Upstream 26.6.4 plus two cherry-picks from upstream's 26.6 release line, unmodified
(git patch-id --stable matches upstream):
- keycloak/keycloak@62dd952 — CVE-2026-18963, reset-credentials flow
- keycloak/keycloak@869c3fd — rollback when reset-credentials token verification fails
Excluded on purpose: keycloak/keycloak@fccbaba, which changes the
BruteForceProtector SPI signature and lockout semantics.
Pom version is deliberately left at 26.6.4; identity is the tag, the image tag and the image
labels. Image: ghcr.io/inform-software/keycloak:26.6.4-inform.1.