Skip to content

Machine Driver Compatibility Bundle 0.16.4

Latest

Choose a tag to compare

@chen21019 chen21019 released this 14 Aug 05:46

Machine Driver Compatibility Bundle 0.16.4

This release provides the reviewed Linux AMD64 compatibility bundle as a reproducible, license-complete artifact.

Security changes

  • Removed the externally controlled license-output path. The collector now writes only to standard output, while the packaging process owns its temporary staging destination.
  • Restricted module-license discovery to the two reviewed source trees or the active Go module cache.
  • Rejected relative paths, directory escapes, symbolic-link escapes, control characters, binary license files, and files larger than 1 MiB.
  • Added nine positive and adversarial regression tests for the complete source-to-output boundary.
  • Updated the pinned build toolchains to Go 1.26.6 and Python 3.14.6 and updated the full-commit-pinned GitHub Actions used by the release gate.

Sources and lifecycle

  • The Docker Machine-compatible executable is rebuilt from GitLab's Apache-2.0 v0.16.2-gitlab.51 source at commit 7e13feeb34e436fbb895cb03fb5386185b68b720.
  • The Packet-compatible driver is rebuilt from the BSD-3-Clause Equinix Metal driver 0.6.0 source at commit 1579a8271d52e00760e38dd153d3935abc302915.
  • The Packet-compatible driver is retained only for compatibility, audit, and rollback. Its provider service is retired and it must not be enabled for new installations.
  • The bundle includes the applicable upstream licenses, third-party notices, exact source coordinates, provider lifecycle statement, and security VEX.

Verification

  • CodeQL: 0 open findings in the reviewed Actions and Python analyses.
  • Source and product scans: 0 Critical, 0 High, and 0 exposed secrets.
  • CycloneDX 1.7: 97 source components and 71 product components.
  • Full upstream tests, race tests, CLI and plugin-protocol checks, exact dependency graph verification, and two byte-identical package builds passed.
  • The Linux AMD64 package SHA-256 is dfecc1cfa2ef544bde9e6744976557fd1c0123670c7782fb9c5d3b099a675843.
  • GitHub Artifact Attestation binds this package digest to the protected main commit 6110328a6b2122abc6b8612834a55742178c2cfa and the security release workflow.

This is an independent clean-room packaging implementation. It does not copy code or binaries from the unlicensed historical packaging repository and does not change the licenses or attribution of third-party work. This release has not been integrated into Server, Catalog, an isolated VM, or a production deployment.