Skip to content

Conversation

sagikazarmark
Copy link
Member

Overview

Upgrade alpine base Go image

Signed-off-by: Mark Sagi-Kazar <mark.sagikazar@gmail.com>
@sagikazarmark sagikazarmark added the release-note/dependency-update Release note: Dependency Updates label Sep 8, 2022
@sagikazarmark sagikazarmark merged commit 4117bac into master Sep 8, 2022
@sagikazarmark sagikazarmark deleted the update-alpine branch September 8, 2022 11:02
@tooptoop4
Copy link

@sagikazarmark when is next release with this fix? will help to resolve my CVE scan results

@sagikazarmark
Copy link
Member Author

It's included in 2.33.1

xtremerui pushed a commit to concourse/dex that referenced this pull request Sep 16, 2022
<!-- Release notes generated using configuration in .github/release.yml at master -->
The official container image for this release can be pulled from
```
ghcr.io/dexidp/dex:v2.34.0
```
## What's Changed
### Exciting New Features 🎉
* updated gomplate version and added ppc64le support by @mayurwaghmode in dexidp#2620
### Enhancements 🚀
* fix: Fallback when group claim is a string instead of an array of strings by @JoooostB in dexidp#2639
* feat(connector/authproxy): support multiple groups by @mclavel in dexidp#2643
* Implement Application Default Credentials for the google connector by @ichbinfrog in dexidp#2530
* build: bump Go version to 1.19 in Nix by @sagikazarmark in dexidp#2648
### Dependency Updates ⬆️
* build(deps): bump alpine from 3.16.1 to 3.16.2 by @dependabot in dexidp#2624
* build(deps): bump github.com/prometheus/client_golang from 1.12.2 to 1.13.0 by @dependabot in dexidp#2623
* build(deps): bump aquasecurity/trivy-action from 0.6.1 to 0.7.0 by @dependabot in dexidp#2632
* build(deps): bump github.com/mattn/go-sqlite3 from 1.14.11 to 1.14.15 by @dependabot in dexidp#2634
* build(deps): bump aquasecurity/trivy-action from 0.7.0 to 0.7.1 by @dependabot in dexidp#2635
* build(deps): bump google.golang.org/api from 0.89.0 to 0.93.0 by @dependabot in dexidp#2633
* build(deps): bump google.golang.org/api from 0.93.0 to 0.94.0 by @dependabot in dexidp#2637
* chore: Bump ent to 0.11.2 by @nabokihms in dexidp#2640
* chore: Bump Go to 1.19 by @nabokihms in dexidp#2641
* build(deps): bump github.com/coreos/go-oidc/v3 from 3.2.0 to 3.3.0 by @dependabot in dexidp#2646
* build(deps): bump google.golang.org/grpc from 1.47.0 to 1.49.0 by @dependabot in dexidp#2636
* build(deps): bump google.golang.org/protobuf from 1.28.0 to 1.28.1 in /api/v2 by @dependabot in dexidp#2611
* build(deps): bump golang from 1.19.0-alpine3.15 to 1.19.1-alpine3.15 by @dependabot in dexidp#2650
* chore: update alpine version in Go image by @sagikazarmark in dexidp#2656
* build(deps): bump github.com/lib/pq from 1.10.5 to 1.10.7 by @dependabot in dexidp#2651
* build(deps): bump google.golang.org/api from 0.94.0 to 0.95.0 by @dependabot in dexidp#2652
* build(deps): bump google.golang.org/grpc from 1.47.0 to 1.49.0 in /api/v2 by @dependabot in dexidp#2638
* build(deps): bump github.com/coreos/go-oidc/v3 from 3.3.0 to 3.4.0 by @dependabot in dexidp#2658

## New Contributors
* @mayurwaghmode made their first contribution in dexidp#2620
* @JoooostB made their first contribution in dexidp#2639
* @mclavel made their first contribution in dexidp#2643
* @ichbinfrog made their first contribution in dexidp#2530

**Full Changelog**: dexidp/dex@v2.33.0...v2.34.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release-note/dependency-update Release note: Dependency Updates
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants