What flipt-io/flipt shipped
Written by FoxPlug from public releases; not affiliated with Flipt. An automatic summary of the public release, pull request and commit data of github.com/flipt-io/flipt. Flipt did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Browser-based evaluation now works correctly behind externally managed origins by exempting evaluation and OFREP POST routes from cross-origin protection when authentication is excluded. Pull request #6608
- Management authorization is hardened with corrected branch operations and fail-closed list filtering for missing or denied scopes. Pull request #6567
- Three bugs in environment storage are fixed, including preventing pushed branches from replacing static environments and correcting stale-revision push retries. Pull request #6592
- Multi-document namespaces now preserve full SHA1 digests instead of truncating to 32 characters, fixing server-issued digest validation in streams. Pull request #6593
- Boolean evaluations now emit match attributes and format variants as true/false, with gRPC server spans enabled for ClickHouse analytics. Pull request #6604
- Authorization data decoding and context ticker leaks are fixed, preventing resource exhaustion during polling. Pull request #6561
- Deep links are restored after OIDC login in v2, fixing redirect loops that sent users back to login instead of their requested page. Pull request #6586
- Git storage now stores evaluation snapshots before publishing them, fixing a race condition in snapshot handling. Pull request #6605
Why it matters
This week addresses critical bugs in authentication flows, authorization enforcement, and multi-document snapshot handling. Browser-based evaluation, analytics accuracy, and environment management are now more reliable. These fixes resolve issues that affected real deployments across OIDC integration, cross-origin scenarios, and stream validation.
Changelog entry
- fix: respect auth exclusion in cross-origin protection - Evaluation and OFREP POST routes are now exempt from cross-origin protection when authentication is excluded, fixing 403 errors for browser-based evaluation Pull request #6608
- fix(authz): harden management authorization - Corrected authorization actions for branch create, propose, and delete; list filtering now fails closed for missing or denied scopes Pull request #6567
- fix: guard branched environments and stale-revision push retries - Prevents pushed branches from replacing static environments and fixes stale-revision push retry handling Pull request #6592
- fix(snapshot): keep full sha1 digest for multi-doc namespaces - Preserved full SHA1 digest instead of truncating to 32 characters for proper stream validation Pull request #6593
- fix(analytics): store boolean evaluation values as true/false - Boolean evaluations now emit match attributes with proper true/false formatting; gRPC spans enabled for ClickHouse Pull request #6604
- fix: auth data decoding and ticker leaks - Authorization data only returned on successful JSON unmarshaling; context cancellation now stops authorization and Git polling tickers Pull request #6561
- fix(ui): restore deep link after OIDC login in v2 - Users are now redirected to their originally requested page after OIDC login instead of the homepage Pull request #6586
- fix(storage/git): store evaluation snapshot before publishing it - Evaluation snapshots are now persisted before publication, eliminating a race condition Pull request #6605
This week: fixed browser evaluation behind external origins, hardened authorization for branch operations, and corrected SHA1 digest handling for multi-doc namespaces. Also patched ticker leaks and OIDC redirect loops.
Flipt's latest release addresses seven critical fixes spanning authentication, authorization, and storage. Browser-based evaluation now respects cross-origin boundaries correctly, branch authorization is hardened to prevent unintended replacements, and multi-document snapshots maintain full digest integrity. We've also eliminated resource leaks in authorization polling and restored OIDC login deep links. These changes improve reliability for production deployments using external identity providers and distributed flag management.
Week of September 14, 2026
What shipped
- Released v2.13.0 with per-service health readiness for gRPC management and evaluation, custom OIDC discovery URLs, claims mapping for non-standard ID tokens, and validation fixes. Release
- Added gRPC health services for management and evaluation that track snapshot readiness, starting at UNKNOWN and moving to SERVING when environments are ready. Pull request #6559
- Added support for custom discovery URLs in OIDC provider configuration for providers whose discovery documents are at non-standard paths. Pull request #6525
- Added
claims_mappingconfiguration to map non-standard OIDC provider claims to Flipt's expected session fields like email, name, picture, and sub. Pull request #6519 - Restored validation for versionless legacy feature files by retrying validation with an explicit version 1.5 when the original document lacks a version field. Pull request #6547
- Hardened offline license validation with deterministic test fixtures covering valid and invalid scenarios including file-key pairing, signature, TTL, and expiry checks. Pull request #6539
- Fixed boolean flag evaluation to return FLAG_DISABLED for disabled flags with no rollouts instead of DEFAULT_EVALUATION_REASON. Pull request #6515
- Fixed segment picker in flag rollouts to search by display name in addition to key when filtering options. Pull request #6550
- Restored deep links after OIDC login instead of always redirecting to the dashboard. Pull request #6518
- Configured Dependabot to skip vulnerability checks in examples and _tools directories to reduce noise. Pull request #6548
Why it matters
v2.13.0 brings enterprise authentication improvements for non-standard OIDC setups, health readiness tracking for service orchestration, and fixes for flag evaluation consistency. These changes address real operational needs in production deployments and improve reliability for teams using feature flags across distributed systems.
Changelog entry
- feat(grpc): per-service health readiness for management and evaluation Release
- fix(build): repair the go:modernize task Release
- fix(evaluation): return FLAG_DISABLED for disabled boolean flag with no rollouts Release
- feat(authn/oidc): support custom discovery URL for OIDC providers Pull request #6525
- feat(authn/oidc): add
claims_mappingfor non-standard ID token claims Pull request #6519 - fix: preserve validation of versionless legacy feature files Pull request #6547
- fix(license): enforce expiry consistently and harden offline license validation Pull request #6539
- fix(ui): match Combobox options by display name, not only key Pull request #6550
- fix(ui): restore deep link after OIDC login instead of landing on dashboard Pull request #6518
- ci: exclude examples and _tools from dependabot vulnerabilities checks Pull request #6548
Flipt v2.13.0 ships with custom OIDC discovery URLs, claims mapping for non-standard ID tokens, gRPC health readiness tracking, and fixes for flag evaluation and legacy file validation.
We released Flipt v2.13.0 today. This version adds support for custom OIDC discovery URLs and claims mapping to handle non-standard ID token claims from enterprise identity providers. We also shipped per-service gRPC health readiness tracking for management and evaluation services, hardened offline license validation, and fixed evaluation consistency for disabled flags. These improvements help teams integrate with diverse authentication systems and deploy Flipt reliably in orchestrated environments.