chore(deps): update ghcr.io/mealie-recipes/mealie docker tag to v3.22.0 - #328
chore(deps): update ghcr.io/mealie-recipes/mealie docker tag to v3.22.0#328bde-dev wants to merge 1 commit into
Conversation
AI Assessment
AnalysisWhile v3.22.0 itself is a stable minor update with improvements and bug fixes, it builds upon v3.21.0 which introduced a breaking change for OIDC authentication. The homelab maintainer needs to verify: (1) whether OIDC is being used, (2) whether their identity provider emits email_verified claim, and (3) if not, whether they need to set the override environment variable. This is medium risk due to the pre-existing breaking change interaction, but the application is non-critical infrastructure. RecommendationNEEDS_REVIEW: Before merging, verify your OIDC configuration (if used). If you use OIDC authentication, confirm your identity provider emits the 'email_verified' claim, or ensure the OIDC_REQUIRES_EMAIL_VERIFICATION environment variable is set to 'false' in your deployment. If you don't use OIDC, this update is safe to apply as it includes improvements to recipe scraping and bug fixes. Analyzed by n8n AI Agent using Claude |
This PR contains the following updates:
v3.21.0→v3.22.0Release Notes
mealie-recipes/mealie (ghcr.io/mealie-recipes/mealie)
v3.22.0Compare Source
🍴🍴🍴🍴🍴🍴
The previous version of Mealie (v3.21.0) introduced a⚠️ BREAKING CHANGE⚠️ for instances using OIDC: Mealie now requires your OIDC provider to confirm the user's email address before allowing the login. This prevents an unverified, self-asserted email address from being used to match (and sign in) to an existing Mealie account.
If an identity provider does not emit the
email_verifiedclaim, logins now fail. If you cannot configure your identity provider to include theemail_verifiedclaim, you can setOIDC_REQUIRES_EMAIL_VERIFICATIONtofalse(this is not recommended per the above security concerns). See the docs for more details.🎉 Highlights
New to this release, many improvements have been made to make importing recipes more reliable. Mealie does a better job of looking like a real browser, rotates between several browser signatures, and retries more intelligently when a site pushes back. This works out of the box, with no configuration.
For sites sitting behind extra bot protection (such as Cloudflare) server admins have two additional controls:
Both require additional configuration to work. Mealie does not ship or manage either one. You supply the proxy, and host FlareSolverr yourself (it runs nicely as a sidecar container). See the configuration docs for the settings, setup details, and an example compose file.
✨ New features
🐛 Bug fixes
🧰 Maintenance
5 changes
🔨 Internal development
⬆️ Dependency updates
5 changes
🍴🍴🍴🍴🍴🍴
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.