Márk Sági-Kazár
2fa0676a5e
Merge pull request from GHSA-gr79-9v6v-gc9r
...
bug: return initialConfig instead of empty tlsConfig
2 years ago
dependabot[bot]
bf10e77154
build(deps): bump github.com/coreos/go-oidc/v3 in /examples ( #3298 )
...
Bumps [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc ) from 3.7.0 to 3.9.0.
- [Release notes](https://github.com/coreos/go-oidc/releases )
- [Commits](https://github.com/coreos/go-oidc/compare/v3.7.0...v3.9.0 )
---
updated-dependencies:
- dependency-name: github.com/coreos/go-oidc/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Márk Sági-Kazár
c323df379a
Merge pull request #3276 from deckhouse/propagate-version-from-build-args
...
Propagate Dex version from build args
2 years ago
Márk Sági-Kazár
d7891d8364
Merge pull request #3268 from deckhouse/dependabot-for-example-app
...
Add dependabot for example app
2 years ago
Márk Sági-Kazár
e3a44c9e97
Merge pull request #3278 from deckhouse/featureflags-pkg
...
Introduce a dedicated pkg for featureflags
2 years ago
Márk Sági-Kazár
cd4604388d
Merge pull request #3280 from deckhouse/pin-dependencies
...
Pin actions and container image dependencies
2 years ago
Márk Sági-Kazár
1aa740cbd1
Merge pull request #3294 from dexidp/dependabot/go_modules/api/v2/google.golang.org/grpc-1.61.0
...
build(deps): bump google.golang.org/grpc from 1.60.1 to 1.61.0 in /api/v2
2 years ago
dependabot[bot]
285deafa5b
build(deps): bump google.golang.org/grpc in /api/v2
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.60.1 to 1.61.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.60.1...v1.61.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
ae6484585a
Merge pull request #3296 from dexidp/dependabot/go_modules/google.golang.org/grpc-1.61.0
...
build(deps): bump google.golang.org/grpc from 1.60.1 to 1.61.0
2 years ago
Márk Sági-Kazár
26e7876eb2
Merge pull request #3291 from dexidp/dependabot/github_actions/anchore/sbom-action-0.15.5
...
build(deps): bump anchore/sbom-action from 0.15.4 to 0.15.5
2 years ago
Márk Sági-Kazár
12eb47c491
Merge pull request #3293 from dexidp/gomplate-3-11-7
...
Bump gomplate to v3.11.7
2 years ago
dependabot[bot]
22899710c5
build(deps): bump google.golang.org/grpc from 1.60.1 to 1.61.0
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.60.1 to 1.61.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.60.1...v1.61.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Maksim Nabokikh
47b2268287
Bump gomplate to v3.11.7
...
Signed-off-by: Maksim Nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
a6f7f6648a
build(deps): bump anchore/sbom-action from 0.15.4 to 0.15.5
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.4 to 0.15.5.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](41f7a6c033...24b0d52385 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
11bea4d53c
build(deps): bump actions/dependency-review-action from 3.1.5 to 4.0.0 ( #3287 )
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 3.1.5 to 4.0.0.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](c74b580d73...4901385134 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
0c59579919
build(deps): bump anchore/sbom-action from 0.15.3 to 0.15.4 ( #3286 )
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.3 to 0.15.4.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](c7f031d924...41f7a6c033 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
bc8cbdbe93
build(deps): bump google.golang.org/api from 0.156.0 to 0.157.0 ( #3285 )
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
f0c41137a5
build(deps): bump github/codeql-action from 3.23.0 to 3.23.1 ( #3282 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.23.0 to 3.23.1.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e5f05b81d5...0b21cf2492 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
m.nabokikh
15511da591
Pin actions and container image dependencies
...
Images:
* builder
* stager
* gomplate
* base alpine
* base distroless
Actions:
* check required labels
* kind
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
Maksim Nabokikh
adde14ba41
Remove the expose call
...
Signed-off-by: Maksim Nabokikh <max.nabokih@gmail.com>
2 years ago
m.nabokikh
08348242a7
Introduce a dedicated pkg for featureflags
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
m.nabokikh
520ed3294c
Propagate Dex version from build args
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
5d64dc7a4c
build(deps): bump google.golang.org/api from 0.155.0 to 0.156.0 ( #3270 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.155.0 to 0.156.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.155.0...v0.156.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Tuomo Tanskanen
8cf9094871
bug: return initialConfig instead of empty tlsConfig
...
When TLS certificate reloading functionality was implemented and
released in Dex 2.37.0, added newTLSReloader() returns empty tlsConfig
and discards the provided, already configured tlsConfig. Server's with
empty tlsConfig override Go's sensible defaults, and starts serving Dex
over TLS 1.0 and TLS 1.1 in addition to Go's defaults TLS 1.2+.
TLS 1.0 and 1.1 are long deprecated and vulnerable, making this a
security risk. Server and its secrets are vulnerable to attackers.
2 years ago
Maksim Nabokikh
665a5b627c
Override OIDC provider discovered claims ( #3267 )
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
m.nabokikh
04643f6e97
Add dependabot for example app
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
231a97d0b7
build(deps): bump golang from 1.21.5-alpine3.18 to 1.21.6-alpine3.18 ( #3266 )
...
Bumps golang from 1.21.5-alpine3.18 to 1.21.6-alpine3.18.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
edc73f8de7
build(deps): bump golang.org/x/oauth2 from 0.15.0 to 0.16.0 ( #3263 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.15.0 to 0.16.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.15.0...v0.16.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Márk Sági-Kazár
92ce3644b6
Merge pull request #3264 from dexidp/dependabot/github_actions/github/codeql-action-3.23.0
...
build(deps): bump github/codeql-action from 3.22.12 to 3.23.0
2 years ago
dependabot[bot]
6ce2d877d8
build(deps): bump docker/metadata-action from 5.4.0 to 5.5.0 ( #3259 )
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 5.4.0 to 5.5.0.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](9dc751fe24...dbef88086f )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
22566677e0
build(deps): bump golang.org/x/crypto from 0.17.0 to 0.18.0 ( #3262 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.17.0 to 0.18.0.
- [Commits](https://github.com/golang/crypto/compare/v0.17.0...v0.18.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
a855881bd9
build(deps): bump aquasecurity/trivy-action from 0.16.0 to 0.16.1 ( #3253 )
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.16.0 to 0.16.1.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](91713af97d...d43c1f16c0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
d93d7b0087
build(deps): bump github.com/beevik/etree from 1.2.0 to 1.3.0 ( #3252 )
...
Bumps [github.com/beevik/etree](https://github.com/beevik/etree ) from 1.2.0 to 1.3.0.
- [Release notes](https://github.com/beevik/etree/releases )
- [Changelog](https://github.com/beevik/etree/blob/main/RELEASE_NOTES.md )
- [Commits](https://github.com/beevik/etree/compare/v1.2.0...v1.3.0 )
---
updated-dependencies:
- dependency-name: github.com/beevik/etree
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
86692dbb85
build(deps): bump anchore/sbom-action from 0.15.1 to 0.15.3 ( #3265 )
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.1 to 0.15.3.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](5ecf649a41...c7f031d924 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
3a95e2f3bf
build(deps): bump github/codeql-action from 3.22.12 to 3.23.0
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.22.12 to 3.23.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](012739e508...e5f05b81d5 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
071e30dc8a
build(deps): bump google.golang.org/api from 0.154.0 to 0.155.0 ( #3257 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.154.0 to 0.155.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.154.0...v0.155.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
83e3ee1e17
build(deps): bump actions/dependency-review-action from 3.1.4 to 3.1.5 ( #3256 )
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](01bc87099b...c74b580d73 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Yan Song Liu
6cdce074d2
Add support for linux/s390x ( #3189 )
...
Signed-off-by: Yan Song Liu <lysliu@cn.ibm.com>
2 years ago
Maksim Nabokikh
85d4261aa9
Bump dependencies ent v0.12.5, protobuf v1.32.0 ( #3249 )
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
Maksim Nabokikh
b2cc58535a
Remote user-facing changes section ( #3248 )
...
It was a copy-paste from Kubernetes, which we never used. As of today, to compose release messages, we use GitHub mechanism that uses PR titles and commits.
Signed-off-by: Maksim Nabokikh <maksim.nabokikh@flant.com>
2 years ago
Maksim Nabokikh
4f307d70c6
Fix lint errors after merging AllowedHeaders feature ( #3247 )
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
Matt Pryor
366e53c1b6
Add support for extra claims to authproxy connector ( #2851 )
...
Signed-off-by: Matt Pryor <matt@stackhpc.com>
2 years ago
Josiah Evans
dce31d82ea
feat: Add configurable CORS Headers ( #3114 )
...
Signed-off-by: Josiah Evans <josiah.evans@lunit.io>
2 years ago
dependabot[bot]
68d2a88ffe
build(deps): bump github.com/prometheus/client_golang ( #3246 )
...
Bumps [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang ) from 1.17.0 to 1.18.0.
- [Release notes](https://github.com/prometheus/client_golang/releases )
- [Changelog](https://github.com/prometheus/client_golang/blob/v1.18.0/CHANGELOG.md )
- [Commits](https://github.com/prometheus/client_golang/compare/v1.17.0...v1.18.0 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/client_golang
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
6725d58002
build(deps): bump github.com/coreos/go-oidc/v3 from 3.7.0 to 3.9.0 ( #3238 )
...
Bumps [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc ) from 3.7.0 to 3.9.0.
- [Release notes](https://github.com/coreos/go-oidc/releases )
- [Commits](https://github.com/coreos/go-oidc/compare/v3.7.0...v3.9.0 )
---
updated-dependencies:
- dependency-name: github.com/coreos/go-oidc/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
9be01eb662
build(deps): bump github.com/gorilla/mux from 1.8.0 to 1.8.1 ( #3239 )
...
Bumps [github.com/gorilla/mux](https://github.com/gorilla/mux ) from 1.8.0 to 1.8.1.
- [Release notes](https://github.com/gorilla/mux/releases )
- [Commits](https://github.com/gorilla/mux/compare/v1.8.0...v1.8.1 )
---
updated-dependencies:
- dependency-name: github.com/gorilla/mux
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
1043ab3a03
build(deps): bump actions/setup-go from 4.1.0 to 5.0.0 ( #3236 )
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 4.1.0 to 5.0.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](93397bea11...0c52d547c9 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
32abec2ddb
build(deps): bump google.golang.org/grpc from 1.59.0 to 1.60.1 ( #3241 )
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.59.0 to 1.60.1.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.59.0...v1.60.1 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
ba383d9606
build(deps): bump docker/metadata-action from 5.0.0 to 5.4.0 ( #3235 )
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 5.0.0 to 5.4.0.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](96383f4557...9dc751fe24 )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Greg Burton
fe3303578c
Patch gomplate to v3.11.6 ( #3234 )
...
Signed-off-by: Greg Burton <9094087+gburton1@users.noreply.github.com>
Co-authored-by: Greg Burton <gburton@taser.com>
2 years ago