Márk Sági-Kazár
7ca42d7f6e
Merge pull request #3297 from dexidp/dependabot/go_modules/examples/golang.org/x/oauth2-0.16.0
...
build(deps): bump golang.org/x/oauth2 from 0.13.0 to 0.16.0 in /examples
2 years ago
dependabot[bot]
205d18dc78
build(deps): bump golang.org/x/oauth2 from 0.13.0 to 0.16.0 in /examples
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.13.0 to 0.16.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.13.0...v0.16.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
392a8edc74
Merge pull request #3299 from dexidp/dependabot/go_modules/examples/github.com/spf13/cobra-1.8.0
...
build(deps): bump github.com/spf13/cobra from 1.7.0 to 1.8.0 in /examples
2 years ago
Márk Sági-Kazár
83ed15e62d
Merge pull request #3301 from dexidp/dependabot/docker/golang-3bd4475
...
build(deps): bump golang from `869193e` to `3bd4475`
2 years ago
dependabot[bot]
08439534f2
build(deps): bump github.com/spf13/cobra in /examples
...
Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra ) from 1.7.0 to 1.8.0.
- [Release notes](https://github.com/spf13/cobra/releases )
- [Commits](https://github.com/spf13/cobra/compare/v1.7.0...v1.8.0 )
---
updated-dependencies:
- dependency-name: github.com/spf13/cobra
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
9a64f2c879
Merge pull request #3300 from dexidp/dependabot/go_modules/examples/google.golang.org/grpc-1.61.0
...
build(deps): bump google.golang.org/grpc from 1.59.0 to 1.61.0 in /examples
2 years ago
Márk Sági-Kazár
dff6f51533
Merge pull request #3269 from deckhouse/add-cosign
...
Sign container images
2 years ago
Márk Sági-Kazár
2fa0676a5e
Merge pull request from GHSA-gr79-9v6v-gc9r
...
bug: return initialConfig instead of empty tlsConfig
2 years ago
dependabot[bot]
bf10e77154
build(deps): bump github.com/coreos/go-oidc/v3 in /examples ( #3298 )
...
Bumps [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc ) from 3.7.0 to 3.9.0.
- [Release notes](https://github.com/coreos/go-oidc/releases )
- [Commits](https://github.com/coreos/go-oidc/compare/v3.7.0...v3.9.0 )
---
updated-dependencies:
- dependency-name: github.com/coreos/go-oidc/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
55861a0c9b
build(deps): bump golang from `869193e` to `3bd4475`
...
Bumps golang from `869193e` to `3bd4475`.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
5c22ad5e3d
build(deps): bump google.golang.org/grpc in /examples
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.59.0 to 1.61.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.59.0...v1.61.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
c323df379a
Merge pull request #3276 from deckhouse/propagate-version-from-build-args
...
Propagate Dex version from build args
2 years ago
Márk Sági-Kazár
d7891d8364
Merge pull request #3268 from deckhouse/dependabot-for-example-app
...
Add dependabot for example app
2 years ago
Márk Sági-Kazár
e3a44c9e97
Merge pull request #3278 from deckhouse/featureflags-pkg
...
Introduce a dedicated pkg for featureflags
2 years ago
Márk Sági-Kazár
cd4604388d
Merge pull request #3280 from deckhouse/pin-dependencies
...
Pin actions and container image dependencies
2 years ago
Márk Sági-Kazár
1aa740cbd1
Merge pull request #3294 from dexidp/dependabot/go_modules/api/v2/google.golang.org/grpc-1.61.0
...
build(deps): bump google.golang.org/grpc from 1.60.1 to 1.61.0 in /api/v2
2 years ago
dependabot[bot]
285deafa5b
build(deps): bump google.golang.org/grpc in /api/v2
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.60.1 to 1.61.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.60.1...v1.61.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
ae6484585a
Merge pull request #3296 from dexidp/dependabot/go_modules/google.golang.org/grpc-1.61.0
...
build(deps): bump google.golang.org/grpc from 1.60.1 to 1.61.0
2 years ago
Márk Sági-Kazár
26e7876eb2
Merge pull request #3291 from dexidp/dependabot/github_actions/anchore/sbom-action-0.15.5
...
build(deps): bump anchore/sbom-action from 0.15.4 to 0.15.5
2 years ago
Márk Sági-Kazár
12eb47c491
Merge pull request #3293 from dexidp/gomplate-3-11-7
...
Bump gomplate to v3.11.7
2 years ago
dependabot[bot]
22899710c5
build(deps): bump google.golang.org/grpc from 1.60.1 to 1.61.0
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.60.1 to 1.61.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.60.1...v1.61.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Maksim Nabokikh
47b2268287
Bump gomplate to v3.11.7
...
Signed-off-by: Maksim Nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
a6f7f6648a
build(deps): bump anchore/sbom-action from 0.15.4 to 0.15.5
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.4 to 0.15.5.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](41f7a6c033...24b0d52385 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
11bea4d53c
build(deps): bump actions/dependency-review-action from 3.1.5 to 4.0.0 ( #3287 )
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 3.1.5 to 4.0.0.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](c74b580d73...4901385134 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
0c59579919
build(deps): bump anchore/sbom-action from 0.15.3 to 0.15.4 ( #3286 )
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.3 to 0.15.4.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](c7f031d924...41f7a6c033 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
bc8cbdbe93
build(deps): bump google.golang.org/api from 0.156.0 to 0.157.0 ( #3285 )
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
f0c41137a5
build(deps): bump github/codeql-action from 3.23.0 to 3.23.1 ( #3282 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.23.0 to 3.23.1.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e5f05b81d5...0b21cf2492 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
m.nabokikh
15511da591
Pin actions and container image dependencies
...
Images:
* builder
* stager
* gomplate
* base alpine
* base distroless
Actions:
* check required labels
* kind
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
Maksim Nabokikh
adde14ba41
Remove the expose call
...
Signed-off-by: Maksim Nabokikh <max.nabokih@gmail.com>
2 years ago
m.nabokikh
08348242a7
Introduce a dedicated pkg for featureflags
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
m.nabokikh
520ed3294c
Propagate Dex version from build args
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
5d64dc7a4c
build(deps): bump google.golang.org/api from 0.155.0 to 0.156.0 ( #3270 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.155.0 to 0.156.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.155.0...v0.156.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Tuomo Tanskanen
8cf9094871
bug: return initialConfig instead of empty tlsConfig
...
When TLS certificate reloading functionality was implemented and
released in Dex 2.37.0, added newTLSReloader() returns empty tlsConfig
and discards the provided, already configured tlsConfig. Server's with
empty tlsConfig override Go's sensible defaults, and starts serving Dex
over TLS 1.0 and TLS 1.1 in addition to Go's defaults TLS 1.2+.
TLS 1.0 and 1.1 are long deprecated and vulnerable, making this a
security risk. Server and its secrets are vulnerable to attackers.
2 years ago
m.nabokikh
d0189b0556
Sign container images
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
Maksim Nabokikh
665a5b627c
Override OIDC provider discovered claims ( #3267 )
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
m.nabokikh
04643f6e97
Add dependabot for example app
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
231a97d0b7
build(deps): bump golang from 1.21.5-alpine3.18 to 1.21.6-alpine3.18 ( #3266 )
...
Bumps golang from 1.21.5-alpine3.18 to 1.21.6-alpine3.18.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
edc73f8de7
build(deps): bump golang.org/x/oauth2 from 0.15.0 to 0.16.0 ( #3263 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.15.0 to 0.16.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.15.0...v0.16.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Márk Sági-Kazár
92ce3644b6
Merge pull request #3264 from dexidp/dependabot/github_actions/github/codeql-action-3.23.0
...
build(deps): bump github/codeql-action from 3.22.12 to 3.23.0
2 years ago
dependabot[bot]
6ce2d877d8
build(deps): bump docker/metadata-action from 5.4.0 to 5.5.0 ( #3259 )
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 5.4.0 to 5.5.0.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](9dc751fe24...dbef88086f )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
22566677e0
build(deps): bump golang.org/x/crypto from 0.17.0 to 0.18.0 ( #3262 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.17.0 to 0.18.0.
- [Commits](https://github.com/golang/crypto/compare/v0.17.0...v0.18.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
a855881bd9
build(deps): bump aquasecurity/trivy-action from 0.16.0 to 0.16.1 ( #3253 )
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.16.0 to 0.16.1.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](91713af97d...d43c1f16c0 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
d93d7b0087
build(deps): bump github.com/beevik/etree from 1.2.0 to 1.3.0 ( #3252 )
...
Bumps [github.com/beevik/etree](https://github.com/beevik/etree ) from 1.2.0 to 1.3.0.
- [Release notes](https://github.com/beevik/etree/releases )
- [Changelog](https://github.com/beevik/etree/blob/main/RELEASE_NOTES.md )
- [Commits](https://github.com/beevik/etree/compare/v1.2.0...v1.3.0 )
---
updated-dependencies:
- dependency-name: github.com/beevik/etree
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
86692dbb85
build(deps): bump anchore/sbom-action from 0.15.1 to 0.15.3 ( #3265 )
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.1 to 0.15.3.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](5ecf649a41...c7f031d924 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
3a95e2f3bf
build(deps): bump github/codeql-action from 3.22.12 to 3.23.0
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.22.12 to 3.23.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](012739e508...e5f05b81d5 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
071e30dc8a
build(deps): bump google.golang.org/api from 0.154.0 to 0.155.0 ( #3257 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.154.0 to 0.155.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.154.0...v0.155.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
83e3ee1e17
build(deps): bump actions/dependency-review-action from 3.1.4 to 3.1.5 ( #3256 )
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](01bc87099b...c74b580d73 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
Yan Song Liu
6cdce074d2
Add support for linux/s390x ( #3189 )
...
Signed-off-by: Yan Song Liu <lysliu@cn.ibm.com>
2 years ago
Maksim Nabokikh
85d4261aa9
Bump dependencies ent v0.12.5, protobuf v1.32.0 ( #3249 )
...
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
Maksim Nabokikh
b2cc58535a
Remote user-facing changes section ( #3248 )
...
It was a copy-paste from Kubernetes, which we never used. As of today, to compose release messages, we use GitHub mechanism that uses PR titles and commits.
Signed-off-by: Maksim Nabokikh <maksim.nabokikh@flant.com>
2 years ago