NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #245 by repository stars
Last release 2 months ago
29 Jul 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
2821 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
autogen: pin v0.8.3-alpha.1.pre.0 release commit
autogen: pin v0.8.3-alpha.1.pre.0 release commit
This patch removes the ability to use domain aliases, an obscure feature rarely used that had several issues and inconsistencies.
Add identity_id index to identity_verifiable_addresses table
(#2147)
(86fd942):
The verifiable addresses are loaded eagerly into the identity. When that
happens, the identity_verifiable_addresses table is queried by nid and
identity_id. This index should greatly improve performance, especially of
the /sessions/whoami endpoint.
Add ability to resume continuity sessions from several cookies (#2131) (8b87bdb), closes #2016 #1786
Admin endpoint /schemas not redirecting to public endpoint
(#2133)
(413833f),
closes #2084
Choose correct CSRF cookie when multiple are set (633076b), closes ory/kratos#2121 ory-corp/cloud#1786:
Resolves an issue where, when multiple CSRF cookies are set, a random one would be used to verify the CSRF token. Now, regardless of how many conflicting CSRF cookies exist, if one of them is valid, the request will pass and clean up the cookie store.
continuity: Properly reset cookies that became invalid (8e4b4fb), closes #2121 ory-corp/cloud#1786:
Resolves several reports related to incorrect handling of invalid continuity issues.
continuity: Remove cookie on any error (428ac03)
Do not send session after registration without hook (#2094) (3044229), closes #2093
Docker-compose standalone definition (3c7065a)
Explain mitigations in cookie error messages (ef4b01a)
Expose network wrapper (a570607)
This patch
See also https://github.com/ory/docusaurus-template/pull/87
Ignore whitespace around identifier with password strategy (#2160) (45335c5), closes #2158
Improve courier test signature (b8888e3)
Include missing type string in config schema (#2142) (ec2c88a):
Inside the config.schema.json under the CORS setting, add the missing type (string) for the items of the allowed_origins array
login: Error handling when failed to prepare for an expired flow (#2120) (fdad834)
Resolve configx regression (672c0ff)
selfservice: Recovery self service flow passes on return_to URL (#1920) (b925d35), closes #914
Send 404 instead of null response for unknown verification flows (#2102) (c9490c8), closes #2099:
Fixes the verification handler to write the error, instead of nil object, when the flow does not exist. Adds tests for every handler to check proper behavior in that regard.
Support setting complex configs from the environment (c45bf83):
Closes https://github.com/ory/kratos/issues/1535 Closes https://github.com/ory/kratos/issues/1792 Closes https://github.com/ory/kratos/issues/1801
Update download urls according to the new names (#2078) (86ae016)
Fix link (c245ed4):
Closes https://github.com/ory/kratos-selfservice-ui-node/issues/164
Upgrade guide (#2132) (4a4ab05):
Closes https://github.com/ory/kratos/discussions/2104
Add preset CSP nonce (#2096) (8913292):
Closes https://github.com/ory/kratos-selfservice-ui-node/issues/162
Added phone number identifier (#1938) (294dfa8), closes #137
Allow registration to be disabled (#2081) (864b00d), closes #882
courier: Override default link base URL (cc99096):
Added a new configuration value selfservice.methods.link.config.base_url
which allows to change the default base URL of recovery and verification
links. This is useful when the email should send a link which does not match
the globally configured base URL.
See https://github.com/ory-corp/cloud/issues/1766
docker: Add jaeger (27ec2b7)
Enable Buildkit (#2079) (f40df5c):
Looks like this was attempted before but the magic comment was not on the first line.
Make the password policy more configurable (#2118) (70c627b), closes #970
security: Add option to disallow private IP ranges in webhooks (05f1e5a), closes #2152
Selfservice and administrative session management (#2011) (0fe4155), closes #655 #2007
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →