[1.4.1] - 2026-10-11
Patch on v1.4.0. No new product features.
Fixed
- Release pins — installer defaults, Compose/Helm/lab image tags, the console package version, and the current-release lines in the docs still pointed at v1.3.0 or older, so a README install pulled the previous release. They now track v1.4.1.
scripts/bump-release-version.shis the release-time bump;scripts/check-release-pins.shfails CI, andrelease.ymlfails the tag push, when those pins do not matchVERSION(or the pushed tag). - Inventory create —
POST /api/v1/inventory/jobsfor a bucket name that does not resolve returned 201 with statusfailedand errornot found. It now returns 404 and does not store a job. The scan uses the same tenant- and owner-scoped resolution as the console and other admin routes, including when another tenant has the same logical name. An unknowndest_bucketis 404 as well. - Inventory list —
GET /api/v1/inventory/jobswas 405. It is now an admin-only list, newest first,limitdefault 50 and maximum 100. OpenAPI full spec includes the operation. - Windows source builds — there was no
.gitattributes, so Git on Windows (core.autocrlf=true) checked*.shout as CRLF. Building the server image then crash-looped withexec /docker-entrypoint.sh: no such file or directory.*.shand the other files copied or bind-mounted into Linux containers are forced to LF. The server and lab Dockerfiles strip CR from entrypoints beforechmod. The server image starts through/usr/local/bin/datasafe-entrypoint, which strips again so a bind-mounteddocker-entrypoint.sh(HA local, local-binary) still runs. The HA object-replicator entrypoint and the Vault overlay do the same for their bind-mounted scripts.
Changed
- Default install is production-safe. Compose and
.env.exampledefaultSTORAGE_DEVto false. The installer writesSTORAGE_DEV=falseunless-Dev,--dev, or profiledev. It generatesSTORAGE_JWT_SECRET,STORAGE_SECRET_KEY, andSTORAGE_METRICS_TOKENwhen they are missing or still the published defaults, and the Compose Prometheus service scrapes with that bearer so Grafana keeps working. ProfileidentitysetsSTORAGE_DEV=trueso the HTTP lab IdP still works. Dev and audit overlays setSTORAGE_DEV=trueexplicitly. Upgrade notes: EN · RU. - Removed the one-shot workflow
.github/workflows/deferred-release-v1.2.0.yml(v1.2.0 is already published). - Lab S3 image — Docker Hub
minio/miniono longer pulls (pull access denied). Feature-audit,scripts/start-minio-test.cmd, the Helm lab target, and the EN/RU gateway examples usepgsty/silo:RELEASE.2026-09-16T00-00-00Z(sameserver /dataarguments and/minio/health/live). Anonymousquay.io/minio/miniopulls return 401, so that registry is not a substitute.
Security
- Go 1.26.9 and golang.org/x/text v0.41.0 —
govulncheckreported GO-2026-6629 ingolang.org/x/text@v0.38.0(fixed in v0.41.0) and net/http issues in the Go 1.26.8 standard library (GO-2026-6617, GO-2026-6613, GO-2026-6612, GO-2026-6611, GO-2026-6610, GO-2026-6608, and the rest of that set), fixed in Go 1.26.9.go.modisgo 1.26.9(that line selects toolchain go1.26.9;go mod tidydrops a redundanttoolchaindirective).deploy/docker/Dockerfileand CIsetup-go(including feature-audit) pin 1.26.9. Release images are built from that Dockerfile.
Honesty
- An empty
STORAGE_METRICS_TOKENstill leaves/metricsopen (v1.1.0 legacy) and logs a warning when dev mode is off. The installer no longer leaves the token empty. A hand-written Compose file that omits it still has open metrics. - The identity lab profile enables dev mode because that lab IdP is plain HTTP. It is not a production install.
GET /inventory/jobsreads the in-process registry (lost on restart) and is capped at 100 rows. It is not a durable export history.- Offline lab scripts still fall back to older local image tags when
v1.4.1is not cached. The preferred default isv1.4.1. - This patch does not publish container images.
ghcr.io/direktorbani/datasafe-storage-server:v1.4.1anddatasafe-console:v1.4.1appear whenrelease.ymlruns on the git tag. - An existing Windows checkout keeps CRLF copies of
*.shuntil Git checks those files out again (git checkout -- "*.sh"after pulling). The image build and the entrypoint launcher still strip CR. Postgres init scripts such as02-replication-hba.share bind-mounted, so they need that refresh (or a fresh clone) before the first database init.
Container images
ghcr.io/direktorbani/datasafe-storage-server:v1.4.1ghcr.io/direktorbani/datasafe-console:v1.4.1
CycloneDX SBOM files and cosign signatures are attached. See SECURITY.md for cosign verify instructions.