silo-pkg 3.14.1 Released
v3.14.1 was published from
fa657ef4.
This is a dependency and tooling release of github.com/pgsty/silo-pkg/v3;
the diff from v3.14.0
changes no package Go source or public API.
Dependency changes
- JWX advances from v3.2.0 to v3.3.0. The vendor’s release notes
identify GHSA-4cf7-xm37-g63h: custom JSON field names must be escaped during
encoding. Reachability depends on accepting attacker-controlled custom claim
names. The package’s
envJWT path uses registered claim names; dependency presence alone does not establish an exploitable mcli path. - Upstream minio-go advances to
v7.3.1-0.20260915093545-32e1f32cb176, including minio-go #2306: recognize an S3CopyObjecterror embedded in an HTTP 200 response instead of reporting a successful copy. The fix applies to the SDK’s CopyObject path; it does not establish every application’s selection of that path. - Testify advances to v1.12.1 and the lint configuration adopts
gomodguard_v2. The Go 1.26 floor, Go 1.27.1 toolchain and go-systemd NetBSD replacement remain.
Component and migration boundary
The v3.14.0 password-policy change remains
in force; this patch does not revert it. Preserve the paired
admin:CreateUser / admin:ChangeMyPassword Deny where that was the intended
restriction, using the migration guide.
mcli 20260916 and Console 2.4.1 select this package. The Server source baseline reviewed on September 16 still selects v3.14.0; publishing a module does not update a compiled Server. The component matrix separates published components from the next Server’s selected dependencies.
Release verification is recorded in the linked release and PR #9. Those records are upstream release evidence, not a new execution of their tests by this documentation update.