Zond modified engine sources, 0.9.28
Toolchain: Go 1.27.1; CGO_ENABLED=0; GOARCH=amd64; GOOS=windows or linux.
Xray: go build -mod=readonly -trimpath -buildvcs=false -ldflags="-s -w -X github.com/xtls/xray-core/core.build=Zond-security-1" ./main
sing-box: go build -mod=readonly -trimpath -buildvcs=false -tags with_clash_api -ldflags="-s -w -X github.com/sagernet/sing-box/constant.Version=1.14.2-zond.1" ./cmd/sing-box
Run the commands inside the corresponding source tree. Modified go.mod/go.sum are included in each tree; upstream sources are otherwise unchanged.
module-cache contains source ZIPs, metadata, checksums and original license files for every module used by both builds. It can serve as a Go file module proxy. The Go compiler and standard library are available at https://go.dev/dl/ .
The reusable source-fetch/build/audit recipe is in zond-build. Scanning happens BEFORE stripping symbols, using govulncheck 1.8.0.
These are Zond builds, not upstream release binaries. Xray's source tag is marked prerelease upstream. Geo-data and third-party native UI/runtime binaries are outside this engine-source archive.
