Repository navigation
Releases: PastureStack/host-provisioner
Release list
Host Provisioner v0.39.7
Host Provisioner v0.39.7
Upgrade golang.org/x/crypto to v0.56.0 to address CVE-2026-56855 and CVE-2026-78662 in the SSH channel dispatch used by host provisioning. Keep the existing reviewed Docker Machine compatibility changes.
- Source: c396df5 (merged PR #6).
- Main validation run: https://github.com/PastureStack/host-provisioner/actions/runs/34137894997
- Main security run: https://github.com/PastureStack/host-provisioner/actions/runs/34137895006
- Complete package tests, race checks, vet/source validation, two focused SSH regression tests, CodeQL, and two byte-identical package builds passed.
- Product scan: no Critical/High findings or secrets; the retained module-level GO-2026-5932 OpenPGP finding is not an SSH finding and the shipped application does not import OpenPGP.
- Build-image kernel-header findings remain separately identified in CI evidence and are not shipped in the CGO-disabled Go executable.
The attached SHA-256 file, Go build metadata, product scan and source revision identify the exact released artifact. This component release alone does not prove the aggregate Server image or a production deployment has passed its security gate.
Host Provisioner v0.39.6
Go 1.27.0 rebuild from the reviewed main commit. The release artifact is bound by SHA-256 and the attached product scan, Go build metadata, and successful validation evidence.
Host Provisioner 0.39.5
Host Provisioner 0.39.5
This release preserves the upstream v0.39.4 history and adds one reviewed PastureStack maintenance commit.
Security and compatibility
- Constrains machine state, stamp, cache, driver, and archive operations to reviewed storage roots.
- Rejects path traversal, cross-machine archive entries, links, devices, special files, unsafe driver names, weak or missing driver checksums, and oversized driver payloads.
- Parses driver tar, tar.gz, and zip archives in-process instead of invoking external extraction tools.
- Preserves legitimate legacy machine identifiers, including spaces and non-ASCII text.
- Retains Ubuntu 26.04, Go 1.26.5, and the checksum-pinned Docker 29.7.2 build tool.
Verification
- Full tests, race tests, static validation, deterministic packaging, CodeQL, source/product secret scans, and supply-chain gates passed for source
0a1e607ca5cb08372457a50c68b2eba48448e24e. - The release archive includes the root license, origin record, and 19 preserved bundled-dependency legal files.
- SHA-256:
08daefc5abb7966ab2861f5e5a75a6fb6f890bd59b8abbe336b68da17954ee1d
Production deployment remains a separate isolated-VM integration step; this release does not modify a running Server.