chore: upgrade keycloak to 26.7.1 #6

Closed
autonomic-bot wants to merge 0 commits from upgrade-0ef3a42 into main
Owner

Upgrade: keycloak 26.7.0 → 26.7.1 (patch)

service image current → new
app keycloak/keycloak 26.7.0 → 26.7.1
db mariadb 12.3 (unchanged)

Upstream release notes: app 26.7.0→26.7.1: https://github.com/keycloak/keycloak/releases/tag/26.7.1

26.7.1 is a patch release — security + bug fixes only (no breaking changes, no migrations, no config changes).
Security fixes: CVE-2026-9793 (JWE request object bypass), CVE-2026-4629 (privilege escalation via role mapper injection), CVE-2026-14209 (FGAP v2 user disclosure), CVE-2026-14614 (FGAP client scope assignment bypass), CVE-2026-14615 (FGAP parent group children bypass).
Bug fixes: WebAuthn attachment policy bypass, clustering test, Kustomize Role/RoleBinding, password-reset double-commit, 500 on duplicate organization scope, LiquibaseDBLockProvider format error.
DB migration is automatic (recipe sets KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update); back up the MariaDB volume before upgrading as a precaution.

Recipe version label left untouched (10.9.0+26.7.0); operator runs after merge:

abra recipe release keycloak -z

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

## Upgrade: keycloak 26.7.0 → 26.7.1 (patch) | service | image | current → new | |---------|-------|---------------| | app | keycloak/keycloak | 26.7.0 → 26.7.1 | | db | mariadb | 12.3 (unchanged) | **Upstream release notes:** app 26.7.0→26.7.1: https://github.com/keycloak/keycloak/releases/tag/26.7.1 26.7.1 is a patch release — security + bug fixes only (no breaking changes, no migrations, no config changes). Security fixes: CVE-2026-9793 (JWE request object bypass), CVE-2026-4629 (privilege escalation via role mapper injection), CVE-2026-14209 (FGAP v2 user disclosure), CVE-2026-14614 (FGAP client scope assignment bypass), CVE-2026-14615 (FGAP parent group children bypass). Bug fixes: WebAuthn attachment policy bypass, clustering test, Kustomize Role/RoleBinding, password-reset double-commit, 500 on duplicate organization scope, LiquibaseDBLockProvider format error. DB migration is automatic (recipe sets `KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update`); back up the MariaDB volume before upgrading as a precaution. Recipe version label left untouched (`10.9.0+26.7.0`); operator runs after merge: abra recipe release keycloak -z Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-08-07 04:05:32 +00:00
autonomic-bot requested review from trav 2026-08-07 04:05:33 +00:00
autonomic-bot requested review from notplants 2026-08-07 04:05:33 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cikeycloak @ 0ef3a426 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `0ef3a426` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1213/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1213) [![level](https://ci.commoninternet.net/runs/1213/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1213) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1213) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-08-11 19:14:19 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/keycloak#6