chore(deps): update docker.io/oryd/kratos docker tag to v26#863
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
chore(deps): update docker.io/oryd/kratos docker tag to v26#863renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v25.4.0→v26.2.0Release Notes
ory/kratos (docker.io/oryd/kratos)
v26.2.0Compare Source
v26.2.0
Bug Fixes
remove more instances of injecting unrecoverable email faults (81e9151):
Add missing indices on identity_id (a085d87):
Add missing StrategyUsed attribute to Login and registration events (e72c297):
Add missing transient nodes clear (ed56dac):
Add oidc linking/unlinking to api settings flow (6a6928c):
Always retry curl invocations to surmount transient third-party failures (2473954):
Base64encoded schemaURL cannot be resolved (a86c212):
Batch identity error propagation (2f9c3e3):
Clarify password import (849b0de):
Context passing in jsonnetsecure (7e33125):
Correctly scan SQL
NULLinto go JSON types (6183672):Courier should not retry message dispatches in one go (70f7b38):
Data race making test flaky (c651ecf):
Deadlock when using -parallel 1 (8adaa02):
Don't attempt to redirect to ory.com in kratos tests (a06b3c2):
Down migrations in newer MySQL versions (e948a0b):
Duplicate credential error placeholder case mismatch (84ee596):
Failing down migration (7bb24c5):
Fetch login challenge after code submissions (048d315):
Fix benchmark test (2886abe):
Fix data race in courier test by protecting slice with mutex (6673982):
Fix flaky email test (01e1dd0):
Handle batch identities errors more gracefully (952d7ea):
Incorrect default value for page_tokens (9a5f8b9):
Incorrect error handling (1757cdd):
Incorrect usage of database/sql (590d898):
kratos: Otp fast-path 2fa body error (95341a8):
Lint (e7045c5):
Pass transient payload to webhooks in API/native OIDC flows (d023775):
Properly accept login challenge in verification after login flows (f6d59bb):
Recovery code expires_in regression (8f54814):
Recovery code expiry error (3447e0a):
Redact subject codes (071ad54):
Remove flaky test for unused function (b4d8591):
Remove redundant ORDER BY in QueryForCredentials (65b27fd):
Remove WithDumpMigrations option to MigrationBox (7ee85fb):
Request log config key (1799e3a):
Resolve incorrect error handling (9144b55):
Resolve null response in OAuth2 flow with existing session (e7d8bd1):
Return a specific error message for email & phone validation errors (d6b0f49):
Return correct CSRF errors (b7b7fd4):
Return oauth2 login challenge on Bad Request in self-service flows (bc33d5c):
Seamlessly migrate existing users to SCIM (76d35cf):
Show captcha on otp submission (039d5bc):
Stray debug print (3da622f):
Transfer OAuth2 login challenge in account linking flow (1ab143c):
Update CONTRIBUTING.md (95bf33b):
Update dependencies and replace @ory/client for kratos-selfserivce-ui-react-native (3d88a43):
Update packages to fix GHSA-7h2j-956f-4vf2 (79fb49d):
Upgrade vulnerable dependencies across Go and npm (c2adee4):
Co-authored-by: Deepak Prabhakara deepak.prabhakara@ory.sh
Use correct client authentication method for Apple OIDC (6c2f8fb):
X data race and parallize some tests (116a66e):
Code Generation
Code Refactoring
Documentation
Improve readme and dev instructions (56be7ba):
Update readmes (bc8dca6):
Features
Add captcha strategy for recovery flow (3dee8f5):
Add captcha strategy for verification flow (420f69d):
Add column identity_id to identity_credential_identifiers and session_devices (57b099f):
Add native api flow support for passkeys (39c341b):
Add ratelimit buckets to swagger definitions (a14c3f2):
Add session to all settings hooks payloads (aebbc2b):
Add support for NULL and more column types to keysetpagination (3f24dbf):
Auto account linking for google and apple (623742e):
Automatic transaction retries for postgres (80dcbac):
Better multi-region queries (af48288):
Collect external latency data and write to logs (97ce640):
Consider Go migrations DirHash when restoring full schema from backups (99c8cdc):
Forward (some) user request headers to SMS HTTP channel (f2ce286):
Generate events for SSO and SCIM provider revisions (da8ec11):
Hydra benchmarking tool (aa3071f):
Improved tracing (46c1028):
Infer regional-by-row region using foreign key constraints (46c18eb):
Keto-cli improvements (86968f5):
kratos: Auto-send code when it is the only available method (86103bc):
Login with uae pass (1544efe):
Make new identity_id column on identifiers and session_devices NOT NULL and establish foreign key (6bf18bf):
Make SCIM work with MySQL (a34e951):
Rename project revision columns (e25723e):
Speed up OIDC login+registration handling (6bfbaf5):
Update GetActiveRecoveryStrategies method (b94f4c9):
Use keysetpagination planner for keto read queries (85590e8):
Tests
Add assertions for json response body (0f5085c):
Deflake and improve performance (0451169):
Deflake directory watcherx (00c4f9e):
Deflake SAML config assertion (71da1e3):
Faster and more reliable courier tests (2a552ea):
Fix data races (4014eeb):
Fix data races (8482dd5):
hydra: Add plaintext backups for all DB types (3369ebd):
Minor setup improvements (b9e094d):
Unclassified
apply review changes (e7d5dd2):
storybook snapshots (3f06c5d):
fixes (7982b73):
Changelog
e7d5dd2apply review changese3d4145autogen(docs): generate and bump docs791b0d5autogen(sdk): bump to05ddc403e9dbcdautogen(sdk): bump to0f7be9ec0f99fbautogen(sdk): bump to17d4d13abbcc57autogen(sdk): bump to2402a6ef909afaautogen(sdk): bump to29329128b52ac9autogen(sdk): bump to2f63cc9ecf73dcautogen(sdk): bump to4c3e8f56876a3bautogen(sdk): bump to4d380b9bdbd733autogen(sdk): bump to5f25484f769f6bautogen(sdk): bump to75ad7a500fa85fautogen(sdk): bump tocab70529d70859autogen: prepare for OSS release - v26.2.0df866b3chore(deps): bump github.com/sirupsen/logrus from 1.8.1 to 1.8.3 in /kratos/kratos-oss/test/e2e/mock/webhook2270ea3chore(deps): update actions/checkout action to v6d964878chore(deps): update actions/upload-artifact action to v6d0e4b09chore(deps): update actions/upload-artifact action to v746f56e7chore(deps): update dependency @types/lodash to v4.17.21eba4233chore(deps): update dependency golangci/golangci-lint to v2.11.1f9431e2chore(deps): update go modules6e6cc75chore(deps): update golangci/golangci-lint-action action to v98301fd4chore(deps): update jackson (major)64fc530chore(deps): update kratos to v4 (major)7710d46chore(deps): update mysql docker tag to v9.6d349787chore(keto): use ory/x router1b8debechore(kratos): use httprouter from ory/x5596300chore: add Kratos OEL tests for connection pooling & add validation for connection pooling misconfiguration/misuse8c6b692chore: add cause to context cancels with 'context.WithTimeoutCause' in ./x946e950chore: add helpers for Kratos OEL to support various databases4e6e4acchore: add recovery code expiresIn regression test06f470fchore: add retries to more curl invocations391495bchore: added CLIENT_SECRET_VERIFIER to our deployment68bea59chore: audit and fix npm dependencies0b6c1bdchore: bump to CRDB v25.49c29335chore: bump to Go 1.26 massive cleanup in ory/x9a4d03bchore: cleanup package-lock files4a06f58chore: correct typosc1df2e8chore: deflake registration expiry unit teste9d8a8cchore: delete unused CRDB changefeed watcherx modulec6c8beachore: deprecate organization APIs2a4be28chore: drop unused indexcb78942chore: fix for critical CVE - GHSA-p77j-4mvh-x3m3362467bchore: fixed typo in API description828b019chore: generate elements locales from source and add CLI helpers9b52402chore: improve clidoc generation55e24dbchore: improve error reporting to help diagnose flaky test1d0309bchore: improve readability of popx.MigrationBoxe006333chore: keysetpagination improvementsf9de4ccchore: make SCIM work with single-region CRDB50f6515chore: more npm security updatescf94909chore: reduce number of auth steps in cypress testf7b5a64chore: remove internal address typesc0b6fbachore: remove repeated VerifiableAddresses assignment in web_hook.goc90675cchore: remove unused code4118515chore: remove unused log code07284c7chore: remove unused x/watcherx/websocket029d8a3chore: rename ./internal to ./pkg to make all functions visible01c7b53chore: run go mod tidy and misc cleanupe0496dechore: run npm audit fixb28c196chore: security updates for glob libraryde64ac1chore: simplify HTTP metrics instrumentation25d35ccchore: simplify decoderx usage7d6e01dchore: split SCIM from multi-region & make it work with SQLitef57f519chore: unify common dependency interfaces8e369dechore: update @openapitools/openapi-generator-cli601c9acchore: update OSS ory.sh to ory.com3bb9244chore: update pop to latest & only run pop.SetNowFunc() inside init()16343d6chore: update to dockertest v49823ae0chore: update uaepass jsonnet stubsb410c7fchore: updated axios286f885chore: updated golang.org/x/crypto7b18f23chore: updated minimatchb922c60chore: updated playwright (except e2e) and other deps5ed2524chore: upgrade AX to next.js 167e2a849chore: use pgx pool in Kratos OEL & fix some OEL commands not using enterprise migrations550fd75chore: use sync.Map instead of custom concurrent map45cc87eci: add docker driver to cve scan56be7badocs: improve readme and dev instructionsbc8dca6docs: update readmes86103bcfeat(kratos): auto-send code when it is the only available method3dee8f5feat: add captcha strategy for recovery flow420f69dfeat: add captcha strategy for verification flow57b099ffeat: add column identity_id to identity_credential_identifiers and session_devices39c341bfeat: add native api flow support for passkeysa14c3f2feat: add ratelimit buckets to swagger definitionsaebbc2bfeat: add session to all settings hooks payloads3f24dbffeat: add support for NULL and more column types to keysetpagination623742efeat: auto account linking for google and apple80dcbacfeat: automatic transaction retries for postgresaf48288feat: better multi-region queries97ce640feat: collect external latency data and write to logs99c8cdcfeat: consider Go migrations DirHash when restoring full schema from backupsf2ce286feat: forward (some) user request headers to SMS HTTP channelda8ec11feat: generate events for SSO and SCIM provider revisionsaa3071ffeat: hydra benchmarking tool46c1028feat: improved tracing46c18ebfeat: infer regional-by-row region using foreign key constraints86968f5feat: keto-cli improvements1544efefeat: login with uae passa34e951feat: make SCIM work with MySQL6bf18bffeat: make new identity_id column on identifiers and session_devices NOT NULL and establish foreign keye25723efeat: rename project revision columns6bfbaf5feat: speed up OIDC login+registration handlingb94f4c9feat: update GetActiveRecoveryStrategies method85590e8feat: use keysetpagination planner for keto read queries95341a8fix(kratos): otp fast-path 2fa body error81e9151fix: remove more instances of injecting unrecoverable email faultse72c297fix: add missing StrategyUsed attribute to Login and registration eventsa085d87fix: add missing indices on identity_ided56dacfix: add missing transient nodes clear6a6928cfix: add oidc linking/unlinking to api settings flow2473954fix: always retry curl invocations to surmount transient third-party failuresa86c212fix: base64encoded schemaURL cannot be resolved2f9c3e3fix: batch identity error propagation849b0defix: clarify password import7e33125fix: context passing in jsonnetsecure6183672fix: correctly scan SQLNULLinto go JSON types70f7b38fix: courier should not retry message dispatches in one goc651ecffix: data race making test flaky8adaa02fix: deadlock when using -parallel 1a06b3c2fix: don't attempt to redirect to ory.com in kratos testse948a0bfix: down migrations in newer MySQL versions84ee596fix: duplicate credential error placeholder case mismatch7bb24c5fix: failing down migration048d315fix: fetch login challenge after code submissions2886abefix: fix benchmark test6673982fix: fix data race in courier test by protecting slice with mutex01e1dd0fix: fix flaky email test952d7eafix: handle batch identities errors more gracefully9a5f8b9fix: incorrect default value for page_tokens1757cddfix: incorrect error handling590d898fix: incorrect usage of database/sqle7045c5fix: lintd023775fix: pass transient payload to webhooks in API/native OIDC flowsf6d59bbfix: properly accept login challenge in verification after login flows8f54814fix: recovery code expires_in regression3447e0afix: recovery code expiry error071ad54fix: redact subject codes7ee85fbfix: remove WithDumpMigrations option to MigrationBoxb4d8591fix: remove flaky test for unused function65b27fdfix: remove redundant ORDER BY in QueryForCredentials1799e3afix: request log config key9144b55fix: resolve incorrect error handlinge7d8bd1fix: resolve null response in OAuth2 flow with existing sessiond6b0f49fix: return a specific error message for email & phone validation errorsb7b7fd4fix: return correct CSRF errorsbc33d5cfix: return oauth2 login challenge on Bad Request in self-service flows76d35cffix: seamlessly migrate existing users to SCIM039d5bcfix: show captcha on otp submission3da622ffix: stray debug print1ab143cfix: transfer OAuth2 login challenge in account linking flow95bf33bfix: update CONTRIBUTING.md3d88a43fix: update dependencies and replace @ory/client for kratos-selfserivce-ui-react-native79fb49dfix: update packages to fix GHSA-7h2j-956f-4vf2c2adee4fix: upgrade vulnerable dependencies across Go and npm6c2f8fbfix: use correct client authentication method for Apple OIDC116a66efix: x data race and parallize some tests7982b73fixes7790322refactor: squash merge old backoffice migration and fix up command3f06c5dstorybook snapshots3369ebdtest(hydra): add plaintext backups for all DB types0f5085ctest: add assertions for json response body71da1e3test: deflake SAML config assertion0451169test: deflake and improve performance00c4f9etest: deflake directory watcherx2a552eatest: faster and more reliable courier tests8482dd5test: fix data races4014eebtest: fix data racesb9e094dtest: minor setup improvementsArtifacts can be verified with cosign using this public key.
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.