Changes
CVE hardening — zero HIGH/CRITICAL CVEs in the runtime image. libarchive removed post-update (CVE-2026-4111). giflib not installed — plg_image_c is the only plugin with giflib CGO linkage and is disabled, making giflib a non-dependency at runtime. Go builder upgraded to golang:1.25-trixie (CVE-2026-25679, stdlib net/url).
Docker — rebuilt on ubi9-minimal base with golang:1.25-trixie builder; runtime libraries installed via inline EPEL 9 repo file; libsharpyuv.so.0 copied from Debian builder stage (amd64 only). Added Dockerfile.local for local dev builds without cloning from GitHub.
Plugin minimization — disabled OpenID, SAML, WebAuthn, Tor, and other plugins with unresolved build dependencies. Removed plg_image_light (CGO-based, no longer needed). Only local storage, S3, passthrough auth, and HTTP starter are compiled in.
S3 backend — credentials and endpoint now read from AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_ENDPOINT_URL environment variables as priority. Form inputs used as fallback if env vars are absent.
Static hook fix — corrected hook registration in plg_override_download.
LF enforcement — .gitattributes enforces LF for all .sh files to prevent CRLF breakage inside Linux containers.
Notes
- amd64 only: libsharpyuv.so.0 is not packaged in UBI9 or EPEL and is copied from the Debian builder stage. Builds will fail on arm64.
- Deployment manifests and Helm charts are maintained in STARLAB1733/starforging (branch feat/stardrive).