NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #681 by repository stars
Last release 10 months ago
20 Nov 2025
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
1103 releases · first in 2015
Nothing published for this version
Nothing published for this version
autogen(docs): regenerate and update changelog
autogen(docs): regenerate and update changelog
Type fosite.TokenType has been renamed to fosite.TokenUse.
Redirct_url with query escape character outside of query is failing (#480) (6e49c57):
See https://github.com/ory/hydra/issues/2055
Co-authored-by: ajanthan <ca52ca6fe18c44787827017e14ca2d0c3c5bdb58>
Rename TokenType to TokenUse in introspection (#486) (4b81316), closes ory/hydra#1762
Return allowed redirect url with preference (f0badc4)
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: make redirect URL checking more strict
fix: make redirect URL checking more strict
The OAuth 2.0 Client's Redirect URL and the Redirect URL used in the OAuth 2.0 flow do not check if the query string is equal:
https://example.com/callbackhttps://example.com/callback?bar=foohttps://example.com/callback?bar=foo with a potentially successful OAuth2 response.Additionally, matching Redirect URLs used strings.ToLower normalization:
https://example.com/callbackhttps://example.com/CALLBACKhttps://example.com/CALLBACK with a potentially successful OAuth2 response.This patch addresses all of these issues and adds regression tests to keep the implementation secure in future releases.
Make redirect URL checking more strict (cdee51e):
The OAuth 2.0 Client's Redirect URL and the Redirect URL used in the OAuth 2.0 flow do not check if the query string is equal:
https://example.com/callbackhttps://example.com/callback?bar=foohttps://example.com/callback?bar=foo with a potentially successful OAuth2 response.Additionally, matching Redirect URLs used strings.ToLower normalization:
https://example.com/callbackhttps://example.com/CALLBACKhttps://example.com/CALLBACK with a potentially successful OAuth2 response.This patch addresses all of these issues and adds regression tests to keep the implementation secure in future releases.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
chore: fix unused const linter error
chore: fix unused const linter error (#484)
fosite.ErrRevocationClientMismatch was removed because it is not part of RFC 6749. Instead, fosite.ErrUnauthorizedClient will be returned when calling RevokeToken with an OAuth2 Client which does not match the Access or Refresh Token to be revoked.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
BREAKING CHANGE: Merges the error description with error hint and error debug, making it easier to consume error messages in standardized OAuth2 clien…
feat: error_hint and error_debug are now exposed through error_description (#460)
BREAKING CHANGE: Merges the error description with error hint and error debug, making it easier to consume error messages in standardized OAuth2 clients.
Merges the error description with error hint and error debug, making it easier to consume error messages in standardized OAuth2 clients.
autogen(docs): regenerate and update changelog
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →