Thursday, January 29, 2026

Re: UPDATE security/vaultwarden and www/vaultwarden-web


Am 31.12.2025 um 11:59 schrieb Kirill A. Korinsky <kirill@openbsd.org>:

On Wed, 31 Dec 2025 08:15:34 +0100,
Bjorn Ketelaars <bket@openbsd.org> wrote:

[1  <text/plain; utf-8 (7bit)>]
On Sun 28/12/2025 17:14, Bjorn Ketelaars wrote:
Diff attached for updating security/vaultwarden to 1.35.0. Changelog:
https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.0.

- Ed448 support in the WebAuthn framework has been patched out as it is
 not supported by LibreSSL [0]. Thanks to tb@ for his work.
- Builds with support for S3 file backend. This feature has been
 introduced as part of 1.34.2, and should be stable enough.

Also attached a diff for updating www/vaultwarden-web to 2025.12.0.
Changes:
https://github.com/dani-garcia/bw_web_builds/compare/v2025.7.0...v2025.12.0.

Both have been run tested on amd64.

OK?

vaultwarden-1.35.1 was just released, which fixes an issue with
applications being logged out after upgrading due to changes to refresh
token parsing. Changes:
https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.1.

Also vaultwarden-web was updated to 2025.12.1. Changes:
https://github.com/dani-garcia/bw_web_builds/compare/v2025.7.0...v2025.12.1.

New diffs attached.

(Also) OK?

Still OK kirill@

Tested on the same setup, works, this time without relogin!

P.S. I think it worth to add yourself as co-maintainer for vaultwarden and
vaultwarden-web, you usually take care of it.

Dear Maintainers,

would if be possible to release this update also to -stable? I'm running stable on my setup and also running into problems with newer clients, which are apparently fixed by this release.

Best regards
Stephan

No comments:

Post a Comment