Zentinel 26.07_3
Cargo version: 0.6.22
What's Changed
Security
- Bump
serde_with3.18.0 → 3.21.0 — fixes GHSA-7gcf-g7xr-8hxj, a serialization
panic (DoS) inKeyValueMap. Zentinel's exposure was low (transitive via
ip2location, noKeyValueMapusage), resolved regardless. (#307)
Changed
- Bump
tokio-tungstenite0.29.0 → 0.30.0. (#306) - Bump
jsonschema0.46.10 → 0.48.1. (#305) - Bump the rust-minor group (
bytes1.12.1,uuid,regex,sysinfo0.39.6). (#309) - Bump the rust-minor group (
tokio1.53,rustls0.23.42,uuid1.24,
regex1.13.1,http-body-util,toml,clap,redis1.4.1,
xxhash-rust). (#310)
Installation
From crates.io
cargo install zentinel-proxyFrom binary
Download the appropriate archive for your platform and extract:
tar -xzf zentinel-26.07_3-linux-amd64.tar.gz
sudo mv zentinel /usr/local/bin/Docker
docker pull ghcr.io/zentinelproxy/zentinel:26.07_3Supply Chain Security
All release archives are signed with Sigstore cosign using keyless signing tied to GitHub Actions OIDC identity. SLSA v1.0 provenance is attached to this release.
Verify a binary
cosign verify-blob --bundle zentinel-26.07_3-linux-amd64.tar.gz.bundle \
--certificate-identity-regexp "github.com/zentinelproxy/zentinel" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
zentinel-26.07_3-linux-amd64.tar.gzVerify the container image
cosign verify ghcr.io/zentinelproxy/zentinel:26.07_3 \
--certificate-identity-regexp "github.com/zentinelproxy/zentinel" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"Checksums
Verify downloads with the .sha256 files.
Software Bill of Materials
CycloneDX 1.5 and SPDX 2.3 SBOMs are attached as release assets.