Pull Request Explorer

Exploring 246 PRs. Want this for your team? Start Free Trial
Title Author Size AI Cycle Time Review Merged
[OID4VCI-FAPI2] Pass fapi2-security-profile-final-refresh-token tdiesler L No 196.6h 0.1h Jun 30, 2026

Summary

Feature

Add support for FAPI2 refresh token conformance

Enables Keycloak to meet FAPI2 security profile by binding refresh tokens to client attestation and adding confirmation metadata, improving token security and compliance.

Health Assessment

Large
Medium
Low
  • The PR had a long cycle time but quick initial review, with AI‑assisted review comments. The change adds significant security features for FAPI2 compliance.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Fix workflow state removeAll() deleting records across all realms sguilhen M No 16.6h 4.4h Jun 30, 2026

Summary

Bug Fix

Fix workflow state removeAll() deleting records

Corrects a bug where removing workflow states deleted records across all realms, ensuring realm isolation and data integrity.

Health Assessment

Medium
Low
Low
  • Quick fix with minimal changes, resolved in under 24 hours, indicating efficient review and low complexity.

AI Details

Tech Stack

Languages: Java
Release notes for ID-JAG mposolda XS No 0.5h 0.1h Jun 30, 2026

Summary

Docs

Release notes for ID-JAG

Adds documentation for experimental support of Identity Assertion JWT Authorization Grant, informing users of the new feature.

Health Assessment

Small
Low
Low
  • Merged within 30 minutes with a single AI review comment, indicating minimal complexity and high confidence.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

initial idjag guide bucchi M No 203.6h 0.1h Jun 30, 2026

Summary

Docs

Add initial ID-JAG guide

Provides a new guide for securing applications using the Identity Assertion JWT Authorization Grant, enabling developers to configure Keycloak for cross‑app access.

Health Assessment

Small
Low
Low
  • PR was reviewed quickly and approved after a single round of comments, indicating a straightforward documentation update with minimal risk.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Restrict java keystore files to a realm folder (#703) rmartinc M No 16.3h 0.1h Jun 30, 2026

Summary

Bug Fix

Restrict Java Keystore Files to Realm Folder

Mitigates CVE-2026-9083 by confining keystore files to a realm-scoped directory, enhancing security and preventing unauthorized access.

Health Assessment

Medium
Low
Low
  • Fast review and merge with minimal changes; the PR addressed a critical security issue with a straightforward implementation.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Migrates SamlClientTest using new Testframework jimmychakkalakal XL No 281.1h 1.7h Jun 30, 2026

Summary

Refactor

Migrate SamlClientTest to new test framework

Replaces legacy Arquillian-based SamlClientTest with the new Keycloak test framework, improving test stability and aligning with current testing infrastructure.

Health Assessment

X-Large
High
Medium
  • The PR required over 11 days to merge, involved AI‑assisted code generation and review, and added more than 1,200 lines of test code, indicating high effort and potential risk.

AI Details

Usage: AI Assisted
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Batch composite-role expansion to avoid an N+1 of getChildRoles on the cache-miss path hakdogan L No 88.6h 0.1h Jun 30, 2026

Summary

Refactor

Optimize composite-role expansion to reduce N+1 queries

Improves CPU and database performance for user role resolution during token issuance and permission checks, enhancing overall system responsiveness.

Health Assessment

Large
Medium
Medium
  • The PR required multiple iterations after the initial review, indicating some friction, but the review was quick and the final merge took almost four days, reflecting a moderate risk for a performance optimization.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Fix broken link to other guide pages for rolling updates ahus1 XS No 93.9h 13.6h Jun 29, 2026

Summary

Docs

Fix broken link to other guide pages for rolling updates

Corrects cross-guide references in the Operator rolling updates guide, ensuring users can navigate documentation accurately.

Health Assessment

Small
Low
Medium
  • Documentation fix completed quickly with minimal changes and a single review round, indicating a smooth process.

AI Details

Usage: AI Assisted
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Bump actions/cache from 5.0.5 to 6.1.0 dependabot XS No 36.1h - Jun 29, 2026

Summary

CI/CD

Bump actions/cache from 5.0.5 to 6.1.0

Updates the GitHub Actions cache action to a newer version, improving cache reliability and performance for CI pipelines.

Health Assessment

Small
Low
Low
  • Quick merge with no review needed, typical dependency bump.

AI Details

Confidence: 1.00

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/corepack-setup dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/corepack-setup

Updates the actions/cache dependency to the latest version, improving cache handling and security for CI workflows.

Health Assessment

Small
Low
Low
  • Fast merge with minimal changes; no review required; typical Dependabot dependency update.

AI Details

Confidence: 0.95

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache/restore from 5.0.5 to 6.1.0 in /.github/actions/maven-cache dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Bump actions/cache/restore from 5.0.5 to 6.1.0

Updates the cache action to the latest version, improving cache reliability and build speed for CI pipelines.

Health Assessment

Small
Low
Low
  • The PR was merged quickly with a single commit and no significant review feedback, indicating a straightforward dependency update.

AI Details

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/maven-cache dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Update actions/cache to v6.1.0

Updates the cache action to the latest version, improving cache reliability and security for CI workflows.

Health Assessment

Small
Low
Low
  • Merged quickly with a single commit and no review comments, indicating a straightforward dependency update with minimal risk.

AI Details

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/node-cache dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Update actions/cache dependency to v6.1.0

Updates the cache action to the latest version, improving cache reliability and security.

Health Assessment

Small
Low
Low
  • Quick dependency bump with immediate merge, minimal review needed.

AI Details

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/pnpm-store-cache dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/pnpm-store-cache

Updates the GitHub Actions cache dependency to the latest version, improving cache reliability and security.

Health Assessment

Small
Low
Low
  • Quick dependency update with immediate merge, minimal review friction.

AI Details

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache from 5.0.5 to 6.1.0 in /.github/actions/prunsrv-setup dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Update actions/cache to v6.1.0

Updates the cache action to the latest version, improving reliability and security.

Health Assessment

Small
Low
Low
  • Quick merge with no rework; minimal impact.

AI Details

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
Bump actions/cache/restore from 5.0.5 to 6.1.0 in /.github/actions/quarkus-snapshot-cache dependabot XS No 36.1h - Jun 29, 2026

Summary

Chore

Bump actions/cache/restore from 5.0.5 to 6.1.0

Updates the cache action to the latest version, improving reliability and security.

Health Assessment

Small
Low
Low
  • Fast merge with minimal changes, no blockers.

AI Details

Tech Stack

Languages: Yaml
Frameworks: Github-Actions
use SHA384 for hashing for session cookies gaoyikeshuer M No 125.4h 2.1h Jun 29, 2026

Summary

Feature

Switch session cookie hashing to SHA-384

Enhances security of session cookies by using a stronger hash algorithm, ensuring consistency between server and browser logic.

Health Assessment

Small
Low
Low
  • The PR was reviewed quickly and required no additional commits, but the overall cycle time was long due to scheduling; the change is a small, low‑risk security improvement.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java, Javascript
Fix workflow state removeAll() deleting records across all realms sguilhen M No 66.3h 0.1h Jun 29, 2026

Summary

Bug Fix

Fix realm isolation bug in workflow cleanup

Prevents accidental deletion of workflow state records when removing a realm, ensuring data integrity across realms.

Health Assessment

Medium
Low
Low
  • Quick review and single commit indicate a straightforward bug fix with minimal risk.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Deprecate the Twitter Identity Broker bkoragan M No 187.9h 0.1h Jun 29, 2026

Summary

Feature

Deprecate the Twitter Identity Broker

Deprecates the built‑in Twitter broker, gating it behind a disabled‑by‑default feature flag to reduce exposure to an unmaintained library and legacy OAuth endpoints.

Health Assessment

Medium
Medium
Medium
  • The PR required multiple review cycles and merges, indicating careful handling of the deprecation, but the overall scope was moderate and the cycle time was within a week.

AI Details

Usage: AI Assisted
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
TokenManager#invokeTokenPostProcessors doesn't respect ProviderFactory#order reda-alaoui XS No 139.6h 0.1h Jun 29, 2026

Summary

Bug Fix

Fix token post-processor ordering

Ensures token post-processors are invoked in correct priority order, improving OIDC token handling reliability.

Health Assessment

Small
Low
Low
  • Fast review and minimal changes led to quick approval, but long cycle time indicates scheduling delays.

AI Details

Usage: AI Assisted
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Increased AES default from 128 to 256 msdaly200 M No 145.0h 0.1h Jun 29, 2026

Summary

Feature

Increased AES default from 128 to 256

Upgrades Keycloak's default AES key size to 256 bits for improved post‑quantum security, adding tests to ensure backward compatibility.

Health Assessment

Medium
Medium
Medium
  • The PR had a long cycle time but a quick initial review, with multiple iterations driven by copilot suggestions and flaky test concerns.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Backport-26.4-Reject redirect URIs containing pre-loaded OIDC response parameters (#49959) jimmychakkalakal M No 259.5h 13.8h Jun 29, 2026

Summary

Bug Fix

Reject redirect URIs with pre-loaded OIDC parameters

This change blocks redirect URIs that contain pre-loaded OIDC response parameters, preventing potential security vulnerabilities by ensuring redirect URIs are not tampered with.

Health Assessment

Medium
Low
Medium
  • The PR was merged after a single review and a moderate cycle time, indicating a straightforward security fix with minimal friction.

AI Details

Confidence: 0.75

Tech Stack

Languages: Java
Improvements for webauthn registration and validation (26.6) rmartinc S No 315.1h 0.1h Jun 29, 2026

Summary

Bug Fix

Improvements for webauthn registration and validation

Enhances WebAuthn registration and validation to improve security and user experience for authentication flows.

Health Assessment

Small
Low
Low
  • Quick review and minimal changes led to a smooth merge, but the long cycle time reflects the backport to a release branch rather than development effort.

AI Details

Tech Stack

Languages: Java
Stop cookie-based SSO re-auth from resetting brute-force counter (26.6) rmartinc M No 305.5h 19.1h Jun 29, 2026

Summary

Bug Fix

Stop cookie-based SSO re-auth from resetting brute-force counter

Prevents malicious actors from bypassing brute-force protection by resetting counters during SSO re-auth, enhancing security for logged-in users.

Health Assessment

Small
Low
Low
  • The PR addressed a critical security issue with minimal changes and received a single approval after a moderate review time, resulting in a slow overall cycle due to the long lead time before review.

AI Details

Tech Stack

Languages: Java
Admin Console sessions page fails with unknown_error when federated u… martin-kanis S No 291.7h 0.0h Jun 29, 2026

Summary

Bug Fix

Fix admin console session error on federated user deletion

Prevents admin console crashes when a federated user is removed while an active session remains, improving stability and user experience.

Health Assessment

Small
Low
Low
  • Quick resolution with minimal changes, indicating a straightforward bug fix.

AI Details

Tech Stack

Languages: Java
[26.6] Upgrade to Infinispan 16.0.12 pruivo S No 268.0h 0.9h Jun 29, 2026

Summary

Chore

Upgrade Infinispan to 16.0.12

Updates the Infinispan cache library to version 16.0.12, ensuring compatibility with the latest features and security patches, and updates configuration examples accordingly.

Health Assessment

Small
Low
Low
  • The PR was reviewed quickly but took a long time to merge, likely due to scheduling or other dependencies.

AI Details

Confidence: 0.95

Tech Stack

Languages: Yaml
Backport-26.6-Reject redirect URIs containing pre-loaded OIDC response parameters (#49959) jimmychakkalakal M No 259.2h 13.6h Jun 29, 2026

Summary

Bug Fix

Reject redirect URIs with pre-loaded OIDC parameters

Prevents malicious redirect URIs that include OIDC response parameters, enhancing security by ensuring redirect URIs are clean and not pre-populated.

Health Assessment

Medium
Medium
Low
  • The PR took over 10 days to merge, but the review was quick and the change was relatively small, indicating a straightforward security fix with minimal friction.

AI Details

Tech Stack

Languages: Java
[26.6] Add warning about the slow migration to 26.6 pruivo S No 171.6h 11.9h Jun 29, 2026

Summary

Docs

Add warning about slow migration to 26.6

Adds a warning to the upgrade documentation to alert users about the slow migration process for version 26.6, helping teams plan and avoid downtime.

Health Assessment

Small
Low
Low
  • Documentation update completed with minimal review, indicating a straightforward change with no significant risk to production.

AI Details

Tech Stack

Reuse the pooled LDAP admin connection instead of re-binding per oper… sguilhen M No 142.2h 3.6h Jun 29, 2026

Summary

Bug Fix

Reuse pooled LDAP admin connection instead of re-binding per operation

Optimizes LDAP admin operations by reusing a single connection, reducing latency and resource usage for authentication services.

Health Assessment

Medium
Low
Low
  • The PR had a moderate cycle time due to extensive LDAP testing, but the review was quick and the changes were straightforward.

AI Details

Tech Stack

Languages: Java
Fix StackOverflowError with FGAP + Organizations on user lookup sguilhen L No 142.2h 3.6h Jun 29, 2026

Summary

Bug Fix

Fix StackOverflowError with FGAP and Organizations

Resolves a StackOverflowError when using FGAP with Organizations on user lookup, improving system stability.

Health Assessment

Small
Low
Low
  • Quick review and merge indicate a straightforward fix for a critical issue.

AI Details

Tech Stack

Languages: Java
Fix admin UI crash when GroupComponent renders without GroupsResource… sguilhen XS No 142.0h 3.4h Jun 29, 2026

Summary

Bug Fix

Fix admin UI crash on missing GroupsResourceContext

This fix prevents the admin UI from crashing when the GroupsResourceContext is missing, ensuring uninterrupted management of user groups.

Health Assessment

Small
Low
Low
  • The PR was reviewed quickly and merged after a single commit, indicating a straightforward bug fix with minimal impact.

AI Details

Tech Stack

Languages: Typescript
Frameworks: React
BACKPORT: fix NPE in migration edewit S No 141.9h 43.5h Jun 29, 2026

Summary

Bug Fix

Backport fix for NPE in migration

Fixes a null pointer exception that could occur during migration to version 26.6.2, improving stability for users upgrading Keycloak.

Health Assessment

Small
Low
High
  • The PR took almost six days to merge, indicating a slow review process, but the change was small and straightforward, suggesting low technical risk.

AI Details

Tech Stack

Languages: Java
RAR scope parsing should explicitly accept client reference (26.6) rmartinc L No 122.0h 0.7h Jun 29, 2026

Summary

Bug Fix

Add explicit client reference to RAR scope parsing

Ensures correct handling of client references in RAR scope parsing, improving security and correctness for 26.6 releases.

Health Assessment

Medium
Medium
Low
  • PR fixed critical dynamic scope bugs; review was quick but long cycle time suggests backlog and moderate risk due to medium scope and extended time to merge.

AI Details

Confidence: 0.75

Tech Stack

Languages: Java
Enforce path containment in FolderTheme.getTemplate() (26.6) rmartinc S No 120.7h 46.3h Jun 29, 2026

Summary

Bug Fix

Enforce path containment in FolderTheme templates

Improves security by ensuring template paths are normalized and confined to allowed directories, preventing path traversal attacks.

Health Assessment

Small
Low
High
  • The PR took 5 days to merge with a single review after 2 days, indicating moderate review friction but minimal code changes.

AI Details

Tech Stack

Languages: Java
Use versioned FreeMarker Configuration defaults (26.6) rmartinc XS No 118.9h 44.5h Jun 29, 2026

Summary

Bug Fix

Initialize FreeMarker with versioned defaults

Updates FreeMarker configuration to use newer defaults, improving security and correctness.

Health Assessment

Small
Low
Medium
  • The PR was a small backport that required a single review after a few days, indicating a straightforward change with minimal risk.

AI Details

Confidence: 0.05

Tech Stack

Languages: Java
[26.6] TimeSelector clears input and switches units when value is 0 in Admin Console mabartos S No 117.1h 0.0h Jun 29, 2026

Summary

Bug Fix

TimeSelector clears input and switches units

Fixes UI behavior in admin console, ensuring zero values reset input and unit selection, improving user experience.

Health Assessment

Small
Low
Low
  • PR had a quick review but a long overall cycle, likely due to scheduling; minimal changes and low risk to production.

AI Details

Confidence: 0.10

Tech Stack

Languages: Typescript
Frameworks: React
[26.6] Client Secret Rotation docs incorrectly mark feature as experimental instead of preview mabartos XS No 74.6h 45.1h Jun 29, 2026

Summary

Docs

Fix client secret rotation docs labeling

The documentation now correctly labels client secret rotation as preview instead of experimental. This reduces confusion for administrators and ensures accurate communication of feature readiness.

Health Assessment

Small
Low
High
  • Documentation update with minimal changes; long review time likely due to scheduling rather than complexity.

AI Details

Tech Stack

Documentation: clarify that running different operator versions on the same cluster is not supported michalvavrik S No 139.6h 0.0h Jun 29, 2026

Summary

Docs

Clarify unsupported operator version mix in cluster

This update warns users that deploying multiple Keycloak Operator versions on a single Kubernetes/OpenShift cluster is unsupported, preventing potential conflicts and ensuring stability.

Health Assessment

Small
Low
Low
  • The PR was reviewed quickly with AI assistance, and the documentation change is minimal, indicating a low-risk, low-effort update.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Admin CLI v2: show connection options in the leaf command help michalvavrik M No 212.3h 0.1h Jun 29, 2026

Summary

Feature

Add connection options to CLI help

Enhances the Admin CLI v2 help output to display global connection options for leaf commands, improving usability for administrators.

Health Assessment

Small
Low
Medium
  • The PR had a long cycle time due to a lengthy review process, but the review was quick and the change was small and straightforward.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Initial documentation for cacheless feature pruivo XL No 67.3h 0.7h Jun 29, 2026

Summary

Docs

Add cacheless feature documentation

Initial documentation for cacheless feature in Keycloak high availability guides

Health Assessment

Medium
Low
Low
  • The PR had a fast review time and low number of comments, indicating a smooth review process

AI Details

Usage: AI Assisted
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Asciidoc
Review of ClientTest jimmychakkalakal M No 65.5h 0.0h Jun 29, 2026

Summary

Refactor

Centralize constants in ClientTest

Improves test maintainability by moving magic strings to constants, simplifying lambda expressions, and removing unused imports, enhancing readability.

Health Assessment

Small
Low
Low
  • Quick review and approval after bot flagged flaky test; minimal changes; low risk refactor.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Review of ImpersonationTest jimmychakkalakal M No 66.0h 0.1h Jun 29, 2026

Summary

Test

Improve ImpersonationTest reliability

Enhances test stability and readability for admin impersonation integration, reducing flaky test failures.

Health Assessment

Medium
Low
Low
  • Fast review and merge with minimal rework, indicating a straightforward test cleanup.

AI Details

Usage: AI Assisted
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Generate queryable fields documentation from code Pepo48 L No 136.0h 0.1h Jun 29, 2026

Summary

Feature

Generate queryable fields documentation from code

Updates the Admin API v2 documentation pipeline to generate queryable fields tables from Java mapper/schema sources, reducing manual effort and ensuring docs stay in sync with code.

Health Assessment

Medium
Low
Low
  • The PR was reviewed quickly by AI and human reviewers, but the overall cycle time was long, indicating a scheduling delay or backlog.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Check if client is enabled when RAT is used graziang M No 67.3h 0.0h Jun 29, 2026

Summary

Bug Fix

Check if client is enabled when RAT is used

Prevents disabled clients from being managed via Registration Access Tokens, addressing CVE-2026-9705 and improving security.

Health Assessment

Small
Low
Low
  • Quick review and approval with minimal changes; security fix resolved promptly.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
[OID4VCI-FAPI2] Pass fapi2-security-profile-final-par-ensure-reused-request-uri-prior-to-auth-completion-succeeds tdiesler M No 258.8h 0.1h Jun 29, 2026

Summary

Bug Fix

Enforce single-use request_uri per FAPI2 spec

Aligns Keycloak’s PAR handling with the FAPI2 Security Profile, ensuring request_uri is only consumed after authentication completes, improving security compliance.

Health Assessment

Medium
High
High
  • The PR required extensive review with multiple AI-generated comments, resulting in a slow cycle time despite a quick first review.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java
Remove support for symmetric algorithms in JWT public key validators graziang L No 65.4h 0.1h Jun 29, 2026

Summary

Bug Fix

Remove support for symmetric algorithms in JWT public key validators

This PR removes support for symmetric algorithms in JWT public key validators to mitigate CVE-2026-11800, ensuring only asymmetric algorithms are accepted and strengthening security for JWT flows.

Health Assessment

Large
Medium
Low
  • Security fix with minimal review iterations, quick approval, moderate scope, and no major blockers.

AI Details

Usage: AI Reviewed
Category: Code AI
Tools: Copilot
Confidence: 0.95

Tech Stack

Languages: Java, Typescript
« Page 5 of 5

Get this analytics stack for your team

Connect GitHub and see cycle time, review bottlenecks, PR flow, and trend changes in minutes.

Connect Repos