·
1 commit
to main
since this release
Immutable
release. Only release title and notes can be modified.
Security
- Patch CVE-2026-75759 / GHSA-533g-4vf3-xwrj by @maennchen in 5f62fbc
What's Changed
- Return an error instead of raising on malformed JSON by @ericmj in #535
- Allow overriding the oidcc_plug version for certification by @maennchen in #536
- Return the provider document from the configuration loaders by @ericmj in #537
- Subtract the Age header when computing a cache deadline by @ericmj in #538
- Report what a JWKS refresh fetched by @ericmj in #540
- Reject issuers carrying a query or fragment by @ericmj in #539
- Derive the at_hash digest from the ID token signing algorithm by @maennchen in #541
Software Updates
- Bump the github-actions group with 4 updates by @dependabot[bot] in #542
- Bump the github-actions group with 5 updates by @dependabot[bot] in #544
- Bump the github-actions group with 4 updates by @dependabot[bot] in #545
Full Changelog: v3.8.0...v3.9.0