Skip to content

chore(deps): update docker.io/vaultwarden/server docker tag to v1.35.4#75

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/docker.io-vaultwarden-server-1.x
Open

chore(deps): update docker.io/vaultwarden/server docker tag to v1.35.4#75
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/docker.io-vaultwarden-server-1.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 13, 2026

This PR contains the following updates:

Package Update Change
docker.io/vaultwarden/server minor 1.34.31.35.4

Release Notes

dani-garcia/vaultwarden (docker.io/vaultwarden/server)

v1.35.4

Compare Source

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

  • GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
  • GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
  • GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.

These are private for now, pending CVE assignment.

What's Changed

New Contributors

Full Changelog: dani-garcia/vaultwarden@1.35.3...1.35.4

v1.35.3

Compare Source

Security Fixes

This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.

  • GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment)
    This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.
What's Changed

Full Changelog: dani-garcia/vaultwarden@1.35.2...1.35.3

v1.35.2

Compare Source

Notable changes

Fixed an issue with the web-vault which prevent creating an organization.

What's Changed

Full Changelog: dani-garcia/vaultwarden@1.35.1...1.35.2

v1.35.1

Compare Source

Notable changes

  • Fixed issue with applications being logged out after upgrading due to changes to refresh token parsing
  • Updated web vault to 2025.12.1
  • Correctly publish alpine tag, which was missing in 1.35.0

What's Changed

Full Changelog: dani-garcia/vaultwarden@1.35.0...1.35.1

v1.35.0

Compare Source

Notable changes

What's Changed

New Contributors

Full Changelog: dani-garcia/vaultwarden@1.34.3...1.35.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title chore(deps): update docker.io/vaultwarden/server docker tag to v1.35.2 chore(deps): update docker.io/vaultwarden/server docker tag to v1.35.3 Feb 10, 2026
@renovate renovate bot force-pushed the renovate/docker.io-vaultwarden-server-1.x branch 2 times, most recently from 4f7571f to b8f7898 Compare February 12, 2026 12:07
@renovate renovate bot changed the title chore(deps): update docker.io/vaultwarden/server docker tag to v1.35.3 chore(deps): update docker.io/vaultwarden/server docker tag to v1.35.4 Feb 23, 2026
@renovate renovate bot force-pushed the renovate/docker.io-vaultwarden-server-1.x branch from b8f7898 to f132675 Compare February 23, 2026 23:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants