forked from dexidp/dex
-
Notifications
You must be signed in to change notification settings - Fork 0
Sync with upstream master #6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
cruizen
wants to merge
1,579
commits into
platform9:master
Choose a base branch
from
dexidp:master
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
1579 commits
Select commit
Hold shift + click to select a range
7360083
Merge pull request #4356 from dexidp/dependabot/go_modules/api/v2/goo…
sagikazarmark 9d3c17d
Merge pull request #4380 from dexidp/dependabot/github_actions/sigsto…
sagikazarmark b652b55
Merge pull request #4374 from dexidp/dependabot/go_modules/golang.org…
sagikazarmark b0a321e
Merge pull request #4373 from dexidp/dependabot/go_modules/github.com…
sagikazarmark f9d257a
Merge pull request #4371 from dexidp/dependabot/docker/golang-aee43c3
sagikazarmark a51ccea
build(deps): bump golang.org/x/oauth2 from 0.31.0 to 0.32.0
dependabot[bot] a498511
build(deps): bump github.com/spf13/cobra in /examples
dependabot[bot] 4206407
build(deps): bump google.golang.org/protobuf in /api/v2
dependabot[bot] 9355759
fix(storage/kubernetes): Only wrap IPv6 addresses in brackets (#4388)
rene-dekker e551db9
Merge pull request #4300 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark 788bc19
Merge pull request #4375 from dexidp/dependabot/go_modules/golang.org…
sagikazarmark 1d3b2b5
Add Terrakube to Adopters (#4316)
shurup e35542e
Merge pull request #4352 from dexidp/dependabot/go_modules/api/v2/goo…
sagikazarmark ae58fdd
build(deps): bump helm/kind-action from 1.12.0 to 1.13.0
dependabot[bot] c425652
build(deps): bump github.com/go-ldap/ldap/v3 from 3.4.11 to 3.4.12
dependabot[bot] 5be29e9
build(deps): bump docker/metadata-action from 5.8.0 to 5.9.0
dependabot[bot] 7869639
build(deps): bump docker/setup-qemu-action from 3.6.0 to 3.7.0
dependabot[bot] 0705d28
build(deps): bump actions/dependency-review-action from 4.8.1 to 4.8.2
dependabot[bot] ac3ccad
build(deps): bump github/codeql-action from 4.31.2 to 4.31.3
dependabot[bot] df0b519
build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0
dependabot[bot] 7300d82
build(deps): bump distroless/static-debian12 from `e8a4044` to `2b7c93f`
dependabot[bot] 3e09c4a
build(deps): bump tonistiigi/xx from 1.8.0 to 1.9.0
dependabot[bot] a72ac95
build(deps): bump golang.org/x/oauth2 from 0.32.0 to 0.34.0 in /examples
dependabot[bot] 356f207
Merge pull request #4430 from dexidp/dependabot/docker/tonistiigi/xx-…
sagikazarmark bf77fcf
Merge pull request #4427 from dexidp/dependabot/docker/distroless/sta…
sagikazarmark c301f78
build(deps): bump golang from 1.25.3-alpine3.22 to 1.25.5-alpine3.22
dependabot[bot] cfa31c4
build(deps): bump alpine from 3.22.2 to 3.23.0
dependabot[bot] 719e405
Merge pull request #4419 from dexidp/dependabot/go_modules/golang.org…
sagikazarmark 24cd880
Merge pull request #4414 from dexidp/dependabot/github_actions/github…
sagikazarmark 7fd0ba9
Merge pull request #4411 from dexidp/dependabot/github_actions/action…
sagikazarmark 1dac07d
Merge pull request #4405 from dexidp/dependabot/github_actions/docker…
sagikazarmark a1e5d58
Merge pull request #4402 from dexidp/dependabot/github_actions/docker…
sagikazarmark 7b3063d
build(deps): bump google.golang.org/api from 0.252.0 to 0.256.0
dependabot[bot] 30b1d6e
Merge pull request #4399 from dexidp/dependabot/github_actions/helm/k…
sagikazarmark f9d49f7
Merge pull request #4425 from dexidp/dependabot/docker/alpine-3.23.0
sagikazarmark 1fa99f3
Merge pull request #4424 from dexidp/dependabot/docker/golang-1.25.5-…
sagikazarmark a6b3152
Merge pull request #4413 from dexidp/dependabot/go_modules/google.gol…
sagikazarmark 06c5a3d
build(deps): bump golang.org/x/oauth2 from 0.32.0 to 0.33.0
dependabot[bot] 9a93f64
build(deps): bump golang.org/x/crypto from 0.43.0 to 0.44.0
dependabot[bot] 93a3732
Merge pull request #4409 from dexidp/dependabot/go_modules/golang.org…
sagikazarmark be38c21
Merge pull request #4412 from dexidp/dependabot/go_modules/golang.org…
sagikazarmark 99df040
Merge pull request #4401 from dexidp/dependabot/go_modules/github.com…
sagikazarmark 7953b07
Merge pull request #4431 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark c0c4408
build(deps): bump google.golang.org/grpc in /examples
dependabot[bot] c71068f
build(deps): bump google.golang.org/grpc in /api/v2
dependabot[bot] 8b10369
Merge pull request #4417 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark 31cfdd7
Merge pull request #4416 from dexidp/dependabot/go_modules/api/v2/goo…
sagikazarmark cfdf8d4
build(deps): bump github.com/spf13/cobra in /examples
dependabot[bot] 8ab38eb
Merge pull request #4426 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark c13246c
build(deps): bump github.com/coreos/go-oidc/v3 in /examples
dependabot[bot] 2da2a22
build(deps): bump actions/setup-go from 6.0.0 to 6.1.0
dependabot[bot] 4d1d54c
build(deps): bump docker/metadata-action from 5.9.0 to 5.10.0
dependabot[bot] 3dea4ba
build(deps): bump anchore/sbom-action from 0.20.9 to 0.20.11
dependabot[bot] 71b893e
build(deps): bump actions/checkout from 5.0.0 to 6.0.1
dependabot[bot] 95bf3d0
build(deps): bump golang.org/x/net from 0.47.0 to 0.48.0
dependabot[bot] ab8306c
build(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2
dependabot[bot] 78363ec
build(deps): bump github/codeql-action from 4.31.3 to 4.31.7
dependabot[bot] 8be9fc3
build(deps): bump github.com/coreos/go-oidc/v3 from 3.14.1 to 3.17.0
dependabot[bot] a023784
build(deps): bump google.golang.org/protobuf from 1.36.10 to 1.36.11
dependabot[bot] 2c5f06e
build(deps): bump google.golang.org/grpc in /examples
dependabot[bot] 895a748
Update distroless base image to debian13 (#4453)
loosebazooka dcbb7bb
fix: device callback URL needs to handle a / (#4448)
cardoe 2d7ecd3
build(deps): bump alpine from 3.23.0 to 3.23.2 (#4455)
dependabot[bot] d1b2722
feat: support groups and preferred_username for staticPasswords (#4456)
Jabejixo debcb5c
fix: hide internal server error details from users
Jabejixo b0a6ee9
fix: hide internal server error details from users
Jabejixo 701c83a
Merge pull request #4457 from Jabejixo/fix/hide-internal-500-error-de…
sagikazarmark 6a65189
Merge pull request #4460 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark e8f5eeb
Merge pull request #4449 from dexidp/dependabot/go_modules/google.gol…
sagikazarmark 30d89fd
Merge pull request #4440 from dexidp/dependabot/github_actions/github…
sagikazarmark 3b06f75
Merge pull request #4439 from dexidp/dependabot/go_modules/github.com…
sagikazarmark 2b15108
Merge pull request #4438 from dexidp/dependabot/go_modules/golang.org…
sagikazarmark 1c0c0b0
Merge pull request #4437 from dexidp/dependabot/github_actions/action…
sagikazarmark a03588a
Merge pull request #4435 from dexidp/dependabot/github_actions/anchor…
sagikazarmark 4646f9f
Merge pull request #4434 from dexidp/dependabot/github_actions/docker…
sagikazarmark 0257f55
Merge pull request #4433 from dexidp/dependabot/github_actions/action…
sagikazarmark 4bd5919
build(deps): bump google.golang.org/protobuf in /api/v2
dependabot[bot] bce74e7
fix: failing go-oidc test after 3.15
sagikazarmark 8fc1f97
Merge pull request #4441 from dexidp/dependabot/go_modules/github.com…
sagikazarmark 4ffb7a2
Merge pull request #4450 from dexidp/dependabot/go_modules/api/v2/goo…
sagikazarmark adf3c82
Merge pull request #4420 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark c44f771
build(deps): bump the etcd group with 2 updates
dependabot[bot] e674097
Merge pull request #4436 from dexidp/dependabot/go_modules/etcd-4fbb4…
sagikazarmark 5cd3432
build(deps): bump golang from 1.25.5-alpine3.22 to 1.25.6-alpine3.22 …
dependabot[bot] ecdd0b8
build(deps): bump distroless/static-debian13 from `b5b9fd0` to `f9f84…
dependabot[bot] 7942817
build(deps): bump actions/setup-go from 6.1.0 to 6.2.0 (#4476)
dependabot[bot] a956bf3
build(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 (#4472)
dependabot[bot] 9ed6bf7
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.32 to 1.14.33…
dependabot[bot] 281c177
build(deps): bump golang.org/x/net from 0.48.0 to 0.49.0 (#4475)
dependabot[bot] 09fee7f
build(deps): bump google.golang.org/grpc from 1.77.0 to 1.78.0 (#4469)
dependabot[bot] f0a9fa4
build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#4477)
dependabot[bot] 1a49fc3
build(deps): bump actions/cache from 4.3.0 to 5.0.1 (#4473)
dependabot[bot] 9f199ac
build(deps): bump github/codeql-action from 4.31.7 to 4.31.10 (#4470)
dependabot[bot] 2725903
build(deps): bump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#…
dependabot[bot] da180b9
build(deps): bump google.golang.org/api from 0.257.0 to 0.259.0 (#4478)
dependabot[bot] 4d103d6
build(deps): bump google.golang.org/grpc in /api/v2 (#4459)
dependabot[bot] 5f0c542
build(deps): bump actions/cache from 5.0.1 to 5.0.2 (#4484)
dependabot[bot] 47f2040
build(deps): bump golang from `d9c983d` to `ad295fc` (#4493)
dependabot[bot] 25d62b7
build(deps): bump actions/attest-build-provenance from 3.0.0 to 3.1.0…
dependabot[bot] dcbaa9d
build(deps): bump anchore/sbom-action from 0.20.11 to 0.22.0 (#4487)
dependabot[bot] d8acc5a
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#4489)
dependabot[bot] b13e020
build(deps): bump github/codeql-action from 4.31.10 to 4.31.11 (#4492)
dependabot[bot] 45b1941
build(deps): bump google.golang.org/api from 0.260.0 to 0.263.0 (#4494)
dependabot[bot] 06b3079
build(deps): bump alpine from 3.23.2 to 3.23.3
dependabot[bot] 227aeb8
build(deps): bump anchore/sbom-action from 0.22.0 to 0.22.1
dependabot[bot] f817d8b
build(deps): bump actions/attest-build-provenance from 3.1.0 to 3.2.0
dependabot[bot] c78b28b
build(deps): bump github/codeql-action from 4.31.11 to 4.32.0
dependabot[bot] 9362179
build(deps): bump actions/cache from 5.0.2 to 5.0.3
dependabot[bot] 0e97ad5
build(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1
dependabot[bot] f7691ce
gitlab: support custom rootCAData (#4496)
Jabejixo a522202
Merge pull request #4505 from dexidp/dependabot/go_modules/github.com…
sagikazarmark 5f6d1b1
Merge pull request #4504 from dexidp/dependabot/github_actions/action…
sagikazarmark 228deee
Merge pull request #4502 from dexidp/dependabot/github_actions/github…
sagikazarmark f976660
Merge pull request #4501 from dexidp/dependabot/github_actions/action…
sagikazarmark 087d4bd
Merge pull request #4499 from dexidp/dependabot/github_actions/anchor…
sagikazarmark 743730f
Merge pull request #4498 from dexidp/dependabot/docker/alpine-3.23.3
sagikazarmark f3a24b2
build(deps): bump google.golang.org/api from 0.263.0 to 0.265.0
dependabot[bot] a15c4a6
Merge pull request #4508 from dexidp/dependabot/go_modules/google.gol…
sagikazarmark 1997f63
build(deps): bump docker/login-action from 3.6.0 to 3.7.0
dependabot[bot] 167ea52
Merge pull request #4503 from dexidp/dependabot/github_actions/docker…
sagikazarmark ec564f2
Enable ContinueOnConnectorFailure feature flag (#4495)
manojVivek 4bdb4f2
chore: extend example configs for idEnv and public (#4443)
cardoe be791c0
feat: add unprivileged user setup in Dockerfile (#4517)
nabokihms e0268e2
build(deps): bump golang from 1.25.6-alpine3.22 to 1.25.7-alpine3.22 …
dependabot[bot] 894af72
build(deps): bump golang.org/x/oauth2 from 0.34.0 to 0.35.0 (#4515)
dependabot[bot] cee32d6
build(deps): bump github/codeql-action from 4.32.0 to 4.32.2 (#4509)
dependabot[bot] 246124e
build(deps): bump anchore/sbom-action from 0.22.1 to 0.22.2 (#4510)
dependabot[bot] 4c94d8a
build(deps): bump golang.org/x/oauth2 from 0.34.0 to 0.35.0 in /examp…
dependabot[bot] b09a9e7
build(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 (#4518)
dependabot[bot] 79e28f5
build(deps): bump golang.org/x/net from 0.49.0 to 0.50.0 (#4519)
dependabot[bot] 56958b1
feat: Add Vault signer for JWT (#4512)
nabokihms 2f6a185
test: Add conformance tests for Vault signer integration (#4520)
nabokihms c016300
build(deps): bump google.golang.org/api from 0.265.0 to 0.266.0 (#4523)
dependabot[bot] 9e37771
feat: add name and emailVerified fields for static passwords (#4526)
Jabejixo 27b5f29
build(deps): bump docker/build-push-action from 6.18.0 to 6.19.1 (#4530)
dependabot[bot] 52c243f
build(deps): bump golang from 1.25.7-alpine3.22 to 1.26.0-alpine3.22 …
dependabot[bot] 5c32fad
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.33 to 1.14.34…
dependabot[bot] 1855a9a
build(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 (#4525)
dependabot[bot] 9bee0b0
build(deps): bump google.golang.org/grpc in /examples (#4537)
dependabot[bot] f2c2526
build(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.0 (#4534)
dependabot[bot] 4955d43
build(deps): bump docker/build-push-action from 6.19.1 to 6.19.2 (#4535)
dependabot[bot] 76d7ed4
build(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0 (#4…
dependabot[bot] 489e37d
fix: suppress deprecation warning for userAttr when not set (#4539)
nabokihms d90827c
fix: use correct id value for label (#4541)
loganripplinger 7850337
feat: refactor signer configuration with local and vault options (#4532)
nabokihms ad3a83e
build(gomplate): update gomplate version to v5.0.0 and add update scr…
nabokihms 9bee809
feat(crd): add CRD handling behavior and configuration options (#4543)
nabokihms a5f4956
Add permissions section to trivydb-cache workflow (#4544)
nabokihms 7c74dd8
build(deps): bump distroless/static-debian13 from `f9f84bd` to `01e55…
dependabot[bot] 2976b23
build(deps): bump google.golang.org/grpc in /examples (#4551)
dependabot[bot] e640a40
build(deps): bump google.golang.org/grpc from 1.79.0 to 1.79.1 (#4549)
dependabot[bot] c331bb9
build(deps): bump the etcd group with 2 updates (#4548)
dependabot[bot] 5593fb7
build(deps): bump github/codeql-action from 4.32.2 to 4.32.3 (#4547)
dependabot[bot] eb9f04b
Debug trivy scans (#4545)
nabokihms adec8b4
Add steps to fetch and extract OCI image tarball (#4552)
nabokihms 955142b
feat: enhance git-version script to generate pseudo-versions with tim…
nabokihms dce4638
build(deps): update gRPC to v1.79.1 and other dependencies (#4554)
nabokihms be13b1f
build(deps): bump helm/kind-action from 1.13.0 to 1.14.0 (#4557)
dependabot[bot] 69f9b7e
build(deps): bump google.golang.org/api from 0.266.0 to 0.267.0 (#4558)
dependabot[bot] 29c7b6f
feat: validate redirect URIs and safely append parameters (#4559)
nabokihms 548b0f5
build(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (#4562)
dependabot[bot] 0108be9
feat: add skopeo copy command to transfer image from OCI layout (#4564)
nabokihms 49c8228
build(deps): bump actions/dependency-review-action from 4.8.2 to 4.8.…
dependabot[bot] 0807930
feat: add debug step to check image metadata in workflow (#4566)
nabokihms 5d27abc
feat: refactor example-app with a new config (#4569)
nabokihms 25591ee
Add support to PKCE in OIDC connector (#3777)
johnvan7 83697b0
fix(server): respond with forbidden if failed to authenticate (#4200)
aljoshare cf17fc6
test: update HandleCallback after merging OIDC PKCE (#4572)
nabokihms 8db7699
feat: implement device code flow in example-app (#4570)
nabokihms 51c66d2
build(deps): bump aquasecurity/trivy-action from 0.34.0 to 0.34.1 (#4…
dependabot[bot] ec26e19
build(deps): bump github/codeql-action from 4.32.3 to 4.32.4 (#4573)
dependabot[bot] bcc2283
feat: enhance test commands to support GitHub Actions formatting (#4575)
nabokihms 0963bbe
build(deps): bump google.golang.org/api from 0.267.0 to 0.268.0 (#4577)
dependabot[bot] a6962a8
fix(mysql): quote `groups` reserved word in query replacer (#4580)
backkem 2ecf64e
build(deps): bump google.golang.org/api from 0.268.0 to 0.269.0 (#4582)
dependabot[bot] 4c3dffd
build(deps): bump actions/setup-go from 6.2.0 to 6.3.0 (#4584)
dependabot[bot] 9cd6668
build(deps): bump anchore/sbom-action from 0.22.2 to 0.23.0 (#4587)
dependabot[bot] c0daa71
build(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#4586)
dependabot[bot] 3295c72
build(deps): bump actions/attest-build-provenance from 3.2.0 to 4.0.0…
dependabot[bot] 49dcb4d
fix: clean up in-memory connector before create (#4529)
loafoe d78d744
feat: Disallow unknown config fields (#4531)
nabokihms 4311931
feat: saml support refresh tokens (#4565)
Jabejixo 44e2749
fix(connector): update authproxy and oauth to match CallbackConnector…
matzegebbe 47e84db
feat(connector): add compile-time checks for connector interfaces (#4…
nabokihms 8ab16cf
build(deps): bump actions/attest-build-provenance from 4.0.0 to 4.1.0…
dependabot[bot] e5e64c6
build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 (#4594)
dependabot[bot] e5c14f1
build(deps): bump distroless/static-debian13 from `01e550f` to `f512d…
dependabot[bot] e1d6c38
fix: Invert condition for unknown fields in config unmarshaller (#4596)
nabokihms 99c4233
fix: fix typo in grpc listener error message (#4598)
kanywst 91e985e
fix: correct error message for device request expiry (#4599)
kanywst a70f592
fix(deviceflow): update redirect URIs to use absolute paths for non-r…
nabokihms 044dcd5
build(deps): bump aquasecurity/trivy-action from 0.34.1 to 0.34.2 (#4…
dependabot[bot] e79638d
build(deps): bump github/codeql-action from 4.32.4 to 4.32.5 (#4603)
dependabot[bot] fec4f53
feat(oauth2): add client credentials flow with opt-in config flag (#4…
matzegebbe 57a601f
build(deps): bump actions/dependency-review-action from 4.8.3 to 4.9.…
dependabot[bot] fb57055
build(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0 (#4608)
dependabot[bot] 3ab0947
build(deps): bump docker/login-action from 3.7.0 to 4.0.0 (#4609)
dependabot[bot] a11b3cd
feat(gitlab): implement TokenIdentity method (#4606)
nabokihms 7870871
build(deps): bump golang from 1.26.0-alpine3.22 to 1.26.1-alpine3.22 …
dependabot[bot] 91bf627
build(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0 (#4…
dependabot[bot] 8dce952
build(deps): bump docker/build-push-action from 6.19.2 to 7.0.0 (#4613)
dependabot[bot] 976e45e
build(deps): bump docker/metadata-action from 5.10.0 to 6.0.0 (#4614)
dependabot[bot] f4c3102
build(deps): bump github/codeql-action from 4.32.5 to 4.32.6 (#4615)
dependabot[bot] 591a201
feat(tests): add MySQL 8 support in CI and tests (#4617)
nabokihms c03a687
fix(server): handle double-submit on approval endpoint (#4620)
mark-liu e2462a2
build(deps): bump golang.org/x/oauth2 from 0.35.0 to 0.36.0 in /examp…
dependabot[bot] 9ba3c3f
build(deps): bump aquasecurity/trivy-action from 0.34.2 to 0.35.0 (#4…
dependabot[bot] 74dd7ee
build(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.2 (#4623)
dependabot[bot] e67c47c
build(deps): bump golang.org/x/oauth2 from 0.35.0 to 0.36.0 (#4624)
dependabot[bot] 01b6822
build(deps): bump google.golang.org/grpc in /examples (#4626)
dependabot[bot] a4136db
build(deps): bump google.golang.org/grpc in /api/v2 (#4625)
dependabot[bot] 35c0b56
build(deps): bump sigstore/cosign-installer from 4.0.0 to 4.1.0 (#4628)
dependabot[bot] 7bd3c2a
build(deps): bump google.golang.org/api from 0.269.0 to 0.270.0 (#4630)
dependabot[bot] ae8c5af
build(deps): bump anchore/sbom-action from 0.23.0 to 0.23.1 (#4629)
dependabot[bot] 3d97c59
test: add concurrency tests for storage implementations (#4631)
nabokihms 47b6454
build(deps): bump google.golang.org/api from 0.270.0 to 0.271.0 (#4633)
dependabot[bot] 7777773
feat(connector): connectors for grants (#4619)
nabokihms f80a89d
feat(client): add allowed connectors field to client configuration (#…
nabokihms 80d297b
feat: update CSS for improved theming and button styles (#4634)
nabokihms 734d60f
build(deps): bump golang.org/x/crypto from 0.48.0 to 0.49.0 (#4636)
dependabot[bot] 13f012f
build(deps): bump golang.org/x/net from 0.51.0 to 0.52.0 (#4635)
dependabot[bot] 2bda646
test: fix token introspection tests to use consistent timestamps (#4639)
nabokihms 5bbfbbe
feat: add PKCE (Proof Key for Code Exchange) configuration to OAuth2 …
nabokihms 0568abe
DEP: CEL integration (#4601)
nabokihms 175dc57
feat(cel): implement CEL compiler with library (#4607)
nabokihms e8f79fe
DEP: Auth Sessions - Introduce (#4561)
nabokihms 5a4395f
feat: add UserIdentity entity and CRUD operations (#4643)
nabokihms 4fb3e78
feat(logger): add excludeFields config for PII redaction (#4621)
mark-liu fe79863
build(deps): bump mheap/github-action-required-labels (#4649)
dependabot[bot] 4433b36
build(deps): bump distroless/static-debian13 from `f512d81` to `e3f94…
dependabot[bot] 93985de
fix: increase lock acquisition attempts from 60 to 200 for better rel…
nabokihms 0f9b7eb
Pin GitHub API version in requests (#4647)
utafrali 12339f2
feat: implement user identity creation and persisting consent (#4645)
nabokihms 6b9ce00
feat: implement AuthSession CRUD operations (#4646)
nabokihms de1e85a
build(deps): bump github/codeql-action from 4.32.6 to 4.33.0 (#4651)
dependabot[bot] 72e63fa
build(deps): bump google.golang.org/api from 0.271.0 to 0.272.0 (#4652)
dependabot[bot] d31ed97
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.34 to 1.14.37…
dependabot[bot] 90fd51b
feat(ldap): allow specifying multiple attributes on username input (#…
yardenshoham 1e65dda
fix(localSigner): simplify Algorithm method to always return RSA algo…
nabokihms 285d83b
build(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3 (#4658)
dependabot[bot] 7f4a5a7
build(deps): bump github.com/go-ldap/ldap/v3 from 3.4.12 to 3.4.13 (#…
dependabot[bot] 8af6d3c
build(deps): bump google.golang.org/grpc in /examples (#4661)
dependabot[bot] cbd7dd7
feat: Create AuthSessions and set cookies (#4650)
nabokihms 503ddca
DEP for Identity Assertion JWT Authorization Grant (ID-JAG) / request…
kanywst 86abd33
Two-Factor authentication (TOTP) (#3712)
nabokihms 8938c98
build(deps): bump github.com/russellhaering/goxmldsig (#4664)
dependabot[bot] 56914a8
build(deps): bump github.com/lib/pq from 1.11.2 to 1.12.0 (#4666)
dependabot[bot] ff5bc7c
build(deps): bump actions/cache from 5.0.3 to 5.0.4 (#4665)
dependabot[bot] 7ec1760
feat: Add OIDC conformance testing scripts and configuration (#4663)
nabokihms c3bc1d7
feat: add auth_time, prompt, and max_age fields (#4662)
nabokihms File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,2 @@ | ||
| .github/ | ||
| .gitpod.yml | ||
| bin/ | ||
| tmp/ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -19,3 +19,6 @@ indent_style = tab | |
|
|
||
| [{config.yaml.dist,config.dev.yaml}] | ||
| indent_size = 2 | ||
|
|
||
| [.golangci.yaml] | ||
| indent_size = 2 | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,6 +1,6 @@ | ||
| if ! has nix_direnv_version || ! nix_direnv_version 1.5.0; then | ||
| source_url "https://raw.githubusercontent.com/nix-community/nix-direnv/1.5.0/direnvrc" "sha256-carKk9aUFHMuHt+IWh74hFj58nY4K3uywpZbwXX0BTI=" | ||
| if ! has nix_direnv_version || ! nix_direnv_version 3.0.6; then | ||
| source_url "https://raw.githubusercontent.com/nix-community/nix-direnv/3.0.6/direnvrc" "sha256-RYcUJaRMf8oF5LznDrlCXbkOQrywm0HDv1VjYGaJGdM=" | ||
| fi | ||
| use flake | ||
| use flake . --impure | ||
|
|
||
| dotenv_if_exists |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,47 @@ | ||
| name: OpenSSF Scorecard | ||
|
|
||
| on: | ||
| branch_protection_rule: | ||
| push: | ||
| branches: [ main ] | ||
| schedule: | ||
| - cron: '30 0 * * 5' | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| analyze: | ||
| name: Analyze | ||
| runs-on: ubuntu-latest | ||
|
|
||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| id-token: write | ||
| security-events: write | ||
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - name: Run analysis | ||
| uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 | ||
| with: | ||
| results_file: results.sarif | ||
| results_format: sarif | ||
| publish_results: true | ||
|
|
||
| - name: Upload results as artifact | ||
| uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 | ||
| with: | ||
| name: OpenSSF Scorecard results | ||
| path: results.sarif | ||
| retention-days: 5 | ||
|
|
||
| - name: Upload results to GitHub Security tab | ||
| uses: github/codeql-action/upload-sarif@b1bff81932f5cdfc8695c7752dcee935dcd061c8 # v3.29.5 | ||
| with: | ||
| sarif_file: results.sarif | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Scorecard workflow targets
maininstead ofmasterLow Severity
The new
analysis-scorecard.yamlworkflow triggers on pushes tobranches: [ main ], but this fork's default branch ismaster(as seen inci.yaml). The scorecard push trigger will never fire. The workflow only runs on the weeklyscheduleandbranch_protection_ruleevents, which may not be the intent.