Skip to content

coder

v2.34.5 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agents dev-tools development-environment go ide jetbrains
+3 more
remote-development terraform vscode

Affected surfaces

auth

Summary

AI summary

Updates Bug fixes, Container image, and Dashboard across a mixed release.

Full changelog

Changelog

[!NOTE]
This is a mainline Coder release. We advise enterprise customers without a staging environment to install our latest stable release while we refine this version. Learn more about our Release Schedule.

Features

  • Add INSECURE oidc email fallback flag for IdP brokers (#26751, 8266eb0fc0)

Bug fixes

  • Server: Enforce required external auth on workspace create (#26314, 98bca81318)
  • Dashboard: Add a custom copy/paste menu to the web terminal (#26015, 9513245d54)
  • Examples: Remove vscode-desktop module from quickstart to avoid duplicate VS Code Desktop (#26789, 210bb5eb3d) (@bpmct)
  • Dashboard: Show only parent agent apps in workspaces table (#26568, c3dd41e1e8)

Documentation

  • Add GitLab read_api scope change to ESR upgrade guide (backport #26829) (#26840, 85d78373e9)

Compare: v2.34.4...v2.34.5

Container image

  • docker pull ghcr.io/coder/coder:2.34.5

Install/upgrade

Refer to our docs to install or upgrade Coder, or use a release asset below.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track coder

Get notified when new releases ship.

Sign up free

About coder

Secure environments for developers and their agents

All releases →

Related context

Earlier breaking changes

  • v2.29.17 Validate HostnameSuffix and SSHConfigOptions
  • v2.29.17 Reject OIDC login when email_verified claim is non-bool or absent
  • v2.29.17 Restrict OIDC email fallback to first-time account linking
  • v2.29.17 Only trust x-forwarded-host from configured trusted proxies

Beta — feedback welcome: [email protected]