-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Open
Description
Preflight Checklist
- I agree to follow the Code of Conduct that this project adheres to.
- I have searched the issue tracker for an issue that matches the one I want to file, without success.
Problem Description
We are often getting CVE reports by community members (example: #4328).
Most of the time these CVEs affect gomplate, a component we use to allow configuration templating.
Proposed Solution
Given that the release cycle of gomplate seems to be slow and irregular, I propose providing a gomplateless image build of Dex.
People can decide if they need gomplate, and use that version if not.
It's a compromise, but there are many ways to do config templating.
Alternatives Considered
Fork gomplate and provide custom builds, but we are already stretched thin.
Additional Information
No response
Metadata
Metadata
Assignees
Labels
No labels