RELEASE.2026-04-17T00-00-00Z #29
Vonng
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
2026-04-17: https://github.com/pgsty/minio/releases/tag/RELEASE.2026-04-17T00-00-00Z
This release is centered on security hardening. It closes multiple issues across OIDC, LDAP STS, S3 Select, replication metadata handling, unsigned-trailer authentication, Snowball upload flows, and dependency plus Go toolchain security maintenance, while also folding in dependency governance, the LDAP TLS regression fix, and a refresh of fork-specific security documentation.
Fixed CVEs
go-josetov4.1.4and pick up the JWT / JOSE dependency-side security fix.go.opentelemetry.iostack to fix the PATH-hijacking issue.X-Minio-Replication-*metadata so objects cannot be forced into invalid replication state.1.26.2and absorb the upstream toolchain / stdlib fixes.Major Changes
minio/pkg/v3withpgsty/minio-pkg/v3and pinning a set of dependencies with known breaking-change behavior.go-jose v4.1.4and newergo.opentelemetry.iocomponents, while preserving the upstream merge lineage in history.OverMaxRecordSizeerror.1.26.2and refresh the corresponding build-image references.SECURITY.md,VULNERABILITY_REPORT.md,docs/sts/ldap.md, and related fork-specific references so the documentation matches the community-maintained ownership model.Beta Was this translation helpful? Give feedback.
All reactions