Skip to content

build(deps): bump the maven-production group across 1 directory with 7 updates - #388

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/maven/maven-production-6eefe36a1d
Closed

build(deps): bump the maven-production group across 1 directory with 7 updates#388
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/maven/maven-production-6eefe36a1d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-production group with 7 updates in the / directory:

Package From To
org.keycloak:keycloak-core 26.6.3 26.6.4
org.keycloak:keycloak-server-spi 26.6.3 26.6.4
org.keycloak:keycloak-server-spi-private 26.6.3 26.6.4
org.keycloak:keycloak-services 26.6.3 26.6.4
org.keycloak:keycloak-crypto-default 26.6.3 26.6.4
org.keycloak:keycloak-model-jpa 26.6.3 26.6.4
redis.clients:jedis 7.5.2 7.5.3

Updates org.keycloak:keycloak-core from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-core's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-server-spi from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-server-spi's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-server-spi-private from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-server-spi-private's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-services from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-services's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-crypto-default from 26.6.3 to 26.6.4

Updates org.keycloak:keycloak-model-jpa from 26.6.3 to 26.6.4

Updates org.keycloak:keycloak-server-spi from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-server-spi's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-server-spi-private from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-server-spi-private's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-services from 26.6.3 to 26.6.4

Release notes

Sourced from org.keycloak:keycloak-services's releases.

26.6.4

Commits
  • dc1bfc5 Set version to 26.6.4
  • 39d40b1 fix(keycloak-admin-client): fix JS failures due to Kiota bug (#49643)
  • d459fc3 Upgrade to Quarkus 3.33.2.1 (#776)
  • 6d61885 CVE-2026-11800 Remove support for symmetric algorithms in JWT public key vali...
  • 32cdceb Consider case-sensitivity when validating prohibited schemes of client URIs (...
  • 1bc0dd3 Restrict java keystore files to a realm folder (#703)
  • be81d60 CVE-2026-9705 check if client is enabled when RAT is used
  • 11b83fc GroupResource.addChild missing requireManage(child) (#707)
  • e5507d9 [26.6] Missing requireMapClientScope in ScopeMappedResource and ScopeMappedCl...
  • bdb4db3 Skip owner managed resources when enforcement mode is set to permissive (#692)
  • Additional commits viewable in compare view

Updates org.keycloak:keycloak-crypto-default from 26.6.3 to 26.6.4

Updates org.keycloak:keycloak-model-jpa from 26.6.3 to 26.6.4

Updates redis.clients:jedis from 7.5.2 to 7.5.3

Release notes

Sourced from redis.clients:jedis's releases.

7.5.3

This is a maintenance release with fixes for FT.HYBRID queries and connection pool handshake overhead. Recommended for any deployment using FT.HYBRID with Combiner.as(...) or MultiDbClient.

🐛 Bug Fixes

  • Fixes FT.HYBRID COMBINE argument count omitting YIELD_SCORE_AS tokens, causing the command to be rejected when a combined-score alias is set via Combiner.as(...). Fix by @​guyroyse in redis/jedis#4575, backported to 7.5.x in redis/jedis#4576.
  • Fixes double initialization of a pooled Connection in TrackingConnectionPool (used by MultiDbClient). redis/jedis#4547, backported to 7.5.x in redis/jedis@dd42b3e.

Full Changelog: redis/jedis@v7.5.2...v7.5.3

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…7 updates

Bumps the maven-production group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.keycloak:keycloak-core](https://github.com/keycloak/keycloak) | `26.6.3` | `26.6.4` |
| [org.keycloak:keycloak-server-spi](https://github.com/keycloak/keycloak) | `26.6.3` | `26.6.4` |
| [org.keycloak:keycloak-server-spi-private](https://github.com/keycloak/keycloak) | `26.6.3` | `26.6.4` |
| [org.keycloak:keycloak-services](https://github.com/keycloak/keycloak) | `26.6.3` | `26.6.4` |
| org.keycloak:keycloak-crypto-default | `26.6.3` | `26.6.4` |
| org.keycloak:keycloak-model-jpa | `26.6.3` | `26.6.4` |
| [redis.clients:jedis](https://github.com/redis/jedis) | `7.5.2` | `7.5.3` |



Updates `org.keycloak:keycloak-core` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-server-spi` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-server-spi-private` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-services` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-crypto-default` from 26.6.3 to 26.6.4

Updates `org.keycloak:keycloak-model-jpa` from 26.6.3 to 26.6.4

Updates `org.keycloak:keycloak-server-spi` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-server-spi-private` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-services` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.6.3...26.6.4)

Updates `org.keycloak:keycloak-crypto-default` from 26.6.3 to 26.6.4

Updates `org.keycloak:keycloak-model-jpa` from 26.6.3 to 26.6.4

Updates `redis.clients:jedis` from 7.5.2 to 7.5.3
- [Release notes](https://github.com/redis/jedis/releases)
- [Commits](redis/jedis@v7.5.2...v7.5.3)

---
updated-dependencies:
- dependency-name: org.keycloak:keycloak-core
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi-private
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-services
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-crypto-default
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-model-jpa
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-server-spi-private
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-services
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-crypto-default
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: org.keycloak:keycloak-model-jpa
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
- dependency-name: redis.clients:jedis
  dependency-version: 7.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jul 1, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 43.33%. Comparing base (107bdc3) to head (1186df8).

Additional details and impacted files
@@            Coverage Diff            @@
##               main     #388   +/-   ##
=========================================
  Coverage     43.33%   43.33%           
  Complexity       58       58           
=========================================
  Files            18       18           
  Lines           450      450           
  Branches         46       46           
=========================================
  Hits            195      195           
  Misses          227      227           
  Partials         28       28           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@hangy

hangy commented Jul 7, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Jul 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 7, 2026
@dependabot
dependabot Bot deleted the dependabot/maven/maven-production-6eefe36a1d branch July 7, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code 💥 Merge Conflicts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants