Machine Driver Compatibility Bundle 0.16.4
This release provides the reviewed Linux AMD64 compatibility bundle as a reproducible, license-complete artifact.
Security changes
- Removed the externally controlled license-output path. The collector now writes only to standard output, while the packaging process owns its temporary staging destination.
- Restricted module-license discovery to the two reviewed source trees or the active Go module cache.
- Rejected relative paths, directory escapes, symbolic-link escapes, control characters, binary license files, and files larger than 1 MiB.
- Added nine positive and adversarial regression tests for the complete source-to-output boundary.
- Updated the pinned build toolchains to Go 1.26.6 and Python 3.14.6 and updated the full-commit-pinned GitHub Actions used by the release gate.
Sources and lifecycle
- The Docker Machine-compatible executable is rebuilt from GitLab's Apache-2.0
v0.16.2-gitlab.51source at commit7e13feeb34e436fbb895cb03fb5386185b68b720. - The Packet-compatible driver is rebuilt from the BSD-3-Clause Equinix Metal driver
0.6.0source at commit1579a8271d52e00760e38dd153d3935abc302915. - The Packet-compatible driver is retained only for compatibility, audit, and rollback. Its provider service is retired and it must not be enabled for new installations.
- The bundle includes the applicable upstream licenses, third-party notices, exact source coordinates, provider lifecycle statement, and security VEX.
Verification
- CodeQL: 0 open findings in the reviewed Actions and Python analyses.
- Source and product scans: 0 Critical, 0 High, and 0 exposed secrets.
- CycloneDX 1.7: 97 source components and 71 product components.
- Full upstream tests, race tests, CLI and plugin-protocol checks, exact dependency graph verification, and two byte-identical package builds passed.
- The Linux AMD64 package SHA-256 is
dfecc1cfa2ef544bde9e6744976557fd1c0123670c7782fb9c5d3b099a675843. - GitHub Artifact Attestation binds this package digest to the protected
maincommit6110328a6b2122abc6b8612834a55742178c2cfaand the security release workflow.
This is an independent clean-room packaging implementation. It does not copy code or binaries from the unlicensed historical packaging repository and does not change the licenses or attribution of third-party work. This release has not been integrated into Server, Catalog, an isolated VM, or a production deployment.