dependabot[bot]
2c74baabab
build(deps): bump aquasecurity/trivy-action from 0.18.0 to 0.20.0
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.18.0 to 0.20.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](062f259268...b2933f565d )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
d3ae7e2372
build(deps): bump golang.org/x/oauth2 from 0.19.0 to 0.20.0 in /examples
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.19.0 to 0.20.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.19.0...v0.20.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
d5b22a6b65
build(deps): bump anchore/sbom-action from 0.15.9 to 0.15.11
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.15.9 to 0.15.11.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Commits](9fece9e200...7ccf588e3c )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
c96c493bca
build(deps): bump golang.org/x/net in /api/v2 in the go_modules group
...
Bumps the go_modules group in /api/v2 with 1 update: [golang.org/x/net](https://github.com/golang/net ).
Updates `golang.org/x/net` from 0.20.0 to 0.23.0
- [Commits](https://github.com/golang/net/compare/v0.20.0...v0.23.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: indirect
dependency-group: go_modules
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Abhisek Datta
677ab36020
feat: Add support for configurable prompt type for Google connector ( #3475 )
...
Signed-off-by: abhisek <abhisek.datta@gmail.com>
Signed-off-by: Maksim Nabokikh <max.nabokih@gmail.com>
Co-authored-by: Maksim Nabokikh <max.nabokih@gmail.com>
2 years ago
Michele Mastropietro
1ca4583920
fix k8s guide link in README ( #3474 )
...
Signed-off-by: Michele Mastropietro <elehcim@users.noreply.github.com>
2 years ago
dependabot[bot]
7cd76c8c79
build(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from 3.4.0 to 3.5.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](e1523de757...59acb6260d )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Maksim Nabokikh
3705207f01
Do not escape password for LDAP connectors ( #3470 )
...
With the change introduced in https://github.com/dexidp/dex/pull/3372 Dex declines passwords that contain special characters. Since password is not passed to any kind of filters, it is safe to pass a password as is. No LDAP query injections are possible.
This commit is a revert of password escaping.
Signed-off-by: m.nabokikh <maksim.nabokikh@flant.com>
2 years ago
dependabot[bot]
cd693d3605
build(deps): bump distroless/static-debian12 from `42c8865` to `e9ac71e`
...
Bumps distroless/static-debian12 from `42c8865` to `e9ac71e`.
---
updated-dependencies:
- dependency-name: distroless/static-debian12
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
b13f5acb5f
build(deps): bump docker/setup-buildx-action from 3.2.0 to 3.3.0
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 3.2.0 to 3.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](2b51285047...d70bba72b1 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
98980cad79
Merge pull request #3438 from dexidp/dependabot/go_modules/google.golang.org/api-0.172.0
...
build(deps): bump google.golang.org/api from 0.171.0 to 0.172.0
2 years ago
Márk Sági-Kazár
ca27d3c1fd
Merge pull request #3442 from dexidp/dependabot/go_modules/go.etcd.io/etcd/client/v3-3.5.13
...
build(deps): bump go.etcd.io/etcd/client/v3 from 3.5.12 to 3.5.13
2 years ago
Márk Sági-Kazár
4078a17e02
Merge pull request #3428 from dexidp/dependabot/github_actions/docker/setup-buildx-action-3.2.0
...
build(deps): bump docker/setup-buildx-action from 3.1.0 to 3.2.0
2 years ago
Márk Sági-Kazár
231481fbc0
Merge pull request #3430 from dexidp/dependabot/github_actions/mheap/github-action-required-labels-5.4.0
...
build(deps): bump mheap/github-action-required-labels from 5.3.0 to 5.4.0
2 years ago
dependabot[bot]
68d8ad01ac
build(deps): bump google.golang.org/api from 0.171.0 to 0.172.0
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.171.0 to 0.172.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.171.0...v0.172.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
e53e962b08
Merge pull request #3434 from dexidp/dependabot/go_modules/github.com/go-sql-driver/mysql-1.8.1
...
build(deps): bump github.com/go-sql-driver/mysql from 1.8.0 to 1.8.1
2 years ago
dependabot[bot]
090d3b02cb
build(deps): bump go.etcd.io/etcd/client/v3 from 3.5.12 to 3.5.13
...
Bumps [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd ) from 3.5.12 to 3.5.13.
- [Release notes](https://github.com/etcd-io/etcd/releases )
- [Commits](https://github.com/etcd-io/etcd/compare/v3.5.12...v3.5.13 )
---
updated-dependencies:
- dependency-name: go.etcd.io/etcd/client/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
b2e0f96010
Merge pull request #3435 from dexidp/dependabot/github_actions/actions/dependency-review-action-4.2.5
...
build(deps): bump actions/dependency-review-action from 4.1.3 to 4.2.5
2 years ago
Márk Sági-Kazár
f1772cb3e3
Merge pull request #3440 from dexidp/dependabot/docker/distroless/static-debian12-42c8865
...
build(deps): bump distroless/static-debian12 from `67686c9` to `42c8865`
2 years ago
Márk Sági-Kazár
3b1b174794
Merge pull request #3443 from dexidp/dependabot/go_modules/go.etcd.io/etcd/client/pkg/v3-3.5.13
...
build(deps): bump go.etcd.io/etcd/client/pkg/v3 from 3.5.12 to 3.5.13
2 years ago
Márk Sági-Kazár
e5123f14dd
Merge pull request #3446 from dexidp/dependabot/docker/golang-1.22.2-alpine3.18
...
build(deps): bump golang from 1.22.1-alpine3.18 to 1.22.2-alpine3.18
2 years ago
Márk Sági-Kazár
02611104e3
Merge pull request #3451 from dexidp/dependabot/go_modules/golang.org/x/net-0.24.0
...
build(deps): bump golang.org/x/net from 0.22.0 to 0.24.0
2 years ago
Márk Sági-Kazár
b12883c208
Merge pull request #3452 from dexidp/dependabot/go_modules/examples/golang.org/x/oauth2-0.19.0
...
build(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 in /examples
2 years ago
Márk Sági-Kazár
f88b7cf375
Merge pull request #3457 from dexidp/dependabot/github_actions/github/codeql-action-3.24.10
...
build(deps): bump github/codeql-action from 3.24.8 to 3.24.10
2 years ago
Márk Sági-Kazár
a3d3f3bcf6
Merge pull request #3458 from cpanato/update-cosign
...
use the default cosign version from the action
2 years ago
dependabot[bot]
b740a265e3
build(deps): bump mheap/github-action-required-labels
...
Bumps [mheap/github-action-required-labels](https://github.com/mheap/github-action-required-labels ) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/mheap/github-action-required-labels/releases )
- [Commits](80a96a4863...132879b972 )
---
updated-dependencies:
- dependency-name: mheap/github-action-required-labels
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Márk Sági-Kazár
65c18a1c1f
Merge pull request #3459 from cpanato/update-ci
...
chore: run release note label ci only in dexidp/dex repo not in forks
2 years ago
cpanato
76f2c8b481
run release note label ci only in dexidp/dex repo not in forks
...
Signed-off-by: cpanato <ctadeu@gmail.com>
2 years ago
cpanato
84954fce7a
use the default cosign version from the action
...
Signed-off-by: cpanato <ctadeu@gmail.com>
2 years ago
dependabot[bot]
af38034abc
build(deps): bump github/codeql-action from 3.24.8 to 3.24.10
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.24.8 to 3.24.10.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](05963f47d8...4355270be1 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
65d8125fcf
build(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 in /examples
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.18.0 to 0.19.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.18.0...v0.19.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
9222b7098b
build(deps): bump golang.org/x/net from 0.22.0 to 0.24.0
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.22.0 to 0.24.0.
- [Commits](https://github.com/golang/net/compare/v0.22.0...v0.24.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
b40f964a47
build(deps): bump golang from 1.22.1-alpine3.18 to 1.22.2-alpine3.18
...
Bumps golang from 1.22.1-alpine3.18 to 1.22.2-alpine3.18.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
1e76411291
build(deps): bump go.etcd.io/etcd/client/pkg/v3 from 3.5.12 to 3.5.13
...
Bumps [go.etcd.io/etcd/client/pkg/v3](https://github.com/etcd-io/etcd ) from 3.5.12 to 3.5.13.
- [Release notes](https://github.com/etcd-io/etcd/releases )
- [Commits](https://github.com/etcd-io/etcd/compare/v3.5.12...v3.5.13 )
---
updated-dependencies:
- dependency-name: go.etcd.io/etcd/client/pkg/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Romain Caire
86e92aaf1a
fix: wrong error code returned in case of inactive token ( #3441 )
...
Signed-off-by: Romain Caire <super.cairos@gmail.com>
2 years ago
dependabot[bot]
3b61d9a78f
build(deps): bump distroless/static-debian12 from `67686c9` to `42c8865`
...
Bumps distroless/static-debian12 from `67686c9` to `42c8865`.
---
updated-dependencies:
- dependency-name: distroless/static-debian12
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Denys Romanenko
7225198ae7
Update max length of kubernetes object to fit kubernetes policy ( #3439 )
...
Signed-off-by: Denys Romanenko <65756796+RomanenkoDenys@users.noreply.github.com>
Signed-off-by: Maksim Nabokikh <max.nabokih@gmail.com>
Co-authored-by: Maksim Nabokikh <max.nabokih@gmail.com>
2 years ago
Hayden B
38cef0c0c0
Update Distroless to Debian 12 ( #3432 )
...
gcr.io/distroless/static is Debian 10, which is quite outdated. Updated to the Debian 12 version of the static image, and used the nonroot tag since the root user isn't needed.
We've been running a version of Dex in production with this image without issue.
Signed-off-by: Hayden B <hblauzvern@google.com>
2 years ago
Romain Caire
8755308759
[RFC7662] Add introspect endpoint to introspect access & refresh token ( #3404 )
...
Signed-off-by: Romain Caire <super.cairos@gmail.com>
2 years ago
dependabot[bot]
5a80a701e9
build(deps): bump actions/dependency-review-action from 4.1.3 to 4.2.5
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 4.1.3 to 4.2.5.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](9129d7d40b...5bbc3ba658 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
fe45a29798
build(deps): bump github.com/go-sql-driver/mysql from 1.8.0 to 1.8.1
...
Bumps [github.com/go-sql-driver/mysql](https://github.com/go-sql-driver/mysql ) from 1.8.0 to 1.8.1.
- [Release notes](https://github.com/go-sql-driver/mysql/releases )
- [Changelog](https://github.com/go-sql-driver/mysql/blob/v1.8.1/CHANGELOG.md )
- [Commits](https://github.com/go-sql-driver/mysql/compare/v1.8.0...v1.8.1 )
---
updated-dependencies:
- dependency-name: github.com/go-sql-driver/mysql
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
9bea2e003f
build(deps): bump docker/setup-buildx-action from 3.1.0 to 3.2.0
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 3.1.0 to 3.2.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](0d103c3126...2b51285047 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
f6114706f6
build(deps): bump google.golang.org/protobuf in /api/v2 ( #3400 )
...
Bumps google.golang.org/protobuf from 1.32.0 to 1.33.0.
---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
55898261ce
build(deps): bump google.golang.org/grpc in /api/v2 ( #3399 )
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.62.0 to 1.62.1.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.62.0...v1.62.1 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
c14eef31bb
build(deps): bump golang from `010f3b3` to `ede158f` ( #3421 )
...
Bumps golang from `010f3b3` to `ede158f`.
---
updated-dependencies:
- dependency-name: golang
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
3871b84cdb
build(deps): bump docker/build-push-action from 5.2.0 to 5.3.0 ( #3420 )
...
Bumps [docker/build-push-action](https://github.com/docker/build-push-action ) from 5.2.0 to 5.3.0.
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](af5a7ed5ba...2cdde995de )
---
updated-dependencies:
- dependency-name: docker/build-push-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
e9f998c2fc
build(deps): bump github.com/coreos/go-oidc/v3 from 3.9.0 to 3.10.0 ( #3425 )
...
Bumps [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc ) from 3.9.0 to 3.10.0.
- [Release notes](https://github.com/coreos/go-oidc/releases )
- [Commits](https://github.com/coreos/go-oidc/compare/v3.9.0...v3.10.0 )
---
updated-dependencies:
- dependency-name: github.com/coreos/go-oidc/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
f0966f84c8
build(deps): bump github.com/coreos/go-oidc/v3 in /examples ( #3424 )
...
Bumps [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc ) from 3.9.0 to 3.10.0.
- [Release notes](https://github.com/coreos/go-oidc/releases )
- [Commits](https://github.com/coreos/go-oidc/compare/v3.9.0...v3.10.0 )
---
updated-dependencies:
- dependency-name: github.com/coreos/go-oidc/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
5c721151ab
build(deps): bump docker/login-action from 3.0.0 to 3.1.0 ( #3418 )
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 3.0.0 to 3.1.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](343f7c4344...e92390c5fb )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago
dependabot[bot]
6832ab5ed7
build(deps): bump google.golang.org/api from 0.169.0 to 0.171.0 ( #3426 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.169.0 to 0.171.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.169.0...v0.171.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 years ago