Márk Sági-Kazár
c333aeec3c
Merge pull request #3462 from dexidp/dependabot/github_actions/docker/setup-buildx-action-3.3.0
...
build(deps): bump docker/setup-buildx-action from 3.2.0 to 3.3.0
2 years ago
Márk Sági-Kazár
d7fb98e70a
Merge pull request #3469 from dexidp/dependabot/docker/distroless/static-debian12-e9ac71e
...
build(deps): bump distroless/static-debian12 from `42c8865` to `e9ac71e`
2 years ago
Márk Sági-Kazár
d2cce5d92f
Merge pull request #3472 from dexidp/dependabot/github_actions/sigstore/cosign-installer-3.5.0
...
build(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0
2 years ago
Márk Sági-Kazár
c240288208
Merge pull request #3483 from dexidp/dependabot/go_modules/api/v2/go_modules-b9ac453758
...
build(deps): bump golang.org/x/net from 0.20.0 to 0.23.0 in /api/v2 in the go_modules group
2 years ago
Márk Sági-Kazár
f9c12cbd05
Merge pull request #3497 from dexidp/dependabot/github_actions/anchore/sbom-action-0.15.11
...
build(deps): bump anchore/sbom-action from 0.15.9 to 0.15.11
2 years ago
Márk Sági-Kazár
c1caa2f93e
Merge pull request #3508 from dexidp/dependabot/go_modules/examples/golang.org/x/oauth2-0.20.0
...
build(deps): bump golang.org/x/oauth2 from 0.19.0 to 0.20.0 in /examples
2 years ago
Márk Sági-Kazár
4129017d08
Merge pull request #3512 from dexidp/dependabot/github_actions/aquasecurity/trivy-action-0.20.0
...
build(deps): bump aquasecurity/trivy-action from 0.18.0 to 0.20.0
2 years ago
Márk Sági-Kazár
3e13398b55
Merge pull request #3514 from dexidp/dependabot/docker/golang-1.22.3-alpine3.18
...
build(deps): bump golang from 1.22.2-alpine3.18 to 1.22.3-alpine3.18
2 years ago
Márk Sági-Kazár
bdb2836838
Merge pull request #3516 from dexidp/dependabot/go_modules/google.golang.org/api-0.179.0
...
build(deps): bump google.golang.org/api from 0.172.0 to 0.179.0
2 years ago
dependabot[bot]
5e7fb0219b
build(deps): bump google.golang.org/api from 0.172.0 to 0.179.0
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.172.0 to 0.179.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.172.0...v0.179.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
3a541ebf7d
build(deps): bump golang from 1.22.2-alpine3.18 to 1.22.3-alpine3.18
...
Bumps golang from 1.22.2-alpine3.18 to 1.22.3-alpine3.18.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
2c74baabab
build(deps): bump aquasecurity/trivy-action from 0.18.0 to 0.20.0
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.18.0 to 0.20.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](062f259268...b2933f565d )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
d3ae7e2372
build(deps): bump golang.org/x/oauth2 from 0.19.0 to 0.20.0 in /examples
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.19.0 to 0.20.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.19.0...v0.20.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
d5b22a6b65
build(deps): bump anchore/sbom-action from 0.15.9 to 0.15.11
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.9 to 0.15.11.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](9fece9e200...7ccf588e3c )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
c96c493bca
build(deps): bump golang.org/x/net in /api/v2 in the go_modules group
...
Bumps the go_modules group in /api/v2 with 1 update: [golang.org/x/net](https://github.com/golang/net ).
Updates `golang.org/x/net` from 0.20.0 to 0.23.0
- [Commits](https://github.com/golang/net/compare/v0.20.0...v0.23.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: indirect
dependency-group: go_modules
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Abhisek Datta
677ab36020
feat: Add support for configurable prompt type for Google connector ( #3475 )
...
Signed-off-by: abhisek <abhisek.datta@gmail.com>
Signed-off-by: Maksim Nabokikh <max.nabokih@gmail.com>
Co-authored-by: Maksim Nabokikh <max.nabokih@gmail.com>
2 years ago
Michele Mastropietro
1ca4583920
fix k8s guide link in README ( #3474 )
...
Signed-off-by: Michele Mastropietro <elehcim@users.noreply.github.com>
2 years ago
dependabot[bot]
7cd76c8c79
build(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from 3.4.0 to 3.5.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](e1523de757...59acb6260d )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Maksim Nabokikh
3705207f01
Do not escape password for LDAP connectors ( #3470 )
...
With the change introduced in https://github.com/dexidp/dex/pull/3372 Dex declines passwords that contain special characters. Since password is not passed to any kind of filters, it is safe to pass a password as is. No LDAP query injections are possible.
This commit is a revert of password escaping.
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
cd693d3605
build(deps): bump distroless/static-debian12 from `42c8865` to `e9ac71e`
...
Bumps distroless/static-debian12 from `42c8865` to `e9ac71e`.
---
updated-dependencies:
- dependency-name: distroless/static-debian12
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
b13f5acb5f
build(deps): bump docker/setup-buildx-action from 3.2.0 to 3.3.0
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 3.2.0 to 3.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](2b51285047...d70bba72b1 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
98980cad79
Merge pull request #3438 from dexidp/dependabot/go_modules/google.golang.org/api-0.172.0
...
build(deps): bump google.golang.org/api from 0.171.0 to 0.172.0
2 years ago
Márk Sági-Kazár
ca27d3c1fd
Merge pull request #3442 from dexidp/dependabot/go_modules/go.etcd.io/etcd/client/v3-3.5.13
...
build(deps): bump go.etcd.io/etcd/client/v3 from 3.5.12 to 3.5.13
2 years ago
Márk Sági-Kazár
4078a17e02
Merge pull request #3428 from dexidp/dependabot/github_actions/docker/setup-buildx-action-3.2.0
...
build(deps): bump docker/setup-buildx-action from 3.1.0 to 3.2.0
2 years ago
Márk Sági-Kazár
231481fbc0
Merge pull request #3430 from dexidp/dependabot/github_actions/mheap/github-action-required-labels-5.4.0
...
build(deps): bump mheap/github-action-required-labels from 5.3.0 to 5.4.0
2 years ago
dependabot[bot]
68d8ad01ac
build(deps): bump google.golang.org/api from 0.171.0 to 0.172.0
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.171.0 to 0.172.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.171.0...v0.172.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
e53e962b08
Merge pull request #3434 from dexidp/dependabot/go_modules/github.com/go-sql-driver/mysql-1.8.1
...
build(deps): bump github.com/go-sql-driver/mysql from 1.8.0 to 1.8.1
2 years ago
dependabot[bot]
090d3b02cb
build(deps): bump go.etcd.io/etcd/client/v3 from 3.5.12 to 3.5.13
...
Bumps [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd ) from 3.5.12 to 3.5.13.
- [Release notes](https://github.com/etcd-io/etcd/releases )
- [Commits](https://github.com/etcd-io/etcd/compare/v3.5.12...v3.5.13 )
---
updated-dependencies:
- dependency-name: go.etcd.io/etcd/client/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
b2e0f96010
Merge pull request #3435 from dexidp/dependabot/github_actions/actions/dependency-review-action-4.2.5
...
build(deps): bump actions/dependency-review-action from 4.1.3 to 4.2.5
2 years ago
Márk Sági-Kazár
f1772cb3e3
Merge pull request #3440 from dexidp/dependabot/docker/distroless/static-debian12-42c8865
...
build(deps): bump distroless/static-debian12 from `67686c9` to `42c8865`
2 years ago
Márk Sági-Kazár
3b1b174794
Merge pull request #3443 from dexidp/dependabot/go_modules/go.etcd.io/etcd/client/pkg/v3-3.5.13
...
build(deps): bump go.etcd.io/etcd/client/pkg/v3 from 3.5.12 to 3.5.13
2 years ago
Márk Sági-Kazár
e5123f14dd
Merge pull request #3446 from dexidp/dependabot/docker/golang-1.22.2-alpine3.18
...
build(deps): bump golang from 1.22.1-alpine3.18 to 1.22.2-alpine3.18
2 years ago
Márk Sági-Kazár
02611104e3
Merge pull request #3451 from dexidp/dependabot/go_modules/golang.org/x/net-0.24.0
...
build(deps): bump golang.org/x/net from 0.22.0 to 0.24.0
2 years ago
Márk Sági-Kazár
b12883c208
Merge pull request #3452 from dexidp/dependabot/go_modules/examples/golang.org/x/oauth2-0.19.0
...
build(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 in /examples
2 years ago
Márk Sági-Kazár
f88b7cf375
Merge pull request #3457 from dexidp/dependabot/github_actions/github/codeql-action-3.24.10
...
build(deps): bump github/codeql-action from 3.24.8 to 3.24.10
2 years ago
Márk Sági-Kazár
a3d3f3bcf6
Merge pull request #3458 from cpanato/update-cosign
...
use the default cosign version from the action
2 years ago
dependabot[bot]
b740a265e3
build(deps): bump mheap/github-action-required-labels
...
Bumps [mheap/github-action-required-labels](https://github.com/mheap/github-action-required-labels ) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/mheap/github-action-required-labels/releases )
- [Commits](80a96a4863...132879b972 )
---
updated-dependencies:
- dependency-name: mheap/github-action-required-labels
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
65c18a1c1f
Merge pull request #3459 from cpanato/update-ci
...
chore: run release note label ci only in dexidp/dex repo not in forks
2 years ago
cpanato
76f2c8b481
run release note label ci only in dexidp/dex repo not in forks
...
Signed-off-by: cpanato <ctadeu@gmail.com>
2 years ago
cpanato
84954fce7a
use the default cosign version from the action
...
Signed-off-by: cpanato <ctadeu@gmail.com>
2 years ago
dependabot[bot]
af38034abc
build(deps): bump github/codeql-action from 3.24.8 to 3.24.10
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.24.8 to 3.24.10.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](05963f47d8...4355270be1 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
65d8125fcf
build(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 in /examples
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.18.0 to 0.19.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.18.0...v0.19.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
9222b7098b
build(deps): bump golang.org/x/net from 0.22.0 to 0.24.0
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.22.0 to 0.24.0.
- [Commits](https://github.com/golang/net/compare/v0.22.0...v0.24.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
b40f964a47
build(deps): bump golang from 1.22.1-alpine3.18 to 1.22.2-alpine3.18
...
Bumps golang from 1.22.1-alpine3.18 to 1.22.2-alpine3.18.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
1e76411291
build(deps): bump go.etcd.io/etcd/client/pkg/v3 from 3.5.12 to 3.5.13
...
Bumps [go.etcd.io/etcd/client/pkg/v3](https://github.com/etcd-io/etcd ) from 3.5.12 to 3.5.13.
- [Release notes](https://github.com/etcd-io/etcd/releases )
- [Commits](https://github.com/etcd-io/etcd/compare/v3.5.12...v3.5.13 )
---
updated-dependencies:
- dependency-name: go.etcd.io/etcd/client/pkg/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Romain Caire
86e92aaf1a
fix: wrong error code returned in case of inactive token ( #3441 )
...
Signed-off-by: Romain Caire <super.cairos@gmail.com>
2 years ago
dependabot[bot]
3b61d9a78f
build(deps): bump distroless/static-debian12 from `67686c9` to `42c8865`
...
Bumps distroless/static-debian12 from `67686c9` to `42c8865`.
---
updated-dependencies:
- dependency-name: distroless/static-debian12
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Denys Romanenko
7225198ae7
Update max length of kubernetes object to fit kubernetes policy ( #3439 )
...
Signed-off-by: Denys Romanenko <65756796+RomanenkoDenys@users.noreply.github.com>
Signed-off-by: Maksim Nabokikh <max.nabokih@gmail.com>
Co-authored-by: Maksim Nabokikh <max.nabokih@gmail.com>
2 years ago
Hayden B
38cef0c0c0
Update Distroless to Debian 12 ( #3432 )
...
gcr.io/distroless/static is Debian 10, which is quite outdated. Updated to the Debian 12 version of the static image, and used the nonroot tag since the root user isn't needed.
We've been running a version of Dex in production with this image without issue.
Signed-off-by: Hayden B <hblauzvern@google.com>
2 years ago
Romain Caire
8755308759
[RFC7662] Add introspect endpoint to introspect access & refresh token ( #3404 )
...
Signed-off-by: Romain Caire <super.cairos@gmail.com>
2 years ago