Skip to content

mcli 20260913 Released

Correctness fixes, pkg v3.14.0, upstream SDK refresh and verified multi-architecture delivery.
Correctness fixes, pkg v3.14.0, upstream SDK refresh and verified multi-architecture delivery.

Release: RELEASE.2026-09-13T00-00-00Z · Package: 20260913000000.0.0 · Source: 4f609a4d.

Changes since 20260903

  • Preserve historical destination versions under mirror --remove --watch.
  • Keep service-restart dry runs from executing a restart and make noninteractive behavior explicit.
  • Return failure for transfer and S3 Select errors, honor explicit checksums on empty uploads, and retain pipe JSON output when quiet mode is enabled.
  • Accept on/off boolean environment values and repair CLI/JSON behavior across supported platforms.
  • Adopt pkg v3.14.0 and upstream SDK v7.3.1-0.20260910142817-60bd07042d49, refresh Go x/* and UBI dependencies, and keep Go 1.27.1. NetBSD retains the go-systemd v22.6.0 portability pin.

The package retains the policy Deny/NotResource and bounded wildcard repairs from pkg v3.13.3. Correctly preserved denies may now reject requests that relied on lost clauses. Recover already-lost clauses from the original policy source.

The new pkg also changes password capabilities. Read the password-policy migration before a coordinated Server upgrade. This mcli release alone does not change an installed Server’s action mapping. As of 2026-09-13, matching Server/Console changes remain unreleased; see the component matrix.

Delivery and validation

The immutable release contains 19 assets: six archives for Linux, macOS and Windows on amd64/arm64, RPM/DEB/APK packages for both Linux architectures, checksums and package checksum sidecars. Archives and the checksum manifest have verified build attestations; RPMs carry the PGSTY GPG signature. Native macOS arm64 version and Go build metadata were checked against the released pins.

The release and latest tags of docker.io/pgsty/mc resolve to the same verified amd64/arm64 manifest:

sha256:aa5cc1401b3e1ab482d215d5717e9e69b4f14970a3656f330ed20a549fe19020

Container publication completed; both architecture images were pulled and their version output checked. Go, cross-compilation, vulnerability and Test Release gates passed before tagging. No reachable or imported vulnerable package was reported; unused OpenPGP retains module-only GO-2026-5932. Compatibility with upstream MinIO and other S3 endpoints is best effort; SILO is the maintained administrative integration target.

Download and installation · Compatibility notes · Complete source diff.