Skip to content

Upgrade Keycloak from 26.1.4 to 26.3.2#11627

Merged
ofahimIQSS merged 5 commits intodevelopfrom
dependabot/maven/conf/keycloak/builtin-users-spi/org.keycloak-keycloak-services-26.3.0
Aug 13, 2025
Merged

Upgrade Keycloak from 26.1.4 to 26.3.2#11627
ofahimIQSS merged 5 commits intodevelopfrom
dependabot/maven/conf/keycloak/builtin-users-spi/org.keycloak-keycloak-services-26.3.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 10, 2025

Bumps org.keycloak:keycloak-services from 26.1.4 to 26.3.0.

Release notes

Sourced from org.keycloak:keycloak-services's releases.

26.3.0

... (truncated)

Commits
  • 88d87bc Set version to 26.3.0
  • 154b8ed Add missing javadocs to published artifacts to allow Maven Central Portal Pub...
  • d2b4601 Add missing artifact descriptions to allow Maven Central Portal Publisher pas...
  • aa00161 Committing **/proto.lock changes
  • 2b44c56 fix: adding logic to isolate realm migration processing (#39377)
  • 3a87dcd update docs regarding to use statefulset and not a deployment
  • df13273 Bump rollup from 4.44.0 to 4.44.1 in /js (#40746)
  • 327900e Bump @​eslint/js from 9.29.0 to 9.30.0 in /js (#40778)
  • 40665d2 Bump react-hook-form from 7.58.1 to 7.59.0 in /js (#40779)
  • a9fbc3c Bump prettier from 3.6.0 to 3.6.2 in /js (#40781)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [org.keycloak:keycloak-services](https://github.com/keycloak/keycloak) from 26.1.4 to 26.3.0.
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@26.1.4...26.3.0)

---
updated-dependencies:
- dependency-name: org.keycloak:keycloak-services
  dependency-version: 26.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jul 10, 2025
@scolapasta scolapasta moved this to Ready for Review ⏩ in IQSS Dataverse Project Jul 14, 2025
@ofahimIQSS ofahimIQSS moved this from Ready for Review ⏩ to In Review 🔎 in IQSS Dataverse Project Jul 15, 2025
@cmbz cmbz added the FY26 Sprint 2 FY26 Sprint 2 (2025-07-16 - 2025-07-30) label Jul 17, 2025
@qqmyers
Copy link
Member

qqmyers commented Jul 22, 2025

FWIW: There is a 26.3.1 now that could be used.

…aven/conf/keycloak/builtin-users-spi/org.keycloak-keycloak-services-26.3.0
@GPortas GPortas changed the title Bump org.keycloak:keycloak-services from 26.1.4 to 26.3.0 in /conf/keycloak/builtin-users-spi Bump org.keycloak:keycloak-services from 26.1.4 to 26.3.2 in /conf/keycloak/builtin-users-spi Jul 26, 2025
@GPortas GPortas changed the title Bump org.keycloak:keycloak-services from 26.1.4 to 26.3.2 in /conf/keycloak/builtin-users-spi Upgrade Keycloak from 26.1.4 to 26.3.2 Jul 26, 2025
@GPortas GPortas moved this from In Review 🔎 to Ready for Review ⏩ in IQSS Dataverse Project Jul 26, 2025
@GPortas GPortas removed their assignment Jul 26, 2025
@GPortas GPortas added Size: 3 A percentage of a sprint. 2.1 hours. SPA.Q3 Not related to any specific Q3 feature Original size: 3 Size: 0.5 A percentage of a sprint. 0.35 hours Original size: 0.5 and removed Size: 3 A percentage of a sprint. 2.1 hours. Original size: 3 labels Jul 26, 2025
@coveralls
Copy link

coveralls commented Jul 26, 2025

Coverage Status

coverage: 23.21%. remained the same
when pulling 6651d86 on dependabot/maven/conf/keycloak/builtin-users-spi/org.keycloak-keycloak-services-26.3.0
into b3e1c78 on develop.

@github-actions

This comment has been minimized.

1 similar comment
@github-actions

This comment has been minimized.

@qqmyers
Copy link
Member

qqmyers commented Jul 26, 2025

FWIW: 26.3.2 updates the postgres driver which has a sec update

@GPortas GPortas moved this from Ready for Review ⏩ to In Progress 💻 in IQSS Dataverse Project Jul 28, 2025
@GPortas GPortas self-assigned this Jul 28, 2025
@GPortas GPortas moved this from In Progress 💻 to Ready for Review ⏩ in IQSS Dataverse Project Jul 28, 2025
@GPortas GPortas removed their assignment Jul 28, 2025
@GPortas
Copy link
Contributor

GPortas commented Jul 28, 2025

FWIW: 26.3.2 updates the postgres driver which has a sec update

I'm not sure I understand your point. The updated Postgres driver should be embedded in the new Keycloak version; an update on our side shouldn't be necessary.

@github-actions

This comment has been minimized.

@qqmyers
Copy link
Member

qqmyers commented Jul 28, 2025

Right - just noting that there's a security aspect - no change to the PR.

@GPortas GPortas added the SPA These changes are required for the Dataverse SPA label Jul 30, 2025
@cmbz cmbz added the FY26 Sprint 3 (2025-07-30 - 2025-08-13) label Jul 31, 2025
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jul 31, 2025

A newer version of org.keycloak:keycloak-services exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@pdurbin pdurbin self-assigned this Aug 11, 2025
@pdurbin pdurbin moved this from Ready for Review ⏩ to In Review 🔎 in IQSS Dataverse Project Aug 11, 2025
Copy link
Member

@pdurbin pdurbin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

…aven/conf/keycloak/builtin-users-spi/org.keycloak-keycloak-services-26.3.0
@GPortas GPortas requested a review from pdurbin August 12, 2025 15:05
@GPortas GPortas removed their assignment Aug 12, 2025
@github-actions
Copy link

📦 Pushed preview images as

ghcr.io/gdcc/dataverse:dependabot-maven-conf-keycloak-builtin-users-spi-org.keycloak-keycloak-services-26.3.0
ghcr.io/gdcc/configbaker:dependabot-maven-conf-keycloak-builtin-users-spi-org.keycloak-keycloak-services-26.3.0

🚢 See on GHCR. Use by referencing with full name as printed above, mind the registry name.

@github-project-automation github-project-automation bot moved this from In Review 🔎 to Ready for QA ⏩ in IQSS Dataverse Project Aug 12, 2025
@pdurbin pdurbin removed their assignment Aug 12, 2025
@ofahimIQSS
Copy link
Contributor

tested in internal - no issues found.

@ofahimIQSS ofahimIQSS merged commit 684e0ba into develop Aug 13, 2025
18 checks passed
@github-project-automation github-project-automation bot moved this from Ready for QA ⏩ to Merged 🚀 in IQSS Dataverse Project Aug 13, 2025
@dependabot dependabot bot deleted the dependabot/maven/conf/keycloak/builtin-users-spi/org.keycloak-keycloak-services-26.3.0 branch August 13, 2025 14:50
@scolapasta scolapasta moved this from Merged 🚀 to Done 🧹 in IQSS Dataverse Project Aug 13, 2025
@pdurbin pdurbin added this to the 6.8 milestone Aug 13, 2025
@cmbz cmbz added the FY26 Sprint 4 FY26 Sprint 4 (2025-08-13 - 2025-08-27) label Aug 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file FY26 Sprint 2 FY26 Sprint 2 (2025-07-16 - 2025-07-30) FY26 Sprint 3 (2025-07-30 - 2025-08-13) FY26 Sprint 4 FY26 Sprint 4 (2025-08-13 - 2025-08-27) java Pull requests that update Java code Original size: 0.5 Size: 0.5 A percentage of a sprint. 0.35 hours SPA.Q3 Not related to any specific Q3 feature SPA These changes are required for the Dataverse SPA

Projects

Status: Done 🧹

Development

Successfully merging this pull request may close these issues.

6 participants