Update bitwarden to v2026.8.1
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| bitwarden/clients | patch | 2026.8.0 → 2026.8.1 |
| bitwarden/server | patch | 2026.8.0 → 2026.8.1 |
Release Notes
bitwarden/clients (bitwarden/clients)
v2026.8.1: Web v2026.8.1
What's Changed
💙 Community Highlight
- [PM-41559] [PM-41539] Recognize both Keeper SSO callback URL forms by @detunized in #22265
- [PM-41979] [PM-41899] [VULN-735] Validate profileId in Chromium importer by @detunized in #22432
- [PM-29036] fix(desktop): set desktopName for Wayland app_id to display correct icon by @thisisryanswift in #17764
- [PM-38964] Remove obsolete LockScreen config from AppX manifest by @hammadxcm in #21229
:shipit: Feature Development
- [PM-40945] add testing to relevant components by @dan-livefront in #22224
- feat(browser): Add autofill for SSH keys by @quexten in #21289
- Auth/PM-39706 - Open Org Invite Link Support by @JaredSnider-Bitwarden in #21574
- [PM-40736] billing terminology update by @JaredScar in #22114
- [PM-32211] fix private key before key rotation by @mzieniukbw in #20392
- [PM-35945] Browser: Show the Health Overview after a scan (gauge and risk categories) by @AlexRubik in #22235
- Auth / PM-41503 & PM-41533 - Registration - Wire new open org invite data into register start and finish by @JaredSnider-Bitwarden in #22333
- [PM-41686]Implement plumbing for inline menu lit components by @dan-livefront in #22286
- [CL-1210] use overflow directive to pack primary actions when needed by @BryanCunningham in #21589
- Feature/webmapper integration by @blackwood in #21738
- desktop-autofill: Refactor UV reprompt and window management [PM-29791] by @iinuwa in #22257
- [PM-40312] Introduce vault items table component by @shane-melton in #22237
- [CL-1245] updated icon tile colors by @BryanCunningham in #22102
- [PM-40330] Add vault list table to desktop behind VFO1Foundation flag by @nick-livefront in #22383
- desktop-autofill: Define the desktop FIDO2 user verification service [PM-29791] by @iinuwa in #22258
- [CL-1237] sidenav updates by @BryanCunningham in #21855
- [PM-35946] Browser: Health report at risk category detail view by @lastbestdev in #22246
- PM-40304: Add the conditional Vaults nav-section logic and vault-type color mapping by @nikwithak in #22119
- desktop-autofill: Implement FIDO2 user verification logic [PM-29791] by @iinuwa in #22259
- VaultPopupListTableComponent + Storybook by @nick-livefront in #22106
- [CL-998] table-v2 polish by @willmartian in #22255
- [PM-41902] Member Access Report terminology changes by @JaredScar in #22410
- [PM-40212] Enable-PAM UI (member toggle + bulk Activate PAM) by @Hinton in #22478
- [PM-37839] Browser: Delete item from at risk category view by @lastbestdev in #22268
- [PM-41687]Implement locked and saved login lit components by @dan-livefront in #22348
- [PM-40318] Introduce Web's VaultNextComponet for VFO1 by @shane-melton in #22425
- [PM-34808] Step 1 remove flagged logic for policy drawers by @JaredScar in #22342
- Browser: Add dark mode image to Health tab intro CTA by @lastbestdev in #22487
- [PM-36628] Browser: Add clean state to Health at risk category detail view by @lastbestdev in #22396
- desktop-autofill: Verify user without UI on assertion when possible [PM-29791] by @iinuwa in #22177
- desktop-autofill: macOS native user verification [PM-29791] by @iinuwa in #22178
- desktop-autofill: Windows native user verification [PM-29791] by @iinuwa in #22179
- desktop-autofill: Refactor FIDO2 modals by @iinuwa in #22433
- [PM-41688] Implement cipher list lit components by @dan-livefront in #22378
- desktop-autofill: Skip registration confirmation by @iinuwa in #22435
- [PM-40395] Add Import button to new vault table by @nikwithak in #22439
- [PM-39455] Use v2 upgrade token when asserting organization public key trust. by @mzieniukbw in #22490
- [PM-40127] Item history redesign using bit-card-segmented by @nick-livefront in #21940
- [PM-40333] Hide side-nav vault filter on desktop by @nick-livefront in #22434
- [PM-40331] Vault Param Redirect by @nick-livefront in #22438
- desktop-autofill: FIDO2 selection modal UI improvements by @iinuwa in #22436
- [PM-41856] Update tooltip wording for icons by @jengstrom-bw in #22345
- [PM-39408] feat: Tee TS logs into LogRecorder sink by @dani-garcia in #22379
- [PM-40814] Add key id support by @quexten in #22444
- Fix/late hydration shadow detection by @blackwood in #21370
- [PM-41949] Enhance SecretsManagerSubscribeComponent with feature flag support by @JaredScar in #22412
- [PM-40313] Restructure the Password Manager side navigation (web) by @gbubemismith in #22283
- [PM-41472] feat(web): add the My folders page by @gbubemismith in #22267
- [CL-1248] Add FAB button component to vault by @nick-livefront in #22523
- [PM-41273] Extend ImportService to expose per-vendor metadata by @harr1424 in #22297
- [PM-40740] Policies list & drawers terminology updates by @JaredScar in #22377
- [CL-1194] responsive breadcrumbs by @BryanCunningham in #21742
- [PM-40318] VFO1 Web vault query param handling by @shane-melton in #22501
- [PM-42183] VFO1 Side nav vault scoping by @shane-melton in #22567
- Add desktop beta icons by @trmartin4 in #22445
- [PM-39223] Browser: Run the vault scan and show its progress and failure states by @AlexRubik in #22346
- [CL-988] Update no items component to status lockup design by @vleague2 in #22386
- [PM-40848] Add the shared folder card grid component (libs/vault) by @jengstrom-bw in #22390
🐛 Bug fixes
- [PM-8711] inconsistent casing between vault management api feedback and api docs by @JaredScar in #22232
- [PM-11607] AC Event Log Buttons vertical alignment by @JaredScar in #22222
- [PM-41691] Fix issue where edit item, hidden passwords wipes password, TOTP by @JaredScar in #22287
- [PM-40258]: AuthRequestResponse refactor by @enmande in #22182
- [PM-41854] fix: skip collections coachmark step for users without collections by @gbubemismith in #22376
- Auth/ PM-41535 & PM-41897 - Open Org Invite Link - Update accept-error classifier for new SDK API error format by @JaredSnider-Bitwarden in #22393
- Auth & KM / PM-41538 - Organization Invite Acceptance - Show invite accepted toast on TDE and KC SSO JIT flows by @JaredSnider-Bitwarden in #22394
- [PM-41880] Quick fix for edit members dialog dependencies by @ttalty in #22407
- fix(biometrics): change the biometric persistent encryption migration to handle the case where the aes-cbc-hmac key has a key id by @quexten in #22336
- [PM-41829] Login Buttons Overlap Owner and Name Elements When Resizing Browser by @jengstrom-bw in #22418
- Auth/PM-41978 - Open Org Invite Acceptance - update error copy for vfo1-foundation vault terminology change by @JaredSnider-Bitwarden in #22485
- [PM-42166] Update member access report terminology by @JaredScar in #22522
- [PM-42006] Self Host Premium Upgrade Copy Change by @JaredScar in #22493
- [PM-41830] Shrinking Window Causes Buttons to Overlap Owner Element and Pushes More Options Menu Offscreen by @jengstrom-bw in #22419
- Auth / PM-32421 - CLI - Login Command - Validate SSO account has a CLI-supported decryption path by @JaredSnider-Bitwarden in #22411
- [PM-42235] Browser: Health at risk category empty state fixes by @lastbestdev in #22538
- [PM-42239] Access Intelligence: Match v2 request password change button behavior to v1 by @lastbestdev in #22537
- [PM-40350] Revert early return introduced in #21836 by @harr1424 in #22453
- [PM-41905] Add Autotype MVP Window Validity Check by @coltonhurst in #22398
- Revert "[PM-42239] Access Intelligence: Match v2 request password change button behavior to v1" by @lastbestdev in #22590
- fix(key-connector): fix sdk-based unlock with key-connector on jit provisioning by @quexten in #22545
- [PM-42470] Add cooldown to user key id backfill migration (#22682) by @quexten in #22750
🍒 [PM-42443] Include member items when fetching org ciphers in Access Intelligence by @Banrion in #22751
⚙️ Maintenance
- chore: remove grype scanning by @sognefej in #22289
- [chore] Add CODEOWNERS entry for the licensed browser DIRT directory by @AlexRubik in #22325
- Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22302
- Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22300
- Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22301
- Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22340
- Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22338
- Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22339
- [PM-38767] Adopt cargo-run-bin for binary tool version pinning in desktop_native by @coroiu in #21169
- refactor(crypto): split out legacy compat key service by @quexten in #22319
- Add PAM Allium specification by @abergs in #22373
- [PM-41874] refactor(crypto): move shared client wiring callers to @bitwarden/legacy-crypto by @quexten in #22368
- [PM-41874] refactor(crypto): move dirt callers to @bitwarden/legacy-crypto by @quexten in #22366
- [PM-41874] refactor(crypto): move admin-console callers to @bitwarden/legacy-crypto by @quexten in #22367
- [PM-41874] refactor(crypto): move desktop-native callers to @bitwarden/legacy-crypto by @quexten in #22372
- refactor(auth): unlock via UnlockService in login strategies by @quexten in #22354
- [PM-36409] Enhance type safety across various components by @JaredScar in #22391
- Remove unused loginApprovalModelRef by @djsmith85 in #22405
- [PM-41874] refactor(crypto): move key-management callers to @bitwarden/legacy-crypto by @quexten in #22362
- Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22423
- Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22422
- Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22424
- [PM-35785] Fix SDK breaking change: missing asUuid by @eliykat in #22392
- refactor(key-management-ui): stop re-setting the user key after unlock by @quexten in #22355
- [BRE-2116] Bump actions/checkout to v7.0.1 + add bypass flag in client build workflows by @brandonbiete in #22385
- Fix: breaking SDK change - use asUuid in tests by @eliykat in #22443
- widen engines pin to include Node 24 by @addisonbeck in #22480
- [PM-38455] Remove unused premiumRequired from app.components by @djsmith85 in #22403
- [PM-41874] refactor(crypto): move tools callers to @bitwarden/legacy-crypto by @quexten in #22364
- [PM-41874] refactor(crypto): move secrets-manager callers to @bitwarden/legacy-crypto by @quexten in #22370
- [PM-41874] refactor(crypto): move platform callers to @bitwarden/legacy-crypto by @quexten in #22369
- [PM-41874] refactor(crypto): move vault callers to @bitwarden/legacy-crypto by @quexten in #22365
- [PM-41684] Remove unused Autotype MVP IPC channels by @coltonhurst in #22285
- [PM-41801] Switch to using policyAppliesToUser$ for the Autotype Default Policy by @coltonhurst in #22322
- [PM-42196] Update Native Passkey Ownership by @coltonhurst in #22529
- refactor(auth): unlock via UnlockService when setting an initial password by @quexten in #22356
- [PM-41874] refactor(crypto): move billing callers to @bitwarden/legacy-crypto by @quexten in #22371
- [PM-41874] refactor(crypto): move auth callers to @bitwarden/legacy-crypto by @quexten in #22363
- refactor(key-management): read the user key via userKey$ by @quexten in #22353
- refactor(unlock): replace UserAutoUnlockKeyService with UnlockService by @quexten in #22359
- refactor(key-management): unlock via UnlockService in key connector conversion by @quexten in #22358
- [PM-41874] Remove legacy-crypto shims (platform) by @quexten in #22579
- chore(lock): Move LockService into libs/unlock and add lock/unlock source tracking by @quexten in #22539
- [PM-41874] Remove legacy-crypto shims (key management) by @quexten in #22578
- ci: Beta Appx manifest changes by @iinuwa in #22564
- Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22568
- Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22569
- refactor(auth): unlock via UnlockService during TDE JIT registration by @quexten in #22357
- Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22570
- Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22607
- refactor(crypto): drop electron key service by @quexten in #22601
- Sign Windows Beta Appx in CI by @iinuwa in #22563
- [PM-38187] Improve isSnapStore detection by @djsmith85 in #21195
- Bump client version(s) by @github-actions[bot] in #22608
📦 Dependency Updates
- Update sdk-internal to 0.2.0-main.956 by @bw-ghapp[bot] in #22146
- [deps] Platform: Update @types/node to v22.20.1 by @renovate[bot] in #22218
- Update sdk-internal to 0.2.0-main.967 by @bw-ghapp[bot] in #22326
- [deps]: Update dtolnay/rust-toolchain digest to
4360b52by @renovate[bot] in #22459 - [deps]: Update actions/stale action to v11 by @renovate[bot] in #22475
- Update sdk-internal to 0.2.0-main.970 by @bw-ghapp[bot] in #22442
- Update sdk-internal to 0.2.0-main.971 by @bw-ghapp[bot] in #22512
- [deps] Desktop Native: Update Rust crate serial_test to v4 by @renovate[bot] in #22469
- [deps] Platform: Update Rust crate serde_with to v3.22.0 by @renovate[bot] in #22462
- [deps]: Update Rust to v1.97.1 by @renovate[bot] in #22467
- Update sdk-internal to 0.2.0-main.978 by @bw-ghapp[bot] in #22518
- Update sdk-internal to 0.2.0-main.979 by @bw-ghapp[bot] in #22581
🎨 Other
- [AI-88] llm: Remove .claude/CONTRIBUTING.md by @SaintPatrck in #22532
New Contributors
- @thisisryanswift made their first contribution in #17764
- @hammadxcm made their first contribution in #21229
Full Changelog: https://github.com/bitwarden/clients/compare/web-v2026.8.0...web-v2026.8.1
bitwarden/server (bitwarden/server)
v2026.8.1: Version 2026.8.1
What's Changed
💙 Community Highlight
- [PM-41468] Fix thread-unsafe StringBuilder in Setup Helpers.Exec by @cttech-io in #8141
:shipit: Feature Development
- Auth/PM-41503 and PM-41533 - Registration - Add open org invite flow support by @JaredSnider-Bitwarden in #8159
- [PM-41268] Declare the PartialData cipher response field by @Hinton in #8114
- [PM-40209] Add PAM access claim and ManageAccessRules permission by @Hinton in #8160
- [PM-32211] fix private key before key rotation by @mzieniukbw in #7548
- [PM-40336] Access Rules: domain, persistence & schema by @Hinton in #7981
- [PM-40210] Add single + bulk PAM enable flows for AccessPam by @Hinton in #8161
- [PM-40211] Authorize Access Rule endpoints with IOrganizationRequirement by @Hinton in #8162
- [PM-40336] Access Rules: API by @Hinton in #7983
- [PM-40525] PAM access rule evaluation engine by @Hinton in #7992
- feat: wire-in key id on registration and key rotation flows by @quexten in #8164
- [PM-40526] Access Leasing: domain by @Hinton in #8001
- [PM-40526] Access Leasing: persistence & schema by @Hinton in #8002
- [PM-41472] feat: add bulk folder delete endpoint by @gbubemismith in #8157
- feat(vault): add key id validation by @quexten in #8184
- [PM-39455] Set Upgrade Tokens for Organizations by @mzieniukbw in #8158
- [PM-39455] Let the organization rotate the account recovery key by @mzieniukbw in #8174
- [PM-41871] Add Chrome extension beta to allowed passkey origins by @trmartin4 in #8197
- [PM-40640] Adjust error messages for Send policy enforcement by @mcamirault in #8196
- [PM-34809] Remove feature flag for policy drawers from server by @JaredScar in #8188
- [PM-29460] feat: Authenticate PricingClient to the pricing service by @amorask-bitwarden in #8054
- [PM-39979] Add full API support for Item-type Sends by @mcamirault in #8192
❗ Breaking Changes
- [PM-36225] Upgrade Stripe SDK to 52.1.0 by @sbrown-livefront in #7643
🐛 Bug fixes
- [SHOT-247] fix: Disable proxy for container healthchecks by @keithhubner in #8170
- Ensure seeder appsettings.{env}.json can be found by @Hinton in #8222
- [PM-5108] fix: Show all owners and admins in admin portal org view by @r-tome in #8099
- [SHOT-187] fix: Make database migration execution timeout configurable by @mimartin12 in #8143
- [PM-41951] sponsored families email template copy by @JaredScar in #8217
- fix(vault): skip key id validation for organization by @quexten in #8219
- [PM-40801] Add option for alternative DataProtection settings on FIPS nodes by @eligrubb in #8092
- PM-42152 - Open Org Invite Status Endpoint - Decode org name by @JaredSnider-Bitwarden in #8227
- [PM-40300]: Restrict Provider Users' Account Recovery by @sven-bitwarden in #8103
- [PM-40350] ManagePolicies should allow read-only access to claimed organization domains by @harr1424 in #8220
- [PM-22405] - Remove invalid users from invites by @jrmccannon in #8151
- [PM-42240] perms still returned for members who were previously custom by @JaredScar in #8244
⚙️ Maintenance
- [PM-40492] Regenerate NuGet lock files during version bump by @Hinton in #8097
- [BRE] Removing build workflow and Dockerfiles by @gitclonebrian in #8173
- [BRE-2162] ci(build): Trigger downstream build on release branches by @fntyler in #8155
- [PM-37320] refactor: consolidate AuthRequest update validation and remove dead code by @ike-kottlowski in #8051
- [PM-41451] Migrate last files off of
AssemblyHelpers.GetVersion()by @justindbaur in #8137 - Remove grype scanning by @sognefej in #8180
- [PM-34546] Add integration tests for Notifications POST /send endpoint by @justindbaur in #8171
- QA-2279: add OrganizationEventScene to the seeder by @awiester-bw in #8175
- [PM-32211] Database testing CI failures fix by @mzieniukbw in #8185
- [PM-34564] Remove Core & SharedWeb from icons by @justindbaur in #8181
- [PM-35601] Add TODO comments about future conditional validation by @rr-bw in #8153
- [PM-41787] Move two-factor integration tests into a CODEOWNERS-compatible path. by @enmande in #8172
- Document the AccessRuleId write contract on ICollectionRepository by @Hinton in #8186
- [BRE-2116] Checkout v7 privileged workflows by @brandonbiete in #8194
- [PM-41917] Add lit inline menu feature flag to server by @dan-livefront in #8198
- Allow seeder to create a Free org with Secrets Manager by @nthompson-bitwarden in #8187
- feat(seeder): add --account-age-days to seed aged individual users by @nthompson-bitwarden in #8201
- [PM-38270] perf: Speed up "claimed by organization" status checks on the Members page by @r-tome in #8125
- [PM-38269] refactor: remove redundant permissions round-trip in OrganizationUserUserDetailsQuery by @r-tome in #8119
- [PM-38272] fix: handle null or empty permissions in OrganizationUserResponseModel by @JaredScar in #8207
- [PM-38326] Utilize cache for UsePolicies by @JaredScar in #8205
- [PM-38271] Speed up load org data by running queries in parallel by @JaredScar in #8202
- [PM-39422] Remove obsolete properties for organization management compatibility by @JaredScar in #8206
- Add dev.playground seeder preset with role-based login emails by @Hinton in #8223
- [PM-39455] Reuse the connection and transaction during user key rotation by @mzieniukbw in #8165
- Auth/PM-41812 - Auth - New Org User Staged Status Audit - Comment changes only by @JaredSnider-Bitwarden in #8225
- Prepare IPushNotificationService for extraction into a push library by @justindbaur in #8199
- Bump version to 2026.8.1 by @github-actions[bot] in #8247
- [BRE-2166] Add metadata to container images by @vgrassia in #8241
- [PM-38329] policies stop converting policy data on every response by @JaredScar in #8204
📦 Dependency Updates
- [deps]: Update CommunityToolkit.Aspire.Hosting.Ngrok to v13.4.0 by @renovate[bot] in #8020
- [SHOT-251] Update Dockerfile to use Ubuntu 22.04 by @mimartin12 in #8183
- [deps]: Update jquery to v4 by @renovate[bot] in #6932
- [deps]: Update dotnet monorepo by @renovate[bot] in #8018
🎨 Other
- [AI-88] llm: Remove .claude/CONTRIBUTING.md by @SaintPatrck in #8233
New Contributors
- @cttech-io made their first contribution in #8141
Full Changelog: https://github.com/bitwarden/server/compare/v2026.8.0...v2026.8.1
Configuration
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
- If you want to rebase/retry this MR, check this box
This MR has been generated by Mend Renovate CLI.