[PR #8984] [CLOSED] chore: version packages #25248

Closed
opened 2026-04-15 22:47:18 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/better-auth/better-auth/pull/8984
Author: @better-release[bot]
Created: 4/6/2026
Status: Closed

Base: mainHead: changeset-release/main


📝 Commits (1)

📊 Changes

46 files changed (+211 additions, -57 deletions)

View changed files

.changeset/deprecate-oidc-provider.md (+0 -7)
.changeset/fix-deps-security-overrides.md (+0 -5)
.changeset/fix-idor-authorization-scim-passkey.md (+0 -5)
.changeset/fix-oauth-provider-par-loopback-dcr.md (+0 -10)
.changeset/pr-8980.md (+0 -5)
.changeset/violet-papayas-see.md (+0 -5)
packages/api-key/CHANGELOG.md (+9 -0)
📝 packages/api-key/package.json (+1 -1)
packages/better-auth/CHANGELOG.md (+24 -0)
📝 packages/better-auth/package.json (+1 -1)
packages/cli/CHANGELOG.md (+10 -0)
📝 packages/cli/package.json (+1 -1)
packages/core/CHANGELOG.md (+3 -0)
📝 packages/core/package.json (+1 -1)
packages/drizzle-adapter/CHANGELOG.md (+8 -0)
📝 packages/drizzle-adapter/package.json (+1 -1)
packages/electron/CHANGELOG.md (+9 -0)
📝 packages/electron/package.json (+1 -1)
packages/expo/CHANGELOG.md (+9 -0)
📝 packages/expo/package.json (+1 -1)

...and 26 more files

📄 Description

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@better-auth/api-key@1.5.7

Patch Changes

better-auth@1.5.7

Patch Changes

  • #8985 dd537cb Thanks @gustavovalverde! - deprecate oidc-provider plugin in favor of @better-auth/oauth-provider

    The oidc-provider plugin now emits a one-time runtime deprecation warning when instantiated and is marked as @deprecated in TypeScript. It will be removed in the next major version. Migrate to @better-auth/oauth-provider.

  • #8843 bd9bd58 Thanks @gustavovalverde! - enforce role-based authorization on SCIM management endpoints and normalize passkey ownership checks via shared authorization middleware

  • #8980 469eee6 Thanks @bytaesu! - fix oauth state double-hashing when verification storeIdentifier is set to hashed

  • #8981 560230f Thanks @bytaesu! - Prevent any from collapsing auth.$Infer and auth.$ERROR_CODES. Preserve client query typing when body is any.

  • Updated dependencies []:

    • @better-auth/core@1.5.7
    • @better-auth/drizzle-adapter@1.5.7
    • @better-auth/kysely-adapter@1.5.7
    • @better-auth/memory-adapter@1.5.7
    • @better-auth/mongo-adapter@1.5.7
    • @better-auth/prisma-adapter@1.5.7
    • @better-auth/telemetry@1.5.7

auth@1.5.7

Patch Changes

@better-auth/drizzle-adapter@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/electron@1.5.7

Patch Changes

@better-auth/expo@1.5.7

Patch Changes

@better-auth/i18n@1.5.7

Patch Changes

@better-auth/kysely-adapter@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/memory-adapter@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/mongo-adapter@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/oauth-provider@1.5.7

Patch Changes

  • #8632 e5091ee Thanks @gustavovalverde! - fix PAR scope loss, loopback redirect matching, and DCR skip_consent

    • PAR (RFC 9126): resolve request_uri into stored params before processing; discard front-channel URL params per §4 to prevent prompt/scope injection
    • Loopback (RFC 8252 §7.3): port-agnostic redirect URI matching for 127.0.0.1 and [::1]; scheme, host, path, and query must still match
    • DCR: accept skip_consent in schema but reject it during dynamic registration to prevent privilege escalation
    • Serialization: fix oAuthState query serialization and preserve non-string values like max_age
  • Updated dependencies [dd537cb, bd9bd58, 469eee6, 560230f]:

    • better-auth@1.5.7
    • @better-auth/core@1.5.7

@better-auth/passkey@1.5.7

Patch Changes

@better-auth/prisma-adapter@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/redis-storage@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/scim@1.5.7

Patch Changes

@better-auth/sso@1.5.7

Patch Changes

  • #8838 ee8b40d Thanks @gustavovalverde! - pin samlify to ~2.10.2 to avoid breaking changes in v2.11.0 and patch transitive node-forge vulnerability (4 HIGH CVEs: signature forgery, cert chain bypass, DoS)

  • Updated dependencies [dd537cb, bd9bd58, 469eee6, 560230f]:

    • better-auth@1.5.7
    • @better-auth/core@1.5.7

@better-auth/stripe@1.5.7

Patch Changes

@better-auth/telemetry@1.5.7

Patch Changes

  • Updated dependencies []:
    • @better-auth/core@1.5.7

@better-auth/test-utils@1.5.7

Patch Changes

@better-auth/core@1.5.7


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/better-auth/better-auth/pull/8984 **Author:** [@better-release[bot]](https://github.com/apps/better-release) **Created:** 4/6/2026 **Status:** ❌ Closed **Base:** `main` ← **Head:** `changeset-release/main` --- ### 📝 Commits (1) - [`8760e70`](https://github.com/better-auth/better-auth/commit/8760e70a2ee907a95d2299fc233b9e69ce76fb5b) chore: version packages ### 📊 Changes **46 files changed** (+211 additions, -57 deletions) <details> <summary>View changed files</summary> ➖ `.changeset/deprecate-oidc-provider.md` (+0 -7) ➖ `.changeset/fix-deps-security-overrides.md` (+0 -5) ➖ `.changeset/fix-idor-authorization-scim-passkey.md` (+0 -5) ➖ `.changeset/fix-oauth-provider-par-loopback-dcr.md` (+0 -10) ➖ `.changeset/pr-8980.md` (+0 -5) ➖ `.changeset/violet-papayas-see.md` (+0 -5) ➕ `packages/api-key/CHANGELOG.md` (+9 -0) 📝 `packages/api-key/package.json` (+1 -1) ➕ `packages/better-auth/CHANGELOG.md` (+24 -0) 📝 `packages/better-auth/package.json` (+1 -1) ➕ `packages/cli/CHANGELOG.md` (+10 -0) 📝 `packages/cli/package.json` (+1 -1) ➕ `packages/core/CHANGELOG.md` (+3 -0) 📝 `packages/core/package.json` (+1 -1) ➕ `packages/drizzle-adapter/CHANGELOG.md` (+8 -0) 📝 `packages/drizzle-adapter/package.json` (+1 -1) ➕ `packages/electron/CHANGELOG.md` (+9 -0) 📝 `packages/electron/package.json` (+1 -1) ➕ `packages/expo/CHANGELOG.md` (+9 -0) 📝 `packages/expo/package.json` (+1 -1) _...and 26 more files_ </details> ### 📄 Description This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @better-auth/api-key@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## better-auth@1.5.7 ### Patch Changes - [#8985](https://github.com/better-auth/better-auth/pull/8985) [`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5) Thanks [@gustavovalverde](https://github.com/gustavovalverde)! - deprecate `oidc-provider` plugin in favor of `@better-auth/oauth-provider` The `oidc-provider` plugin now emits a one-time runtime deprecation warning when instantiated and is marked as `@deprecated` in TypeScript. It will be removed in the next major version. Migrate to `@better-auth/oauth-provider`. - [#8843](https://github.com/better-auth/better-auth/pull/8843) [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5) Thanks [@gustavovalverde](https://github.com/gustavovalverde)! - enforce role-based authorization on SCIM management endpoints and normalize passkey ownership checks via shared authorization middleware - [#8980](https://github.com/better-auth/better-auth/pull/8980) [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc) Thanks [@bytaesu](https://github.com/bytaesu)! - fix oauth state double-hashing when verification storeIdentifier is set to hashed - [#8981](https://github.com/better-auth/better-auth/pull/8981) [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea) Thanks [@bytaesu](https://github.com/bytaesu)! - Prevent `any` from collapsing `auth.$Infer` and `auth.$ERROR_CODES`. Preserve client query typing when body is `any`. - Updated dependencies \[]: - @better-auth/core@1.5.7 - @better-auth/drizzle-adapter@1.5.7 - @better-auth/kysely-adapter@1.5.7 - @better-auth/memory-adapter@1.5.7 - @better-auth/mongo-adapter@1.5.7 - @better-auth/prisma-adapter@1.5.7 - @better-auth/telemetry@1.5.7 ## auth@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 - @better-auth/telemetry@1.5.7 ## @better-auth/drizzle-adapter@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/electron@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/expo@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/i18n@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/kysely-adapter@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/memory-adapter@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/mongo-adapter@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/oauth-provider@1.5.7 ### Patch Changes - [#8632](https://github.com/better-auth/better-auth/pull/8632) [`e5091ee`](https://github.com/better-auth/better-auth/commit/e5091ee1e64fcbe69bdeb4ed86e774e32ca85d7d) Thanks [@gustavovalverde](https://github.com/gustavovalverde)! - fix PAR scope loss, loopback redirect matching, and DCR skip_consent - **PAR (RFC 9126)**: resolve `request_uri` into stored params before processing; discard front-channel URL params per §4 to prevent prompt/scope injection - **Loopback (RFC 8252 §7.3)**: port-agnostic redirect URI matching for `127.0.0.1` and `[::1]`; scheme, host, path, and query must still match - **DCR**: accept `skip_consent` in schema but reject it during dynamic registration to prevent privilege escalation - **Serialization**: fix `oAuthState` query serialization and preserve non-string values like `max_age` - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/passkey@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/prisma-adapter@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/redis-storage@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/scim@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/sso@1.5.7 ### Patch Changes - [#8838](https://github.com/better-auth/better-auth/pull/8838) [`ee8b40d`](https://github.com/better-auth/better-auth/commit/ee8b40d502bb392bd56748ac48aadf0e6c71e929) Thanks [@gustavovalverde](https://github.com/gustavovalverde)! - pin `samlify` to `~2.10.2` to avoid breaking changes in v2.11.0 and patch transitive `node-forge` vulnerability (4 HIGH CVEs: signature forgery, cert chain bypass, DoS) - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/stripe@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/telemetry@1.5.7 ### Patch Changes - Updated dependencies \[]: - @better-auth/core@1.5.7 ## @better-auth/test-utils@1.5.7 ### Patch Changes - Updated dependencies \[[`dd537cb`](https://github.com/better-auth/better-auth/commit/dd537cbdeb618abe9e274129f1670d0c03e89ae5), [`bd9bd58`](https://github.com/better-auth/better-auth/commit/bd9bd58f8768b2512f211c98c227148769d533c5), [`469eee6`](https://github.com/better-auth/better-auth/commit/469eee6d846b32a43f36b418868e6a4c916382dc), [`560230f`](https://github.com/better-auth/better-auth/commit/560230f751dfc5d6efc8f7f3f12e5970c9ba09ea)]: - better-auth@1.5.7 - @better-auth/core@1.5.7 ## @better-auth/core@1.5.7 --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-15 22:47:18 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/better-auth#25248