Update vaultwarden/server Docker tag to v1.36.0 #321

Open
renovate-bot wants to merge 1 commit from renovate/vaultwarden-server-1.x into master
Collaborator

This PR contains the following updates:

Package Update Change
vaultwarden/server minor 1.35.41.36.0

Release Notes

dani-garcia/vaultwarden (vaultwarden/server)

v1.36.0

Compare Source

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Notes

What's Changed

New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.8...1.36.0

You can discuss this release here https://github.com/dani-garcia/vaultwarden/discussions/7177

v1.35.8

Compare Source

What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.7...1.35.8

v1.35.7

Compare Source

What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.6...1.35.7

v1.35.6

Compare Source

Notes

The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all.
This has been fixed now in this release.

What's Changed

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.5...1.35.6

v1.35.5

Compare Source

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Notes

  • The admin templates have changed, please update them if you override these via templates.
  • Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.

What's Changed

New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.4...1.35.5


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [vaultwarden/server](https://github.com/dani-garcia/vaultwarden) | minor | `1.35.4` → `1.36.0` | --- ### Release Notes <details> <summary>dani-garcia/vaultwarden (vaultwarden/server)</summary> ### [`v1.36.0`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.35.8...1.36.0) #### Security Fixes This release contains security fixes for the following advisories. We strongly advice to update as soon as possible. - SSO Login CSRF [GHSA-pfp2-jhgq-6hg5](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-pfp2-jhgq-6hg5) [GHSA-w6h6-8r66-hcv7](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-w6h6-8r66-hcv7) - User/Organization Enumeration [GHSA-hxqh-ff5p-wfr3](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-hxqh-ff5p-wfr3) - SSO existing-user binding [GHSA-j4j8-gpvj-7fqr](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-j4j8-gpvj-7fqr) [GHSA-6x5c-84vm-5j56](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6x5c-84vm-5j56) - SSRF via Icon Endpoint [GHSA-72vh-x5jq-m82g](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-72vh-x5jq-m82g) - Some crate's updated and other minor security enhancements These are private for now, pending CVE assignment. #### Notes - Archiving of items is available <https://bitwarden.com/blog/keep-your-vault-tidy-with-item-archiving/> <https://bitwarden.com/nl-nl/help/managing-items/#archive> - Web Vault updated to v2026.4.1 #### What's Changed - SSO fallback to UserInfo preferred\_username by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7128](https://github.com/dani-garcia/vaultwarden/pull/7128) - Dummy identifier need to pass for a guid by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7154](https://github.com/dani-garcia/vaultwarden/pull/7154) - add new /identity/accounts/prelogin/password by [@&#8203;stefan0xC](https://github.com/stefan0xC) in [#&#8203;7156](https://github.com/dani-garcia/vaultwarden/pull/7156) - Add DuckDuckGo browser device type by [@&#8203;dfunkt](https://github.com/dfunkt) in [#&#8203;7147](https://github.com/dani-garcia/vaultwarden/pull/7147) - Apply `duration_suboptimal_units` lint findings by [@&#8203;dfunkt](https://github.com/dfunkt) in [#&#8203;7144](https://github.com/dani-garcia/vaultwarden/pull/7144) - Apply `ref_option` lint findings by [@&#8203;dfunkt](https://github.com/dfunkt) in [#&#8203;7143](https://github.com/dani-garcia/vaultwarden/pull/7143) - Fix hardcoded sso identifier by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7157](https://github.com/dani-garcia/vaultwarden/pull/7157) - Update crates and fix a nightly lint by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7161](https://github.com/dani-garcia/vaultwarden/pull/7161) - Fix Host/IP resolving by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7162](https://github.com/dani-garcia/vaultwarden/pull/7162) - Several SSO Fixes by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7163](https://github.com/dani-garcia/vaultwarden/pull/7163) - Add support for archiving items by [@&#8203;matt-aaron](https://github.com/matt-aaron) in [#&#8203;6916](https://github.com/dani-garcia/vaultwarden/pull/6916) - Fix favicon fetching to check all icon links instead of just the first one by [@&#8203;Shocker](https://github.com/Shocker) in [#&#8203;6880](https://github.com/dani-garcia/vaultwarden/pull/6880) - Fix merge conflict by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7164](https://github.com/dani-garcia/vaultwarden/pull/7164) - Replace organization\_uuid unwrap with proper error handling by [@&#8203;xjohnyknox](https://github.com/xjohnyknox) in [#&#8203;6936](https://github.com/dani-garcia/vaultwarden/pull/6936) - fix: return Err instead of panic on unknown cipher atype in to\_json() by [@&#8203;mango766](https://github.com/mango766) in [#&#8203;7068](https://github.com/dani-garcia/vaultwarden/pull/7068) - Allow SQLite to be linked against dynamically by [@&#8203;ISSOtm](https://github.com/ISSOtm) in [#&#8203;7057](https://github.com/dani-garcia/vaultwarden/pull/7057) - Update crates and web-vault by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7171](https://github.com/dani-garcia/vaultwarden/pull/7171) - Update hickory by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7175](https://github.com/dani-garcia/vaultwarden/pull/7175) #### New Contributors - [@&#8203;matt-aaron](https://github.com/matt-aaron) made their first contribution in [#&#8203;6916](https://github.com/dani-garcia/vaultwarden/pull/6916) - [@&#8203;Shocker](https://github.com/Shocker) made their first contribution in [#&#8203;6880](https://github.com/dani-garcia/vaultwarden/pull/6880) - [@&#8203;xjohnyknox](https://github.com/xjohnyknox) made their first contribution in [#&#8203;6936](https://github.com/dani-garcia/vaultwarden/pull/6936) - [@&#8203;mango766](https://github.com/mango766) made their first contribution in [#&#8203;7068](https://github.com/dani-garcia/vaultwarden/pull/7068) - [@&#8203;ISSOtm](https://github.com/ISSOtm) made their first contribution in [#&#8203;7057](https://github.com/dani-garcia/vaultwarden/pull/7057) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.35.8...1.36.0> You can discuss this release here <https://github.com/dani-garcia/vaultwarden/discussions/7177> ### [`v1.35.8`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.8) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.35.7...1.35.8) #### What's Changed - Dummy org Master password policy auth fix by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7097](https://github.com/dani-garcia/vaultwarden/pull/7097) - Fix recovery-code not working by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7102](https://github.com/dani-garcia/vaultwarden/pull/7102) - Fix invalid refresh token response by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7105](https://github.com/dani-garcia/vaultwarden/pull/7105) - Update Rust, Crates, GHA and fix a DNS issue by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7108](https://github.com/dani-garcia/vaultwarden/pull/7108) - Update web-vault and crates by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7121](https://github.com/dani-garcia/vaultwarden/pull/7121) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.35.7...1.35.8> ### [`v1.35.7`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.7) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.35.6...1.35.7) #### What's Changed - Fix 2FA for Android by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7093](https://github.com/dani-garcia/vaultwarden/pull/7093) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.35.6...1.35.7> ### [`v1.35.6`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.6) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.35.5...1.35.6) #### Notes The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all. This has been fixed now in this release. #### What's Changed - Fix MFA Remember by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7085](https://github.com/dani-garcia/vaultwarden/pull/7085) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.35.5...1.35.6> ### [`v1.35.5`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.5) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.35.4...1.35.5) #### Security Fixes This release contains security fixes for the following advisories. We strongly advice to update as soon as possible. - [GHSA-937x-3j8m-7w7p](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-937x-3j8m-7w7p) Unconfirmed Owner Can Purge Entire Organization Vault. - [GHSA-569v-845w-g82p](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-569v-845w-g82p) Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization - [GHSA-6j4w-g4jh-xjfx](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6j4w-g4jh-xjfx) Refresh tokens not invalidated on security stamp rotation These are private for now, pending CVE assignment. #### Notes - The admin templates have changed, please update them if you override these via templates. - Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading. #### What's Changed - apply policies only to confirmed members by [@&#8203;stefan0xC](https://github.com/stefan0xC) in [#&#8203;6892](https://github.com/dani-garcia/vaultwarden/pull/6892) - Feat(config): add feature flag for Safari account switching by [@&#8203;DerPlayer2001](https://github.com/DerPlayer2001) in [#&#8203;6891](https://github.com/dani-garcia/vaultwarden/pull/6891) - fix: add ForcePasswordReset to api key login by [@&#8203;montdidier](https://github.com/montdidier) in [#&#8203;6904](https://github.com/dani-garcia/vaultwarden/pull/6904) - Add Webauthn related origins flag to known flags. by [@&#8203;pasarenicu](https://github.com/pasarenicu) in [#&#8203;6900](https://github.com/dani-garcia/vaultwarden/pull/6900) - Add 30s cache to SSO exchange\_refresh\_token by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;6866](https://github.com/dani-garcia/vaultwarden/pull/6866) - Add cxp-import-mobile and cxp-export-mobile: feature flags on mobile by [@&#8203;phoeagon](https://github.com/phoeagon) in [#&#8203;6853](https://github.com/dani-garcia/vaultwarden/pull/6853) - Misc updates and fixes by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;6910](https://github.com/dani-garcia/vaultwarden/pull/6910) - Support new desktop origin on CORS by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;6920](https://github.com/dani-garcia/vaultwarden/pull/6920) - Fix `checkout` action version by [@&#8203;dfunkt](https://github.com/dfunkt) in [#&#8203;6921](https://github.com/dani-garcia/vaultwarden/pull/6921) - Fix apikey login by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;6922](https://github.com/dani-garcia/vaultwarden/pull/6922) - Fix email header base64 padding by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;6961](https://github.com/dani-garcia/vaultwarden/pull/6961) - Update Feature Flags by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;6981](https://github.com/dani-garcia/vaultwarden/pull/6981) - Update crates and GHA by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;6980](https://github.com/dani-garcia/vaultwarden/pull/6980) - Use protected CI environment by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7004](https://github.com/dani-garcia/vaultwarden/pull/7004) - Fix 2FA Remember to actually be 30 days by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;6929](https://github.com/dani-garcia/vaultwarden/pull/6929) - Misc Updates by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7027](https://github.com/dani-garcia/vaultwarden/pull/7027) - Switch to `attest` action by [@&#8203;dfunkt](https://github.com/dfunkt) in [#&#8203;7017](https://github.com/dani-garcia/vaultwarden/pull/7017) - Rotate refresh-tokens on sstamp reset by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7031](https://github.com/dani-garcia/vaultwarden/pull/7031) - Misc org fixes by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7032](https://github.com/dani-garcia/vaultwarden/pull/7032) - Fix empty string FolderId by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7048](https://github.com/dani-garcia/vaultwarden/pull/7048) - Disable deployments for release env by [@&#8203;dfunkt](https://github.com/dfunkt) in [#&#8203;7033](https://github.com/dani-garcia/vaultwarden/pull/7033) - Fix Send icons by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7051](https://github.com/dani-garcia/vaultwarden/pull/7051) - prevent managers from creating collections by [@&#8203;stefan0xC](https://github.com/stefan0xC) in [#&#8203;6890](https://github.com/dani-garcia/vaultwarden/pull/6890) - Change SQLite backup to use VACUUM INTO query by [@&#8203;getaaron](https://github.com/getaaron) in [#&#8203;6989](https://github.com/dani-garcia/vaultwarden/pull/6989) - Handle `SIGTERM` and `SIGQUIT` shutdown signals. by [@&#8203;0x484558](https://github.com/0x484558) in [#&#8203;7008](https://github.com/dani-garcia/vaultwarden/pull/7008) - Do not display unavailable 2FA options by [@&#8203;0x484558](https://github.com/0x484558) in [#&#8203;7013](https://github.com/dani-garcia/vaultwarden/pull/7013) - Fix logout push identifiers and send logout before clearing devices by [@&#8203;qaz741wsd856](https://github.com/qaz741wsd856) in [#&#8203;7047](https://github.com/dani-garcia/vaultwarden/pull/7047) - Fix windows build issues by [@&#8203;idontneedonetho](https://github.com/idontneedonetho) in [#&#8203;7065](https://github.com/dani-garcia/vaultwarden/pull/7065) - Crate and GHA updates by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7081](https://github.com/dani-garcia/vaultwarden/pull/7081) #### New Contributors - [@&#8203;DerPlayer2001](https://github.com/DerPlayer2001) made their first contribution in [#&#8203;6891](https://github.com/dani-garcia/vaultwarden/pull/6891) - [@&#8203;montdidier](https://github.com/montdidier) made their first contribution in [#&#8203;6904](https://github.com/dani-garcia/vaultwarden/pull/6904) - [@&#8203;pasarenicu](https://github.com/pasarenicu) made their first contribution in [#&#8203;6900](https://github.com/dani-garcia/vaultwarden/pull/6900) - [@&#8203;phoeagon](https://github.com/phoeagon) made their first contribution in [#&#8203;6853](https://github.com/dani-garcia/vaultwarden/pull/6853) - [@&#8203;getaaron](https://github.com/getaaron) made their first contribution in [#&#8203;6989](https://github.com/dani-garcia/vaultwarden/pull/6989) - [@&#8203;0x484558](https://github.com/0x484558) made their first contribution in [#&#8203;7008](https://github.com/dani-garcia/vaultwarden/pull/7008) - [@&#8203;qaz741wsd856](https://github.com/qaz741wsd856) made their first contribution in [#&#8203;7047](https://github.com/dani-garcia/vaultwarden/pull/7047) - [@&#8203;idontneedonetho](https://github.com/idontneedonetho) made their first contribution in [#&#8203;7065](https://github.com/dani-garcia/vaultwarden/pull/7065) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.35.4...1.35.5> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDQuMiIsInVwZGF0ZWRJblZlciI6IjQzLjEwNC4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
renovate-bot force-pushed renovate/vaultwarden-server-1.x from 7c3f2023de to add88ee2d4 2026-05-04 00:04:08 +00:00 Compare
renovate-bot changed title from Update vaultwarden/server Docker tag to v1.35.8 to Update vaultwarden/server Docker tag to v1.36.0 2026-05-04 00:04:08 +00:00
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/vaultwarden-server-1.x:renovate/vaultwarden-server-1.x
git switch renovate/vaultwarden-server-1.x

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch master
git merge --no-ff renovate/vaultwarden-server-1.x
git switch renovate/vaultwarden-server-1.x
git rebase master
git switch master
git merge --ff-only renovate/vaultwarden-server-1.x
git switch renovate/vaultwarden-server-1.x
git rebase master
git switch master
git merge --no-ff renovate/vaultwarden-server-1.x
git switch master
git merge --squash renovate/vaultwarden-server-1.x
git switch master
git merge --ff-only renovate/vaultwarden-server-1.x
git switch master
git merge renovate/vaultwarden-server-1.x
git push origin master
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
peter/homelab-docker-config!321
No description provided.