Gestion d'identité et SSO
Find a file
Stan Silvert 8e46047410
Some checks are pending
Keycloak CI / Check conditional workflows and jobs (push) Waiting to run
Keycloak CI / Build (push) Blocked by required conditions
Keycloak CI / Base UT (push) Blocked by required conditions
Keycloak CI / Base IT (push) Blocked by required conditions
Keycloak CI / Adapter IT (push) Blocked by required conditions
Keycloak CI / Adapter IT Strict Cookies (push) Blocked by required conditions
Keycloak CI / Quarkus UT (push) Blocked by required conditions
Keycloak CI / Quarkus IT (push) Blocked by required conditions
Keycloak CI / Java Distribution IT (push) Blocked by required conditions
Keycloak CI / Login Theme v1 tests (push) Blocked by required conditions
Keycloak CI / Volatile Sessions IT (push) Blocked by required conditions
Keycloak CI / External Infinispan IT (push) Blocked by required conditions
Keycloak CI / AuroraDB IT (push) Blocked by required conditions
Keycloak CI / Store IT (push) Blocked by required conditions
Keycloak CI / Store Model Tests (push) Blocked by required conditions
Keycloak CI / Clustering IT (push) Blocked by required conditions
Keycloak CI / FIPS UT (push) Blocked by required conditions
Keycloak CI / FIPS IT (push) Blocked by required conditions
Keycloak CI / Forms IT (push) Blocked by required conditions
Keycloak CI / WebAuthn IT (push) Blocked by required conditions
Keycloak CI / SSSD (push) Blocked by required conditions
Keycloak CI / Migration Tests (push) Blocked by required conditions
Keycloak CI / Test Framework (push) Blocked by required conditions
Keycloak CI / Base IT (new) (push) Blocked by required conditions
Keycloak CI / Status Check - Keycloak CI (push) Blocked by required conditions
CodeQL / Check conditional workflows and jobs (push) Waiting to run
CodeQL / CodeQL Java (push) Blocked by required conditions
CodeQL / CodeQL JavaScript (push) Blocked by required conditions
CodeQL / CodeQL TypeScript (push) Blocked by required conditions
CodeQL / Status Check - CodeQL (push) Blocked by required conditions
Keycloak Documentation / Check conditional workflows and jobs (push) Waiting to run
Keycloak Documentation / Build (push) Blocked by required conditions
Keycloak Documentation / External links check (push) Blocked by required conditions
Keycloak Documentation / Status Check - Keycloak Documentation (push) Blocked by required conditions
Keycloak Guides / Check conditional workflows and jobs (push) Waiting to run
Keycloak Guides / Build (push) Blocked by required conditions
Keycloak Guides / Status Check - Keycloak Guides (push) Blocked by required conditions
Keycloak JavaScript CI / Check conditional workflows and jobs (push) Waiting to run
Keycloak JavaScript CI / Build Keycloak (push) Blocked by required conditions
Keycloak JavaScript CI / Admin Client (push) Blocked by required conditions
Keycloak JavaScript CI / UI Shared (push) Blocked by required conditions
Keycloak JavaScript CI / Account UI (push) Blocked by required conditions
Keycloak JavaScript CI / Admin UI (push) Blocked by required conditions
Keycloak JavaScript CI / Account UI E2E (push) Blocked by required conditions
Keycloak JavaScript CI / Generate Test Seed (push) Blocked by required conditions
Keycloak JavaScript CI / Admin UI E2E (push) Blocked by required conditions
Keycloak JavaScript CI / Status Check - Keycloak JavaScript CI (push) Blocked by required conditions
Keycloak Operator CI / Check conditional workflows and jobs (push) Waiting to run
Keycloak Operator CI / Build distribution (push) Blocked by required conditions
Keycloak Operator CI / Test local (push) Blocked by required conditions
Keycloak Operator CI / Test remote (push) Blocked by required conditions
Keycloak Operator CI / Test OLM installation (push) Blocked by required conditions
Keycloak Operator CI / Status Check - Keycloak Operator CI (push) Blocked by required conditions
Fix high-severity npm transitive dependency vulnerabilities via pnpm … (#48139)
* Fix high-severity npm transitive dependency vulnerabilities via pnpm overrides (#47657)

Apply pnpm.overrides in js/package.json to force patched versions of
vulnerable transitive dependencies:

- picomatch ^2.3.1 → ^2.3.2 (ReDoS via extglob quantifiers)
- flatted ^3.2.9 → ^3.4.2 (Prototype Pollution and unbounded recursion DoS)
- minimatch ~3 → ^3.1.4 (multiple ReDoS vectors)
- minimatch ~9 → ^9.0.7 (ReDoS via repeated wildcards)
- @isaacs/brace-expansion ^5 → ^5.0.1 (uncontrolled resource consumption)
- serialize-javascript ^6 → ^7.0.3 (RCE via RegExp.flags)

pnpm.overrides is used here because none of the direct dependencies that
pull in these transitive packages have released fixes upstream yet:

- wireit 0.14.12 (latest stable) → picomatch 2.3.1 via chokidar/micromatch
- eslint 9.x → flatted 3.3.3 via flat-cache, minimatch 3.1.2
- mocha 11.x → serialize-javascript 6.0.2
- vite-plugin-dts 4.x → minimatch 9.0.5, @isaacs/brace-expansion 5.0.0

Since the vulnerable ranges (e.g. ^2.3.1, ^3.2.9) already permit the
patched versions, overrides simply force pnpm to resolve to the fixed
minor/patch release rather than the previously locked version.

Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
(cherry picked from commit e556494cec)

* Fix linting errors.

Signed-off-by: Stan Silvert <ssilvert@redhat.com>

---------

Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
Signed-off-by: Stan Silvert <ssilvert@redhat.com>
Co-authored-by: Bruno Oliveira da Silva <bruno@abstractj.com>
2026-04-17 11:01:31 +02:00
.github [26.2] Fix tests for the release branch (#46417) 2026-02-23 12:37:56 +01:00
.idea Add Intellij project icon 2023-09-18 12:39:16 +02:00
.mvn Update custom Maven build cache configuration for js directory 2024-12-10 10:07:02 +00:00
adapters Ensure that an encrypted assertion is signed if response is not signed (#358) 2026-02-23 14:31:56 +01:00
authz Also deploy keycloak-authz-client-tests when deploy-testsuite profile is active 2026-04-08 17:17:53 +02:00
boms Add publishing plugin for Maven Central Repository migration (#40029) (#40176) 2025-06-03 13:42:47 +02:00
common Adding namespaces for single-use cache entries for PAR and OAuth code (#485) 2026-03-23 11:46:25 +01:00
core Aligning partial evaluation with the outcome from regular evaluations 2025-04-03 12:07:30 -03:00
crypto Configure Argon2's type correctly in Argon2PasswordHashProviderFactory 2025-06-04 13:47:07 +00:00
dependencies Add initial IPA-Tuura federation (#35467) 2024-12-02 14:59:21 -03:00
distribution Adding ISPN processor annotations to the API docs generation 2025-03-03 12:33:06 +01:00
docs Fixing link as it has changed and is redirecting 2026-04-07 10:39:36 +02:00
federation [26.2] Only allow LDAP URL references when following referrals (#286) 2025-11-21 11:20:33 +01:00
integration Update javadoc of java admin-client for Keycloak 26.2 2025-03-25 10:55:43 +01:00
js Fix high-severity npm transitive dependency vulnerabilities via pnpm … (#48139) 2026-04-17 11:01:31 +02:00
misc Avoid unbalanced curly braces in message properties 2025-06-04 09:53:50 +02:00
model Update protolock file list 2025-11-18 18:32:07 +00:00
operator Use quay.io instead of DockerHub in testsuite createCurlContainer() 2026-03-11 14:08:10 +01:00
quarkus Use virtual threads when there are at least four cores to avoid deadlocks 2026-01-16 07:58:46 -03:00
rest [FGAP] AvailableRoleMappings do not consider all-clients permissions 2025-04-16 12:59:42 +02:00
saml-core Ensure that an encrypted assertion is signed if response is not signed (#358) 2026-02-23 14:31:56 +01:00
saml-core-api Use a default Java version from root POM (#29927) 2024-06-21 14:19:31 +02:00
server-spi Adding namespaces for single-use cache entries for PAR and OAuth code (#485) 2026-03-23 11:46:25 +01:00
server-spi-private Enforce disabled checks when processing brokering flows (#365) 2026-02-25 07:45:26 +01:00
services Make sure disabled organizations are not available from selection 2026-04-07 08:31:59 +02:00
test-framework Unbounded login_hint parameter Can Corrupt KC_RESTART Cookie 2025-09-09 17:09:12 +02:00
tests Unbounded login_hint parameter Can Corrupt KC_RESTART Cookie 2025-09-09 17:09:12 +02:00
testsuite Make sure disabled organizations are not available from selection 2026-04-07 08:31:59 +02:00
themes Disable email verification when email manually changed by idp review 2025-06-26 16:15:15 +02:00
util Artifact SLF4J LOG4J-12 has been relocated (#20113) 2023-05-05 13:57:45 +02:00
.editorconfig Disable trim_trailing_whitespace in editorconfig 2024-11-07 17:48:17 +01:00
.gitattributes Use lf as line-ending for sh files 2022-07-19 08:57:57 +02:00
.gitignore Rename .env-test to .env.test (#36975) 2025-02-03 07:41:56 +01:00
.gitleaks.toml Updated .gitleaks.toml to ignore false positive in RedirectUtilsTest (#33346) 2024-09-27 14:32:36 +02:00
ADOPTERS.md Adding Minder & Stacklok usage (#34357) 2024-10-29 10:27:24 +01:00
CONTRIBUTING.md Add reason for issue requirement to CONTRIBUTING.md 2024-11-25 08:36:45 +01:00
get-version.sh Use Maven wrapper instead of platform dependent Maven version (#29988) 2024-06-03 15:45:39 +02:00
GOVERNANCE.md Update governance model around changes in maintainership (#29292) 2024-05-22 08:24:10 +02:00
LICENSE.txt Added text version of ASL2 license 2019-11-08 12:43:10 +01:00
MAINTAINERS.md Update maintainers (#31798) 2024-08-12 11:54:53 +02:00
maven-settings.xml [KEYCLOAK-11764] Upgrade to Wildfly 19 2020-04-24 08:19:43 -03:00
mvnw Upgrade Maven and wrapper to latest version 2024-06-19 10:42:33 +02:00
mvnw.cmd Upgrade Maven and wrapper to latest version 2024-06-19 10:42:33 +02:00
pom.xml Upgrade to Quarkus 3.20.6 (#47443) 2026-04-15 14:16:40 +02:00
PR-CHECKLIST.md Introduce CODEOWNERS (#16637) 2023-01-30 13:05:45 +01:00
README.md Add CLOMonitor Badge to the README 2025-02-20 12:31:58 -03:00
SECURITY-INSIGHTS.yml Provide an OpenSSF security insights manifest file 2024-02-15 11:02:33 -03:00
set-version.sh Remove Keycloak JS from repository (#37057) 2025-02-12 16:31:21 +00:00

Keycloak

GitHub Release OpenSSF Best Practices CLOMonitor OpenSSF Scorecard Artifact Hub GitHub Repo stars GitHub commit activity Translation status

Open Source Identity and Access Management

Add authentication to applications and secure services with minimum effort. No need to deal with storing users or authenticating users.

Keycloak provides user federation, strong authentication, user management, fine-grained authorization, and more.

Help and Documentation

Reporting Security Vulnerabilities

If you have found a security vulnerability, please look at the instructions on how to properly report it.

Reporting an issue

If you believe you have discovered a defect in Keycloak, please open an issue. Please remember to provide a good summary, description as well as steps to reproduce the issue.

Getting started

To run Keycloak, download the distribution from our website. Unzip and run:

bin/kc.[sh|bat] start-dev

Alternatively, you can use the Docker image by running:

docker run quay.io/keycloak/keycloak start-dev

For more details refer to the Keycloak Documentation.

Building from Source

To build from source, refer to the building and working with the code base guide.

Testing

To run tests, refer to the running tests guide.

Writing Tests

To write tests, refer to the writing tests guide.

Contributing

Before contributing to Keycloak, please read our contributing guidelines. Participation in the Keycloak project is governed by the CNCF Code of Conduct.

Joining a community meeting is a great way to get involved and help shape the future of Keycloak.

Other Keycloak Projects

License