# Quarkus

Quarkus is a full-stack Java framework and developer platform optimized for fast, Kubernetes-native applications.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Keycloak 26.7.4 released

DevFeed: [Keycloak 26.7.4 released](<https://devfeed.tech/articles/keycloak-26-7-4-released-31792.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/09/keycloak-2674-released>)

Author: Keycloak Team

Published: 2026-09-16T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [MariaDB](<https://devfeed.tech/topics/mariadb.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [mariadb](<https://devfeed.tech/tags/mariadb.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.7.4 was released on September 16, 2026. The release includes security fixes for several CVEs, an upgrade to Quarkus 3.33.3.2, and fixes for performance, testing, documentation, administration, and UI issues.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [CVE-2026-79651] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [CVE-2026-74909] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher #52837 [CVE-2026-19607] Username Takeover Leading to Account Lockout #52838 [CVE-2026-17526] Privilege escalation: the "impersonation" role can impersonate a realm administrator #52839 [CVE-2026-18212] SAML Redirect DEFLATE helpers leak native zlib state Enhancements #52354 Upgrade to Quarkus 3.33.3.2 dist/quarkus Bugs #49635 Performance issue with 26.6.2 dist/quarkus #51102 Flaky test: org.keycloak.testsuite.oauth.AccessTokenTest#accessTokenRequest ci #52015 New links errors for https://quarkus.io/guides docs #52172 Cached `RealmAdapter.isUserManagedAccessAllowed()` returns `isEnabled()` infinispan #52173 `realm_client` is computed into a client's attributes and then persisted on save admin/api #52233 Oracle 19 full client OCI driver crashes on startup since 26.6.0 -- SQLFeatureNotSupportedException on setNetworkTimeout dist/quarkus #52241 Clicking on a sub group in the admin console throws an exception admin/ui #52283 Flaky test SessionRestServiceTest.testGetDevicesSessions testsuite #52430 Flaky test: userprofile.spec.ts fails with timeout on "no-users-found-empty-action" in serial suite testsuite

## Java Weekly, Issue 661

DevFeed: [Java Weekly, Issue 661](<https://devfeed.tech/articles/java-weekly-issue-661-4500.md>)

Original publisher: [Read original article](<https://www.baeldung.com/java-weekly-661>)

Author: baeldung

Published: 2026-08-26T17:15:42Z

Content type: article

Language: en

Sources: [Baeldung](<https://devfeed.tech/sources/baeldung.md>)

Topics: [IntelliJ IDEA](<https://devfeed.tech/topics/intellij-idea.md>), [Spring Boot 4](<https://devfeed.tech/topics/spring-boot-4.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [Scripting](<https://devfeed.tech/topics/scripting.md>), [GUI](<https://devfeed.tech/topics/gui.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [boot](<https://devfeed.tech/tags/boot.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [gui](<https://devfeed.tech/tags/gui.md>), [intellij](<https://devfeed.tech/tags/intellij.md>), [intellij-idea](<https://devfeed.tech/tags/intellij-idea.md>), [java](<https://devfeed.tech/tags/java.md>), [json](<https://devfeed.tech/tags/json.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [netflix](<https://devfeed.tech/tags/netflix.md>), [no-ads](<https://devfeed.tech/tags/no-ads.md>), [no-after-post](<https://devfeed.tech/tags/no-after-post.md>), [no-before-post](<https://devfeed.tech/tags/no-before-post.md>), [no-optins](<https://devfeed.tech/tags/no-optins.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [post](<https://devfeed.tech/tags/post.md>), [release](<https://devfeed.tech/tags/release.md>), [scripting](<https://devfeed.tech/tags/scripting.md>), [security](<https://devfeed.tech/tags/security.md>), [weekly-review](<https://devfeed.tech/tags/weekly-review.md>), [weekly-review-no-ads-no-after-post-no-before-post-no-optins](<https://devfeed.tech/tags/weekly-review-no-ads-no-after-post-no-before-post-no-optins.md>)

### AI overview

Java Weekly, Issue 661 is a roundup covering IntelliJ IDEA Conf, the JDK 27 release candidate, early JDK 28 developments, Spring and Java updates, technical articles, webinars, and recent framework and library releases. It also highlights Netflix Conductor's evolution as a workflow orchestration engine.

### Source excerpt

IntelliJ IDEA Conf is back, JDK 27 got its first RC and JDK 28 is already looking solid The post Java Weekly, Issue 661 first appeared on Baeldung.

## Java Weekly, Issue 660

DevFeed: [Java Weekly, Issue 660](<https://devfeed.tech/articles/java-weekly-issue-660-4499.md>)

Original publisher: [Read original article](<https://www.baeldung.com/java-weekly-660>)

Author: baeldung

Published: 2026-08-22T11:26:18Z

Content type: article

Language: en

Sources: [Baeldung](<https://devfeed.tech/sources/baeldung.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Gradle](<https://devfeed.tech/topics/gradle.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Amazon Bedrock](<https://devfeed.tech/topics/amazon-bedrock.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>)

Tags: [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [api](<https://devfeed.tech/tags/api.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [java](<https://devfeed.tech/tags/java.md>), [json](<https://devfeed.tech/tags/json.md>), [no-ads](<https://devfeed.tech/tags/no-ads.md>), [no-after-post](<https://devfeed.tech/tags/no-after-post.md>), [no-before-post](<https://devfeed.tech/tags/no-before-post.md>), [no-optins](<https://devfeed.tech/tags/no-optins.md>), [rag](<https://devfeed.tech/tags/rag.md>), [release](<https://devfeed.tech/tags/release.md>), [weekly-review](<https://devfeed.tech/tags/weekly-review.md>), [weekly-review-no-ads-no-after-post-no-before-post-no-optins](<https://devfeed.tech/tags/weekly-review-no-ads-no-after-post-no-before-post-no-optins.md>)

### AI overview

Java Weekly, Issue 660 is a roundup of Java ecosystem news, including a Hibernate second-level cache performance case study, a proposed small JSON API for JDK 28, Gradle and Renovate integration, AI and RAG resources, and recent Quarkus and other library releases.

### Source excerpt

A clear Hibernate speedup and a new JSON API coming to Java. The post Java Weekly, Issue 660 first appeared on Baeldung.

## Keycloak 26.7.2 released

DevFeed: [Keycloak 26.7.2 released](<https://devfeed.tech/articles/keycloak-26-7-2-released-31788.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/08/keycloak-2672-released>)

Author: Keycloak Team

Published: 2026-08-19T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Jackson](<https://devfeed.tech/topics/jackson.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [cve](<https://devfeed.tech/tags/cve.md>), [idm](<https://devfeed.tech/tags/idm.md>), [jackson](<https://devfeed.tech/tags/jackson.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [password](<https://devfeed.tech/tags/password.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [resolved](<https://devfeed.tech/tags/resolved.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.7.2 is released with security fixes, a Quarkus upgrade, and additional bug fixes and enhancements. The release addresses issues including account takeover, permission bypasses, secret disclosure, and WebAuthn behavior.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [CVE-2026-59888 and CVE-2026-59889] Upgrade jackson-databind to 2.21.5 to fix #50966 [CVE-2026-15945] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions #51145 [CVE-2026-17048] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass Weaknesses #50844 show-config prints the vault keystore password in cleartext dist/quarkus Enhancements #51344 Upgrade to Quarkus 3.33.3.1 Bugs #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication #50849 Correct SCIM name.formated scim #50855 Rotated client secret remains valid when the feature is disabled oidc #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn #51088 Verify email not working in incognito browser tab after Keycloak restart authentication #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan #51164 WebAuthn tests are being skipped in Githu

## ScarfBench: Benchmarking AI Agents for Enterprise Java Framework Migration

DevFeed: [ScarfBench: Benchmarking AI Agents for Enterprise Java Framework Migration](<https://devfeed.tech/articles/scarfbench-benchmarking-ai-agents-for-enterprise-java-framework-migration-7269.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/ibm-research/scarfbench>)

Author: Raju Pavuluri; Rahul Krishna; Srikanth Govindaraj Tamilselvam; Bridget M; Ashita Saxena; George Safta; Advait Pavuluri; Michele Merler

Published: 2026-06-30T18:32:50Z

Content type: article

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [migration](<https://devfeed.tech/topics/migration.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [coding](<https://devfeed.tech/topics/coding.md>), [Jakarta EE](<https://devfeed.tech/topics/jakarta-ee.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Refactoring](<https://devfeed.tech/topics/refactoring.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [applications](<https://devfeed.tech/tags/applications.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [coding](<https://devfeed.tech/tags/coding.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [java](<https://devfeed.tech/tags/java.md>), [leaderboard](<https://devfeed.tech/tags/leaderboard.md>), [migration](<https://devfeed.tech/tags/migration.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [open](<https://devfeed.tech/tags/open.md>), [software](<https://devfeed.tech/tags/software.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [spring](<https://devfeed.tech/tags/spring.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

ScarfBench is an open benchmark for evaluating AI agents on enterprise Java framework migrations across Spring, Jakarta EE, and Quarkus. It measures whether migrated applications build, deploy, and preserve behavior, and reports that current agents achieve less than 10% behavioral success on the benchmark.

### Source excerpt

Recent advances in coding agents have sparked excitement around AI-assisted modernization. But an important question remains: Can AI agents reliably modernize real-world enterprise applications? Existing software engineering benchmarks have demonstrated impressive progress in bug fixing and code generation, but framework migration presents a fundamentally different challenge.

## Keycloak 26.5.7 released

DevFeed: [Keycloak 26.5.7 released](<https://devfeed.tech/articles/keycloak-26-5-7-released-31764.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/04/keycloak-2657-released>)

Author: Keycloak Team

Published: 2026-04-02T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.5.7 was released on April 2, 2026. The release includes multiple security fixes, including issues involving access control, information disclosure, denial of service, unauthorized permission grants, OIDC redirect URI validation, and authorization-code privilege escalation. It also upgrades to Quarkus 3.27.3 and resolves a Host-header error.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #45493 CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure admin/api #45569 CVE-2026-1002 - io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files #47069 CVE-2026-3429 Improper Access Control for LoA During Credential Deletion account/api #47716 CVE-2026-4634 Keycloak Application-Level DoS via Scope Processing #47717 CVE-2026-4636 UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants #47718 CVE-2026-3872 Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint #47719 CVE-2026-4282 Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw Enhancements #46631 Upgrade to Quarkus 3.27.3 dist/quarkus Bugs #45204 Call without Host header throws uncaught error core

## Discover Roq, the Quarkus Way for Static Site Generation in Java

DevFeed: [Discover Roq, the Quarkus Way for Static Site Generation in Java](<https://devfeed.tech/articles/discover-roq-the-quarkus-way-for-static-site-generation-in-java-23016.md>)

Original publisher: [Read original article](<https://www.javaadvent.com/2025/12/discover-roq-the-quarkus-way-for-static-site-generation-in-java.html>)

Author: Andy Damevin

Published: 2025-12-09T02:02:47Z

Content type: tutorial

Language: en

Sources: [Java Advent Calendar](<https://devfeed.tech/sources/java-advent-calendar.md>)

Topics: [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Java](<https://devfeed.tech/topics/java.md>), [Development](<https://devfeed.tech/topics/development.md>), [Tailwind CSS](<https://devfeed.tech/topics/tailwind.md>), [gatsby](<https://devfeed.tech/topics/gatsby.md>), [Jekyll](<https://devfeed.tech/topics/jekyll.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [cms](<https://devfeed.tech/tags/cms.md>), [dev](<https://devfeed.tech/tags/dev.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [hugo](<https://devfeed.tech/tags/hugo.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [jvm](<https://devfeed.tech/tags/jvm.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [ssg](<https://devfeed.tech/tags/ssg.md>), [static-site-generator](<https://devfeed.tech/tags/static-site-generator.md>), [tailwindcss](<https://devfeed.tech/tags/tailwindcss.md>), [themes](<https://devfeed.tech/tags/themes.md>)

### AI overview

This tutorial introduces Roq, a static-site generator built as a thin layer on Quarkus for Java. It explains how Roq uses Quarkus features such as Qute templates, extensions, Dev Mode, plugins, themes, data files, and static-site export, then demonstrates setup and live reloading with a Quarkus, Roq, and Tailwind project.

### Source excerpt

Did you know about Roq? A powerful new tool that combines Java and Quarkus. Ok, prep a warm drink and put on some soft music and let's find out why Roq is so cool with the comfort of Quarkus Dev Mode and all its eco-system. Bonus: a touch of TailwindCss to make it look great! The post Discover Roq, the Quarkus Way for Static Site Generation in Java appeared first on JVM Advent.

## Building a Quarkus LangChain4j Extension for Java LLM Applications

DevFeed: [Building a Quarkus LangChain4j Extension for Java LLM Applications](<https://devfeed.tech/articles/quarkus-langchain4j-extension-from-grounds-up-23027.md>)

Original publisher: [Read original article](<https://www.javaadvent.com/2025/12/quarkus-langchain4j-extension-from-grounds-up.html>)

Author: Martin Toshev

Published: 2025-12-02T04:33:13Z

Content type: tutorial

Language: en

Sources: [Java Advent Calendar](<https://devfeed.tech/sources/java-advent-calendar.md>)

Topics: [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Java](<https://devfeed.tech/topics/java.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [observability](<https://devfeed.tech/topics/observability.md>), [tracing](<https://devfeed.tech/topics/tracing.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [frameworks](<https://devfeed.tech/tags/frameworks.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [java](<https://devfeed.tech/tags/java.md>), [langchain4j](<https://devfeed.tech/tags/langchain4j.md>), [large-language-models](<https://devfeed.tech/tags/large-language-models.md>), [observability](<https://devfeed.tech/tags/observability.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [tracing](<https://devfeed.tech/tags/tracing.md>)

### AI overview

This tutorial explains how the Quarkus LangChain4j extension simplifies integrating Java applications with large language models. It covers build-time and native-image optimizations, CDI-based AI service discovery, type-safe configuration, Quarkus dev mode integration, and observability features before demonstrating an agentic healthcare application.

### Source excerpt

LangChain4j is a top (if not the top) library in use for integrating Java applications with various LLMs (large language models). It provides a number of features such as a unified API for LLM integration, support for vector stores, prompt templates, RAG (retrievalaugmented generation) and more. While we can use it directly in popular frameworks [...] The post Quarkus LangChain4j extension from grounds up appeared first on JVM Advent.

## Lighting the Way: Java, AI, and a Season of New Ideas

DevFeed: [Lighting the Way: Java, AI, and a Season of New Ideas](<https://devfeed.tech/articles/lighting-the-way-java-ai-and-a-season-of-new-ideas-23023.md>)

Original publisher: [Read original article](<https://www.javaadvent.com/2025/12/lighting-the-way-java-ai-and-a-season-of-new-ideas.html>)

Author: Markus Eisele

Published: 2025-12-01T01:00:25Z

Content type: article

Language: en

Sources: [Java Advent Calendar](<https://devfeed.tech/sources/java-advent-calendar.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [java](<https://devfeed.tech/tags/java.md>), [llms](<https://devfeed.tech/tags/llms.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>)

### AI overview

An introductory 2025 Java Advent Calendar article discusses how Java developers are integrating AI and LLMs into production systems. It highlights Quarkus and the Java ecosystem, then introduces a models-as-services pattern using LangChain4j and a Quarkus chat example.

### Source excerpt

When December arrives, I always feel the same mix of nostalgia and excitement. The year starts to slow down, calendars fill with end-of-year meetings, and yet this is when the Java community does something uniquely joyful. We show up every day for 24 days and share what we've learned, built, discovered, and struggled with. It's [...] The post Lighting the Way: Java, AI, and a Season of New Ideas appeared first on JVM Advent.

## Keycloak 26.4.7 released

DevFeed: [Keycloak 26.4.7 released](<https://devfeed.tech/articles/keycloak-26-4-7-released-31740.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/12/keycloak-2647-released>)

Author: Keycloak Team

Published: 2025-12-01T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [saml](<https://devfeed.tech/topics/saml.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [headers](<https://devfeed.tech/tags/headers.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [resolved](<https://devfeed.tech/tags/resolved.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Keycloak 26.4.7 is released with documentation and Quarkus 3.27.1 upgrades, plus fixes for SAML initialization errors and persistent group permissions during concurrent membership changes.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #43156 [Docs] Warn users about printing headers in HTTP access logs docs #43643 Upgrade to Quarkus 3.27.1 dist/quarkus Bugs #44438 Intermittent ConcurrentModificationException during SAML initialization causing status code 400 for clients saml #44480 Wrong persistent group permissions when multiple group membership changes happen in the same request core

## Keycloak 26.4.4 released

DevFeed: [Keycloak 26.4.4 released](<https://devfeed.tech/articles/keycloak-26-4-4-released-31735.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/11/keycloak-2644-released>)

Author: Keycloak Team

Published: 2025-11-07T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [version](<https://devfeed.tech/topics/version.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [changes](<https://devfeed.tech/tags/changes.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Keycloak 26.4.4 is released with enhancements and fixes covering client-scope discovery, verification-email rate limiting, workflow authorization, fine-grained permissions, OIDC, LDAP, WebAuthn, memory usage, and other administration and infrastructure issues.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #10388 Allow to hide client scopes from scopes_supported in discovery endpoint #43076 Add rate limiter for sending verification emails in context of update email #43509 Role authorization for workflows. admin/api Bugs #41270 Cannot save new attribute group admin/ui #41271 Changing user profile attribute results in an error everytime admin/ui #43082 ExternalLinksTest is broken due to missing path parameters docs #43091 Duplicate Email Fields on Temporarily Locked Out Sign In With Organization Identity-First Login login/ui #43160 Regression in DEBUG_PORT handling since 26.4.0 - host binding (*:port / 0.0.0.0:port) no longer works dist/quarkus #43460 FGAP/UI: `reset-password` succeeds but UI shows 403 without Users:manage admin/fine-grained-permissions #43505 DPoP proof replay check doesn't consider clock skew oidc #43516 Deleting Client is slow and fails when a lot of client sessions exist core #43578 "admin" client role now requires server admin user admin/api #43579 403 Forbidden when assigning realm-management client roles with realm-admin despite FGAP disabled (regression in 26.4.0+) admin/fine-grained-permissions #43596 FGAP: user can no longer open account management page, broken by `reset-password` admin/fine-grained-permissions #43621 Version 26.4.1 breaks existing ldap users with capital letters in username ldap #43682 When syncing roles, the database layer can see deadlocks #43698 Role Mapper is updating the user every time on login identity-brokering #43723 Only add the none verifier when attestation conveyance preference is none (or default) authentication/webauthn #43734 Refresh token allowed for offline session even the related scope is removed #43736 FGAP V2: reset-password scope error when viewing users with Group permissions only core #43744 Increased memory usage due to leaking Keyc

## Building a persistent conversational AI chatbot with Temporal

DevFeed: [Building a persistent conversational AI chatbot with Temporal](<https://devfeed.tech/articles/building-a-persistent-conversational-ai-chatbot-with-temporal-35740.md>)

Original publisher: [Read original article](<https://temporal.io/blog/building-a-persistent-conversational-ai-chatbot-with-temporal>)

Author: Pablo González Granados

Published: 2025-10-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Conversational AI](<https://devfeed.tech/topics/conversational-ai.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Chat Bot](<https://devfeed.tech/topics/chatbot.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Java](<https://devfeed.tech/topics/java.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [conversational-ai](<https://devfeed.tech/tags/conversational-ai.md>), [history](<https://devfeed.tech/tags/history.md>), [java](<https://devfeed.tech/tags/java.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [retries](<https://devfeed.tech/tags/retries.md>), [stateful](<https://devfeed.tech/tags/stateful.md>), [stateless](<https://devfeed.tech/tags/stateless.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This tutorial explains how to build a persistent conversational AI chatbot with Temporal by modeling each conversation as a workflow. It describes maintaining conversation context across restarts, deployments, and scaling events, while supporting long-running interactions, summaries, and retrieval.

### Source excerpt

Build a persistent, infinitely scalable chatbot with Temporal Workflows -- stateless apps, full conversation history across restarts, and resilient retries in Java/Quarkus.

## Keycloak 26.3.5 released

DevFeed: [Keycloak 26.3.5 released](<https://devfeed.tech/articles/keycloak-26-3-5-released-31722.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/09/keycloak-2635-released>)

Author: Keycloak Team

Published: 2025-09-25T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Netty](<https://devfeed.tech/topics/netty.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [MariaDB](<https://devfeed.tech/topics/mariadb.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Caching](<https://devfeed.tech/topics/caching.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [cache](<https://devfeed.tech/tags/cache.md>), [http](<https://devfeed.tech/tags/http.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [mariadb](<https://devfeed.tech/tags/mariadb.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Keycloak 26.3.5 is released with an upgrade to Quarkus 3.20.3 LTS, removal of the explicit MariaDB connector dependency, and fixes for administrative UI, organization, cache, OIDC, and security issues including two Netty vulnerabilities.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #41371 Upgrade to Quarkus 3.20.3 LTS dist/quarkus #41373 Remove explicit MariaDB connector dependency dist/quarkus Bugs #41418 Access to user details for restricted admin fails after enabling organizationin realm organizations #42405 Old hmac-generated (32bit) is recreated when order is changed in realm keys ui core #42491 CVE-2025-58057 - Netty BrotliDecoder / Data Amplification vulnerability dist/quarkus #42492 CVE-2025-58056 - Netty HTTP Request Smuggling vulnerability dist/quarkus #42736 Reset password in admin UI with 'not recently used' password policy leads to error 'Device already exists with the same name' core #42769 Missing switch "ID Token as detached signature" in the admin console client settings oidc #42922 Dynamic Client Registration invalidates the realm cache core

## Comparing Java ZGC and G1 for Tail Latency in a Quarkus Microservice

DevFeed: [Comparing Java ZGC and G1 for Tail Latency in a Quarkus Microservice](<https://devfeed.tech/articles/let-s-take-a-look-at-lower-java-tail-latencies-with-zgc-18850.md>)

Original publisher: [Read original article](<https://www.morling.dev/blog/lower-java-tail-latencies-with-zgc/>)

Published: 2025-09-17T15:09:00Z

Content type: article

Language: en

Sources: [Gunnar Morling](<https://devfeed.tech/sources/gunnar-morling.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [gc](<https://devfeed.tech/tags/gc.md>), [java](<https://devfeed.tech/tags/java.md>), [lts](<https://devfeed.tech/tags/lts.md>), [performance](<https://devfeed.tech/tags/performance.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [sample](<https://devfeed.tech/tags/sample.md>)

### AI overview

This article compares Java's ZGC and G1 garbage collectors using default settings in a sample Quarkus microservice that reads data from a Postgres database. The benchmark applies 1,000 requests per second and measures request latencies on a four-core, 4 GB RAM instance. The supplied excerpt does not include the comparison results.

### Source excerpt

Table of Contents ZGC Allocation Stalls Summary In the "Let's Take a Look at...!" blog series I am exploring interesting projects, developments and technologies in the data and streaming space. This can be KIPs and FLIPs, open-source projects, services, relevant improvements to Java and the JVM, and more. The idea is to get some hands-on experience, learn about potential use cases and applications, and understand the trade-offs involved. If you think there's a specific subject I should take a look at, let me know in the comments below. Java 25 was released earlier this week, and it is the first Java release with long-term support (LTS) which ships with Generational ZGC as the one (and only) flavor of the ZGC garbage collector. ZGC itself is a relatively new concurrent collector, originally added in Java 11.

## Keycloak 26.3.4 released

DevFeed: [Keycloak 26.3.4 released](<https://devfeed.tech/articles/keycloak-26-3-4-released-31721.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/09/keycloak-2634-released>)

Author: Keycloak Team

Published: 2025-09-12T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Database](<https://devfeed.tech/topics/database.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>)

Tags: [database](<https://devfeed.tech/tags/database.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.3.4 is a release that includes an enhancement, an upgrade to Quarkus 3.20.2.2, and fixes covering session timeouts, database errors, login flows, LDAP group synchronization, configuration, documentation, user-profile validation, and the admin UI.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #40630 Double check when working with multithreading. SAST #42245 Upgrade to Quarkus 3.20.2.2 Bugs #35825 Per client session idle time capped by realm level client idle timeout core #40374 Random but frequent duplicate key value violates unique constraint \"constraint_offl_us_ses_pk2\" errors authentication #40463 Login to Account Console produces two consecutive LOGIN events account/ui #40857 Unbounded login_hint Parameter Can Corrupt KC_RESTART Cookie and Break Login Flow oidc #41427 Parallel token exchange fails if client session is expired token-exchange #41801 Lack of coordination in database creation in 26.3.0 causes deployment failures (Reopen) core #41942 Uncaught server error: org.keycloak.models.ModelException: Database operation failed : Sync LDAP Groups to Keycloak (Custom Provider) core #42012 Client session timestamp not updated in the database if running multiple nodes infinispan #42046 KeycloakRealmImport placeholder replacement provides access to sensitive environment variables. operator #42158 Bug in configuration keycoak via keycloak.conf dist/quarkus #42164 [Keycloak CI - Docs] Broken links core #42178 Integer validation error not shown for user profile fields user-profile #42182 Validation errors for required actions don't show translated messages admin/ui #42270 Missing double-dash in the events documentation core #42339 Allowed Client Scopes add openid scope in scope list oidc #42369 Missing client session offline settings on realm level in the admin UI admin/ui

## Keycloak 26.3.3 released

DevFeed: [Keycloak 26.3.3 released](<https://devfeed.tech/articles/keycloak-26-3-3-released-31719.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/08/keycloak-2633-released>)

Author: Keycloak Team

Published: 2025-08-20T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cve](<https://devfeed.tech/tags/cve.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Keycloak 26.3.3 is released with enhancements, dependency upgrades, and fixes across caching, Quarkus, LDAP, OIDC, documentation, clustering, administration, and security. The release includes a fix for CVE-2025-7962 in Jakarta Mail.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #41558 Ensure cache configuration has correct number of owners #41934 Infinispan 15.0.19.Final #41963 Upgrade to Quarkus 3.20.2.1 dist/quarkus Bugs #39562 Breaking template change: Unknown `locale` input field added to user-profile registration page user-profile #40984 Backchannel logout token with an unexpected signature algorithm key oidc #41023 Can't send e-mails to international e-mail addresses: bad UTF-8 syntax core #41098 Locked out after upgrade to 26.3.1 due to missing sub in lightweight access token core #41268 `--optimized` flag and providers jar are incompatible when used with tools changing `last-modify-date` dist/quarkus #41290 Concurrent starts with JDBC_PING lead to a split cluster infinispan #41390 JDBC_PING2 doesn't merge split clusters after a while infinispan #41421 Broken link securing-cache-communication in caching docs docs #41423 Duplicate IDs in generated all configuration docs docs #41469 Uncaught exception cases unclosed spans in tracing dist/quarkus #41488 Synchronize Maven surefire plugin with Quarkus dist/quarkus #41491 ExternalLinks are broken in documentation docs #41520 LDAP Import: KERBEROS_PRINCIPAL not updated when UserPrincipal changes and KERBEROS_PRINCIPAL was null on creation ldap #41532 LDAP Sync all users takes unexpectedly long in 26.3 (> 30 min) ldap #41537 Getting error 405 "Method Not Allowed" when calling the "certs" endpoint with HEAD method oidc #41643 Test SMTP connection fails when no port is specified admin/api #41663 Typo in the caching doc docs #41677 Provider default regression dist/quarkus #41808 CVE-2025-7962 In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages core #41842 memberOf attribute empty or values with a DN that does not match the role base DN fet

## Keycloak 26.1.5 released

DevFeed: [Keycloak 26.1.5 released](<https://devfeed.tech/articles/keycloak-26-1-5-released-31695.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/04/keycloak-2615-released>)

Author: Keycloak Team

Published: 2025-04-11T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [tracing](<https://devfeed.tech/topics/tracing.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [reCAPTCHA](<https://devfeed.tech/topics/recaptcha.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [docs](<https://devfeed.tech/tags/docs.md>), [idm](<https://devfeed.tech/tags/idm.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [recaptcha](<https://devfeed.tech/tags/recaptcha.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [tests](<https://devfeed.tech/tags/tests.md>), [tracing](<https://devfeed.tech/tags/tracing.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Keycloak 26.1.5 is a release containing an upgrade to Quarkus 3.15.4, OpenTelemetry-related changes, and fixes across administration, authentication, account UI, documentation, CI, and other components.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #38409 Upgrade to Quarkus 3.15.4 dist/quarkus #38764 OTel: Unable to disable sampling at runtime; tracing-sampler-ratio validation prevents setting 0.0 dist/quarkus Bugs #36482 The root cause of error is suppressed in KC 26 at building dependencies #37792 Save Button Not Enabled When Switching OTP Type from "Time Based" to "Counter Based" admin/ui #37869 ConditionalOtpFormAuthenticator fails to set CONFIGURE_TOTP required action for LDAP read-only users #38041 [Keycloak CI] - WebAuthn tests ci #38063 Issue in clearing offline sessions internally using ClearExpiredUserSessions Scheduled task #38152 Broken guides link on reverseproxy page docs #38353 Keycloak email message ID contains the local host name or IP address core #38454 Keycloak account console is missing the Keycloak logo account/ui #38576 Define a max expiration window for Signed JWT client authentication oidc #38607 Recaptcha secret key configuration lost when migrating from 24.0.5 to 26.1.4 authentication #38740 OTelHttpClientFactory not configured properly when tracing enabled dist/quarkus

## Simplifying JVM App Development with Heroku's Buildpack Magic

DevFeed: [Simplifying JVM App Development with Heroku's Buildpack Magic](<https://devfeed.tech/articles/simplifying-jvm-app-development-with-heroku-s-buildpack-magic-26495.md>)

Original publisher: [Read original article](<https://www.heroku.com/blog/simplifying-jvm-app-development-herokus-buildpack-magic/>)

Author: Andrew Fawcett

Published: 2025-03-24T15:00:00Z

Content type: tutorial

Language: en

Sources: [Heroku](<https://devfeed.tech/sources/heroku.md>)

Topics: [Buildpacks](<https://devfeed.tech/topics/buildpacks.md>), [Heroku](<https://devfeed.tech/topics/heroku.md>), [Java](<https://devfeed.tech/topics/java.md>), [Spring Boot](<https://devfeed.tech/topics/spring-boot.md>), [Micronaut](<https://devfeed.tech/topics/micronaut.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [build-tools](<https://devfeed.tech/tags/build-tools.md>), [buildpacks](<https://devfeed.tech/tags/buildpacks.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer-tools](<https://devfeed.tech/tags/developer-tools.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [heroku](<https://devfeed.tech/tags/heroku.md>), [heroku-key-value-store](<https://devfeed.tech/tags/heroku-key-value-store.md>), [heroku-postgres](<https://devfeed.tech/tags/heroku-postgres.md>), [java](<https://devfeed.tech/tags/java.md>), [languages](<https://devfeed.tech/tags/languages.md>), [maven](<https://devfeed.tech/tags/maven.md>), [micronaut](<https://devfeed.tech/tags/micronaut.md>), [procfile](<https://devfeed.tech/tags/procfile.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [spring-boot](<https://devfeed.tech/tags/spring-boot.md>)

### AI overview

Heroku's Java buildpack automates much of the process of deploying JVM applications. It detects languages and frameworks, obtains build tools, configures the runtime, and can provide framework-specific settings for Spring Boot, Quarkus, and Micronaut applications.

### Source excerpt

Heroku's commitment to developer productivity shines through in its powerful buildpack system. They handle the heavy lifting of building your app, letting you focus on what matters most: writing code. A prime example is the Heroku Java buildpack, a versatile tool that simplifies deploying Java applications, especially those built with popular frameworks like Spring Boot, [...] The post Simplifying JVM App Development with Heroku's Buildpack Magic appeared first on Heroku.

## Keycloak 25.0.6 released

DevFeed: [Keycloak 25.0.6 released](<https://devfeed.tech/articles/keycloak-25-0-6-released-31656.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/09/keycloak-2506-released>)

Author: Keycloak Team

Published: 2024-09-19T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [saml](<https://devfeed.tech/topics/saml.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [cve](<https://devfeed.tech/tags/cve.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 25.0.6 is released with resolved issues affecting network responses, user properties, WebAuthn login flows, hostname paths, client annotations, realm imports, LDAP searches, and SAML security. The release also addresses two CVEs.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Bugs #30604 Network response was not OK. saml #31165 Re-enabling a temporarily locked user (brute-force) deletes all user properties and attributes admin/ui #32100 Remember Me with External Infinispan is not works properly infinispan #32578 WebAuthn Flows Broken in login.v2 login/ui #32643 Dots are not allowed in the path in Hostname v2 dist/quarkus #32731 KeyCloak Admin Client uses non-standard `@NoCache` annotation which is an issue for Quarkus admin/client-java #32799 Realm import fails when client configures default_acr values import-export #32870 Increased DB activity due to changes in LDAPStorageManager.searchForUserByUserAttributeStream ldap #33115 CVE-2024-8883 Vulnerable Redirect URI Validation Results in Open Redirect #33116 CVE-2024-8698 Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak

## Keycloak 25.0.2 released

DevFeed: [Keycloak 25.0.2 released](<https://devfeed.tech/articles/keycloak-25-0-2-released-31650.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/07/keycloak-2502-released>)

Author: Keycloak Team

Published: 2024-07-18T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [migration](<https://devfeed.tech/topics/migration.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [health-checks](<https://devfeed.tech/tags/health-checks.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [migration](<https://devfeed.tech/tags/migration.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [saml](<https://devfeed.tech/tags/saml.md>), [secret-rotation](<https://devfeed.tech/tags/secret-rotation.md>), [sso](<https://devfeed.tech/tags/sso.md>), [translation](<https://devfeed.tech/tags/translation.md>)

### AI overview

Keycloak 25.0.2 was released on July 18, 2024. The release includes enhancements to management-interface configuration, Admin REST API documentation, and documentation language, along with fixes across the user interface, LDAP synchronization, authorization, migration, operators, and other components.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #30094 Do not inherit 'https-client-auth' property for the management interface #30537 Document how Admin REST API endpoints work with Hostname config docs #30856 Remove inclusive language foreword docs Bugs #19070 authBaseUrl error on different hostname-admin-url, hostname-url admin/ui #26042 Issue when start-dev in 23.0.1 dist/quarkus #28489 Missing help text on tokens tab admin/ui #29407 Need refresh attributes group translations on Users > Details tab admin/ui #29566 User Profile attributes/groups in Admin UI are not translated using Localization for non-master realm when signed in the master realm account/ui #29761 bug: disabling all default features no longer works core #29784 Exception while trying to run a LDAP sync with a group importer and a batch size less then the actual number of groups ldap #30329 Client secret rotation UI shows wrong rotated secret admin/ui #30355 New operator failing on health checks operator #30383 Account Console (v3) no longer highlights the current page in the nav bar account/ui #30436 Client Roles are not shown when clientId property is set admin/ui #30440 UI theme bug in KC 25.0.0 admin/ui #30444 Failed to evaluate permissions when fetchRoles is enabled on role policies authorization-services #30449 Migration stuck if versions incompatible operator #30521 "Client Offline Session Max" no longer available admin/ui #30541 Account UI resources try to load from admin path instead of frontend path account/ui #30552 After migrating from 24 to 25, the signature algorithms names do not display in drop down menu admin/ui #30591 Invalid character in spanish translation file for Identity Provider Link Template translations #30652 Default server port is used instead of the management interface port in the guide about running Keycloak in a container #30662 User policy -> se

## Keycloak 24.0.4 released

DevFeed: [Keycloak 24.0.4 released](<https://devfeed.tech/articles/keycloak-24-0-4-released-31640.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/05/keycloak-2404-released>)

Author: Keycloak Team

Published: 2024-05-08T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [API](<https://devfeed.tech/topics/api.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [container](<https://devfeed.tech/topics/container.md>), [like](<https://devfeed.tech/topics/like.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [container](<https://devfeed.tech/tags/container.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vault](<https://devfeed.tech/tags/vault.md>)

### AI overview

Keycloak 24.0.4 is released. The update removes support for partial user-attribute updates through the Admin User API, upgrades Quarkus to 3.8.4, and includes enhancements and bug fixes across administration, import/export, LDAP, OIDC, SAML, and related components.

### Source excerpt

To download the release go to Keycloak downloads. Highlights Partial update to user attributes when updating users through the Admin User API is no longer supported When updating user attributes through the Admin User API, you cannot execute partial updates when updating the user attributes, including the root attributes like username, email, firstName, and lastName. For more details, see the Upgrading Guide. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #27508 Use new remote-store options in HA guides #28429 Add details to error messages, especially around refresh tokens #28729 Emphasize the need for setting container limit docs #28880 Upgrade to Quarkus 3.8.4 dist/quarkus #29183 Minor corrections to High Availability Guide docs Bugs #16345 Unable to delete realm names with invalid URL characters admin/api #22617 kc export fails when using User Federation (LDAP) with file-based Vault enabled import-export #24568 iframe for frontend logout gets blocked if a custom CSP header is used core #24878 NoClassDefFoundError for Apache XML and EAP8 adapter/jee-saml #27021 Workflow failure: Fuse adapter tests ci #27080 Workflow failure: Operator CI - KeycloakTruststoresTests#testTrustroreExists ci #27514 Uncaught server error: java.lang.IllegalArgumentException: Path parameter not provided oidc #28079 Group search does not work in user view admin/ui #28187 Admin UI drag & drop in flow config seems to delete actions admin/ui #28220 Admin API: User PUT operation clears firstname, lastname email fields admin/api #28303 WARN - Event object wasn't available in remote cache after event was received infinispan #28377 Broken lists in import/export server guide docs #28431 Dedicated client scopes always show up when searching admin/ui #28514 Message for searchClientRegistration is missing admin/ui #28666 Accessing a transient (lightweight) user through client session fails in admin-api/-ui admin/ui #28684 "Exten

## Keycloak 23.0.7 released

DevFeed: [Keycloak 23.0.7 released](<https://devfeed.tech/articles/keycloak-23-0-7-released-31634.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/02/keycloak-2307-released>)

Author: Keycloak Team

Published: 2024-02-22T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [kerberos](<https://devfeed.tech/topics/kerberos.md>), [Localization (l10n)](<https://devfeed.tech/topics/localization.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [changes](<https://devfeed.tech/tags/changes.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [reports](<https://devfeed.tech/tags/reports.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 23.0.7 is released with an enhancement to shorten offline session cache entry lifespans in memory storage and fixes affecting localization, Kerberos and LDAP integration, MySQL native SQL schema names, Freemarker URL handling, Microsoft social login tests, and CI workflows.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Enhancements #26810 Shorter lifespan for offline session cache entries in memory storage Bugs #22431 Localization: Admin UI doesn't pick up message bundles from realms other than master admin/ui #23786 Failure: FipsDistTest ci #25294 Kerberos principal attribute not found on LDAP user - even if kerberos authentication is off ldap #25883 ldap-group-mapper fails when empty member: attribute is present ldap #25912 LDAP federation reports "Creating new LDAP Store..." on every login ldap #25961 Native SQL Schema names broken on MySQL storage #26374 Workflow failure: Quarkus IT - FipsDistTest#testUnsupportedHttpsPkcs12KeyStoreInStrictMode ci #26529 Workflow failure: Quarkus IT - FipsDistTest#testUnsupportedHttpsPkcs12KeyStoreInStrictMode ci #26826 Freemarker erroneously escapes/sanitizes URL in template.ftl (&) login/ui #27120 Microsoft social login failure testsuite

## Keycloak 23.0.5 released

DevFeed: [Keycloak 23.0.5 released](<https://devfeed.tech/articles/keycloak-23-0-5-released-31632.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/01/keycloak-2305-released>)

Author: Keycloak Team

Published: 2024-01-29T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [new-features](<https://devfeed.tech/tags/new-features.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Keycloak 23.0.5 is released with documentation updates, a Quarkus 3.2.10 update, enhancements, and fixes for authentication, authorization, Admin Console, account UI, command-line parsing, CI workflows, and other issues.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues New features #25733 Update Route53 HA guide to be compatible with ROSA and Openshift 4.14.x #26028 Remove conditional statements about Windows / Linux from the docs docs Enhancements #20125 Role mapping tab no longer visible when using fine grained permissions after upgrade from 20.0.3 to 21.0.2 admin/ui #26006 Clarification needed of use of containers #26083 Change RHDG references to Infinispan #26220 Don't differentiate Windows for getting started docs #26417 Update to Quarkus 3.2.10 Bugs #14448 Multiple failures in OfflineServletsAdapterTest (testServlet, testServletWithConsent, testServletWithRevoke) testsuite #24219 admin-fine-grained-authz + client authorization settings requires view-client role admin/ui #24586 Read Only Access of a realm clients' Authz is broken for Admin Console admin/ui #24918 User details tab does not display or update attibutes with dot admin/ui #25054 Read Only Access of the realm users' "Role mapping" tab is broken for Admin Console admin/ui #25078 Log Injection during WebAuthn authentication/registration authentication #25392 Admin Console: Realm Dropdown should only show the realms the user has access to admin/ui #25502 Account v3 theme - theme.properties Custom theme scripts not loading account/ui #25677 Removing all group attributes no longer works with keycloak-admin-client (java) admin/client-java #25679 `/admin/realms/{realm-name}/ui-ext/realms` endpoint leaks realms the user doesn't have access to see admin/ui #25714 Flaky test: org.keycloak.testsuite.adapter.servlet.OfflineServletsAdapterTest#testServlet ci #25783 Since 23, start-dev command line arguments parsing is buggy dist/quarkus #25827 admin ui uses hyphen instead of dot as realm attribute separator admin/ui #25909 Keycloak HA Guide uses token for cross-site setup that expires #25981 GitHub Status check is green if

## 2nd edition of the Keycloak book is out

DevFeed: [2nd edition of the Keycloak book is out](<https://devfeed.tech/articles/2nd-edition-of-the-keycloak-book-is-out-31616.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2023/09/book-2nd-edition>)

Author: Stian Thorgersen

Published: 2023-09-11T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [console](<https://devfeed.tech/topics/console.md>), [amazon](<https://devfeed.tech/topics/amazon.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [application](<https://devfeed.tech/tags/application.md>), [book](<https://devfeed.tech/tags/book.md>), [getting-started](<https://devfeed.tech/tags/getting-started.md>), [guide](<https://devfeed.tech/tags/guide.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [latest-release](<https://devfeed.tech/tags/latest-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak announces the second edition of its book, available for purchase on Amazon. The updated edition covers the latest Keycloak release, the Quarkus distribution, the administration console, getting started, and securing different application types.

### Source excerpt

We're pleased to announce that the 2nd edition of the Keycloak book is out, and available for available for purchase on Amazon. This new edition has been updated to the latest release of Keycloak, making the book compatible with the newer Quarkus distribution of Keycloak, as well as the new administration console. If you are new to Keycloak this book brings an excellent guide to getting started with Keycloak, including how to secure a range of different application types with Keycloak.

[Next page](<https://devfeed.tech/topics/quarkus.md?cursor=WyIyMDIzLTA5LTExVDAwOjAwOjAwKzAwOjAwIiwgIjMwOWUzNDgwLTVjZDUtNGYwZS05YzE5LTdkZjgxMDA1MjdkYSJd>)