Repository navigation
A maintenance release: the go directive raised to 1.27, the build toolchain moved to go1.27.1, and the dependencies brought current. No configuration key, endpoint or command-line flag changes.
Two runtime defaults change
Go compiles a module that declares an older version with that version's compatibility settings, so the v1.2.0 binaries carry DefaultGODEBUG=tracebacklabels=0,x509sslcertoverrideplatform=0. Raising the go directive from 1.26.0 to 1.27.0 drops both pins, and the v1.3.0 binaries, built with go1.27.1, carry no DefaultGODEBUG entry at all:
| setting | 0, until now | 1, the Go 1.27 default |
|---|---|---|
tracebacklabels |
goroutine labels absent from tracebacks | labels appear |
x509sslcertoverrideplatform |
the platform certificate store always wins | on Windows and darwin, crypto/x509 loads roots from disk when SSL_CERT_FILE or SSL_CERT_DIR is set |
The second one is the operationally relevant one. When --ldap-server names an ldaps:// URL, raybeam connects to the directory over TLS without a TLS configuration of its own, so the handshake trusts whatever roots crypto/x509 loads. An operator who runs the Windows or darwin binary, sets either variable, and relies on the platform store winning should set GODEBUG=x509sslcertoverrideplatform=0. The Linux binaries and the container image are unaffected — the setting exists only for those two platforms (#280 by @CybotTM).
Dependencies
netresearch/simple-ldap-go 1.16.0 → 1.18.0 (#279, #282), golang.org/x/crypto 0.55.0 → 0.57.0 (#276, #278), the Alpine base image 3.24.1 → 3.24.2 (#281), and the build toolchain go1.27.0 → go1.27.1 (#275). Indirect dependencies moved with them.
Documentation
The development and architecture guides and AGENTS.md state the Go 1.27 requirement (#280 by @CybotTM).
CI
The Dependabot configuration is removed, leaving Renovate as the only updater (#277 by @CybotTM).
Full changelog: v1.2.0...v1.3.0
Container image
ghcr.io/netresearch/raybeam:1.3.0
ghcr.io/netresearch/raybeam:1.3
ghcr.io/netresearch/raybeam:1
Verify your download
Per-asset signatures are bundled. Verify any single file:
cosign verify-blob \
--bundle raybeam-linux-amd64.sigstore.json \
--certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
raybeam-linux-amd64Verify checksums against the signed manifest:
cosign verify-blob \
--bundle checksums.txt.sigstore.json \
--certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
checksums.txt
sha256sum -c checksums.txt --ignore-missingVerify build provenance. Releases are built by a reusable
workflow, so the signing identity is that workflow rather than
this repository -- --signer-workflow is required and
verification fails without it:
gh attestation verify <artifact> \
--repo netresearch/raybeam \
--signer-workflow netresearch/.github/.github/workflows/release-go-app.ymlVerify container image:
cosign verify ghcr.io/netresearch/raybeam:1.3.0 \
--certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"
gh attestation verify oci://ghcr.io/netresearch/raybeam:1.3.0 \
--repo netresearch/raybeam \
--signer-workflow netresearch/.github/.github/workflows/release-go-app.yml