<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>pkg on SILO</title><link>https://silo.pgsty.com/tags/pkg/</link><description>Recent content in pkg on SILO</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 05 Aug 2026 07:48:52 +0800</lastBuildDate><atom:link href="https://silo.pgsty.com/tags/pkg/index.xml" rel="self" type="application/rss+xml"/><item><title>silo-pkg 3.11.0 Released</title><link>https://silo.pgsty.com/blog/release/pkg-3.11.0/</link><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/release/pkg-3.11.0/</guid><description>&lt;p&gt;&lt;strong&gt;Release date:&lt;/strong&gt; 2026-08-04 · &lt;strong&gt;Version:&lt;/strong&gt; &lt;a href="https://github.com/pgsty/silo-pkg/releases/tag/v3.11.0"&gt;v3.11.0&lt;/a&gt; · &lt;strong&gt;Commit:&lt;/strong&gt; &lt;a href="https://github.com/pgsty/silo-pkg/commit/d8b1fa7"&gt;&lt;code&gt;d8b1fa7&lt;/code&gt;&lt;/a&gt; · &lt;strong&gt;Repository:&lt;/strong&gt; &lt;a href="https://github.com/pgsty/silo-pkg"&gt;pgsty/silo-pkg&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This is the fork&amp;rsquo;s &lt;strong&gt;first pinned release&lt;/strong&gt;. It restores the IAM bucket/object resource boundary reported as upstream &lt;a href="https://github.com/minio/minio/issues/20449"&gt;minio/minio#20449&lt;/a&gt;: a policy condition-key bypass fix, three LDAP connection defects, a certificate watcher leak, a seeded-RNG defect, and the module&amp;rsquo;s real minimum Go version.&lt;/p&gt;
&lt;div class="alert alert-warning" role="alert"&gt;
&lt;p&gt;&lt;strong&gt;Two things to check before upgrading&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;This release tightens authorization.&lt;/strong&gt; Twelve bucket-level write actions are no longer reachable through an object-only resource pattern such as &lt;code&gt;arn:aws:s3:::bucket/*&lt;/code&gt;. If you write your own bucket-scoped policies, read &lt;a href="https://silo.pgsty.com/blog/release/pkg-3.11.0/#bucket-boundary"&gt;The IAM bucket/object boundary&lt;/a&gt; — the fix is one line of policy for anyone affected, and &lt;code&gt;MINIO_API_LEGACY_BUCKET_RESOURCE_MATCH=on&lt;/code&gt; restores the previous behaviour in full.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The condition-key fix still needs its server half.&lt;/strong&gt; The policy lookup change and the server changes that reserve internal condition-key names each cover one half of that problem. The companion server work exists in &lt;code&gt;pgsty/minio&lt;/code&gt; commit &lt;code&gt;2f55347f7&lt;/code&gt; but is not yet on public &lt;code&gt;origin/master&lt;/code&gt;, and no published Silo server release contains it. Verify that a later server release explicitly includes it.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;h2 id="what-is-this"&gt;What This Repository Is&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;silo-pkg&lt;/code&gt; is a maintained fork of &lt;a href="https://github.com/minio/pkg"&gt;minio/pkg&lt;/a&gt;, carrying fixes needed by community MinIO forks that the now commercially driven upstream no longer accepts. The repository was renamed from &lt;code&gt;pgsty/minio-pkg&lt;/code&gt; on 2026-08-02.&lt;/p&gt;</description></item></channel></rss>