Download Latest Version soft-serve_0.12.3_Windows_x86_64.zip (11.5 MB) Google Add to Preferred Sources
Home / v0.12.3
Name Modified Size InfoDownloads / Week
Parent folder
checksums.txt 2026-10-05 3.3 kB
checksums.txt.sigstore.json 2026-10-05 10.5 kB
soft-serve-0.12.3.tar.gz.sbom.json 2026-10-05 229.6 kB
soft-serve_0.12.3_Darwin_x86_64.tar.gz.sbom.json 2026-10-05 145.4 kB
soft-serve-0.12.3-1.x86_64.rpm 2026-10-05 11.3 MB
soft-serve_0.12.3_amd64.deb 2026-10-05 11.3 MB
soft-serve_0.12.3_arm64.deb 2026-10-05 10.4 MB
soft-serve_0.12.3_armhf.deb 2026-10-05 10.7 MB
soft-serve_0.12.3_Darwin_arm64.tar.gz.sbom.json 2026-10-05 145.2 kB
soft-serve_0.12.3_Freebsd_arm64.tar.gz.sbom.json 2026-10-05 147.4 kB
soft-serve_0.12.3_Freebsd_x86_64.tar.gz.sbom.json 2026-10-05 147.6 kB
soft-serve_0.12.3_i386.deb 2026-10-05 10.7 MB
soft-serve_0.12.3_Linux_arm64.tar.gz.sbom.json 2026-10-05 143.5 kB
soft-serve_0.12.3_Linux_arm.tar.gz.sbom.json 2026-10-05 142.9 kB
soft-serve_0.12.3_Linux_i386.tar.gz.sbom.json 2026-10-05 143.2 kB
soft-serve_0.12.3_Linux_x86_64.tar.gz.sbom.json 2026-10-05 143.7 kB
soft-serve_0.12.3_Windows_x86_64.zip.sbom.json 2026-10-05 147.5 kB
soft-serve-0.12.3-1.armv7hl.rpm 2026-10-05 10.7 MB
soft-serve-0.12.3.tar.gz 2026-10-05 231.2 kB
soft-serve_0.12.3_aarch64.apk 2026-10-05 10.9 MB
soft-serve_0.12.3_armv7.apk 2026-10-05 11.2 MB
soft-serve_0.12.3_Darwin_arm64.tar.gz 2026-10-05 10.8 MB
soft-serve_0.12.3_Linux_arm64.tar.gz 2026-10-05 10.4 MB
soft-serve_0.12.3_x86.apk 2026-10-05 11.2 MB
soft-serve-0.12.3-1.aarch64.rpm 2026-10-05 10.4 MB
soft-serve-0.12.3-1.i386.rpm 2026-10-05 10.7 MB
soft-serve_0.12.3_Darwin_x86_64.tar.gz 2026-10-05 11.7 MB
soft-serve_0.12.3_Freebsd_arm64.tar.gz 2026-10-05 10.4 MB
soft-serve_0.12.3_Freebsd_x86_64.tar.gz 2026-10-05 11.3 MB
soft-serve_0.12.3_Linux_arm.tar.gz 2026-10-05 10.7 MB
soft-serve_0.12.3_Linux_i386.tar.gz 2026-10-05 10.7 MB
soft-serve_0.12.3_Linux_x86_64.tar.gz 2026-10-05 11.3 MB
soft-serve_0.12.3_Windows_x86_64.zip 2026-10-05 11.5 MB
soft-serve_0.12.3_x86_64.apk 2026-10-05 11.8 MB
README.md 2026-10-05 4.8 kB
v0.12.3 source code.tar.gz 2026-10-05 230.9 kB
v0.12.3 source code.zip 2026-10-05 380.6 kB
Totals: 37 Items   232.5 MB 0

This release fixes three security issues reported by @sondt99 and @Xiaoyiyi23.

Security

Private repository names disclosed over HTTP ([GHSA-fgxm-5hvv-x4vh], medium)

Soft Serve's implementation of Go's ?go-get=1 could expose a private repo name that a user didn't have access to.

The Git and LFS routes could leak the name as well via status code.

no-access collaborators could read private repositories ([GHSA-pmgj-8mr6-9rff], medium)

Previously on private repositories a no-access collaborator was elevated to read-only due to a mis ordered check.

Repositories could stay public after being made private ([GHSA-f3fj-9625-rv3m], medium)

Repository records were cached in memory with no expiry and trusted for all access checks. Making a repository private cleared the cache before the change was saved, allow for a race condition where a request arriving before the save took effect could cache the old public record, and the repository would stay readable until the server restarted. Multiple instances sharing a database also had a variant of this which caused the cache of one instance to never get propagated to the others.

Fixed

  • Deleting a user who owns repositories always failed with "database is locked". It now refuses with a list of the repositories they own.
  • A repository whose directory had already been deleted couldn't be deleted. Now the database entry is removed regardless of the directory removal.
  • The repository_visibility_change webhook fired every time visibility was set, even if the value didn't change.

Changelog

Fixed

  • dc351aa0d824c8bef528c6924a7acdfb9f20c852: fix: answer the same for private and missing repositories over HTTP (@taciturnaxolotl)
  • 5b307b4da4db285f797cc028b381ba4d3d853019: fix: keep a repository private after its visibility changes (@taciturnaxolotl)
  • d108e2c4a395b6995738d740d23c82fd0f9c4828: fix: refuse to delete users who still own repositories (@taciturnaxolotl)
  • 0a4e6f0b7e063927c7128756e1c1b3db871edabf: fix: send the visibility webhook only when visibility changes (@taciturnaxolotl)
  • bf0f7bb23f6d81ff3244e640dbbde7fbe53b654d: fix: stop failed logins and stray requests from creating repositories (@taciturnaxolotl)
  • 74e41543304d1e12fd54fc59e410bd428373dd34: fix: stop go-get requests from revealing private repository names (@taciturnaxolotl)
  • db6e0d0bc324eebee999aa459610f32875891604: fix: stop granting read access to no-access collaborators on private repos (@taciturnaxolotl)

Deps

  • 8877a1460cbc6bc1ea2a1725efe1f33fc9687b35: fix(deps): update Go and x/crypto to clear reported vulnerabilities (@taciturnaxolotl)

Other stuff

  • 37685d36f5b7bf0e32217ddd7c8e045c57772619: ci: sync dependabot config (#927) (@charmcli)
  • e89e3102edf8ec2168e0ac0eaf5636dc0f0b35e5: refactor: move LFS lock handlers into their own file (@taciturnaxolotl)
  • d12156d95533294607e78900802be1d9b6fe064a: refactor: share the missing-repository check across LFS handlers (@taciturnaxolotl)
  • 6b169bc3af4d407aec43fb64c606d02af520bd0e: v0.12.3 (@taciturnaxolotl)

Verifying the artifacts First, download the [`checksums.txt` file](https://github.com/charmbracelet/soft-serve/releases/download/v0.12.3/checksums.txt) and the [`checksums.txt.sigstore.json` file](https://github.com/charmbracelet/soft-serve/releases/download/v0.12.3/checksums.txt.sigstore.json) files, for example, with `wget`: :::bash wget 'https://github.com/charmbracelet/soft-serve/releases/download/v0.12.3/checksums.txt' wget 'https://github.com/charmbracelet/soft-serve/releases/download/v0.12.3/checksums.txt.sigstore.json' Then, verify it using [`cosign`](https://github.com/sigstore/cosign): :::bash cosign verify-blob \ --certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@refs/heads/main' \ --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \ --bundle 'checksums.txt.sigstore.json' \ ./checksums.txt If the output is `Verified OK`, you can safely use it to verify the checksums of other artifacts you downloaded from the release using `sha256sum`: :::bash sha256sum --ignore-missing -c checksums.txt Done! You artifacts are now verified!

The Charm logo

Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.

Source: README.md, updated 2026-10-05