abuckit
ab4a101ab0
fix: resolve dependabot alerts
2026-06-17 09:18:34 -04:00
abuckit
e701c06571
ci: fix lint and verifier workflow failures
2026-06-14 13:57:47 -04:00
abuckit
de269229bc
ci: stabilize Go and lint workflow tooling
2026-06-13 22:55:34 -04:00
abuckit
3f9e6c8a6d
deps: bump go-jose to v4.1.4 to fix govulncheck
...
Resolves GO-2026-4945 (JWE decryption panic in github.com/go-jose/go-jose/v4),
reachable via the OIDC init path (cmd/utils.go -> oidc.init -> jose.init).
Fixed in go-jose/v4 v4.1.4.
2026-05-29 23:09:58 -04:00
abuckit
f0c2589239
deps: bump x/crypto to v0.52.0 and x/net to v0.55.0 to fix govulncheck
...
Resolves govulncheck failures flagged in CI:
- GO-2026-5013..5023 (golang.org/x/crypto/ssh) — fixed in v0.52.0
- GO-2026-5026 (golang.org/x/net/idna) — fixed in v0.55.0
x/sys bumped to v0.45.0 as a transitive dependency.
2026-05-29 23:01:51 -04:00
abuckit
eb9bd45e13
Bump console dependency to pick up self-hosted Montserrat font
...
Pulls in buckit-io/console@f8ce35f8 , which replaces the
CSP-blocked Google Fonts <link> with a 6.7 KB embedded
Montserrat subset for the BuckitLogo wordmark.
2026-05-23 22:07:03 -04:00
abuckit
c4d5c58014
deps: switch buckit to buckit madmin-go and minio-go forks
2026-05-21 22:05:21 -04:00
abuckit
01ecad1ea9
fix: update CI scripts and workflows for buckit
...
- Rename all 'minio server' references to './buckit server'
- Update default credentials from minioadmin to buckitadmin
- Add 'pkill -9 buckit' to all test cleanup functions
- Pin workflow Go version to 1.25.10
- Update vulnerable Go modules
- Fix resiliency tests: restore docker compose --wait, add
MC_HOST_local env var, fix induce_bitrot_for_xlmeta typo
- Update mint docker-compose images to buckit
- Update IAM integration and root lockdown test scripts
2026-05-09 16:31:50 -04:00
abuckit
5bd6b356f2
chore: rebrand repo metadata, build paths, and CI tooling for Buckit
2026-05-08 13:37:11 -04:00
abuckit
4969a9c426
Fix github Actions
2026-04-30 16:06:15 -04:00
Mark Theunissen
ba3c0fd1c7
Bump Go version in toolchain directive to 1.24.8 ( #21629 )
2025-10-10 11:57:03 -07:00
Klaus Post
b8631cf531
Use new gofumpt ( #21613 )
...
Update tinylib. Should fix CI.
`gofumpt -w .&&go generate ./...`
2025-09-28 13:59:21 -07:00
Alex
9fdbf6fe83
Updated object-browser to the latest version v2.0.4 ( #21564 )
...
Signed-off-by: Benjamin Perez <benjamin@bexsoft.net >
2025-09-06 10:33:19 -07:00
Alex
752abc2e2c
Update console to v2.0.3 ( #21474 )
...
Signed-off-by: Benjamin Perez <benjamin@bexsoft.net >
Co-authored-by: Benjamin Perez <benjamin@bexsoft.net >
2025-07-30 10:57:17 -07:00
Alex
a65292cab1
Update Console to latest version ( #21397 )
...
Signed-off-by: Benjamin Perez <benjamin@bexsoft.net >
2025-06-24 17:33:22 -07:00
Alex
160f8a901b
Update Console UI to latest version ( #21294 )
2025-05-21 08:59:37 -07:00
Alex
8cad40a483
Update UI console to the latest version ( #21278 )
...
Signed-off-by: Benjamin Perez <benjamin@bexsoft.net >
2025-05-09 13:09:54 -07:00
Klaus Post
f01374950f
Use go mod tool to install tools for go generate ( #21232 )
...
Use go tool for generators
* Use go.mod tool section
* Install tools with go generate
* Update dependencies
* Remove madmin fork.
2025-04-24 16:34:11 -07:00
Andreas Auernhammer
427826abc5
update minio/kms-go/kms SDK ( #21233 )
...
Signed-off-by: Andreas Auernhammer <github@aead.dev >
2025-04-24 08:33:57 -07:00
Harshavardhana
43aa8e4259
support autogenerated credentials for KMS_SECRET_KEY properly ( #21223 )
...
we had a chicken and egg problem with this feature even
when used with kes the credentials generation would
not work in correct sequence causing setup/deployment
disruptions.
This PR streamlines all of this properly to ensure that
this functionality works as advertised.
2025-04-21 09:23:51 -07:00
dependabot[bot]
7ee75368e0
build(deps): bump github.com/nats-io/nats-server/v2 from 2.9.23 to 2.10.27 ( #21191 )
...
build(deps): bump github.com/nats-io/nats-server/v2
Bumps [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server ) from 2.9.23 to 2.10.27.
- [Release notes](https://github.com/nats-io/nats-server/releases )
- [Changelog](https://github.com/nats-io/nats-server/blob/main/.goreleaser.yml )
- [Commits](https://github.com/nats-io/nats-server/compare/v2.9.23...v2.10.27 )
---
updated-dependencies:
- dependency-name: github.com/nats-io/nats-server/v2
dependency-version: 2.10.27
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-17 04:45:51 -07:00
dependabot[bot]
0581001b6f
build(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 ( #21200 )
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.37.0 to 0.38.0.
- [Commits](https://github.com/golang/net/compare/v0.37.0...v0.38.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-version: 0.38.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-17 04:45:15 -07:00
Taran Pelkey
eb33bc6bf5
Add New Accesskey Info and OpenID Accesskey List API endpoints ( #21097 )
2025-04-16 00:34:24 -07:00
Harshavardhana
2b34e5b9ae
move to go1.24 ( #21114 )
2025-04-09 07:28:39 -07:00
Taran Pelkey
53d40e41bc
Add new API endpoint to revoke STS tokens ( #21072 )
2025-03-31 11:51:24 -07:00
dependabot[bot]
b67f0cf721
build(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 ( #21056 )
...
Bumps [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt ) from 4.5.1 to 4.5.2.
- [Release notes](https://github.com/golang-jwt/jwt/releases )
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md )
- [Commits](https://github.com/golang-jwt/jwt/compare/v4.5.1...v4.5.2 )
---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v4
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-23 08:18:21 -07:00
dependabot[bot]
670edb4fcf
build(deps): bump github.com/golang-jwt/jwt/v5 from 5.2.1 to 5.2.2 ( #21055 )
...
Bumps [github.com/golang-jwt/jwt/v5](https://github.com/golang-jwt/jwt ) from 5.2.1 to 5.2.2.
- [Release notes](https://github.com/golang-jwt/jwt/releases )
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md )
- [Commits](https://github.com/golang-jwt/jwt/compare/v5.2.1...v5.2.2 )
---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-22 08:21:04 -07:00
Harshavardhana
5e2eb372bf
update dependencies for CVE fix x/net
2025-03-12 22:29:51 -07:00
Aditya Manthramurthy
8aa0e9ff7c
Update ssh and jws libs for fixed CVEs ( #21017 )
...
- https://pkg.go.dev/vuln/GO-2025-3488
- https://pkg.go.dev/vuln/GO-2025-3487
2025-03-12 08:16:19 -07:00
Anis Eleuch
f129fd48f2
Update golang.org/x/crypto to address govulncheck complaint ( #20983 )
2025-02-26 08:15:09 -08:00
dependabot[bot]
526053339b
build(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 ( #20976 )
...
Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose ) from 4.0.4 to 4.0.5.
- [Release notes](https://github.com/go-jose/go-jose/releases )
- [Changelog](https://github.com/go-jose/go-jose/blob/main/CHANGELOG.md )
- [Commits](https://github.com/go-jose/go-jose/compare/v4.0.4...v4.0.5 )
---
updated-dependencies:
- dependency-name: github.com/go-jose/go-jose/v4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-26 01:25:19 -08:00
Taran Pelkey
62a35b3e77
Update SRSvcAccCreate with new type ( #20974 )
2025-02-24 17:43:59 -08:00
Cesar N.
447054b841
Update console to 1.7.6 ( #20925 )
2025-02-11 15:43:04 -08:00
Andreas Auernhammer
703f51164d
kms: add MINIO_KMS_REPLICATE_KEYID option ( #20909 )
...
This commit adds the `MINIO_KMS_REPLICATE_KEYID` env. variable.
By default - if not specified or not set to `off` - MinIO will
replicate the KMS key ID of an object.
If `MINIO_KMS_REPLICATE_KEYID=off`, MinIO does not include the
object's KMS Key ID when replicating an object. However, it always
sets the SSE-KMS encryption header. This ensures that the object
gets encrypted using SSE-KMS. The target site chooses the KMS key
ID that gets used based on the site and bucket config.
Signed-off-by: Andreas Auernhammer <github@aead.dev >
2025-02-07 15:21:09 -08:00
Harshavardhana
4b6eadbd80
update deps ( #20851 )
2025-01-17 16:31:37 -08:00
Andreas Auernhammer
b4ac53d157
update github.com/minio/kms-go/kes to v0.3.1 ( #20843 )
...
Signed-off-by: Andreas Auernhammer <github@aead.dev >
2025-01-16 01:13:28 -08:00
Anis Eleuch
00b2ef2932
Bump golang.org/x/net to silence wrong vuln checker ( #20814 )
2025-01-08 16:39:24 +05:30
Harshavardhana
02f770a0c0
update all dependencies and use latest msgp ( #20768 )
2024-12-16 04:20:12 +05:30
dependabot[bot]
2f4c79bc0f
Bump golang.org/x/crypto from 0.29.0 to 0.31.0 ( #20767 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.29.0 to 0.31.0.
- [Commits](https://github.com/golang/crypto/compare/v0.29.0...v0.31.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-14 23:04:23 -08:00
Cesar N.
9cdd204ae4
Upgrade Console version to v1.7.5 ( #20748 )
2024-12-11 16:23:53 +05:30
Alex
f0d4ef604c
Updated Console to v1.7.4 ( #20693 )
...
Signed-off-by: Benjamin Perez <benjamin@bexsoft.net >
2024-11-28 13:14:11 +05:30
Eng Zer Jun
c07e5b49d4
refactor: replace experimental maps and slices with stdlib ( #20679 )
...
The experimental functions are now available in the standard library in
Go 1.23 [1].
[1]: https://go.dev/doc/go1.23#new-unique-package
Signed-off-by: Eng Zer Jun <engzerjun@gmail.com >
2024-11-25 09:10:22 -08:00
Nao Yonashiro
7e0c1c9413
feat: bump github.com/cosnicolaou/pbzip2 from 1.0.3 to 1.0.5 ( #20671 )
...
Update github.com/cosnicolaou/pbzip2 to latest version for
significant performance improvements. This update brings a 45%
reduction in processing time.
2024-11-20 18:53:52 -08:00
Harshavardhana
4ee3434854
updating all dependencies as per regular cadence ( #20646 )
2024-11-14 12:33:18 -08:00
dependabot[bot]
7cb4b5c636
Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 ( #20611 )
...
Bumps [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt ) from 4.5.0 to 4.5.1.
- [Release notes](https://github.com/golang-jwt/jwt/releases )
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md )
- [Commits](https://github.com/golang-jwt/jwt/compare/v4.5.0...v4.5.1 )
---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v4
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-05 02:22:36 -08:00
Cesar N.
7ee42b3ff5
Update console package to v1.7.3 ( #20606 )
2024-11-04 08:47:08 -08:00
Klaus Post
51410c9023
Clear omitted fields ( #20575 )
...
Searched `msg:"[a-zA-Z0-9]*,omitempty` through the codebase.
Uses latest tinylib master.
2024-10-22 08:30:50 -07:00
Harshavardhana
ab7714b01e
upgrade relevant dependencies ( #20507 )
2024-10-01 23:37:55 -07:00
Harshavardhana
7f1e1713ab
use absolute path for binary checksum verification ( #20487 )
2024-09-26 08:03:08 -07:00
Klaus Post
974cbb3bb7
Limit jstream parse depth ( #20474 )
...
Add https://github.com/bcicen/jstream/pull/15 by vendoring the package.
Sets JSON depth limit to 100 entries in S3 Select.
2024-09-23 12:35:41 -07:00