassword, preserving the original conditions and resources. Saved policies are not rewritten. See migration guidance. - Enable optional changes separately. Bucket metadata tombstone export stays off by default. Strict multipart listing requires upgraded writers, drained legacy uploads, read-only preflight and capacity validation. See the multipart contract.
- Check TLS-inspecting devices on outbound paths. Handshake contents changed with the Go 1.27 toolchain in 20260903 and again here. An SSL-inspection NGFW, SASE gateway or IDS/IPS — or a JA3/JA4 client-fingerprint allow-list — can reset identity provider, webhook, remote tier or replication connections with
connection reset by peerwhilecurlfrom the same container succeeds. Verify OIDC discovery and JWKS, audit and notification targets, remote tiers and replication endpoints after upgrading. Remedies and their trade-offs: pinned TLS parameters and handshake compatibility. - Audit historical state independently. Upgrading does not restore previously lost tags, policy clauses or revocation history, nor automatically repair old encrypted objects or every pending purge. See the replica audit runbook.
Known limitations
- #217: source-side marker rechecks do not fence creations already in flight or replayed from another site, or guarantee cleanup of post-crash minority residue.
- #218: successful ListObjects can still omit readable keys during rolling restarts with concurrent overwrites. Do not run sync tools that delete destination objects based on such listings; list again after the cluster stabilizes.
- #79: strict multipart pages rescan durable state, require capacity validation, and do not provide a durable fence against delayed upload-creation writes after cancellation.
- [#154](https://github.com/pgsty/silo/is...
RELEASE.2026-09-03T13-18-01Z
SILO 20260903 is a correctness and compatibility release built from 9b11dc9469e650815b775cb47b039610644f5da4. It is the complete supported release boundary after RELEASE.2026-08-06T00-00-00Z.
Highlights
- Adds complete per-bucket CORS support, including site-replication convergence.
- Serializes whole-record bucket metadata updates across configuration types, migration, import, adoption, and healing.
- Aligns multipart and CopyObject checksum behavior, including server-computed part checksums and
ChecksumTypepropagation. - Preserves SSE-C correctness for zero-byte reads, object attributes, copies, null-version rewrites, and key rotation.
- Aligns explicit-version deletion and user/group status authorization with the requested operation.
- Hardens
MINIO_CONFIG_ENV_FILEparsing and legacy database-notification migration. - Moves to Go 1.27.1 and pins the maintained SILO dependency line.
Coordinated components
- mcli:
RELEASE.2026-09-03T07-13-05Z github.com/pgsty/silo-pkg/v3:v3.13.2- embedded Console: source
464a59d73ada, with the v2.3.0 version identity - upstream
minio-go/v7: revision0e78d3f18efe
Verification
The exact release source passed Go CI, the complete cmd race suite, internal tests, lint, generated-file and compatibility guards, vulnerability scanning, cross-compilation, and the Test Release pipeline. Final functional acceptance used four Ubuntu 24.04 arm64 VMs with 16 XFS data disks and covered:
- coordinated 20260806 → 20260903 upgrade, rollback, and second upgrade;
- the mcli functional suite over TLS;
- 1,004-object upload/download checksum comparison;
- one-node outage, quorum loss, recovery, and single-drive reconstruction;
- two-site replication, versions, CORS, tags, quota, ILM, Object Lock, IAM, delete markers, and offline catch-up.
Release archives and packages include SHA-256 manifests, SBOMs, and build provenance. RPMs carry the PGSTY GPG signature. Classic and distroless container images are published for linux/amd64 and linux/arm64.
The first container workflow stopped before pushing because the tagged Dockerfile retained stale mcli archive pins. The recovery workflow then resolved both pins from the immutable, attested mcli 20260903 checksum manifest and built from this Release's original Server archives. Run 33847571968 published and attested the final manifests:
- classic release and
latest:sha256:b616a0cf8cb281e7e6bb3c9b1fb53875b4016a2878223925541c18f82d6c5ca3 - distroless release and rolling tag:
sha256:2711cdc5bce0ada353a4871dcda60f48f46414fdd69a45c36c71f6b7ebe1aead
Upgrade notes
- Upgrade every node in a distributed cluster in one coordinated maintenance operation.
- Upgrade every site-replication member before creating or changing per-bucket CORS.
- Review grants for
s3:DeleteObjectVersionand the separate enable/disable admin actions. - Correct bare ARN prefixes before re-submitting policies.
- Add connection strings to enabled legacy PostgreSQL/MySQL notification targets.
- The signed tag's bundled Chart 7.0.2 retains a provisional
T00-00-00Zimage value. When rendering the chart from the tagged source archive, overrideimage.tag=RELEASE.2026-09-03T13-18-01Z; the corrected current chart is onmainat4c164907f.
Known limitations, rollback guidance, and the full change ledger are documented in the complete release notes. Downloads and installation commands are on the SILO download page.
Component status — 2026-09-13
This remains the latest published Server. Later security, storage and dependency changes are on main only. In particular, SN-2026-011 is fixed on main but affects this and earlier public Server releases. New mcli/pkg releases do not patch this Server binary or replace its embedded Console/client.
See the current component matrix, password-policy migration and website release notes.
RELEASE.2026-08-06T00-00-00Z
SILO 20260806 is the first release published under the Silo name. The previous release, 20260804, was the last one delivered as pgsty/minio; this release completes the cutover to github.com/pgsty/silo and renames every delivery surface — binary, packages, container images, systemd unit, Helm chart — while deliberately preserving every wire and configuration surface a MinIO deployment depends on. On top of the rename it adds native health checking (silo healthcheck), a distroless container image pilot, complete license-compliance materials in every artifact, and a release pipeline gated on compatibility snapshots and build provenance.
25 commits after RELEASE.2026-08-04T00-00-00Z (394 files, +26,895/−19,558). Passed a six-phase pre-release acceptance, including a real four-node TLS cluster migration from MinIO to Silo — byte-verified data integrity, maintenance-gated rolling restarts, fault injection, and a full rollback rehearsal.
Highlights
- The rebrand is complete, and compatibility is the contract — repository, binary (
/usr/bin/silo), packages (silorpm/deb/apk), images (docker.io/pgsty/silo), and service (silo.service) are renamed; the S3 and admin APIs,/minio/*routes,MINIO_*environment variables,x-minio-*headers, on-disk.minio.sysformat, and Go module paths are all preserved and frozen by a CI compatibility guard. - Native health checking —
silo healthcheck [live|ready|cluster|cluster-read]probes the server's own health API with correct exit codes, decoded quorum diagnostics, TLS auto-detection, and a--maintenancepre-drain gate — no shell,curl, ormcrequired in the container. - Distroless image pilot —
pgsty/silo:RELEASE.2026-08-06T00-00-00Z-distrolessships exactly one program ongcr.io/distroless/static(128 MB vs. the classic 199 MB), with an exec-formHEALTHCHECKbaked in and/datacreated writable in the image layer (fixes #55 in this variant). - The classic image does not change behavior — same entrypoint, same bundled tools,
mc ready localkeeps working; it now bundlesmcli20260806 (with themccompatibility alias), anddocker run pgsty/silo minio server /datastill works. - Compliance completed — LICENSE and NOTICE ship in every package and image, CREDITS is regenerated from the actually-linked module set (291 modules) and guarded in CI, and the project adopts a no-CLA, DCO-based contribution policy.
- Components — SILO Console 2.1.1 ·
silo-pkg3.11.0 ·mcli20260806 · Go 1.26.5.
Migration
silo.service is built for takeover: it conflicts with and supersedes minio.service, and reads /etc/default/minio before /etc/default/silo, so an existing MinIO configuration is inherited without edits. Keep data ownership stable with the documented legacy-user drop-in.
Warning
Distributed migrations must switch all nodes together. A mixed Silo/MinIO cluster does not form — new nodes wait in activating indefinitely. Stop MinIO on all nodes, then start Silo on all nodes near-simultaneously. Once every node runs Silo, gate each rolling restart with silo healthcheck --maintenance cluster.
See the migration section of the full notes for the verified procedure, TLS/certificate troubleshooting, and the rollback path.
Artifacts
- Checksummed platform archives for Linux, Darwin, and Windows on amd64 and arm64, each with an SPDX SBOM.
- RPM, DEB, and APK packages under the PGSTY identity. RPMs are GPG-signed with the maintainer key (fingerprint
9592A7BC 7A682E73 33376E09 E7935D8D B9BD8B20); verify them viarpmkeys --checksigand their per-file.sha256sum(regenerated after signing). DEB/APK trust is anchored at the repository layer. - Sigstore-signed checksum manifests and a build-provenance bundle (
silo_*_provenance.sigstore.json); release artifacts carry GitHub Attestations —gh attestation verify --repo pgsty/silo <file>. docker.io/pgsty/silo:RELEASE.2026-08-06T00-00-00Zand the-distrolessvariant are built only from this release's checksum- and attestation-verified archives.
govulncheck reports no vulnerability reachable from the server code (VulnCheck CI green on the released commit).
Acknowledgments
Four contributors have code merged into this fork, and the Git history carries their authorship: @ZouhairCharef patched CVE-2026-34986 in go-jose (#18), @mfredenhagen patched CVE-2026-39883 in OpenTelemetry (#19), @pinginfo implemented Flush on trackingResponseWriter to repair bucket notification streaming (#34), and @waterkip repointed the documentation links to the Silo portal (#41).
A first release under a new name is also the right moment to thank everyone who has filed issues against this fork — bug reports, compatibility findings, and proposals alike, resolved and still open: @mosesdd (#1), @Xavier-777 (#2, #17), @jiadzh (#3), @TLINDEN (#4), @AntonOfTheWoods (#5), @zylpsrs (#6), @nsanitate (#7), @makinikm (#9), @magicxor (#10), @spaceg00se-r (#11, #14), @heroes1412 (#13), @vampywiz17 (#15), @davinkevin (#20), @chalukyaj (#30), @cbornet (#31, #32), @jvasile (#33), @Kesavaambati (#35), @redfoxfox (#38), @kuldeep-link11 (#39, #40), @meesudzu (#42), @pmezhuev (#43), @kh0mka (#51).
Several of this release's headline items trace straight back to those reports: the bundled-client guarantee (#4, #9), the LDAP-over-TLS repair (#15), the completed package payload (#33), GPG-signed RPMs (#43), the migration guide (#42), and the distroless /data fix (#55).
Special thanks to @davinkevin, whose distroless image PR (#21) anticipated this release's pilot months in advance — the shipped variant supersedes it with the native health check built in, but the direction was proposed there first. Conformance PRs from @magicxor (#12) and @ycjlin (#37) are queued for review immediately after this release.
Everyone who has contributed to this fork is recorded in CONTRIBUTORS.md, which is now the project's attribution record — GitHub generates no contributor graph for forks.
RELEASE.2026-08-04T00-00-00Z
SILO 20260804 is a security, correctness, and release-engineering update to the pgsty/minio community fork. It completes the internode storage-containment work begun with CVE-2026-42600, stops request-controlled values from impersonating server-calculated S3/IAM policy conditions, restores streaming flush behavior, fixes several multipart and versioning edge cases, hardens notification configuration, moves the baseline to Go 1.26.5, and rebuilds the release pipeline to produce reproducible binaries and GPG-signed packages.
50 commits after the pre-2026-06-18 baseline (155 files, +9,241/-981). Reviewed against this tagged commit and verified on macOS ARM64 and Linux AMD64 with GitHub CI green on the released HEAD.
Highlights
- Internode containment completed — validates storage-REST bodies, storage Grid frames, and peer-S3 Grid requests at the storage boundary, closing the remaining path, volume, erasure-metadata, panic, and unbounded-allocation defects left after removing
ReadMultiple. - S3/IAM decisions use effective values — client input can no longer shadow internal condition values; request tags and existing-object tags are separated;
s3:signatureAgeis confined to verified presigned requests;s3:versionidfollows the version the server actually acts on. - Bucket and object resources separated — twelve sensitive bucket-level writes are no longer authorized through an object-only
bucket/*pattern (documented compatibility switch available). - Multipart correctness — full-object checksum completion works without per-part checksums where the protocol permits; zero-length checksums are preserved; duplicate part numbers are rejected instead of assembling duplicated data.
- Streaming reliability restored —
trackingResponseWriterimplementsFlushcorrectly and records implicit HTTP 200, repairingmcli watch, bucket-notification listeners, and S3 Select keep-alives. - Notification hardening — NATS/AMQP parser and migration keys are registered and round-trip; libpq parameters are quoted safely; invalid-key errors no longer echo secrets.
- Reproducible, signed pipeline — binaries drop the build-machine paths, packages install under the canonical systemd path, RPMs are GPG-signed, and the container entrypoint shuts down gracefully on every privilege path.
Security Hardening
Four hardening areas, each with a full advisory:
- Internode storage & Grid containment — SN-2026-002. Path/volume traversal rejection, peer-S3 coverage, erasure-parameter and allocation bounds (
ReadFilecapped at 5 GiB), panic containment. Distributed-erasure only; single-node S3 unchanged. - Effective policy-condition values — SN-2026-003. Internal condition names cannot be supplied as client values;
s3:versionidis absent when no version is named and rebound perDeleteObjectsentry, closing a Multi-Delete fail-open trap. - Bucket/object resource boundary — SN-2026-004. An object-only
bucket/*grant no longer authorizes twelve sensitive bucket writes onAllowstatements. - Trusted client-address boundary — source-address trust.
MINIO_API_TRUSTED_PROXIESgives an enforceable, opt-in boundary foraws:SourceIpand audit attribution; unset preserves historical behavior.
Compatibility & Upgrade Notes
- Keep every node on one release during a rollout — internode validation changed on storage-REST and Grid surfaces; mixed binaries were not production-tested.
- Audit custom IAM policies — add the bare bucket ARN (
arn:aws:s3:::bucket) alongsidebucket/*for the twelve protected writes.MINIO_API_LEGACY_BUCKET_RESOURCE_MATCH=onis a temporary migration control only. - Configure client-address trust deliberately — if
aws:SourceIpor audit attribution matters, setMINIO_API_TRUSTED_PROXIESand close direct paths around the proxy. - Duplicate multipart completion entries now fail — the same part number sent more than once returns
InvalidPartOrderinstead of a corrupted successful object. Gapped/non-1 part lists remain accepted. - Review legacy database notification settings — convert pre-connection-string Postgres/MySQL
host/user/passwordfields before restart; a migrated config can otherwise fail validation, and target loading is fail-fast. - Use the matching
mcli20260804 — self-update is disabled; upgrade through packages or GitHub Releases.
Components
Go 1.26.5 · klauspost/compress 1.18.7 · Apache Thrift 0.24.0 · SILO Console 2.0.0 · silo-pkg 3.11.0 · mcli 20260804. go-systemd is held at 22.6.0 (22.7.0 breaks the NetBSD cross-build).
Artifacts
- Checksummed platform archives for Linux, Darwin, and Windows on amd64 and arm64.
- RPM, DEB, and APK packages under the PGSTY identity. RPMs are GPG-signed with the maintainer key (fingerprint
9592A7BC 7A682E73 33376E09 E7935D8D B9BD8B20); import it before enablinggpgcheck. DEB/APK trust is anchored at the repository layer. - The systemd unit installs at
/usr/lib/systemd/system/minio.servicewithType=notify. docker.io/pgsty/minio:RELEASE.2026-08-04T00-00-00Zand the release-selectedlatesttag are published on demand from this release.
govulncheck reports no vulnerability reachable from the server code.
RELEASE.2026-06-18T00-00-00Z
RELEASE.2026-06-18T00-00-00Z
2026-06-18: https://github.com/pgsty/minio/releases/tag/RELEASE.2026-06-18T00-00-00Z
This release is a security and dependency-maintenance update for the pgsty/minio fork. It hardens LDAP STS throttling, completes S3 Select oversized-record enforcement, removes the obsolete ReadMultiple internode storage-REST API, upgrades the Go build baseline to 1.26.4, and refreshes Go module dependencies to pick up additional third-party security fixes.
Major Changes
- Remove the obsolete
ReadMultiplestorage-REST API: the legacy/rmplinternode endpoint is removed rather than patched in place, including its route, handler, client wrapper, storage interfaces, xlStorage methods, generated datatypes, and related metric. No production caller is expected after upstream multipart handling moved toReadParts, but clusters should still run a consistent release during rolling upgrades. - Complete S3 Select oversized-record enforcement: JSON Lines input now uses the bounded reader path, so oversized records are rejected consistently instead of bypassing limits on SIMD-capable CPUs. S3 Select stream errors now preserve the intended error code and wrap JSON parser failures as
JSONParsingError. - Harden LDAP STS rate-limit source bucketing: throttling is now keyed only by source IP, avoiding username-shared buckets that could be drained by one client to lock out a legitimate user. Trusted-proxy handling now resolves
X-Forwarded-Forfrom right to left, rejects catch-all trusted-proxy CIDRs, ignores RFC 7239Forwarded, and documents theX-Real-IPdeployment contract. - Refresh the Go runtime and module baseline: release, hotfix, goreleaser, and old-CPU Docker builds now use
golang:1.26.4-alpine;go.modis updated to Go1.26.4; and dependencies are refreshed across NATS, Prometheus, Azure SDK, Apache Thrift, gRPC, OpenTelemetry, Google API/auth, Gox/*, and related transitive libraries.
Direct Security Fixes
- CVE-2026-42600: remove the obsolete
ReadMultiplestorage-REST API to close the legacy internode file-read path exposed through/rmpl. - CVE-2026-39414: complete oversized S3 Select record enforcement for JSON Lines inputs and preserve correct S3 Select error semantics.
- CVE-2026-33419: further harden LDAP STS rate-limit accounting and trusted-proxy source-IP handling.
Dependency Security Updates
- Update
github.com/Azure/go-ntlmsspfromv0.1.0tov0.1.1, fixing CVE-2026-32952, where malformed NTLM challenges could panic a Go process. - Update
github.com/apache/thriftfromv0.22.0tov0.23.0, fixing CVE-2026-41602 in the GoTFramedTransportimplementation. - Update
github.com/nats-io/nats-server/v2fromv2.11.1tov2.11.15, absorbing the NATS 2.11.x security patch line. Notable fixes include pre-auth WebSocket and leafnode denial-of-service issues, MQTT authorization issues, JetStream management API authorization hardening, credential exposure fixes, and request identity-spoofing fixes, including CVE-2026-27889, CVE-2026-29785, CVE-2026-33217, CVE-2026-33218, CVE-2026-33222, and CVE-2026-33247. - Update
github.com/prometheus/prometheusfromv0.310.0tov0.311.3, absorbing Prometheus security fixes for remote-read denial of service, stored XSS in UI surfaces, and remote-write configuration secret exposure, including CVE-2026-42154, CVE-2026-44903, CVE-2026-42151, and CVE-2026-40179. - Upgrade the release build baseline through Go
1.26.4and refresh supporting Go module families, includinggolang.org/x/crypto,golang.org/x/net,golang.org/x/sys,golang.org/x/text,google.golang.org/grpc, and OpenTelemetry. These updates keep the fork aligned with patched upstream dependency baselines even where the previously pinned version was already past the specific public advisory range.
Related Commits
- 5e40665: fix: harden LDAP STS rate-limit source bucketing
- fd69c89: fix: complete CVE-2026-39414 S3 Select record limit enforcement
- 73ac524: fix: CVE-2026-42600 remove ReadMultiple storage-REST API
- df627ff: fix: bump Go toolchain to 1.26.4
- 3e61b1d: chore: update Go module dependencies
RELEASE.2026-04-17T00-00-00Z
RELEASE.2026-04-17T00-00-00Z
2026-04-17: https://github.com/pgsty/minio/releases/tag/RELEASE.2026-04-17T00-00-00Z
This release focuses on security hardening and compatibility tightening. It bundles fixes across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer flows, the Snowball upload path, and multiple dependency- and Go toolchain-related security issues, while also incorporating the LDAP TLS regression fix and a cleanup of community-fork documentation.
Major Changes
- Tighten the identity-authentication flow: OIDC / WebIdentity now accepts only asymmetrically signed
ID Tokenvalues backed by the IdPJWKS; symmetrically signed tokens such asHS256are no longer accepted. LDAP STS also now hides the distinction between unknown-user and bad-password failures to reduce username-enumeration risk. - Update LDAP STS rate limiting: limits now apply to both source IP and normalized username, and successful requests no longer consume quota incorrectly. By default MinIO now uses only the socket peer address as the source and no longer trusts
X-Forwarded-For,X-Real-IP, orForwarded; to rate-limit by real client IP, configureMINIO_IDENTITY_LDAP_STS_TRUSTED_PROXIESexplicitly. - Make upload and write paths stricter: presigned query parameters can no longer be combined with
unsigned-trailerPUTor multipart uploads. Snowball auto-extract now also performs full signature validation on theunsigned-trailerpath and rejects anonymous or forged-signature requests. - Prevent replication metadata spoofing: internal
X-Minio-Replication-*headers attached to ordinaryPUT/COPYrequests are now rejected or ignored, and only trusted replication flows may write the related internal metadata. - Clarify S3 Select error semantics: oversized CSV and line-delimited JSON records now return
OverMaxRecordSizedirectly instead of the genericInternalError; clients or alerting rules that depend on the old error code should be adjusted. - Upgrade the runtime and dependency baseline: fix the regression where
ldaps://did not correctly apply TLS settings, replaceminio/pkg/v3withpgsty/minio-pkg/v3, and pin several critical dependencies that are prone to breaking changes. The release also upgradesgo-jose,go.opentelemetry.io, and Go1.26.2to unify the build and release baseline. - Refresh documentation and security guidance: update
SECURITY.md,VULNERABILITY_REPORT.md,docs/sts/ldap.md, and related documents, add a security advisory index, and switch upstreamminio/minioreferences in the security guidance over topgsty/minio.
Fixed CVEs
- CVE-2026-34986: upgrade
go-josetov4.1.4and fix known security issues in the JWT / JOSE dependency chain. - CVE-2026-39883: upgrade the
go.opentelemetry.iodependency stack to fix the PATH-hijacking risk. - CVE-2026-33322: restore the strict JWKS-only OIDC JWT verification path to block keyring injection and algorithm-confusion risk.
- CVE-2026-33419: systematically harden LDAP STS authentication, rate limiting, source-address identification, and accounting logic across four follow-up fixes.
- CVE-2026-34204: reject injection of
X-Minio-Replication-*metadata by untrusted requests to prevent objects from being written with invalid replication state. - CVE-2026-39414: reject oversized S3 Select records early to avoid continued buffering and parsing of abnormal inputs.
- GHSA-hv4r-mvr4-25vw: close the unsigned-trailer query-auth bypass.
- GHSA-9c4q-hq6p-c237: harden unsigned-trailer authentication and signature validation in Snowball auto-extract scenarios.
- CVE-2026-32280, CVE-2026-32281, and CVE-2026-32283: upgrade Go to
1.26.2and absorb the upstream toolchain and stdlib security fixes.
Related Commits
- c878ca0: fix: pin deps with breaking changes and fix LDAP TLS regression (#15)
- e970ec5: fix: upgrade go-jose to v4.1.4 to patch CVE-2026-34986
- a206510: fix: CVE-2026-39883 upgrade go.opentelemetry.io
- fd65f11: merge: PR #18 upgrade go-jose to v4.1.4 for CVE-2026-34986
- bc087e4: merge: PR #19 upgrade go.opentelemetry.io for CVE-2026-39883
- f1f2239: fix: CVE-2026-33322 restore JWKS-only OIDC JWT verification
- 6619d0c: fix: CVE-2026-33419 harden LDAP STS auth
- fcb8f24: fix: CVE-2026-34204 reject untrusted replication metadata
- c5765dc: fix: CVE-2026-39414 reject oversized S3 Select records
- fa7c579: fix: GHSA-hv4r-mvr4-25vw block unsigned-trailer query auth bypass
- b50ab58: fix: GHSA-9c4q-hq6p-c237 harden Snowball unsigned-trailer auth
- 9a4b3cd: fix: CVE-2026-32280/CVE-2026-32281/CVE-2026-32283 upgrade Go to 1.26.2
- c55b52c: fix: CVE-2026-33419 preserve LDAP STS rate limits on success
- 817a457: fix: CVE-2026-33419 harden LDAP STS rate-limit source IP
- 084a154: fix: CVE-2026-33419 tighten LDAP STS rate-limit accounting
- 16e34f9: docs: refresh security guidance and fork references
RELEASE.2026-03-25T00-00-00Z
This release is mainly a packaging and stability update. It bundles mcli/mc into the Docker image with checksum verification, removes unused upstream CI/CD workflows from the pgsty/minio fork, and fixes an LDAP TLS regression for ldaps:// while pinning several dependencies to avoid compatibility breakage. (#15)
- This release fixes three security vulnerabilities: CVE-2026-24051, CVE-2025-10543, and CVE-2025-58181.
- The fixes are included through dependency updates to
go.opentelemetry.io/otel/sdk,github.com/eclipse/paho.mqtt.golang, andgolang.org/x/crypto. - Users should upgrade to this release to receive the patched versions of these components.
Changelog
RELEASE.2026-03-21T00-00-00Z
This release upgrades MinIO to Go 1.26.1, updates dependencies, and includes small compatibility fixes needed for the newer toolchain. No new features are introduced; this is primarily a maintenance and build-environment update.
Changelog
RELEASE.2026-03-14T12-00-00Z
RELEASE.2026-03-14T12-00-00Z with go 1.26.0
Switch to community-maintained console fork (georgmangold/console v1.9.1)
and update dependencies accordingly. Fix go vet format directive in
grid_test.go and adapt test status code for Go 1.26 HTTP semantics.