This release includes breaking changes for platform teams planning a safe upgrade.
Published 6d
Productivity & Wikis
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
agile
ai-integration
collaboration
docker
go
i18n
+9 more
kanban
mcp
mcp-server
oidc
project-management
pwa
scrum
self-hosted
sqlite
Affected surfaces
auth
deps
Summary
AI summaryUpdates ci, chore, and Authentik across a mixed release.
Full changelog
What's Changed
- Audit/test suite by @markrai in https://github.com/markrai/scrumboy/pull/124
- oidc: tolerate trailing-slash issuer (Authentik) in discovery by @vicmike in https://github.com/markrai/scrumboy/pull/126
- ci: publish multi-arch (amd64 + arm64) images by @jordanfelle in https://github.com/markrai/scrumboy/pull/127
- Add SMTP email support for self-service password reset by @jordanfelle in https://github.com/markrai/scrumboy/pull/128
- Add OAuth 2.1 authorization server support for MCP clients by @jordanfelle in https://github.com/markrai/scrumboy/pull/130
- ci: build test images directly from pull requests by @markrai in https://github.com/markrai/scrumboy/pull/132
- Auth: explicit SSO linking, first password, and owner recovery (3.21.0) by @markrai in https://github.com/markrai/scrumboy/pull/134
- Mcp/spec normalization by @markrai in https://github.com/markrai/scrumboy/pull/135
- Security/dependency upgrades by @markrai in https://github.com/markrai/scrumboy/pull/136
- security docs + snyk badge by @markrai in https://github.com/markrai/scrumboy/pull/137
- Update Buy Me a Coffee username in FUNDING.yml by @markrai in https://github.com/markrai/scrumboy/pull/138
- Security/frontend toolchain updates by @markrai in https://github.com/markrai/scrumboy/pull/139
- build artifacts for v3.23.0 / PR #136 / dependency upgrade correction… by @markrai in https://github.com/markrai/scrumboy/pull/140
- ci: replace deprecated DCO actions by @markrai in https://github.com/markrai/scrumboy/pull/142
- Bring branch up to date with main by @markrai in https://github.com/markrai/scrumboy/pull/143
- small fix so that merges are not subject to dco by @markrai in https://github.com/markrai/scrumboy/pull/144
- chore: bring branch up to date with main by @markrai in https://github.com/markrai/scrumboy/pull/145
- chore: add dependabot config by @markrai in https://github.com/markrai/scrumboy/pull/141
- chore: dco skips check on dependabot opened branches by @tungstendev9 in https://github.com/markrai/scrumboy/pull/150
- initial osv-scanner workflow by @markrai in https://github.com/markrai/scrumboy/pull/151
- security: update Go dependencies for OSV findings by @markrai in https://github.com/markrai/scrumboy/pull/152
- patch version bump for v3.22.3 by @markrai in https://github.com/markrai/scrumboy/pull/153
- bring branch up to date with main by @markrai in https://github.com/markrai/scrumboy/pull/154
- Security/trivy by @markrai in https://github.com/markrai/scrumboy/pull/155
- security: pin workflow dependencies by @markrai in https://github.com/markrai/scrumboy/pull/156
- security: apply least-privilege workflow permissions by @markrai in https://github.com/markrai/scrumboy/pull/158
- Security/openssf by @markrai in https://github.com/markrai/scrumboy/pull/159
- ci(release): add signed provenance for Windows release artifacts by @markrai in https://github.com/markrai/scrumboy/pull/160
New Contributors
- @vicmike made their first contribution in https://github.com/markrai/scrumboy/pull/126
- @jordanfelle made their first contribution in https://github.com/markrai/scrumboy/pull/127
Full Changelog: https://github.com/markrai/scrumboy/compare/v3.18.23...v3.22.4
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About markrai/scrumboy
All releases →Beta — feedback welcome: [email protected]