Skip to content

v1.3.0

Latest

Choose a tag to compare

@github-actions github-actions released this 22 Sep 17:47
· 15 commits to main since this release
Immutable release. Only release title and notes can be modified.
v1.3.0
6630c53

A maintenance release: the go directive raised to 1.27, the build toolchain moved to go1.27.1, and the dependencies brought current. No configuration key, endpoint or command-line flag changes.

Two runtime defaults change

Go compiles a module that declares an older version with that version's compatibility settings, so the v1.2.0 binaries carry DefaultGODEBUG=tracebacklabels=0,x509sslcertoverrideplatform=0. Raising the go directive from 1.26.0 to 1.27.0 drops both pins, and the v1.3.0 binaries, built with go1.27.1, carry no DefaultGODEBUG entry at all:

setting 0, until now 1, the Go 1.27 default
tracebacklabels goroutine labels absent from tracebacks labels appear
x509sslcertoverrideplatform the platform certificate store always wins on Windows and darwin, crypto/x509 loads roots from disk when SSL_CERT_FILE or SSL_CERT_DIR is set

The second one is the operationally relevant one. When --ldap-server names an ldaps:// URL, raybeam connects to the directory over TLS without a TLS configuration of its own, so the handshake trusts whatever roots crypto/x509 loads. An operator who runs the Windows or darwin binary, sets either variable, and relies on the platform store winning should set GODEBUG=x509sslcertoverrideplatform=0. The Linux binaries and the container image are unaffected — the setting exists only for those two platforms (#280 by @CybotTM).

Dependencies

netresearch/simple-ldap-go 1.16.0 → 1.18.0 (#279, #282), golang.org/x/crypto 0.55.0 → 0.57.0 (#276, #278), the Alpine base image 3.24.1 → 3.24.2 (#281), and the build toolchain go1.27.0 → go1.27.1 (#275). Indirect dependencies moved with them.

Documentation

The development and architecture guides and AGENTS.md state the Go 1.27 requirement (#280 by @CybotTM).

CI

The Dependabot configuration is removed, leaving Renovate as the only updater (#277 by @CybotTM).

Full changelog: v1.2.0...v1.3.0

Container image

ghcr.io/netresearch/raybeam:1.3.0
ghcr.io/netresearch/raybeam:1.3
ghcr.io/netresearch/raybeam:1

Verify your download

Per-asset signatures are bundled. Verify any single file:

cosign verify-blob \
  --bundle raybeam-linux-amd64.sigstore.json \
  --certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  raybeam-linux-amd64

Verify checksums against the signed manifest:

cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  checksums.txt
sha256sum -c checksums.txt --ignore-missing

Verify build provenance. Releases are built by a reusable
workflow, so the signing identity is that workflow rather than
this repository -- --signer-workflow is required and
verification fails without it:

gh attestation verify <artifact> \
  --repo netresearch/raybeam \
  --signer-workflow netresearch/.github/.github/workflows/release-go-app.yml

Verify container image:

cosign verify ghcr.io/netresearch/raybeam:1.3.0 \
  --certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"
gh attestation verify oci://ghcr.io/netresearch/raybeam:1.3.0 \
  --repo netresearch/raybeam \
  --signer-workflow netresearch/.github/.github/workflows/release-go-app.yml