Update ghcr.io/dexidp/dex Docker tag to v2.35.3 #1154

Closed
renovate-bot wants to merge 1 commits from renovate/ghcr.io-dexidp-dex-2.x into master
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/dexidp/dex minor v2.32.0 -> v2.35.3

Release Notes

dexidp/dex

v2.35.3

Compare Source

The official container image for this release can be pulled from

ghcr.io/dexidp/dex:v2.35.3

What's Changed

Dependency Updates ⬆️

Full Changelog: https://github.com/dexidp/dex/compare/v2.35.2...v2.35.3

v2.35.2

Compare Source

The official container image for this release can be pulled from

ghcr.io/dexidp/dex:v2.35.2

What's Changed

Bug Fixes 🐛
Dependency Updates ⬆️

Full Changelog: https://github.com/dexidp/dex/compare/v2.35.1...v2.35.2

v2.35.1

Compare Source

The official container image for this release can be pulled from

ghcr.io/dexidp/dex:v2.35.1

What's Changed

Bug Fixes 🐛

Full Changelog: https://github.com/dexidp/dex/compare/v2.35.0...v2.35.1

v2.35.0

Compare Source

⚠️ This release fixes a major vulnerability in Dex. We advise everyone to upgrade as soon as possible! ⚠️

If you use the Google connector, please upgrade to 2.35.1 instead.

The official container image for this release can be pulled from

ghcr.io/dexidp/dex:v2.35.0

What's Changed

Enhancements 🚀
Bug Fixes 🐛
Dependency Updates ⬆️

New Contributors

Full Changelog: https://github.com/dexidp/dex/compare/v2.34.0...v2.35.0

v2.34.0

Compare Source

The official container image for this release can be pulled from

ghcr.io/dexidp/dex:v2.34.0

What's Changed

Exciting New Features 🎉
Enhancements 🚀
Dependency Updates ⬆️

New Contributors

Full Changelog: https://github.com/dexidp/dex/compare/v2.33.0...v2.34.0

v2.33.1

Compare Source

What's Changed

Enhancements 🚀

Full Changelog: https://github.com/dexidp/dex/compare/v2.33.0...v2.33.1

v2.33.0

Compare Source

The official container image for this release can be pulled from

ghcr.io/dexidp/dex:v2.33.0

What's Changed

Exciting New Features 🎉
Enhancements 🚀
Bug Fixes 🐛
Dependency Updates ⬆️

New Contributors

Full Changelog: https://github.com/dexidp/dex/compare/v2.32.0...v2.33.0

v2.32.1

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/dexidp/dex](https://github.com/dexidp/dex) | minor | `v2.32.0` -> `v2.35.3` | --- ### Release Notes <details> <summary>dexidp/dex</summary> ### [`v2.35.3`](https://github.com/dexidp/dex/releases/tag/v2.35.3) [Compare Source](https://github.com/dexidp/dex/compare/v2.35.2...v2.35.3) The official container image for this release can be pulled from ghcr.io/dexidp/dex:v2.35.3 <!-- Release notes generated using configuration in .github/release.yml at v2.35.3 --> #### What's Changed ##### Dependency Updates ⬆️ - Backport [#&#8203;2705](https://github.com/dexidp/dex/issues/2705) to v2.35.x by [@&#8203;nabokihms](https://github.com/nabokihms) in https://github.com/dexidp/dex/pull/2706 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.35.2...v2.35.3 ### [`v2.35.2`](https://github.com/dexidp/dex/releases/tag/v2.35.2) [Compare Source](https://github.com/dexidp/dex/compare/v2.35.1...v2.35.2) The official container image for this release can be pulled from ghcr.io/dexidp/dex:v2.35.2 <!-- Release notes generated using configuration in .github/release.yml at v2.35.2 --> #### What's Changed ##### Bug Fixes 🐛 - Backport [#&#8203;2700](https://github.com/dexidp/dex/issues/2700) to v2.35.x by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2702 ##### Dependency Updates ⬆️ - Backport Go update to v2.35.x by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2698 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.35.1...v2.35.2 ### [`v2.35.1`](https://github.com/dexidp/dex/releases/tag/v2.35.1) [Compare Source](https://github.com/dexidp/dex/compare/v2.35.0...v2.35.1) The official container image for this release can be pulled from ghcr.io/dexidp/dex:v2.35.1 <!-- Release notes generated using configuration in .github/release.yml at v2.35.1 --> #### What's Changed ##### Bug Fixes 🐛 - Backport [#&#8203;2694](https://github.com/dexidp/dex/issues/2694) to v2.35.x by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2696 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.35.0...v2.35.1 ### [`v2.35.0`](https://github.com/dexidp/dex/releases/tag/v2.35.0) [Compare Source](https://github.com/dexidp/dex/compare/v2.34.0...v2.35.0) **⚠️ This release fixes a [major vulnerability](https://github.com/dexidp/dex/security/advisories/GHSA-vh7g-p26c-j2cw) in Dex. We advise everyone to upgrade as soon as possible! ⚠️** **If you use the Google connector, please upgrade to 2.35.1 instead.** The official container image for this release can be pulled from ghcr.io/dexidp/dex:v2.35.0 <!-- Release notes generated using configuration in .github/release.yml at v2.35.0 --> #### What's Changed ##### Enhancements 🚀 - Reduce HTTP client creations in the Keystone connector by [@&#8203;erwinvaneyk](https://github.com/erwinvaneyk) in https://github.com/dexidp/dex/pull/2659 ##### Bug Fixes 🐛 - fix for issue 2670; check for no serviceAccountFilePath and no email by [@&#8203;bobcallaway](https://github.com/bobcallaway) in https://github.com/dexidp/dex/pull/2679 - supply HMACKey in test case by [@&#8203;bobcallaway](https://github.com/bobcallaway) in https://github.com/dexidp/dex/pull/2683 - fix: refresh token only once for all concurrent requests by [@&#8203;nabokihms](https://github.com/nabokihms) in https://github.com/dexidp/dex/pull/2692 ##### Dependency Updates ⬆️ - build(deps): bump google.golang.org/api from 0.95.0 to 0.97.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2677 - build(deps): bump go.etcd.io/etcd/client/v3 from 3.5.4 to 3.5.5 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2666 - build(deps): bump google.golang.org/api from 0.97.0 to 0.98.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2682 - build(deps): bump helm/kind-action from 1.3.0 to 1.4.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2681 - build(deps): bump entgo.io/ent from 0.11.2 to 0.11.3 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2684 - Update golang.org/x packages by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2688 #### New Contributors - [@&#8203;jannfis](https://github.com/jannfis) made their first contribution in https://github.com/dexidp/dex/pull/2691 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.34.0...v2.35.0 ### [`v2.34.0`](https://github.com/dexidp/dex/releases/tag/v2.34.0) [Compare Source](https://github.com/dexidp/dex/compare/v2.33.1...v2.34.0) <!-- Release notes generated using configuration in .github/release.yml at master --> The official container image for this release can be pulled from ghcr.io/dexidp/dex:v2.34.0 #### What's Changed ##### Exciting New Features 🎉 - updated gomplate version and added ppc64le support by [@&#8203;mayurwaghmode](https://github.com/mayurwaghmode) in https://github.com/dexidp/dex/pull/2620 ##### Enhancements 🚀 - fix: Fallback when group claim is a string instead of an array of strings by [@&#8203;JoooostB](https://github.com/JoooostB) in https://github.com/dexidp/dex/pull/2639 - feat(connector/authproxy): support multiple groups by [@&#8203;mclavel](https://github.com/mclavel) in https://github.com/dexidp/dex/pull/2643 - Implement Application Default Credentials for the google connector by [@&#8203;ichbinfrog](https://github.com/ichbinfrog) in https://github.com/dexidp/dex/pull/2530 - build: bump Go version to 1.19 in Nix by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2648 ##### Dependency Updates ⬆️ - build(deps): bump alpine from 3.16.1 to 3.16.2 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2624 - build(deps): bump github.com/prometheus/client_golang from 1.12.2 to 1.13.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2623 - build(deps): bump aquasecurity/trivy-action from 0.6.1 to 0.7.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2632 - build(deps): bump github.com/mattn/go-sqlite3 from 1.14.11 to 1.14.15 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2634 - build(deps): bump aquasecurity/trivy-action from 0.7.0 to 0.7.1 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2635 - build(deps): bump google.golang.org/api from 0.89.0 to 0.93.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2633 - build(deps): bump google.golang.org/api from 0.93.0 to 0.94.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2637 - chore: Bump ent to 0.11.2 by [@&#8203;nabokihms](https://github.com/nabokihms) in https://github.com/dexidp/dex/pull/2640 - chore: Bump Go to 1.19 by [@&#8203;nabokihms](https://github.com/nabokihms) in https://github.com/dexidp/dex/pull/2641 - build(deps): bump github.com/coreos/go-oidc/v3 from 3.2.0 to 3.3.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2646 - build(deps): bump google.golang.org/grpc from 1.47.0 to 1.49.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2636 - build(deps): bump google.golang.org/protobuf from 1.28.0 to 1.28.1 in /api/v2 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2611 - build(deps): bump golang from 1.19.0-alpine3.15 to 1.19.1-alpine3.15 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2650 - chore: update alpine version in Go image by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2656 - build(deps): bump github.com/lib/pq from 1.10.5 to 1.10.7 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2651 - build(deps): bump google.golang.org/api from 0.94.0 to 0.95.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2652 - build(deps): bump google.golang.org/grpc from 1.47.0 to 1.49.0 in /api/v2 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2638 - build(deps): bump github.com/coreos/go-oidc/v3 from 3.3.0 to 3.4.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2658 #### New Contributors - [@&#8203;mayurwaghmode](https://github.com/mayurwaghmode) made their first contribution in https://github.com/dexidp/dex/pull/2620 - [@&#8203;JoooostB](https://github.com/JoooostB) made their first contribution in https://github.com/dexidp/dex/pull/2639 - [@&#8203;mclavel](https://github.com/mclavel) made their first contribution in https://github.com/dexidp/dex/pull/2643 - [@&#8203;ichbinfrog](https://github.com/ichbinfrog) made their first contribution in https://github.com/dexidp/dex/pull/2530 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.33.0...v2.34.0 ### [`v2.33.1`](https://github.com/dexidp/dex/releases/tag/v2.33.1) [Compare Source](https://github.com/dexidp/dex/compare/v2.33.0...v2.33.1) <!-- Release notes generated using configuration in .github/release.yml at v2.33.1 --> #### What's Changed ##### Enhancements 🚀 - chore: upgrade alpine to 3.16.2 by [@&#8203;sagikazarmark](https://github.com/sagikazarmark) in https://github.com/dexidp/dex/pull/2655 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.33.0...v2.33.1 ### [`v2.33.0`](https://github.com/dexidp/dex/releases/tag/v2.33.0) [Compare Source](https://github.com/dexidp/dex/compare/v2.32.1...v2.33.0) The official container image for this release can be pulled from ghcr.io/dexidp/dex:v2.33.0 <!-- Release notes generated using configuration in .github/release.yml at v2.33.x --> #### What's Changed ##### Exciting New Features 🎉 - add PKCE support to device code flow by [@&#8203;bobcallaway](https://github.com/bobcallaway) in https://github.com/dexidp/dex/pull/2575 ##### Enhancements 🚀 - Limit the amount of objects we attempt to GC on each cycle by [@&#8203;kellyma2](https://github.com/kellyma2) in https://github.com/dexidp/dex/pull/2524 - Use GitLab's refresh_token during Refresh. by [@&#8203;dhaus67](https://github.com/dhaus67) in https://github.com/dexidp/dex/pull/2352 - Add domainHint parameter to Microsoft Connector by [@&#8203;josephtknight](https://github.com/josephtknight) in https://github.com/dexidp/dex/pull/2586 - add config to explicitly set scopes for microsoft connector by [@&#8203;bobcallaway](https://github.com/bobcallaway) in https://github.com/dexidp/dex/pull/2582 ##### Bug Fixes 🐛 - fix: prevent cross-site scripting for the device flow by [@&#8203;nabokihms](https://github.com/nabokihms) in https://github.com/dexidp/dex/pull/2468 - grpc-client: Do not crash on empty response by [@&#8203;bbusse](https://github.com/bbusse) in https://github.com/dexidp/dex/pull/2584 ##### Dependency Updates ⬆️ - build(deps): bump helm/kind-action from 1.2.0 to 1.3.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2555 - build(deps): bump aquasecurity/trivy-action from 0.3.0 to 0.4.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2557 - build(deps): bump github.com/stretchr/testify from 1.7.2 to 1.8.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2577 - build(deps): bump aquasecurity/trivy-action from 0.4.0 to 0.5.1 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2576 - build(deps): bump mheap/github-action-required-labels from 1 to 2 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2565 - build(deps): bump google.golang.org/api from 0.82.0 to 0.86.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2574 - build(deps): bump github.com/spf13/cobra from 1.4.0 to 1.5.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2560 - build(deps): bump aquasecurity/trivy-action from 0.5.1 to 0.6.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2602 - build(deps): bump alpine from 3.16.0 to 3.16.1 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2598 - build(deps): bump golang from 1.18.3-alpine3.15 to 1.18.4-alpine3.15 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2592 - build(deps): bump github.com/sirupsen/logrus from 1.8.1 to 1.9.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2599 - build(deps): bump github.com/go-ldap/ldap/v3 from 3.4.2 to 3.4.4 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2606 - build(deps): bump google.golang.org/api from 0.86.0 to 0.89.0 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2605 - build(deps): bump aquasecurity/trivy-action from 0.6.0 to 0.6.1 by [@&#8203;dependabot](https://github.com/dependabot) in https://github.com/dexidp/dex/pull/2604 #### New Contributors - [@&#8203;kellyma2](https://github.com/kellyma2) made their first contribution in https://github.com/dexidp/dex/pull/2524 - [@&#8203;josephtknight](https://github.com/josephtknight) made their first contribution in https://github.com/dexidp/dex/pull/2586 - [@&#8203;bbusse](https://github.com/bbusse) made their first contribution in https://github.com/dexidp/dex/pull/2584 **Full Changelog**: https://github.com/dexidp/dex/compare/v2.32.0...v2.33.0 ### [`v2.32.1`](https://github.com/dexidp/dex/compare/v2.32.0...v2.32.1) [Compare Source](https://github.com/dexidp/dex/compare/v2.32.0...v2.32.1) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4xLjUiLCJ1cGRhdGVkSW5WZXIiOiIzNC4xMDcuMSJ9-->
renovate-bot added 1 commit 2022-10-27 16:44:43 +00:00
continuous-integration/drone/pr Build encountered an error Details
continuous-integration/drone/push Build encountered an error Details
2a82f13003
Update ghcr.io/dexidp/dex Docker tag to v2.35.3
renovate-bot force-pushed renovate/ghcr.io-dexidp-dex-2.x from 2a82f13003 to 7d94f5d433 2023-03-13 18:45:06 +00:00 Compare
renovate-bot force-pushed renovate/ghcr.io-dexidp-dex-2.x from 7d94f5d433 to 2b0fbe4a10 2023-03-16 18:45:10 +00:00 Compare
tobru closed this pull request 2023-04-02 17:41:06 +00:00
This repo is archived. You cannot comment on pull requests.
No reviewers
No Label
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Reference: tobru/gitops-tbrnt#1154
No description provided.