Skip to content

v1.2.0

Latest

Choose a tag to compare

@waahhaa waahhaa released this 26 Mar 03:23
7e40503

Changes

CVE hardening — zero HIGH/CRITICAL CVEs in the runtime image. libarchive removed post-update (CVE-2026-4111). giflib not installed — plg_image_c is the only plugin with giflib CGO linkage and is disabled, making giflib a non-dependency at runtime. Go builder upgraded to golang:1.25-trixie (CVE-2026-25679, stdlib net/url).

Docker — rebuilt on ubi9-minimal base with golang:1.25-trixie builder; runtime libraries installed via inline EPEL 9 repo file; libsharpyuv.so.0 copied from Debian builder stage (amd64 only). Added Dockerfile.local for local dev builds without cloning from GitHub.

Plugin minimization — disabled OpenID, SAML, WebAuthn, Tor, and other plugins with unresolved build dependencies. Removed plg_image_light (CGO-based, no longer needed). Only local storage, S3, passthrough auth, and HTTP starter are compiled in.

S3 backend — credentials and endpoint now read from AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_ENDPOINT_URL environment variables as priority. Form inputs used as fallback if env vars are absent.

Static hook fix — corrected hook registration in plg_override_download.

LF enforcement — .gitattributes enforces LF for all .sh files to prevent CRLF breakage inside Linux containers.

Notes

  • amd64 only: libsharpyuv.so.0 is not packaged in UBI9 or EPEL and is copied from the Debian builder stage. Builds will fail on arm64.
  • Deployment manifests and Helm charts are maintained in STARLAB1733/starforging (branch feat/stardrive).