Silo is an independent, community-maintained object-storage server derived from the open-source MinIO server. Upstream MinIO security contacts do not handle Silo-specific fixes or release notes.
Security fixes are tracked on the active development branch and summarized in docs/security/advisories.md. Only the current Silo release line is supported unless an advisory says otherwise.
The canonical ledger also records security fixes inherited from upstream when they are part of the Silo release baseline. Source and fork commits are linked separately even when the fork preserves the original commit object and SHA.
- CVE-2025-62506:
upstream PR #21642 merged as
minio/minio@c1a49490, inherited unchanged aspgsty/silo@c1a49490, and is present in every Silo community release beginning withRELEASE.2025-12-03T12-00-00Z. The inherited service-account and STS regression groups remain part ofgo test ./cmd; see the canonical ledger for the operator-facing record.
For vulnerabilities in this fork:
- Follow the fork-specific expectations in VULNERABILITY_REPORT.md.
- Prefer this repository's private GitHub security advisory workflow.
- If private reporting is unavailable, contact the maintainers through the repository without publishing exploit details until a private channel is established.
- If you confirm the issue also affects upstream
minio/minio, report it upstream separately.
Fork-specific fixes and user-visible upgrade notes are published in docs/security/advisories.md. The fork-specific triage and remediation process is described in VULNERABILITY_REPORT.md.