Repository navigation
Release 2026-10-05 - (expected chart version 5.37.0) - #5585
Merged
Merged
Conversation
Master->Develop after release
When an Issuer gets replaced by an IdP update, it is kept in the oldIssuers list for this IdP. But, it doesn't reference an active IdP anymore. Thus, looking up IdPs by this Issuer is deemed to fail. Previously, deleting IdPs with such updated Issuers failed (erroneously). This commit fixes this behaviour by acknowledging the fact, that an old issuer may not point to an active IdP.
`minio/minio` was removed from docker hub. But, it is still available via the official quay.io repo. This was spotted when the related SBOMs pipeline failed.
* saml2-web-sso: Delete test verifying that base64-bytestring works the same as coreutils The test is absurd in this package, if base64-bytestring is not spec compliant it should be a bug in the library. The library already has tests against particular strings, so this test is adding nothing. * saml2-web-sso: Remove unused deps
…ss-services (#5236) * fix: WPB-25750 Enable passing cspExtraConnectSrc value to nginx-ingress-services when working with multi-ingresses * fix: WPB-25750 fix typos for account host names in multi-ingress related configs * fix: WPB-25750 enabling integration tests for nginx * fix: WPB-25750 set envoy to be default ingress mode * fix: WPB-25750 enabling integration tests for nginx * ci trigger * ci trigger * ci trigger * wpb-25750: update blacklist url to point to wire-prod
This image is not part of the `wireServer.images*` attribute set, so it need to be defined separately. This fixed the bug of missing SBOMs for nginz in dependency track.
* WPB-28985: add wire meetings type * WPB-28985: freeze legacy update schemas (drop type) Legacy V15-V18 update endpoints used type aliases of the V19 UpdateMeeting, so the V19-only 'type' field leaked into the frozen request schemas and pre-V19 clients could mutate the stored meeting type. Introduce UpdateMeetingLegacy without mtype and map legacy updates onto the shared implementation with mtype = Nothing. * WPB-28985: fix toLegacyV18 Haddock (Meeting -> MeetingV18) * WPB-28985: DRY integration helpers (parameterize version)
* WPB-28987: add meeting join link * Remove meetings.has_code: derive join-code presence at read time Replace the denormalized meetings.has_code boolean (PR #5558) with a read-time lookup in the code store via a new CodeStore.GetMeetingCode effect: - Postgres: point lookup on conversation_codes PK - Cassandra: pure Nothing short-circuit (no round trip; meeting codes never live there) - DualWrite: Postgres-only routing (GetCode reads Cassandra, which cannot hold meeting codes) - test mock mirrors production keying storedMeetingToMeeting / storedMeetingToMeetingWithConversation are now effectful; all callers updated. hasCode removed from StoredMeeting, the store operation, all SQL statements, the migration, and postgres-schema.sql. Behavior is preserved: meetings with a join-code row serve the real link, all others the nil-UUID placeholder. As a side effect the flag-drift failure class (stale flag serving a dead link, e.g. after code TTL expiry) is eliminated; expired codes now degrade to the placeholder. Stacked PRs: rebasing #5559 drops SetMeetingHasCode entirely (refresh becomes delete + recreate); #5560 unaffected. Verified: wire-subsystems test suite 601 examples 0 failures (both link specs pass); whole project type checks via make c. * fix integration test: use getMeetingV with version argument * fix: code are Maybe * fix: copilot comment * Hello CI * Hello CI * Hello CI * Hello CI * Hello CI * Hello CI
* UserStore.Migration: Tolerate invalid assets Co-authored-by: VeryMilkyJoe <jana.chadt+github@posteo.com>
Add sections for team-settings and account-pages. And, describe more settings in the webapp's section.
…S 1.3+PQ options by default (#5480) * See https://wearezeta.atlassian.net/browse/WPB-27369 envoy gateway: FIPS_2022_05 settings, to help with BSI TR-02102-2 TLS conformance This has been deployed to a few internal environments with different settings; the results can be seen under https://wearezeta.atlassian.net/wiki/spaces/PET/pages/3280273465/TLS+versions+ciphers+ingress+nginx+envoy - [x] Add a new entry in an appropriate subdirectory of `changelog.d` - [x] Read and follow the [PR guidelines](https://docs.wire.com/latest/developer/developer/pr-guidelines.html)
During user password verification, we check that passwords are longer than 8 characters, as older accounts might have been created before these checks were introduced.
verify that a personal user who is the last conversation admin gets a 403 adminless-conversation when trying to leave while there are still eligeble members in the conversation
…n between tests (#5576)
fisx
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[2026-10-05] (Chart Release 5.37.0)
Release notes
emailSMS.general.emailSendernow rejects domains whose final label starts with a digit, aligning validation with AWS SES requirements. (WPB-20524activate/sendreturning 5xx error for invalid domain names #5550)API changes
The meetings endpoints (POST /meetings, PUT /meetings/{domain}/{id}, GET /meetings/{domain}/{id}, GET /meetings/list) expose a
typefield ("immediate"or"scheduled") on the meeting object starting at API version V19: required on create, optional on update (omitting it keeps the stored type). Meetings created via V15–V18 endpoints and all pre-existing meetings arescheduled. The V17/V18 endpoint shapes are unchanged. (WPB-28985: add wire meetings type #5556)The meetings endpoints (POST /meetings, PUT /meetings/{domain}/{id}, GET /meetings/{domain}/{id}, GET /meetings/list) expose a
linkfield on the meeting object starting at API version V19: an https join link whose final path segment is the meeting's UUID. The field is present only when the meeting has a live join code; it is omitted otherwise (e.g. meetings created before this change, deployments whose code store cannot hold meeting codes, or multi-ingress deployments with no join-link URI configured for the user's domain). The V15-V18 endpoint shapes are unchanged. (WPB-28987: add meeting join link #5558)Features
Adminless group protection and automatic admin promotion now apply to channels as well as regular group conversations. (WPB-29162 auto promotion of admins should target groups and channels alike #5579)
charts/wire-ingress: Set more secure TLS defaults (minimum TLS 1.3, allow post-quantum key exchange). Add support for a new
FIPS_202205_tls_profilevariable, which overrides TLS settings and can help with (but is alone not sufficient for) BSI's TR-02102-2 conformance. See the wire-ingress README for more details. (Envoy gateway: BSI TR-02102-2 TLS (FIPS2022) mode, and TLS 1.3+PQoptions by default #5480)Bug fixes and other updates
Check whether old passwords are shorter than 8 characters, and warn users, if they are. (WPB-11756 Check length when verifying user passwords #5543)
An IdP could no longer be deleted once its issuer had been updated via the
IdP management API (deletion failed with 404). (Fix: IdP deletion after issuer update #5548)
Return an invalid-email error instead of a 500 response when SES rejects an activation email because of an invalid domain. (WPB-20524
activate/sendreturning 5xx error for invalid domain names #5550)Fix: always send MLS remove proposals when removing users from team conversations.
This reproduces and fixes two related issues:
Enable passing cspExtraConnectSrc value to nginx-ingress-services when working with multi-ingresses (renderCSPInIngress=True). It would be required for webapp to connect to third party sft servers. (fix: WPB-25750 Enable passing cspExtraConnectSrc value to nginx-ingress-services #5236)
Tolerate invalid assets when migrating users to postgresql. These assets are simply ignored. (UserStore.Migration: Tolerate invalid assets #5569)
Documentation
existing documentation of the webapp. Add a section for team-settings,
explaining that it doesn't support multi-ingress (yet). (Document account-pages' multi-ingress configuration #5568)
Internal changes
brig: migrate blacklist (BlockListStore) from Cassandra to PostgreSQL (WPB-22965: migrate blacklist to PostGreSQL #5409)
Add diagnostic logging for rejected MLS commit bundles, including proposal type, target and held clients, group ID, and epoch. (WPB-27269 improvement of galley logs on client mismatch error #5566)
Replace minio with garagehq in ./deploy/dockerephemeral/. ([WPB-29050] replace minio with garagehq for local devs #5567)
Fix broken test setup due to unavailable minio image (Update integration tests: use minio mirror for fake-aws-s3 #5575)(overwritten by [WPB-29050] replace minio with garagehq for local devs #5567)Galley now publishes team events to the FIFO queue using the team ID as the message group, preserving ordering within each team while allowing events from different teams to be processed concurrently. (WPB-29185 [fix] team events SQS message grouping #5580)
Migration of password reset from cassandra to postgres (WPB-22969: migrate password-reset to PostGreSQL #5412)
The
nginzimage was missing fromnix-docker-*SBOMs since it's built as astandalone flake derivation (
#nginz) and not part of#wireServer.images*.The related SBOM script now takes any flake attrpath (attrset or single
derivation) and gets called for both.
Our local development setups (docker-compose environments) rely on
(overwritten by [WPB-29050] replace minio with garagehq for local devs #5567)minio/minioimages. These were removed from Docker Hub. As they are stillavailable from the official quay.io account, we're now sourcing them from
there. (Use minio image from quay.io #5551)