Shipped · DevOps and infrastructure

What seaweedfs/seaweedfs shipped

The public repository of Seaweedfs · github.com/seaweedfs/seaweedfs

Written by FoxPlug from public releases; not affiliated with Seaweedfs. An automatic summary of the public release, pull request and commit data of github.com/seaweedfs/seaweedfs. Seaweedfs did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.

Get a weekly update like this for your product, free

Or Use it as a GitHub Action

Follow seaweedfs's weekly shipped digest

Week of September 21, 2026

What shipped

Why it matters

This week's fixes address critical security gaps in S3 authorization, prevent data corruption and loss scenarios in volume operations, eliminate lock-holding patterns that cause availability issues at scale, and restore missing documentation. Multiple authorization bypasses, memory exhaustion bugs, and silent data delivery issues are now closed.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

Weekly fixes: S3 authorization gaps closed, volume locks held shorter, empty volumes now reclaimed, corrupt needles rejected, lock ring recovery fixed, and REST API docs restored.

Post for LinkedIn

This week in SeaweedFS: fixed S3 authorization bypasses where prefix parameters leaked between actions, shortened volume server lock holds to prevent heartbeat stalls and memory exhaustion, enabled vacuum to reclaim empty volume slots at capacity, rejected corrupt needle delivery, fixed master lock ring poisoning after failover, and restored the HTTP REST API reference documentation.

Week of September 14, 2026

What shipped

Why it matters

This week fixes critical data integrity issues in erasure coding, volume storage, and S3 multipart uploads that could cause data corruption or node outages. Several P0-severity bugs in EC and negative-size handling are now closed. S3 gateway improvements prevent orphaned chunks and ensure atomic completion of multipart uploads.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

4.47.1 fixes: EC BatchDelete validation, negative Size rejection preventing node brick, tomb­stone scrubbing, corrupt needle loops, multipart upload atomicity, and orphaned chunk safety.

Post for LinkedIn

Seaweedfs 4.47.1 addresses critical data integrity issues: EC BatchDelete now validates cookies preventing bypass attacks, negative Size values are rejected before poisoning store locks, corrupt needle headers no longer cause infinite loops, and S3 multipart uploads complete atomically. Erasure coding validation at gRPC boundaries prevents ShardId truncation attacks. S3 orphaned chunk deletion waits for entry confirmation. Volume scrubbing now processes tombstones correctly.

Weeks with too little public activity are left out rather than filled in. Last updated 2026-09-28.

Is this your repo? Ask us to remove this page.