Skip to content

fix: bump lua-resty-saml to 0.2.6 - #13799

Open
shreemaan-abhishek wants to merge 1 commit into
apache:masterfrom
shreemaan-abhishek:fix/bump-lua-resty-saml
Open

fix: bump lua-resty-saml to 0.2.6#13799
shreemaan-abhishek wants to merge 1 commit into
apache:masterfrom
shreemaan-abhishek:fix/bump-lua-resty-saml

Conversation

@shreemaan-abhishek

@shreemaan-abhishek shreemaan-abhishek commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Description

Bumps the pinned lua-resty-saml dependency from 0.2.5 to 0.2.6.

0.2.6 hardens response handling so identity is only read from a
response that carries exactly one assertion, keeping the extracted
identity aligned with the verified signature. The behaviour change and
its regression test live in lua-resty-saml (api7/lua-resty-saml#32);
this PR only moves the pin.

Which issue(s) this PR fixes:

Fixes #

Checklist

  • I have explained the need for this PR and the problem it solves
  • I have explained the changes or the new features added to this PR
  • I have added tests corresponding to this change (the regression test ships in the dependency, fix: require exactly one assertion in a verified SAML response api7/lua-resty-saml#32)
  • I have updated the documentation to reflect this change (dependency version bump; no docs affected)
  • I have verified that this change is backward compatible

@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. dependencies Pull requests that update a dependency file labels Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant