Project
openstack/keystone
Weekly code activity and mailing-list discussion for openstack/keystone, summarized by Stackers Network.
18 merges this week ▲ +118% vs 4-wk avg 🔥
- Week of 2026-09-05 18 merges · 4 contributors 5418 lines changed
- Week of 2026-06-13 14 merges · 5 contributors 3805 lines changed
- Week of 2026-06-06 13 merges · 3 contributors 2976 lines changed
In the Mailing-List Digests
Weekly issues that touched openstack/keystone, newest first.
- 2026-10-10 OSSA-2026-043 — Zaqar WebSocket (CVE-2026-107363): An authenticated attacker knowing a target project UUID can substitute it in WebSocket frames and enumerate/modify/delete that…
- 2026-10-03 A new vision for Keystone, authn, and authz. Artem Goncharov published a long-form personal vision document explaining the direction of keystone-rs and arguing for a substantial…
- 2026-09-26 OSSA-2026-042 — Zaqar auth bypass (CVE-2026-97404). An empty URL-Signature header bypasses both Keystone auth and pre-signed URL verification; an unauthenticated remote attacker…
- 2026-09-19 The Hibiscus (2026.2) cycle is winding down, with RC1 tagged for most projects and the coordinated release just two weeks away. The week's dominant themes are the tail end of the…
- 2026-09-05 Operator ask. Nguyễn Hữu Khôi asked how to limit resource usage per Availability Zone with Nova moving toward Keystone Unified Limits — an open question worth watching for anyone…
- 2026-08-29 The 2026.2 "Hibiscus" release is in the home stretch: Milestone-3 / feature freeze landed on Thursday August 27, and the mailing lists reflect it — a wave of FFE requests, a…
- 2026-08-15 Bhavna Sorte proposed a Keystone federation pattern for VDI/session brokers using Kasm as a reference implementation (broker-agnostic — Guacamole, Leostream also fit). Keystone…
- 2026-08-08 Security dominated the week: the VMT published a fresh Ironic advisory plus errata (with new CVE identifiers) for four previously-issued Swift and Keystone advisories, and two new…