Update Routine updates - #376
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
commit: |
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 13, 2026 09:38
63dc237 to
87fb859
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 14, 2026 18:34
87fb859 to
8e9ad8a
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 14, 2026 20:25
8e9ad8a to
4d7b750
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 15, 2026 01:29
4d7b750 to
1787003
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 15, 2026 17:14
1787003 to
931f226
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 16, 2026 12:42
931f226 to
267cd41
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 16, 2026 17:23
267cd41 to
e56c97b
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 16, 2026 21:10
e56c97b to
0351eb0
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 17, 2026 09:36
0351eb0 to
1c30557
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 18, 2026 01:28
1c30557 to
fe7ffe2
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 18, 2026 11:11
fe7ffe2 to
8545fd6
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 18, 2026 20:39
8545fd6 to
541d1b4
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 19, 2026 01:42
541d1b4 to
470bc50
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 22, 2026 09:53
f63f20d to
2d561dd
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 22, 2026 15:47
2d561dd to
8ebc2c3
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 22, 2026 17:57
8ebc2c3 to
c85954d
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 22, 2026 23:08
c85954d to
1540bb6
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 22, 2026 23:23
1540bb6 to
bc74f48
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 23, 2026 09:56
bc74f48 to
6fea059
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 23, 2026 12:24
6fea059 to
6c27629
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 23, 2026 21:41
6c27629 to
8a95d30
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 24, 2026 00:48
8a95d30 to
7ac7b81
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 24, 2026 08:41
7ac7b81 to
2f2291a
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 24, 2026 20:35
2f2291a to
9da4dbe
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 25, 2026 01:58
9da4dbe to
21066f2
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 26, 2026 15:43
21066f2 to
e4a7540
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
May 27, 2026 01:41
e4a7540 to
940f01b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.6.15→1.6.251.6.15→1.6.251.1.21→1.3.13.3.5→3.3.69.39.4→9.39.51.60.0→1.62.01.62.14.3.0→4.3.31.167.65→1.168.321.168.34(+1)2.0.13→2.0.1424.12.3→24.13.319.2.14→19.2.1719.2.1848b55a0→2499707^0.5.16→^0.6.01.6.15→1.6.2510.0.3→10.0.41.41.0→1.42.31.43.00.1.116→0.1.1200.0.51→0.0.549.39.4→9.39.510.3.0→10.8.016.2.6→16.2.120.5.2→0.5.316.8.8→16.13.016.14.016.8.8→16.13.016.14.017.6.0→17.8.06.2.3→6.2.46.2.6(+1)16.2.6→16.2.1216.2.6→16.2.120.0.71→0.0.820.0.86(+2)8.5.14→8.5.248.5.253.8.3→3.9.6v2.1.2→v2.2.019.2.6→19.2.819.2.6→19.2.819.2.6→19.2.819.2.6→19.2.82.34.0→2.39.07.8.0→7.8.54.3.0→4.3.35.6.0→5.8.08.59.2→8.65.04.1.5→4.1.10v0.5.6→v0.6.0v0.6.1Release Notes
better-auth/better-auth (@better-auth/core)
v1.6.25Compare Source
Patch Changes
0ffd1fbThanks @jsj! - Send Apple OAuth PKCE code challenges during authorization so callback token exchanges include a matching code verifier.v1.6.24Compare Source
Patch Changes
#9862
54fab08Thanks @OrangeManLi! - Fix a request-stateAsyncLocalStorageinitialization race that could intermittently throwNo request state found. Please make sure you are calling this function within a runWithRequestState callback.ensureAsyncStorage()now memoizes its in-flight initialization so concurrent first-callers share a singleAsyncLocalStorageinstance instead of each constructing one and the last write winning. This surfaced on serverless cold start (e.g. Cloudflare Workers) where the first requests arrive before the lazynode:async_hooksimport settles, causingrunWithRequestState().run()and a nestedgetCurrentRequestState()to land on different instances.#10376
c4d1ddaThanks @ping-maxwell! - Pass the request endpoint context as a third argument toverifyIdToken, so custom ID token verifiers can read request headers (for example Apple'suser-agentrequirement).v1.6.23Compare Source
v1.6.22Compare Source
Patch Changes
#10241
8bd43d9Thanks @gustavovalverde! - Refuse HTTP redirects on server-side OAuth requestsBetter Auth refuses HTTP redirects on the server-side OAuth requests it makes: the token exchange, token refresh, client-credentials, token introspection, and JWKS requests. A provider endpoint cannot redirect one of these requests to an unintended internal address. Conformant OAuth providers answer these endpoints with a direct response and never redirect, so standard integrations are unaffected.
v1.6.21Compare Source
Patch Changes
#10180
90d509eThanks @ping-maxwell! -adapter.updatenow returnsnullwhen no row matches or when it is called without a predicate. UseupdateManyfor intentional bulk updates.The Kysely MySQL adapter no longer returns a row after a guarded update misses. Updates with an
idguard also return the targeted row whenidis not the first predicate. Keep MySQL rows-matched semantics enabled, which mysql2 does by default throughFOUND_ROWS; disabling it can make idempotent updates look like misses.The Prisma adapter now returns
nullwhen an update guard excludes the targeted row instead of surfacing Prisma's not-found exception. The shared adapter test suite now asserts the same fail-closed update behavior for adapter implementations.#10197
816d7f9Thanks @Paola3stefania! - Google sign-in now acceptshd: "*"to allow any Google Workspace hosted domain while still rejecting tokens with no hosted-domain claim.Google One Tap now applies the configured Google hosted-domain restriction before creating a session.
#10198
570267cThanks @rachit367! - HonordisableMigrationon plugin schema tables. Tables flagged withdisableMigration: trueare now skipped bybetter-auth generate(Drizzle and Prisma output) and by the runtime migrator, instead of being emitted and created anyway. The flag was previously dropped while assembling the table list, so it had no effect.#10203
5953157Thanks @bytaesu! - Rate limiting no longer trusts multi-hopX-Forwarded-Forchains, preventing a client behind an appending proxy from spoofing the leftmost hop to bypass the per-IP rate limit. Single-value IP headers continue to work. To key the real client behind a proxy chain, setadvanced.ipAddress.trustedProxiesto your reverse-proxy IPs or CIDR ranges (the chain is walked right to left, skipping trusted hops), or pointadvanced.ipAddress.ipAddressHeadersat a single trusted client-IP header.v1.6.20Compare Source
v1.6.19Compare Source
Patch Changes
#10086
5bd5e1cThanks @gustavovalverde! - Refresh-token rotation and token revocation, two-factor backup-code regeneration, device-code claiming, and organization invitation acceptance now work on Prisma. Concurrent or repeat requests in these flows could previously return an error on Prisma instead of the expected result.On MongoDB servers older than 5.0, these flows and other guarded value updates (rate-limit window resets, API-key refills) no longer fail with an empty-update error.
@better-auth/core:incrementOnenow reports a clear error when called with noincrementand noset.#10070
a787e0bThanks @gustavovalverde! - Single-use verification flows no longer hang on database adapters that use a one-connection pool. This fixes magic-link verification and similar token checks in connection-limited serverless database setups.v1.6.18Compare Source
Patch Changes
b21a5f7Thanks @GautamBytes! - Fix plugin-provided client methods and additional session fields not being inferred in composite monorepos.v1.6.17Compare Source
Patch Changes
#9993
baeaa00Thanks @gustavovalverde! - Add the optionalincrementOneadapter method and the optionalSecondaryStorage.incrementmethod.incrementOneatomically applies signed numeric deltas to a single row under a where-clause guard (for example, decrementing a remaining-uses counter only while it is still positive) and returns the updated row, or null when the guard matched no row. Adapters that do not implement it natively keep working through a transaction-based fallback.SecondaryStorage.incrementatomically increments a counter and sets its time-to-live only when the key is first created.#9987
7343284Thanks @bytaesu! - Fixed a memory leak where the JWKS cache could grow on every access token verification.#10003
fdef997Thanks @gustavovalverde! - Microsoft Entra ID sign-in now honors the configured tenant restriction.tenantId: "organizations"rejects personal Microsoft accounts, andtenantId: "consumers"rejects work and school accounts. Both were accepted before.#9993
baeaa00Thanks @gustavovalverde! - Concurrent requests can no longer slip past the configured rate limit. The in-memory rate-limit store no longer grows without bound, and the database backend removes expired entries on its own. A custom rate-limit storage may implement a new optionalconsumemethod for strict enforcement; without it, the previous behavior is kept and a one-time warning is logged.#10003
fdef997Thanks @gustavovalverde! - A Reddit user with no email now receives a non-routable placeholder address (<id>@​reddit.invalid) instead of one on the realreddit.comdomain, so it cannot match a deliverable mailbox. The address stays unverified, andmapProfileToUsercan supply a real email.#9993
baeaa00Thanks @gustavovalverde! - AddinternalAdapter.reserveVerificationValue. It atomically records a single-use marker (such as a replay tombstone) so that exactly one of several concurrent callers succeeds and the rest observe that the marker is already taken. Database-backed verification storage is atomic; secondary-storage-only verification is best-effort.#9990
1dbf5bbThanks @gustavovalverde! - Hardens how requests are trusted across several flows. Rate limiting is now enforced even when a client IP cannot be determined, instead of being skipped. WhenbaseURLis not configured, password-reset and verification links use the current request's host rather than the host of the first request the server handled, and a request-scopedtrustedOriginscallback no longer affects other concurrent requests. The OAuth proxy, Google One Tap, and the Expo authorization proxy reject redirect and callback targets that are not intrustedOrigins. Google reCAPTCHA and Cloudflare Turnstile accept optionalexpectedActionandallowedHostnamesto reject tokens minted for a different action or hostname. Server-side fetches reject additional reserved IPv6 ranges, and malformed redirect parameters return a 400 instead of a 500.#10003
fdef997Thanks @gustavovalverde! - WeChat sign-in now succeeds with the documented default setup, which previously failed because WeChat returns no email address. The created user receives a stable, unverified placeholder email; supply a real one withmapProfileToUser.v1.6.16Compare Source
Patch Changes
#9974
cb1cbfaThanks @Bekacru! - Validate Facebook opaque access tokens against the configured app. PreviouslyverifyIdTokenreturnedtruefor any non-JWT token andgetUserInfocalled Graph/mewith the caller-supplied token without checking which app issued it, so tokens issued for other Facebook apps were not distinguished on the direct sign-in path. Facebook tokens are now inspected via thedebug_tokenendpoint, requiringis_valid, anapp_idthat matches one of the configured client ids, and auser_idthat matches the returned profile, before the token is accepted. A client secret must be configured for access-token sign-in to work.#9974
cb1cbfaThanks @Bekacru! - Enforce the Googlehd(hosted domain) option against the id token. Previouslyhdwas only sent to Google as an authorization hint, which does not by itself restrict sign-in to the configured Workspace domain. Whenhdis set, thehdclaim on the verified id token (verifyIdToken) and the decoded callback profile (getUserInfo) must be present and match, otherwise sign-in is rejected.#9974
cb1cbfaThanks @Bekacru! - Scope the JWKS cache per source. Access-token verification previously kept a single global key set and reused it whenever it contained a key matching the token'skid, without considering which JWKS source the verification was for. When verifying tokens against more than one source, a token could end up matched against keys fetched for a different source if the two shared akid. The cache is now keyed per JWKS source and honors a TTL, so each verification uses the keys for its own source and rotated or removed keys are no longer used after the TTL elapses.#9974
cb1cbfaThanks @Bekacru! - Cryptographically verify PayPal ID tokens on direct sign-in. PreviouslyverifyIdTokenonly decoded the JWT and checked that asubclaim was present, performing no signature, issuer, audience, or expiration checks, so any well-formed token paired with a valid access token would be accepted. The token is now verified against PayPal's issuer and published JWKS (RS256) or the client secret (HS256), with theaudpinned to the configuredclientId, amaxTokenAgebound, and thenoncechecked when supplied.#9974
cb1cbfaThanks @Bekacru! - Stop mapping the Redditoauth_client_idto the user's email. Reddit'sidentityscope does not return an email address, and the provider previously storedoauth_client_id(which identifies the OAuth application and is the same for every user of the app) asuser.emailwithhas_verified_emailasemailVerified. This collapsed all Reddit users of the same app onto a single "verified" email, which could enable implicit account linking/takeover. The Reddit provider now uses the email returned frommapProfileToUserwhen provided, otherwise falls back to a unique per-user synthetic address (<reddit-user-id>@​reddit.com), and no longer marks it as verified. Provide a real email viamapProfileToUserif you need the actual address.#9974
cb1cbfaThanks @Bekacru! - FixverifyAccessTokensilently dropping the configured audience check during remote introspection. Previously, when a requiredaudiencewas set inverifyOptionsbut the introspection response omitted theaudclaim, audience validation was skipped and any active token from the issuer was accepted — so a token issued for a different resource or client on the same issuer could also pass verification. Verification now requires the claim: a missing or mismatchingaudis rejected. Authorization servers that legitimately omitaudfrom introspection responses (it is OPTIONAL per RFC 7662) can opt back into the old behavior with the newremoteVerify.allowMissingAudience: trueflag, which still rejects mismatching audiences.better-auth/better-auth (@better-auth/test-utils)
v1.6.25Compare Source
Patch Changes
5124c34,0ffd1fb,7439359]:v1.6.24Compare Source
Patch Changes
03dc5a0,7508940,bae7198,ef4d273,6758231,99dbdd7,086ca91,8f2dedd,4e685ee,3bf0e49,f59a0ee,54fab08,0f2cc1b,ae78109,46d2bf0,29a373e,f6d18fa,f23ce50,c4d1dda]:v1.6.23Compare Source
Patch Changes
8581f97]:v1.6.22Compare Source
Patch Changes
c06a56d,8bd43d9,3a035e9]:v1.6.21Compare Source
Patch Changes
#10180
90d509eThanks @ping-maxwell! -adapter.updatenow returnsnullwhen no row matches or when it is called without a predicate. UseupdateManyfor intentional bulk updates.The Kysely MySQL adapter no longer returns a row after a guarded update misses. Updates with an
idguard also return the targeted row whenidis not the first predicate. Keep MySQL rows-matched semantics enabled, which mysql2 does by default throughFOUND_ROWS; disabling it can make idempotent updates look like misses.The Prisma adapter now returns
nullwhen an update guard excludes the targeted row instead of surfacing Prisma's not-found exception. The shared adapter test suite now asserts the same fail-closed update behavior for adapter implementations.Updated dependencies [
e0762a1,882cf9e,f52e1ab,90d509e,b5bec19,816d7f9,239bcc8,1bc370a,570267c,461ca6f,88409b0,5953157,b046f9e,ae647b4]:v1.6.20Compare Source
Patch Changes
21448b1,8ecf238,930f534]:v1.6.19Compare Source
Patch Changes
#10081
0895993Thanks @gustavovalverde! - Password reset tokens now work with the Drizzle MySQL adapter after they are consumed during reset.Adapter auth-flow tests now cover password reset and replay rejection, and wrapped adapters exercise their native single-use consume and guarded increment behavior when available.
Updated dependencies [
de4aa52,b4b0266,5bd5e1c,581f827,8407885,c1a8a64,635f190,a787e0b,c2f718f,7d18175]:v1.6.18Compare Source
Patch Changes
9ef7240,b21a5f7]:v1.6.17Compare Source
Patch Changes
baeaa00,3e99e6c,96c78c3,baeaa00,baeaa00,0c3856f,baeaa00,baeaa00,ed7b6c9,e0a768c,7343284,0c3856f,baeaa00,baeaa00,7343284,7343284,0c3856f,fdef997,0c3856f,d9c526b,0c3856f,fdef997,baeaa00,baeaa00,baeaa00,baeaa00,fdef997,7343284,baeaa00,8960f5f,baeaa00,5c289b5,1dbf5bb,baeaa00,baeaa00,59e0ccb,b803c61,fdef997]:v1.6.16Compare Source
Patch Changes
cb1cbfa,cb1cbfa,cb1cbfa,cb1cbfa,cb1cbfa,cb1cbfa,87e7aa5,cb1cbfa,cb1cbfa,cb1cbfa,893cf6c,cb1cbfa,cb1cbfa,5e49c56,cb1cbfa]:better-auth/better-fetch (@better-fetch/fetch)
v1.3.1Compare Source
🐞 Bug Fixes
[View changes on GitHub](https://redirect.github.com/better-auth/better-fetch/compare/v1.3.0...
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
* * * * 1-5)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.