Skip to content

[v13] Update go-oidc to get final go-jose v2 -> v3 updates#36581

Merged
jentfoo merged 1 commit intobranch/v13from
jent/final-go-jose-v2-update-v13
Jan 11, 2024
Merged

[v13] Update go-oidc to get final go-jose v2 -> v3 updates#36581
jentfoo merged 1 commit intobranch/v13from
jent/final-go-jose-v2-update-v13

Conversation

@jentfoo
Copy link
Copy Markdown
Contributor

@jentfoo jentfoo commented Jan 11, 2024

v13 backport of go-jose update from #36514

* Update go-oidc to get final go-jose v2 updates

This updates our replaced go-oidc fork to use a tag with go-jose updated to v3: gravitational/go-oidc#19

This update removes the final usage of v2, and fully addresses the GHSA-2c7c-3mj9-8fqh DoS.

* Update gopkg.in/go-jose/go-jose.v2 to 2.6.2 to get p2c DoS fix
@jentfoo jentfoo added go Issues related to Go builds/tooling dependencies Pull requests that update a dependency file no-changelog Indicates that a PR does not require a changelog entry labels Jan 11, 2024
@jentfoo jentfoo added this pull request to the merge queue Jan 11, 2024
Merged via the queue into branch/v13 with commit 0d6ff91 Jan 11, 2024
@jentfoo jentfoo deleted the jent/final-go-jose-v2-update-v13 branch January 11, 2024 19:33
@jentfoo jentfoo self-assigned this Mar 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport dependencies Pull requests that update a dependency file go Issues related to Go builds/tooling no-changelog Indicates that a PR does not require a changelog entry size/sm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants