• v1.36.6 f0228cccfd

    Vaultwarden-Plus v1.36.6
    All checks were successful
    auto-image-build / docker-build (push) Successful in 21m36s
    ci / rust-checks (push) Successful in 2m45s
    validate-publish-surface / validate-publish-surface (push) Successful in 4s
    Stable

    StefanSA released this 2026-07-27 15:12:59 +02:00 | 5 commits to main since this release

    Vaultwarden-Plus v1.36.6

    Client-compatibility maintenance release for Bitwarden 2026.7.x clients, published directly from the validated Vaultwarden-Plus commit.

    Client Compatibility

    • Added Bitwarden 2026.7.x API compatibility while retaining the existing Vaultwarden-Plus architecture.
    • Added current prelogin kdfSettings and salt fields while preserving legacy KDF response fields.
    • Updated /api/config compatibility, including the supported server version contract, onboarding setting, and communication field.
    • Added Bank Account, Driver's License, and Passport cipher-type compatibility.
    • Added collection type and defaultUserCollectionEmail response compatibility.
    • Added user accountKeys responses and current organization capability flags.
    • Added the vNext organization-member restore route, Apple application-site association response, Linux biometrics feature flag, and CLI email two-factor compatibility.
    • Removed the obsolete cipher data response wrapper and obsolete required KDF-change fields.
    • Hardened database URL classification so malformed connection URLs cannot silently fall back to a new SQLite database.

    Security and Preserved Features

    • No security regressions were identified in focused or broader affected regression testing.
    • The v1.36.5 security hardening remains intact.
    • Account Recovery, Passkey Login/PRF, Trusted Devices, Authentication Requests, Device Login, Send Email OTP, SES, DKIM, and mail hardening remain preserved.

    Validation Notes

    • Release target: f0228cccfd1b5cdc8896c871ba36448c71382eb0.
    • Rust formatting and SQLite, MySQL/MariaDB, PostgreSQL, and sqlite,ses compile checks passed.
    • Focused Bitwarden 2026.7.x compatibility tests and isolated broader affected API/client regressions passed.
    • The existing monolithic test-harness SIGSEGV is unrelated to this compatibility change and does not represent a Rust assertion or compatibility failure.
    • No database schema migration is required.
    • The successful CI image build from the validated commit is reused for the release artifact and all Registry tags; no duplicate image build is performed.

    Images

    • forgejo.sabolowitsch.org/stefansa/vaultwarden-plus:1.36.6
    • forgejo.sabolowitsch.org/stefansa/vaultwarden-plus:f0228cccfd1b
    • forgejo.sabolowitsch.org/stefansa/vaultwarden-plus:latest
    Downloads