Skip to content

Update concourse/dex dependancy to at least v2.39.0 from upstream #8970

@taylorsilva

Description

@taylorsilva

Discussed in #8961

Originally posted by Kump3r May 22, 2024
Hello all,
With the following PR, we contributed to the dexidp/dex, in order to log failed authentication requests, which is a security requirement to have a mechanism of coping with brute force attacks. I am opening this discussion and I have also written a comment in #5525 and in discord thread. Following this documentation, I was able to validate successfully, that the upstream change, will log such attempts in the web logs in the future. Can you provide an estimate as to when a release, containing dex upstream changes from v2.39.0, would be available for Concourse? Thanks in advance!


Someone needs to update our fork here: https://github.com/concourse/dex

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions