Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 3, 2025

This PR contains the following updates:

Package Update Change
BookStackApp/BookStack patch v25.11.4 -> v25.11.6

Release Notes

BookStackApp/BookStack (BookStackApp/BookStack)

v25.11.6: BookStack v25.11.6

Compare Source

Security Release

BookStack v25.11.6 has been released.

This is a security release to address a vulnerability in our dependencies related to XML
handling, which could allow users to replay SAML authentication requests with specially crafted & manipulated requests.

It's strongly advised to update if you're using SAML authentication for BookStack.

Full List of Changes
  • Updated application PHP dependencies.

v25.11.5: BookStack v25.11.5

Compare Source

Links
Full List of Changes

This release contains the following fixes and changes:

  • Updated OIDC state handling to prevent other requests causing the process to fail, which was occurring in Chromium based browsers. (#​5929)
  • Updated session history handling to prevent redirects to common asset locations. (#​5925)
  • Updated PHP dependency versions.

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added dependencies Upgrade or downgrade of project dependencies. no-stale This issue or PR is exempted from the stable bot. labels Dec 3, 2025
@coderabbitai
Copy link

coderabbitai bot commented Dec 3, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate bot force-pushed the renovate/bookstackapp-bookstack-25.x branch from f1f6de8 to 4534564 Compare December 10, 2025 03:12
@renovate renovate bot changed the title ⬆️ Update BookStackApp/BookStack to v25.11.5 ⬆️ Update BookStackApp/BookStack to v25.11.6 Dec 10, 2025
@frenck frenck merged commit cc8b306 into main Dec 10, 2025
19 checks passed
@frenck frenck deleted the renovate/bookstackapp-bookstack-25.x branch December 10, 2025 06:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Upgrade or downgrade of project dependencies. no-stale This issue or PR is exempted from the stable bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants