Skip to content

build(deps): bump the maven-production group across 1 directory with 7 updates - #382

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/maven/maven-production-048dcb5a01
Closed

build(deps): bump the maven-production group across 1 directory with 7 updates#382
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/maven/maven-production-048dcb5a01

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-production group with 7 updates in the / directory:

Package From To
org.keycloak:keycloak-core 26.6.2 26.6.3
org.keycloak:keycloak-server-spi 26.6.2 26.6.3
org.keycloak:keycloak-server-spi-private 26.6.2 26.6.3
org.keycloak:keycloak-services 26.6.2 26.6.3
org.keycloak:keycloak-crypto-default 26.6.2 26.6.3
org.keycloak:keycloak-model-jpa 26.6.2 26.6.3
redis.clients:jedis 7.5.0 7.5.2

Updates org.keycloak:keycloak-core from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-core's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-server-spi from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-server-spi's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-server-spi-private from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-server-spi-private's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-services from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-services's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-crypto-default from 26.6.2 to 26.6.3

Updates org.keycloak:keycloak-model-jpa from 26.6.2 to 26.6.3

Updates org.keycloak:keycloak-server-spi from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-server-spi's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-server-spi-private from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-server-spi-private's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-services from 26.6.2 to 26.6.3

Release notes

Sourced from org.keycloak:keycloak-services's releases.

26.6.3

... (truncated)

Commits
  • 8a67e82 Set version to 26.6.3
  • 00dd0dd Added validation to client_session_host (#49682)
  • ad34724 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified J...
  • 0e706e7 [CVE-2026-9791] Organization data exposed in tokens and account API when Orga...
  • 7750e3f [CVE-2026-9794] SAML ECP faultstring discloses client existence and configura...
  • 20e56d1 fix: enforce user profile attribute permissions on group and organization mem...
  • 5263a59 fix critical and high CVEs in JavaScript modules (#49596)
  • 06337a5 Enforce resource server predicates if one was given despite the IS_ADMIN flag...
  • 717a8ac External ID should be part of email verification single object key (#49671)
  • 2a8f2ae Validate sequence length against the remaining elements in the buffer (#49672)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-crypto-default from 26.6.2 to 26.6.3

Updates org.keycloak:keycloak-model-jpa from 26.6.2 to 26.6.3

Updates redis.clients:jedis from 7.5.0 to 7.5.2

Release notes

Sourced from redis.clients:jedis's releases.

7.5.2

This is a maintenance release focused on improving the stability of the Automatic Failover feature (MultiDbClient). Recommended for any deployment using MultiDbClient / multi-database failover.

🐛 Bug Fixes

  • Fixes a connection pool leak in experimental multi-database failover when ping() fails during acquisition. redis/jedis#4546

🧰 Maintenance

Commits
  • e5c1e55 Use validated flag to close connection
  • 9ccfe9f Fix connection leak in MultiDbConnectionSupplier
  • 9673859 CommandObjects refactoring Part 4: Backport deprecations to 7.5.x (#4517)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…7 updates

Bumps the maven-production group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.keycloak:keycloak-core](https://github.com/keycloak/keycloak) | `26.6.2` | `26.6.3` |
| [org.keycloak:keycloak-server-spi](https://github.com/keycloak/keycloak) | `26.6.2` | `26.6.3` |
| [org.keycloak:keycloak-server-spi-private](https://github.com/keycloak/keycloak) | `26.6.2` | `26.6.3` |
| [org.keycloak:keycloak-services](https://github.com/keycloak/keycloak) | `26.6.2` | `26.6.3` |
| org.keycloak:keycloak-crypto-default | `26.6.2` | `26.6.3` |
| org.keycloak:keycloak-model-jpa | `26.6.2` | `26.6.3` |
| [redis.clients:jedis](https://github.com/redis/jedis) | `7.5.0` | `7.5.2` |



Updates `org.keycloak:keycloak-core` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-server-spi` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-server-spi-private` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-services` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-crypto-default` from 26.6.2 to 26.6.3

Updates `org.keycloak:keycloak-model-jpa` from 26.6.2 to 26.6.3

Updates `org.keycloak:keycloak-server-spi` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-server-spi-private` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-services` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.2...26.6.3)

Updates `org.keycloak:keycloak-crypto-default` from 26.6.2 to 26.6.3

Updates `org.keycloak:keycloak-model-jpa` from 26.6.2 to 26.6.3

Updates `redis.clients:jedis` from 7.5.0 to 7.5.2
- [Release notes](https://github.com/redis/jedis/releases)
- [Commits](redis/jedis@v7.5.0...v7.5.2)

---
updated-dependencies:
- dependency-name: org.keycloak:keycloak-core
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi-private
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-services
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-crypto-default
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-model-jpa
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi-private
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-services
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-crypto-default
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-model-jpa
  dependency-version: 26.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: redis.clients:jedis
  dependency-version: 7.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jun 6, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 43.33%. Comparing base (79c2017) to head (776d7ab).

Additional details and impacted files
@@            Coverage Diff            @@
##               main     #382   +/-   ##
=========================================
  Coverage     43.33%   43.33%           
  Complexity       58       58           
=========================================
  Files            18       18           
  Lines           450      450           
  Branches         46       46           
=========================================
  Hits            195      195           
  Misses          227      227           
  Partials         28       28           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@hangy

hangy commented Jun 6, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Jun 6, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 6, 2026
@dependabot
dependabot Bot deleted the dependabot/maven/maven-production-048dcb5a01 branch June 6, 2026 08:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants