Skip to content

Update all non-major dependencies - #527

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

Update all non-major dependencies#527
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@sentry/vue (source) 10.68.010.71.0 age confidence dependencies minor 10.72.0
axios (source) 1.18.11.20.0 age confidence dependencies minor
django-allauth (changelog) ==65.18.0==65.19.1 age confidence project.dependencies minor
django-ninja ==1.6.2==1.6.3 age confidence project.dependencies patch
django-oauth-toolkit ==3.4.0==3.4.1 age confidence project.dependencies patch
faker (changelog) ==40.36.0==40.37.0 age confidence project.optional-dependencies minor
ipython ==9.15.0==9.16.1 age confidence project.optional-dependencies minor 9.17.0
kitware-resonant/resonant/heroku (source) 3.3.03.4.0 age confidence module minor
numpy (changelog) ==2.5.1==2.5.2 age confidence project.optional-dependencies patch
opencv-python-headless ==4.13.0.92==4.14.0.94 age confidence project.optional-dependencies minor
scipy ==1.18.0==1.18.1 age confidence project.optional-dependencies patch
sentry-sdk (changelog) ==2.66.1==2.68.1 age confidence project.dependencies minor
tqdm (changelog) ==4.69.1==4.70.0 age confidence project.dependencies minor
vue (source) 3.5.403.5.41 age confidence dependencies patch 3.5.42
vuetify (source) 3.12.113.13.2 age confidence dependencies minor

Release Notes

getsentry/sentry-javascript (@​sentry/vue)

v10.71.0

Compare Source

Important Changes
  • feat(v10/core)!: Enable logs by default (#​23311)

The enableLogs client option now defaults to true, so Sentry Logs work without any manual opt-in. Nothing is captured unless you call the Sentry.logger.* APIs or add a log-forwarding integration (such as consoleLoggingIntegration, pinoIntegration, or the winston transport), and you can set enableLogs: false to opt out. Although a default change like this would normally land in a major release, we are shipping it in a minor after careful consideration, since it sends no data on its own and only takes effect once you actively use the logging APIs or a logging integration.

Other Changes
  • feat(v10/core): Deprecate scope.clear() method (#​23231)
  • fix(v10/core): Bound child span tracking on long-lived spans (#​23406)
  • fix(v10/core): Read Supabase PostgREST headers from Headers instances (#​23241)
  • fix(v10/hono): Use captureException from scope, not from Client (#​23280)
  • fix(v10/nuxt): Delete source maps after Nitro finishes building (#​23508)
  • fix(v10/react-router): Carry multi-byte UTF-8 across SSR stream chunk boundaries (#​23421)
  • fix(v10/react): Match TanStack Router pageload against the router location (#​23494)
Internal Changes
  • test(v10/nextjs): Add e2e app for a user-owned OpenTelemetry setup (#​23278)

Bundle size 📦

Path Size
@​sentry/browser 27.1 KB
@​sentry/browser - with treeshaking flags 25.58 KB
@​sentry/browser (incl. Tracing) 45.51 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.25 KB
@​sentry/browser (incl. Tracing, Profiling) 50.15 KB
@​sentry/browser (incl. Tracing, Replay) 83.83 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 73.71 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 88.45 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 100.79 KB
@​sentry/browser (incl. Feedback) 43.87 KB
@​sentry/browser (incl. sendFeedback) 31.78 KB
@​sentry/browser (incl. FeedbackAsync) 36.79 KB
@​sentry/browser (incl. Metrics) 28.16 KB
@​sentry/browser (incl. Logs) 28.38 KB
@​sentry/browser (incl. Metrics & Logs) 29.06 KB
@​sentry/react 28.86 KB
@​sentry/react (incl. Tracing) 47.72 KB
@​sentry/vue 32.4 KB
@​sentry/vue (incl. Tracing) 47.43 KB
@​sentry/svelte 27.12 KB
CDN Bundle 29.43 KB
CDN Bundle (incl. Tracing) 47.43 KB
CDN Bundle (incl. Logs, Metrics) 30.98 KB
CDN Bundle (incl. Tracing, Logs, Metrics) 48.7 KB
CDN Bundle (incl. Replay, Logs, Metrics) 69.32 KB
CDN Bundle (incl. Tracing, Replay) 84.05 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.33 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 89.72 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 90.96 KB
CDN Bundle - uncompressed 87.76 KB
CDN Bundle (incl. Tracing) - uncompressed 143.35 KB
CDN Bundle (incl. Logs, Metrics) - uncompressed 92.36 KB
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 147.24 KB
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 214.2 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 259.79 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 263.67 KB
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 273.17 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 277.04 KB
@​sentry/nextjs (client) 50.2 KB
@​sentry/sveltekit (client) 45.92 KB
@​sentry/core/server 78.73 KB
@​sentry/core/browser 65.27 KB
@​sentry/node-core 61.77 KB
@​sentry/node 122.94 KB
@​sentry/node (incl. diagnostics channel injection) 147.78 KB
@​sentry/node/import (ESM hook with diagnostics-channel injection) 68.39 KB
@​sentry/node/light 50.21 KB
@​sentry/node - without tracing 73.19 KB
@​sentry/aws-serverless 82.24 KB
@​sentry/cloudflare (withSentry) - minified 197.31 KB
@​sentry/cloudflare (withSentry) 485.11 KB

v10.70.0

Compare Source

  • feat(v10/core): Support stable MCP SDK v2 (#​22986)
  • feat(v10/deps): Bump @sentry/node-cpu-profiler to 2.4.3 (#​22992)
  • feat(v10/solid,solidstart): Support @solidjs/router v1 (#​23163)
  • fix(v10/cloudflare): Fork the isolation scope for Durable Object methods (#​23189)
  • fix(v10/cloudflare): Get original waituntil in workflows (#​23192)
  • fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy (#​23190)
  • fix(v10/cloudflare): Set agent conversation id on the onRequest path (#​22985)
  • fix(v10/cloudflare): Set conversation id independent of session name (#​23193)
  • fix(v10/cloudflare): Try/catch on non-configurable prototypes (#​23191)
  • fix(v10/cloudflare): Use gen_ai.agent.name for class names (#​22987)
  • fix(v10/core,browser): Handle errors from other realms (#​23201)
  • fix(v10/core): Sample errors after beforeSend while preserving session updates (#​22819)
  • fix(v10/hono): Include originalException in captured exception hint (#​22990)
  • fix(v10/nextjs): meriyah issue for standalone build (#​23055)
  • fix(v10/nextjs): Remove tracing from middleware wrappers (#​22904)
  • fix(v10/profiling-node): Respect profileSessionSampleRate in trace profile lifecycle (#​22940)
  • fix(v10/react-router): Preserve sourcemaps.disable when unstable_sentryVitePluginOptions is set (#​22966)
  • fix(v10/react): Remove routes from shared set on <Routes> unmount (#​22948)
  • fix(v10/sveltekit): Export metrics from worker entry point (#​23027)
Internal Changes
  • test(v10/e2e): Add missing @sentry/core dep to nextjs-16-userfeedback (#​23009)
  • test(v10/e2e): Fix failing sveltekit-3 test (#​23016)
  • test(v10/e2e): Fix type error in nextjs ai-error tests (#​23011)
  • test(v10/e2e): Pin tanstackstart-react e2e deps to unblock tunnel tests (#​23048)

Work in this release was contributed by @​davidmurdoch, @​Jxxunnn, and @​kamilogorek. Thank you for your contributions!

Bundle size 📦

Path Size
@​sentry/browser 27.09 KB
@​sentry/browser - with treeshaking flags 25.58 KB
@​sentry/browser (incl. Tracing) 45.5 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.24 KB
@​sentry/browser (incl. Tracing, Profiling) 50.13 KB
@​sentry/browser (incl. Tracing, Replay) 83.82 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 73.7 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 88.42 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 100.78 KB
@​sentry/browser (incl. Feedback) 43.87 KB
@​sentry/browser (incl. sendFeedback) 31.78 KB
@​sentry/browser (incl. FeedbackAsync) 36.79 KB
@​sentry/browser (incl. Metrics) 28.16 KB
@​sentry/browser (incl. Logs) 28.38 KB
@​sentry/browser (incl. Metrics & Logs) 29.06 KB
@​sentry/react 28.86 KB
@​sentry/react (incl. Tracing) 47.7 KB
@​sentry/vue 32.39 KB
@​sentry/vue (incl. Tracing) 47.41 KB
@​sentry/svelte 27.12 KB
CDN Bundle 29.43 KB
CDN Bundle (incl. Tracing) 47.41 KB
CDN Bundle (incl. Logs, Metrics) 30.97 KB
CDN Bundle (incl. Tracing, Logs, Metrics) 48.69 KB
CDN Bundle (incl. Replay, Logs, Metrics) 69.32 KB
CDN Bundle (incl. Tracing, Replay) 84.03 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.31 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 89.71 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 90.94 KB
CDN Bundle - uncompressed 87.76 KB
CDN Bundle (incl. Tracing) - uncompressed 143.3 KB
CDN Bundle (incl. Logs, Metrics) - uncompressed 92.36 KB
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 147.19 KB
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 214.2 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 259.75 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 263.62 KB
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 273.13 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 276.99 KB
@​sentry/nextjs (client) 50.19 KB
@​sentry/sveltekit (client) 45.91 KB
@​sentry/core/server 78.66 KB
@​sentry/core/browser 65.21 KB
@​sentry/node-core 61.76 KB
@​sentry/node 122.92 KB
@​sentry/node (incl. diagnostics channel injection) 147.77 KB
@​sentry/node/import (ESM hook with diagnostics-channel injection) 68.39 KB
@​sentry/node/light 50.2 KB
@​sentry/node - without tracing 73.18 KB
@​sentry/aws-serverless 82.22 KB
@​sentry/cloudflare (withSentry) - minified 197.26 KB
@​sentry/cloudflare (withSentry) 484.82 KB

v10.69.0

Compare Source

Important Changes
  • feat(v10/cloudflare): Add instrumentAgentWithSentry for Cloudflare Agents (#​22786)

The Cloudflare SDK adds a new instrumentAgentWithSentry API for Cloudflare Agents. It works like instrumentDurableObjectWithSentry for Agent classes from the agents SDK and additionally creates spans for @callable RPC methods and automatically sets the conversationId based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically (#​22788).

Other Changes
  • feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding (#​22796)
  • feat(v10/cloudflare): Add wranglerConfigPath to Vite options (#​22803)
  • feat(v10/cloudflare): Filter framework-internal Durable Object storage spans (#​22770)
  • feat(v10/cloudflare): Instrument Agents automatically (#​22788)
  • feat(v10/cloudflare): Rotate agent conversation id on chat clear (#​22787)
  • fix(v10/cloudflare): Also skip cf: prefixed DOs (#​22802)
  • fix(v10/cloudflare): Filter CREATE INDEX spans on cf_-prefixed tables (#​22767)
  • fix(v10/cloudflare): Prevent AI provider skips (#​22771)
  • fix(v10/core): Summarize SQLite upserts so Durable Object cf_ spans stay filtered (#​22766)
  • fix(v10/effect): Set sentry.origin on logs from SentryEffectLogger (#​22806)
  • fix(v10/gatsby): Add React 19 to peer dependency range (#​22675)
  • fix(v10/node): Unpin @apm-js-collab/code-transformer-bundler-plugins (#​22678)
  • fix(v10/server-utils): Do not inject dc into client bundle (#​22765)
Internal Changes
  • test(v10/cloudflare): Pin mcp as agent depends on it (#​22769)

Bundle size 📦

Path Size
@​sentry/browser 27.11 KB
@​sentry/browser - with treeshaking flags 25.59 KB
@​sentry/browser (incl. Tracing) 45.51 KB
@​sentry/browser (incl. Tracing + Span Streaming) 47.25 KB
@​sentry/browser (incl. Tracing, Profiling) 50.15 KB
@​sentry/browser (incl. Tracing, Replay) 83.84 KB
@​sentry/browser (incl. Tracing, Replay) - with treeshaking flags 73.71 KB
@​sentry/browser (incl. Tracing, Replay with Canvas) 88.44 KB
@​sentry/browser (incl. Tracing, Replay, Feedback) 100.79 KB
@​sentry/browser (incl. Feedback) 43.88 KB
@​sentry/browser (incl. sendFeedback) 31.79 KB
@​sentry/browser (incl. FeedbackAsync) 36.8 KB
@​sentry/browser (incl. Metrics) 28.17 KB
@​sentry/browser (incl. Logs) 28.39 KB
@​sentry/browser (incl. Metrics & Logs) 29.07 KB
@​sentry/react 28.87 KB
@​sentry/react (incl. Tracing) 47.72 KB
@​sentry/vue 32.41 KB
@​sentry/vue (incl. Tracing) 47.43 KB
@​sentry/svelte 27.13 KB
CDN Bundle 29.45 KB
CDN Bundle (incl. Tracing) 47.42 KB
CDN Bundle (incl. Logs, Metrics) 30.99 KB
CDN Bundle (incl. Tracing, Logs, Metrics) 48.7 KB
CDN Bundle (incl. Replay, Logs, Metrics) 69.34 KB
CDN Bundle (incl. Tracing, Replay) 84.04 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.32 KB
CDN Bundle (incl. Tracing, Replay, Feedback) 89.71 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 90.94 KB
CDN Bundle - uncompressed 87.8 KB
CDN Bundle (incl. Tracing) - uncompressed 143.35 KB
CDN Bundle (incl. Logs, Metrics) - uncompressed 92.4 KB
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 147.23 KB
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 214.24 KB
CDN Bundle (incl. Tracing, Replay) - uncompressed 259.79 KB
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 263.66 KB
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 273.17 KB
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 277.03 KB
@​sentry/nextjs (client) 50.2 KB
@​sentry/sveltekit (client) 45.92 KB
@​sentry/core/server 78.56 KB
@​sentry/core/browser 65.22 KB
@​sentry/node-core 61.78 KB
@​sentry/node 122.95 KB
@​sentry/node (incl. diagnostics channel injection) 147.79 KB
@​sentry/node/import (ESM hook with diagnostics-channel injection) 68.39 KB
@​sentry/node/light 50.21 KB
@​sentry/node - without tracing 73.19 KB
@​sentry/aws-serverless 82.24 KB
@​sentry/cloudflare (withSentry) - minified 195.81 KB
@​sentry/cloudflare (withSentry) 481.16 KB
axios/axios (axios)

v1.20.0

Compare Source

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#​11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#​11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#​11087, #​11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#​11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#​11094, #​11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#​11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#​11096)

🔧 Maintenance & Chores

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

v1.19.0

Compare Source

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

allauth/django-allauth (django-allauth)

v65.19.1

Compare Source

v65.19.0

Compare Source

vitalik/django-ninja (django-ninja)

v1.6.3: 1.6.3

Compare Source

What's Changed

Hotfix release cut from v1.6.2 — contains only the changes above, none of the other work currently on master.

Full Changelog: vitalik/django-ninja@v1.6.2...v1.6.3

django-oauth/django-oauth-toolkit (django-oauth-toolkit)

v3.4.1

Compare Source

This release is dominated by security hardening of redirect URI matching, token revocation and
refresh token handling
. Several entries below change behavior that was previously accepted, and
they are spread across Fixed and Security: the "Upgrading to 3.4.1" section of the
Upgrading guide collects everything you need to act on in one place, so start there. Of particular
note: redirect URIs are now matched exactly per
RFC 9700 §2.1, so a request may no
longer carry query parameters, path parameters, credentials or a fragment that the registered URI
does not have; REFRESH_TOKEN_EXPIRE_SECONDS, where set, is now enforced when a refresh token is
presented rather than only by the cleartokens sweep; and the built-in templates now link a
stylesheet shipped with the package instead of a CDN, so run collectstatic or the pages render
unstyled.

Added
  • #​681 Redirect URI mismatches are now diagnosed on the oauth2_provider logger at DEBUG,
    reporting the requested URI, every registered candidate it was compared against, and which
    component of each one differed (scheme, hostname, port, path, query). The same detail is
    emitted for post_logout_redirect_uri and for the token endpoint's comparison against the
    URI recorded on the grant. The error response is unchanged: the registered URIs are never
    disclosed to the requester, only to the server's log. See "Debugging redirect URI
    mismatches" in the documentation. Note that AbstractApplication.redirect_uri_allowed()
    and post_logout_redirect_uri_allowed() now call the new check_redirect_to_uri_allowed()
    (same verdict, plus the mismatch reasons) instead of redirect_to_uri_allowed(), so code
    that wrapped or patched the latter to influence those methods must target the former.
  • #​634 A system check (oauth2_provider.W011) that warns when the AccessToken and
    RefreshToken models are swapped into different apps, and a new
    "Extending the token models" documentation section explaining how to swap the
    interrelated token models together.
  • #​1623 Documentation ("Content Security Policy and the authorization form") on completing
    the authorization-code flow under a strict form-action Content Security Policy, which
    Chromium enforces against the post-authorization redirect to the client's redirect_uri.
  • #​410 Documentation ("Resource scope syntax") clarifying that TokenHasResourceScope
    checks each required_scopes entry suffixed with the READ_SCOPE/WRITE_SCOPE setting
    value (defaults read/write, e.g. music:read, music:write), so a bare music scope
    is rejected; with the default settings-based scopes backend the suffixed scopes must be
    declared in SCOPES.
  • #​1157 An "Upgrading" documentation page collecting the breaking changes and upgrade steps for
    every release that needs them — 2.0, 3.0 and this release — linked from the documentation index,
    so upgrade guidance is discoverable outside the CHANGELOG. A release that asks nothing of you has
    no section there, so a gap between two versions is an answer rather than an omission.
  • #​452 Documentation ("Custom scopes backend") explaining how to replace the default
    settings-driven scopes backend via SCOPES_BACKEND_CLASS, including a worked model-based
    example that stores scopes in the database.
  • #​1045 Tutorial ("Managing applications and tokens in the Django admin") walking through the
    admin site for applications and issued tokens, including client-secret hashing, credential
    masking, and that tokens cannot be created by hand.
  • #​403 Translatable (gettext_lazy) verbose_name labels on every field of the
    Application, Grant, AccessToken, RefreshToken, IDToken and DeviceGrant models, so
    the Django admin and the authorization UI can be localized. Migration
    oauth2_provider.0021_translatable_field_labels records the label changes; it makes no
    database schema changes.
Deprecated
  • #​1773 JSONOAuthLibCore (OAUTH2_PROVIDER["OAUTH2_BACKEND_CLASS"] set to
    oauth2_provider.oauth2_backends.JSONOAuthLibCore) is deprecated and now emits a
    DeprecationWarning. It makes the OAuth token, introspection, and
    revocation endpoints read application/json bodies, but those endpoints are defined to
    use application/x-www-form-urlencoded (RFC 6749, RFC 7662, RFC 7009); the JSON mode is
    non-standard and breaks interoperability with spec-compliant clients. It is scheduled for
    removal in 4.0.
Changed
  • #​1343 Application.clean() now reports its validation errors per field instead of as
    non-field errors, and reports all of them at once instead of stopping at the first
    problem. The application forms (the built-in registration/edit views and the Django
    admin) render each message next to the offending input — a rejected redirect URI on
    redirect_uris, a non-https CORS origin on allowed_origins, an unusable algorithm on
    algorithm, and the HS256 client-secret conflicts on client_secret /
    hash_client_secret. ValidationError.message_dict is keyed by those field names, so
    callers of Application.full_clean() (including dynamic client registration and CIMD)
    now surface the field name alongside the message. A custom ModelForm that omits one of
    those fields still gets the message as a non-field error, provided it subclasses
    oauth2_provider.forms.ApplicationForm.
  • #​730 The templates shipped with the toolkit no longer load Bootstrap 2.3.2 from a
    third-party CDN. oauth2_provider/base.html now links a small stylesheet distributed
    with the package (static/oauth2_provider/css/oauth2_provider.css), which also absorbs
    the inline <style> block that template carried. The built-in pages therefore render in
    air-gapped installs and under a strict Content Security Policy such as
    default-src 'self', which blocks a foreign style host and an inline style block alike,
    and the authorization page no longer makes an unpinned (no Subresource Integrity)
    third-party request while the user is making a consent decision. The stylesheet is served
    through staticfiles, so run collectstatic for the pages to be styled. The Bootstrap 2
    class names used by the templates are unchanged, and the css block of base.html is
    still the supported way to substitute your own styles.
  • The AccessToken and RefreshToken admins now invalidate tokens through a "Revoke selected"
    action instead of raw delete (delete is disabled on those two admins). A raw delete of an access
    token left its bound refresh token behind (RefreshToken.access_token is SET_NULL) — an orphan
    that could still mint new access tokens — and a raw delete of a refresh token discarded the
    revoked tombstone that REFRESH_TOKEN_REUSE_PROTECTION relies on. The revoke action invalidates
    the whole token family consistently; expired rows are still pruned by cleartokens. Grant and
    IDToken admins keep the default delete. The access-token revoke logic is now a single shared
    oauth2_provider.models.revoke_access_token() helper used by the admin action, the /revoke/
    endpoint, and AuthorizedTokenDeleteView.
  • #​522 The cleartokens management command now prints a warning to stderr when
    REFRESH_TOKEN_EXPIRE_SECONDS is unset (or 0), explaining that only revoked and
    orphaned refresh tokens are removed and that expired access/ID tokens still bound to a
    refresh token are retained until that refresh token is gone. The management-command docs
    were clarified to match.
  • #​746 Revoking an access token (via the RFC 7009 /revoke/ endpoint) now also revokes
    the refresh token bound to it, matching the admin "delete access token" view and
    RFC 7009 §2.1. Previously the refresh token survived and could immediately mint a new
    access token, defeating the revocation and leaving the refresh token an active "orphan"
    (its access_token foreign key is SET_NULL). Whether a refresh token may survive
    access-token revocation will become a configurable policy in 4.0.
  • #​1715 Security guidance in the settings reference: recommend a finite
    REFRESH_TOKEN_EXPIRE_SECONDS as defense-in-depth (rotation remains the primary
    mitigation), and document why OIDC_RP_INITIATED_LOGOUT_ACCEPT_EXPIRED_TOKENS defaults
    to True (the id_token_hint is a previously issued token per OIDC RP-Initiated Logout)
    and how to harden it.
Fixed
  • The system check that verifies the AccessToken, IDToken, and RefreshToken models are
    routed to a single database is now registered under the models tag instead of database.
    Django 6.1 stopped running database-tagged checks unless a database alias is passed
    explicitly (manage.py check --database default), because such checks may do more than
    static analysis; this one only asks the configured routers where the token models would be
    written and never opens a connection, so under the old tag a plain manage.py check would
    have silently stopped reporting a cross-database token configuration on Django 6.1.
  • #​1809 REFRESH_TOKEN_REUSE_PROTECTION now revokes a compromised token family as a set
    instead of one row at a time. A rotating client keeps every refresh token it has ever been
    issued in the same family, so the old per-row loop cost one SELECT ... FOR UPDATE round
    trip per token in the family, paid again on every replay of the stale token: a client stuck
    on a retry timer could hold a worker and a database connection for tens of seconds per
    request. The sweep now runs in a fixed number of queries whatever the size of the family,
    through the new AbstractRefreshToken.revoke_family(), and token_family is indexed
    (migration 0022_refreshtoken_token_family_index) so it no longer scans the whole refresh
    token table. What gets revoked is unchanged: every live member of the family, and the
    family's access tokens. If you swap in your own refresh token model, run makemigrations to
    pick up the index, and if you override revoke() override revoke_family() to match.
  • #​1796 Redirect URIs using an RFC 8252 §7.1 private-use URI scheme can now be registered.
    Such a scheme has no naming authority, so only a single slash follows it
    (com.example.app:/oauth2redirect), but Application.clean() reassembled every URI with
    :// before validating and rejected the result with "Enter a valid URL." — leaving native
    apps no way to register the form the RFC prescribes and their clients actually send. The
    double-slash variant was not a workaround: the two spellings parse to different hostnames
    and produce redirect_uri_mismatch against each other. Schemes that require an authority
    (http, https, ws, wss, ftp) must still include a host, and the redundant
    com.example.app:///oauth2redirect and rootless com.example.app:oauth2redirect spellings
    are rejected so that each callback has one canonical registration (RFC 9700 §2.1).
    Upgrade note: the rootless spelling was previously accepted, but the same reassembly
    rewrote it to com.example.app://oauth2redirect — registering oauth2redirect as a
    hostname, which no client matches. It is now rejected at registration instead of

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 1, 2026

Copy link
Copy Markdown

Deploying bats-ai with  Cloudflare Pages  Cloudflare Pages

Latest commit: 1764d48
Status: ✅  Deploy successful!
Preview URL: https://b0e5984d.bats-ai.pages.dev
Branch Preview URL: https://renovate-all-minor-patch.bats-ai.pages.dev

View logs

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from f206a39 to ec884c8 Compare August 7, 2026 17:56
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 2d8a506 to 5cc482d Compare August 15, 2026 05:03
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 5 times, most recently from 844d33c to 29b37cf Compare August 21, 2026 06:10
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 7491fe3 to 4fc2c4a Compare August 27, 2026 16:32
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 4fc2c4a to 1764d48 Compare August 29, 2026 09:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants