Skip to content

build(deps): update oryd/kratos docker tag to v26 - #83

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/oryd-kratos-26.x
Open

build(deps): update oryd/kratos docker tag to v26#83
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/oryd-kratos-26.x

Conversation

@renovate

@renovate renovate Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
oryd/kratos (source) major v1.3.1v26.2.0

Release Notes

ory/kratos (oryd/kratos)

v26.2.0

Compare Source

v26.2.0

Bug Fixes
  • remove more instances of injecting unrecoverable email faults (81e9151):

  • Add missing indices on identity_id (a085d87):

  • Add missing StrategyUsed attribute to Login and registration events (e72c297):

  • Add missing transient nodes clear (ed56dac):

  • Add oidc linking/unlinking to api settings flow (6a6928c):

  • Always retry curl invocations to surmount transient third-party failures (2473954):

  • Base64encoded schemaURL cannot be resolved (a86c212):

  • Batch identity error propagation (2f9c3e3):

  • Clarify password import (849b0de):

  • Context passing in jsonnetsecure (7e33125):

  • Correctly scan SQL NULL into go JSON types (6183672):

  • Courier should not retry message dispatches in one go (70f7b38):

  • Data race making test flaky (c651ecf):

  • Deadlock when using -parallel 1 (8adaa02):

  • Don't attempt to redirect to ory.com in kratos tests (a06b3c2):

  • Down migrations in newer MySQL versions (e948a0b):

  • Duplicate credential error placeholder case mismatch (84ee596):

  • Failing down migration (7bb24c5):

  • Fetch login challenge after code submissions (048d315):

  • Fix benchmark test (2886abe):

  • Fix data race in courier test by protecting slice with mutex (6673982):

  • Fix flaky email test (01e1dd0):

  • Handle batch identities errors more gracefully (952d7ea):

  • Incorrect default value for page_tokens (9a5f8b9):

  • Incorrect error handling (1757cdd):

  • Incorrect usage of database/sql (590d898):

  • kratos: Otp fast-path 2fa body error (95341a8):

  • Lint (e7045c5):

  • Pass transient payload to webhooks in API/native OIDC flows (d023775):

  • Properly accept login challenge in verification after login flows (f6d59bb):

  • Recovery code expires_in regression (8f54814):

  • Recovery code expiry error (3447e0a):

  • Redact subject codes (071ad54):

  • Remove flaky test for unused function (b4d8591):

  • Remove redundant ORDER BY in QueryForCredentials (65b27fd):

  • Remove WithDumpMigrations option to MigrationBox (7ee85fb):

  • Request log config key (1799e3a):

  • Resolve incorrect error handling (9144b55):

  • Resolve null response in OAuth2 flow with existing session (e7d8bd1):

  • Return a specific error message for email & phone validation errors (d6b0f49):

  • Return correct CSRF errors (b7b7fd4):

  • Return oauth2 login challenge on Bad Request in self-service flows (bc33d5c):

  • Seamlessly migrate existing users to SCIM (76d35cf):

  • Show captcha on otp submission (039d5bc):

  • Stray debug print (3da622f):

  • Transfer OAuth2 login challenge in account linking flow (1ab143c):

  • Update CONTRIBUTING.md (95bf33b):

  • Update dependencies and replace @​ory/client for kratos-selfserivce-ui-react-native (3d88a43):

  • Update packages to fix GHSA-7h2j-956f-4vf2 (79fb49d):

  • Upgrade vulnerable dependencies across Go and npm (c2adee4):

    Co-authored-by: Deepak Prabhakara deepak.prabhakara@ory.sh

  • Use correct client authentication method for Apple OIDC (6c2f8fb):

  • X data race and parallize some tests (116a66e):

Code Generation
  • Prepare for OSS release - v26.2.0 (9d70859):
Code Refactoring
  • Squash merge old backoffice migration and fix up command (7790322):
Documentation
  • Improve readme and dev instructions (56be7ba):

  • Update readmes (bc8dca6):

Features
  • Add captcha strategy for recovery flow (3dee8f5):

  • Add captcha strategy for verification flow (420f69d):

  • Add column identity_id to identity_credential_identifiers and session_devices (57b099f):

  • Add native api flow support for passkeys (39c341b):

  • Add ratelimit buckets to swagger definitions (a14c3f2):

  • Add session to all settings hooks payloads (aebbc2b):

  • Add support for NULL and more column types to keysetpagination (3f24dbf):

  • Auto account linking for google and apple (623742e):

  • Automatic transaction retries for postgres (80dcbac):

  • Better multi-region queries (af48288):

  • Collect external latency data and write to logs (97ce640):

  • Consider Go migrations DirHash when restoring full schema from backups (99c8cdc):

  • Forward (some) user request headers to SMS HTTP channel (f2ce286):

  • Generate events for SSO and SCIM provider revisions (da8ec11):

  • Hydra benchmarking tool (aa3071f):

  • Improved tracing (46c1028):

  • Infer regional-by-row region using foreign key constraints (46c18eb):

  • Keto-cli improvements (86968f5):

  • kratos: Auto-send code when it is the only available method (86103bc):

  • Login with uae pass (1544efe):

  • Make new identity_id column on identifiers and session_devices NOT NULL and establish foreign key (6bf18bf):

  • Make SCIM work with MySQL (a34e951):

  • Rename project revision columns (e25723e):

  • Speed up OIDC login+registration handling (6bfbaf5):

  • Update GetActiveRecoveryStrategies method (b94f4c9):

  • Use keysetpagination planner for keto read queries (85590e8):

Tests
  • Add assertions for json response body (0f5085c):

  • Deflake and improve performance (0451169):

  • Deflake directory watcherx (00c4f9e):

  • Deflake SAML config assertion (71da1e3):

  • Faster and more reliable courier tests (2a552ea):

  • Fix data races (4014eeb):

  • Fix data races (8482dd5):

  • hydra: Add plaintext backups for all DB types (3369ebd):

  • Minor setup improvements (b9e094d):

Unclassified
Changelog
  • e7d5dd2 apply review changes
  • e3d4145 autogen(docs): generate and bump docs
  • 791b0d5 autogen(sdk): bump to 05ddc40
  • 3e9dbcd autogen(sdk): bump to 0f7be9e
  • c0f99fb autogen(sdk): bump to 17d4d13
  • abbcc57 autogen(sdk): bump to 2402a6e
  • f909afa autogen(sdk): bump to 2932912
  • 8b52ac9 autogen(sdk): bump to 2f63cc9
  • ecf73dc autogen(sdk): bump to 4c3e8f5
  • 6876a3b autogen(sdk): bump to 4d380b9
  • bdbd733 autogen(sdk): bump to 5f25484
  • f769f6b autogen(sdk): bump to 75ad7a5
  • 00fa85f autogen(sdk): bump to cab7052
  • 9d70859 autogen: prepare for OSS release - v26.2.0
  • df866b3 chore(deps): bump github.com/sirupsen/logrus from 1.8.1 to 1.8.3 in /kratos/kratos-oss/test/e2e/mock/webhook
  • 2270ea3 chore(deps): update actions/checkout action to v6
  • d964878 chore(deps): update actions/upload-artifact action to v6
  • d0e4b09 chore(deps): update actions/upload-artifact action to v7
  • 46f56e7 chore(deps): update dependency @​types/lodash to v4.17.21
  • eba4233 chore(deps): update dependency golangci/golangci-lint to v2.11.1
  • f9431e2 chore(deps): update go modules
  • 6e6cc75 chore(deps): update golangci/golangci-lint-action action to v9
  • 8301fd4 chore(deps): update jackson (major)
  • 64fc530 chore(deps): update kratos to v4 (major)
  • 7710d46 chore(deps): update mysql docker tag to v9.6
  • d349787 chore(keto): use ory/x router
  • 1b8debe chore(kratos): use httprouter from ory/x
  • 5596300 chore: add Kratos OEL tests for connection pooling & add validation for connection pooling misconfiguration/misuse
  • 8c6b692 chore: add cause to context cancels with 'context.WithTimeoutCause' in ./x
  • 946e950 chore: add helpers for Kratos OEL to support various databases
  • 4e6e4ac chore: add recovery code expiresIn regression test
  • 06f470f chore: add retries to more curl invocations
  • 391495b chore: added CLIENT_SECRET_VERIFIER to our deployment
  • 68bea59 chore: audit and fix npm dependencies
  • 0b6c1bd chore: bump to CRDB v25.4
  • 9c29335 chore: bump to Go 1.26 massive cleanup in ory/x
  • 9a4d03b chore: cleanup package-lock files
  • 4a06f58 chore: correct typos
  • c1df2e8 chore: deflake registration expiry unit test
  • e9d8a8c chore: delete unused CRDB changefeed watcherx module
  • c6c8bea chore: deprecate organization APIs
  • 2a4be28 chore: drop unused index
  • cb78942 chore: fix for critical CVE - GHSA-p77j-4mvh-x3m3
  • 362467b chore: fixed typo in API description
  • 828b019 chore: generate elements locales from source and add CLI helpers
  • 9b52402 chore: improve clidoc generation
  • 55e24db chore: improve error reporting to help diagnose flaky test
  • 1d0309b chore: improve readability of popx.MigrationBox
  • e006333 chore: keysetpagination improvements
  • f9de4cc chore: make SCIM work with single-region CRDB
  • 50f6515 chore: more npm security updates
  • cf94909 chore: reduce number of auth steps in cypress test
  • f7b5a64 chore: remove internal address types
  • c0b6fba chore: remove repeated VerifiableAddresses assignment in web_hook.go
  • c90675c chore: remove unused code
  • 4118515 chore: remove unused log code
  • 07284c7 chore: remove unused x/watcherx/websocket
  • 029d8a3 chore: rename ./internal to ./pkg to make all functions visible
  • 01c7b53 chore: run go mod tidy and misc cleanup
  • e0496de chore: run npm audit fix
  • b28c196 chore: security updates for glob library
  • de64ac1 chore: simplify HTTP metrics instrumentation
  • 25d35cc chore: simplify decoderx usage
  • 7d6e01d chore: split SCIM from multi-region & make it work with SQLite
  • f57f519 chore: unify common dependency interfaces
  • 8e369de chore: update @​openapitools/openapi-generator-cli
  • 601c9ac chore: update OSS ory.sh to ory.com
  • 3bb9244 chore: update pop to latest & only run pop.SetNowFunc() inside init()
  • 16343d6 chore: update to dockertest v4
  • 9823ae0 chore: update uaepass jsonnet stubs
  • b410c7f chore: updated axios
  • 286f885 chore: updated golang.org/x/crypto
  • 7b18f23 chore: updated minimatch
  • b922c60 chore: updated playwright (except e2e) and other deps
  • 5ed2524 chore: upgrade AX to next.js 16
  • 7e2a849 chore: use pgx pool in Kratos OEL & fix some OEL commands not using enterprise migrations
  • 550fd75 chore: use sync.Map instead of custom concurrent map
  • 45cc87e ci: add docker driver to cve scan
  • 56be7ba docs: improve readme and dev instructions
  • bc8dca6 docs: update readmes
  • 86103bc feat(kratos): auto-send code when it is the only available method
  • 3dee8f5 feat: add captcha strategy for recovery flow
  • 420f69d feat: add captcha strategy for verification flow
  • 57b099f feat: add column identity_id to identity_credential_identifiers and session_devices
  • 39c341b feat: add native api flow support for passkeys
  • a14c3f2 feat: add ratelimit buckets to swagger definitions
  • aebbc2b feat: add session to all settings hooks payloads
  • 3f24dbf feat: add support for NULL and more column types to keysetpagination
  • 623742e feat: auto account linking for google and apple
  • 80dcbac feat: automatic transaction retries for postgres
  • af48288 feat: better multi-region queries
  • 97ce640 feat: collect external latency data and write to logs
  • 99c8cdc feat: consider Go migrations DirHash when restoring full schema from backups
  • f2ce286 feat: forward (some) user request headers to SMS HTTP channel
  • da8ec11 feat: generate events for SSO and SCIM provider revisions
  • aa3071f feat: hydra benchmarking tool
  • 46c1028 feat: improved tracing
  • 46c18eb feat: infer regional-by-row region using foreign key constraints
  • 86968f5 feat: keto-cli improvements
  • 1544efe feat: login with uae pass
  • a34e951 feat: make SCIM work with MySQL
  • 6bf18bf feat: make new identity_id column on identifiers and session_devices NOT NULL and establish foreign key
  • e25723e feat: rename project revision columns
  • 6bfbaf5 feat: speed up OIDC login+registration handling
  • b94f4c9 feat: update GetActiveRecoveryStrategies method
  • 85590e8 feat: use keysetpagination planner for keto read queries
  • 95341a8 fix(kratos): otp fast-path 2fa body error
  • 81e9151 fix: remove more instances of injecting unrecoverable email faults
  • e72c297 fix: add missing StrategyUsed attribute to Login and registration events
  • a085d87 fix: add missing indices on identity_id
  • ed56dac fix: add missing transient nodes clear
  • 6a6928c fix: add oidc linking/unlinking to api settings flow
  • 2473954 fix: always retry curl invocations to surmount transient third-party failures
  • a86c212 fix: base64encoded schemaURL cannot be resolved
  • 2f9c3e3 fix: batch identity error propagation
  • 849b0de fix: clarify password import
  • 7e33125 fix: context passing in jsonnetsecure
  • 6183672 fix: correctly scan SQL NULL into go JSON types
  • 70f7b38 fix: courier should not retry message dispatches in one go
  • c651ecf fix: data race making test flaky
  • 8adaa02 fix: deadlock when using -parallel 1
  • a06b3c2 fix: don't attempt to redirect to ory.com in kratos tests
  • e948a0b fix: down migrations in newer MySQL versions
  • 84ee596 fix: duplicate credential error placeholder case mismatch
  • 7bb24c5 fix: failing down migration
  • 048d315 fix: fetch login challenge after code submissions
  • 2886abe fix: fix benchmark test
  • 6673982 fix: fix data race in courier test by protecting slice with mutex
  • 01e1dd0 fix: fix flaky email test
  • 952d7ea fix: handle batch identities errors more gracefully
  • 9a5f8b9 fix: incorrect default value for page_tokens
  • 1757cdd fix: incorrect error handling
  • 590d898 fix: incorrect usage of database/sql
  • e7045c5 fix: lint
  • d023775 fix: pass transient payload to webhooks in API/native OIDC flows
  • f6d59bb fix: properly accept login challenge in verification after login flows
  • 8f54814 fix: recovery code expires_in regression
  • 3447e0a fix: recovery code expiry error
  • 071ad54 fix: redact subject codes
  • 7ee85fb fix: remove WithDumpMigrations option to MigrationBox
  • b4d8591 fix: remove flaky test for unused function
  • 65b27fd fix: remove redundant ORDER BY in QueryForCredentials
  • 1799e3a fix: request log config key
  • 9144b55 fix: resolve incorrect error handling
  • e7d8bd1 fix: resolve null response in OAuth2 flow with existing session
  • d6b0f49 fix: return a specific error message for email & phone validation errors
  • b7b7fd4 fix: return correct CSRF errors
  • bc33d5c fix: return oauth2 login challenge on Bad Request in self-service flows
  • 76d35cf fix: seamlessly migrate existing users to SCIM
  • 039d5bc fix: show captcha on otp submission
  • 3da622f fix: stray debug print
  • 1ab143c fix: transfer OAuth2 login challenge in account linking flow
  • 95bf33b fix: update CONTRIBUTING.md
  • 3d88a43 fix: update dependencies and replace @​ory/client for kratos-selfserivce-ui-react-native
  • 79fb49d fix: update packages to fix GHSA-7h2j-956f-4vf2
  • c2adee4 fix: upgrade vulnerable dependencies across Go and npm
  • 6c2f8fb fix: use correct client authentication method for Apple OIDC
  • 116a66e fix: x data race and parallize some tests
  • 7982b73 fixes
  • 7790322 refactor: squash merge old backoffice migration and fix up command
  • 3f06c5d storybook snapshots
  • 3369ebd test(hydra): add plaintext backups for all DB types
  • 0f5085c test: add assertions for json response body
  • 71da1e3 test: deflake SAML config assertion
  • 0451169 test: deflake and improve performance
  • 00c4f9e test: deflake directory watcherx
  • 2a552ea test: faster and more reliable courier tests
  • 8482dd5 test: fix data races
  • 4014eeb test: fix data races
  • b9e094d test: minor setup improvements

Artifacts can be verified with cosign using this public key.

v25.4.0

Compare Source

This release introduces passwordless authentication via SMS, expanded passkey and WebAuthn support, new SAML and OIDC features, extended event emission for observability, and significant database and API optimizations. Ory Kratos v25.4 also prepares for compatibility with the new Ory Elements v1.0 by introducing improvements to self-service flows.

Operators gain better migration tooling, performance improvements, and more robust hooks.

Ory has moved to a new versioning scheme. Read about our new version scheme. Interested in self-hosting Ory with support, SLAs, and advanced features (b2b sso, organization login, FedCM, multi-tenancy …)? Check out our offerings.

Highlights

Passwordless and recovery improvements
  • Added passwordless login and registration via SMS.
  • Recovery codes can now be delivered by SMS.
  • Significantly improved recovery flows that now work with any and multiple address types (email or SMS).
  • Added resend node for verification after registration.
Passkeys and other credentials
  • Support for Android WebAuthn origins, enabling secure passkeys on Android.
  • Emission of oryWebAuthnInitialized event when WebAuthn is ready in the browser.
  • Graceful handling of failing password rehashing during login, improving reliability for long passwords.
  • Conditional passkey handling improved (better retry behavior).
OIDC and SAML
  • Added support for importing SAML credentials (Enterprise/Network only).
  • Added support for Line v2.1 OIDC provider.
  • Microsoft OIDC now uses oid instead of sub for stable identifiers.
  • Added caching of OIDC providers to reduce calls to discovery endpoints.
  • New policy callbacks for customizing OIDC credential linking.
  • Added more extension points to the registry.
User flow enhancements
  • require_verified_address now automatically starts a verification flow instead of failing.
  • Captcha improvements: first-step captcha groups and domain allowlists (Ory Enterprise License / Ory Network only).
  • Improved error reporting and handling across login, registration, and linking flows (Ory Enterprise License / Ory Network only).
  • OIDC signup and account linking flows more robust, including better handling of login challenges in SPAs.
  • alreadyAuthenticated cases in native login/registration flows now handled correctly.
  • Verification hooks improved: correct status handling in recovery hooks and support in settings flows.
  • Auto-linking and identifier updates fixed to ensure identities remain consistent.
  • Division UI nodes added for dynamic script hooks.
  • Console UI now supports multiple identity schemas.
  • Admin API now allows deleting password credentials if not the last factor.
Events and observability
  • New events: LoginStartedRegistrationStarted.
  • New courier events: CourierMessageAbandonedCourierMessageDispatched.
  • Events now emitted on Jsonnet mapping failures (OIDC claims, JWT templating).
  • Admin recovery code events are logged.
  • More attributes added to webhook events for better debugging.
  • Extended tracing in settings, courier, and credential linking flows.
Operational and performance improvements
  • Optimized secondary indices for self-service, session, and identity tables.
  • Removed unused indices and improved query plans for CockroachDB.
  • Reduced duplicate queries in settings and credential flows.
  • Faster lookups for credential types and session handling.
  • Added index hints for CockroachDB identity credential deletion.
  • Improved handling of identity imports with reduced DB load.
  • Recovery and OTP code submit count mechanism redesigned to prevent brute-forcing.
  • New kratos migrate sql up|down|status commands replace old migration CLI commands.
  • OIDC sessions now loaded only once when middleware is used.
  • Courier improved with HTML email support and more reliable tracing.
  • Added explicit config flag for secure cookies.
  • External ID support for identities via API and webhooks.
  • New endpoint to tokenize JWTs using webhooks.
  • Improved domain telemetry for OSS deployments.
  • Autoconfiguration for kratos-changefeed (Ory Enterprise License / Ory Network only).
  • High-performance SQL connection pool with tracing and metrics (Ory Enterprise License / Ory Network only).
Developer and extension improvements
  • More extension points available in registry and OIDC flows.
  • Jsonnet body templating enabled for password migration hook.
  • New attributes available for Login and Registration events.
  • Webhook configuration handling refactored and extended.
  • New division node attributes for UI extensibility.
  • Added email domain matcher for flows.
  • Added external IDs and webhook configurability.
  • Console support for choosing identity schema during registration/login (Enterprise).
Documentation and tooling
  • Improved docs for OAS verification, Facebook Graph API, and OIDC subject sources.
  • Clarified error messages in security-related contexts.
  • Better migration error handling and improved messages for operators.
  • Added help text for new migration commands.
  • CI/CD stability fixes, improved code coverage configuration, and dependency updates.

Breaking changes

  • Sessions API: The x-total-count header has been removed from GET /admin/sessions.

    Commit: e24f993ea

  • Account linking: Failed OIDC account linking flows now return HTTP 400 instead of 200 OK.

    Commit: ed4fba3ef

  • Verification flow: The show_verification_ui element is only included if the hook is explicitly configured.

    Commit: 5b00fe15d

  • OIDC registration: Failing fields are now placed in the default node group instead of oidc. Legacy behavior can be restored with feature_flags.legacy_oidc_registration_node_group=true.

    Commit: dc8b32e00

Known regressions

Unfortunately, this release contains a breaking change. Most applications will be unaffected by this issue. Read more about it here: #​4499

Auto-generated release notes

The require_verified_address hook no longer returns a
plain error. Previously, users had to manually start the verification
flow, which caused a poor experience. Now, Ory Kratos automatically
creates a verification flow and redirects the user using continue_with
or an HTTP redirect. The verification flow starts with the first
verified address found for the user. This aligns the behavior of
require_verified_address with using the verification and
show_verification_ui hook combination for login.

Going forward, the node group of fields that are
failing validation during oidc sign up are default and no longer
oidc. For now, you can get the legacy behavior back by turning on
feature_flags.legacy_oidc_registration_node_group=true.

Co-authored-by: Jonas Hungershausen jonas.hungershausen@ory.sh

Before this change, show_verification_ui would
always be included in continue_with for the registration flow when
verification was enabled. After this change, show_verification_ui is
only included when the show_verification_ui post-registration hook is
defined.

Account linking incorrectly returned a 200 OK status
code even though the login flow was not completed successfully. Going
forward, the correct 400 OK status code will be sent when using the API
flow or Accept: application/json.

This patch changes the behavior of configuration item foo to do bar. To keep the existing
behavior please do baz.

Bug Fixes
  • Accept login challenge in session_issuer on SPA flows (#​4288) (e13687a)

  • Accept login_challenge in SPA verification flows (#​4284) (7ca3b6b)

  • Account linking should only happen after 2fa when required (#​4174) (8e29b68)

  • Account linking with 2FA (#​4188) (4a870a6):

    This fixes some edge cases with OIDC account linking for accounts with 2FA enabled.

  • Add default issuer URL for LINE (#​4415) (292f65d):

    Fixed+expanded relevant comment.

    Fixed some tracing issues.

    Added error info and missing res.Body.Close() in courier.

  • Add exists clause (#​4191) (a313dd6)

  • Add missing autocomplete attributes to identifier_first strategy (#​4215) (e1f29c2)

  • Add missing csrf_token (#​4363) (f441f41)

  • Add missing discriminator (#​4365) (c10bb06)

  • Add missing saml group (#​4268) (44eb305)

  • Add missing submit group (#​4354) (106163d)

  • Add missing values to the session method enum (a043b43):

  • Add resend node to after registration verification flow (#​4260) (9bc83a4)

  • Add transient payload to fedcm (#​4369) (245f5dc), closes #​1234 #​1234:

  • Allow patching some /credentials sub-paths (#​4277) (aefa806), closes #​1234 #​1234:

  • Also update identifiers (#​4321) (7c63727):

    This fixes a bug where when an identity is merged into another, the
    identifier of the original identity was not updated.

  • Another apple fix (8a220c0):

  • Apply strategy filters in identifier first as well (#​4352) (ec3ecc5)

  • Better tracing in proxy HTTP (ff5fa9b):

  • Cancel conditional passkey before trying again (#​4247) (d9f6f75)

  • Check aal on sessions list endpoint (#​4305) (44f97b8), closes #​3671:

    The session check to list a user's own sessions now requires the same AAL level as the whoami check.

  • Clarify import responses (2a44fd5):

  • Context passing and missing body close (79f4e2a):

  • Copybara script (b3af828):

  • Correctly handle HTTP route patterns in metrics (dc992d3):

  • Count MFA addresses in CountActiveMultiFactorCredentials for code method (9860c9a), closes ory/network#409

  • Deduplicate down migrations (a000460):

  • deps: Update go-x (ae80380):

  • Detect whether external_id is set in webhook response (7d0d7f6):

  • Div decoding (#​4362) (ef9ee23)

  • Do not roll back transaction on partial identity insert error (#​4211) (82660f0)

  • Don't remove OIDC buttons if invalid identifier is submitted (97848c7):

  • Don't show oidc subject in login hints (#​4264) (b95fd3f)

  • Duplicate autocomplete trigger (6bbf915)

  • Enable b2b_sso hook in more places (#​4168) (0c48ad1):

    fix: allow b2b_sso hook in more places

  • Ensure make quickstart-dev works without options (#​4401) (327c5a4):

    make quickstart-dev uses the make variable QUICKSTART_OPTIONS which
    is set to "" by default. This will result in two double quotes ("")
    in the final shell command e.g. docker-compose "" up when the variable
    is not set on the make command line, which fails at the shell level. The
    fix is to leave the variable empty by default. No semantic changes.

  • Ensure authentication method is added to session after linking OIDC provider (5cae1f7):

  • Ensure context is not canceled during password hashing (#​4364) (e9c6a18):

    Especially during large imports of plaintext passwords there can be a
    lot of useless hashing, even after

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants