Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1656 commits
Select commit Hold shift + click to select a range
bce74e7
fix: failing go-oidc test after 3.15
sagikazarmark Jan 13, 2026
8fc1f97
Merge pull request #4441 from dexidp/dependabot/go_modules/github.com…
sagikazarmark Jan 13, 2026
4ffb7a2
Merge pull request #4450 from dexidp/dependabot/go_modules/api/v2/goo…
sagikazarmark Jan 13, 2026
adf3c82
Merge pull request #4420 from dexidp/dependabot/go_modules/examples/g…
sagikazarmark Jan 13, 2026
c44f771
build(deps): bump the etcd group with 2 updates
dependabot[bot] Jan 13, 2026
e674097
Merge pull request #4436 from dexidp/dependabot/go_modules/etcd-4fbb4…
sagikazarmark Jan 13, 2026
5cd3432
build(deps): bump golang from 1.25.5-alpine3.22 to 1.25.6-alpine3.22 …
dependabot[bot] Jan 21, 2026
ecdd0b8
build(deps): bump distroless/static-debian13 from `b5b9fd0` to `f9f84…
dependabot[bot] Jan 21, 2026
7942817
build(deps): bump actions/setup-go from 6.1.0 to 6.2.0 (#4476)
dependabot[bot] Jan 21, 2026
a956bf3
build(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 (#4472)
dependabot[bot] Jan 21, 2026
9ed6bf7
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.32 to 1.14.33…
dependabot[bot] Jan 21, 2026
281c177
build(deps): bump golang.org/x/net from 0.48.0 to 0.49.0 (#4475)
dependabot[bot] Jan 21, 2026
09fee7f
build(deps): bump google.golang.org/grpc from 1.77.0 to 1.78.0 (#4469)
dependabot[bot] Jan 21, 2026
f0a9fa4
build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#4477)
dependabot[bot] Jan 21, 2026
1a49fc3
build(deps): bump actions/cache from 4.3.0 to 5.0.1 (#4473)
dependabot[bot] Jan 21, 2026
9f199ac
build(deps): bump github/codeql-action from 4.31.7 to 4.31.10 (#4470)
dependabot[bot] Jan 21, 2026
2725903
build(deps): bump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#…
dependabot[bot] Jan 21, 2026
da180b9
build(deps): bump google.golang.org/api from 0.257.0 to 0.259.0 (#4478)
dependabot[bot] Jan 21, 2026
4d103d6
build(deps): bump google.golang.org/grpc in /api/v2 (#4459)
dependabot[bot] Jan 21, 2026
5f0c542
build(deps): bump actions/cache from 5.0.1 to 5.0.2 (#4484)
dependabot[bot] Jan 28, 2026
47f2040
build(deps): bump golang from `d9c983d` to `ad295fc` (#4493)
dependabot[bot] Jan 28, 2026
25d62b7
build(deps): bump actions/attest-build-provenance from 3.0.0 to 3.1.0…
dependabot[bot] Jan 28, 2026
dcbaa9d
build(deps): bump anchore/sbom-action from 0.20.11 to 0.22.0 (#4487)
dependabot[bot] Jan 28, 2026
d8acc5a
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#4489)
dependabot[bot] Jan 28, 2026
b13e020
build(deps): bump github/codeql-action from 4.31.10 to 4.31.11 (#4492)
dependabot[bot] Jan 28, 2026
45b1941
build(deps): bump google.golang.org/api from 0.260.0 to 0.263.0 (#4494)
dependabot[bot] Jan 28, 2026
06b3079
build(deps): bump alpine from 3.23.2 to 3.23.3
dependabot[bot] Jan 29, 2026
227aeb8
build(deps): bump anchore/sbom-action from 0.22.0 to 0.22.1
dependabot[bot] Jan 29, 2026
f817d8b
build(deps): bump actions/attest-build-provenance from 3.1.0 to 3.2.0
dependabot[bot] Jan 29, 2026
c78b28b
build(deps): bump github/codeql-action from 4.31.11 to 4.32.0
dependabot[bot] Jan 29, 2026
9362179
build(deps): bump actions/cache from 5.0.2 to 5.0.3
dependabot[bot] Jan 30, 2026
0e97ad5
build(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1
dependabot[bot] Jan 30, 2026
f7691ce
gitlab: support custom rootCAData (#4496)
Jabejixo Jan 30, 2026
a522202
Merge pull request #4505 from dexidp/dependabot/go_modules/github.com…
sagikazarmark Feb 5, 2026
5f6d1b1
Merge pull request #4504 from dexidp/dependabot/github_actions/action…
sagikazarmark Feb 5, 2026
228deee
Merge pull request #4502 from dexidp/dependabot/github_actions/github…
sagikazarmark Feb 5, 2026
f976660
Merge pull request #4501 from dexidp/dependabot/github_actions/action…
sagikazarmark Feb 5, 2026
087d4bd
Merge pull request #4499 from dexidp/dependabot/github_actions/anchor…
sagikazarmark Feb 5, 2026
743730f
Merge pull request #4498 from dexidp/dependabot/docker/alpine-3.23.3
sagikazarmark Feb 5, 2026
f3a24b2
build(deps): bump google.golang.org/api from 0.263.0 to 0.265.0
dependabot[bot] Feb 5, 2026
a15c4a6
Merge pull request #4508 from dexidp/dependabot/go_modules/google.gol…
sagikazarmark Feb 5, 2026
1997f63
build(deps): bump docker/login-action from 3.6.0 to 3.7.0
dependabot[bot] Feb 5, 2026
167ea52
Merge pull request #4503 from dexidp/dependabot/github_actions/docker…
sagikazarmark Feb 5, 2026
ec564f2
Enable ContinueOnConnectorFailure feature flag (#4495)
manojVivek Feb 6, 2026
4bdb4f2
chore: extend example configs for idEnv and public (#4443)
cardoe Feb 9, 2026
be791c0
feat: add unprivileged user setup in Dockerfile (#4517)
nabokihms Feb 9, 2026
e0268e2
build(deps): bump golang from 1.25.6-alpine3.22 to 1.25.7-alpine3.22 …
dependabot[bot] Feb 9, 2026
894af72
build(deps): bump golang.org/x/oauth2 from 0.34.0 to 0.35.0 (#4515)
dependabot[bot] Feb 9, 2026
cee32d6
build(deps): bump github/codeql-action from 4.32.0 to 4.32.2 (#4509)
dependabot[bot] Feb 9, 2026
246124e
build(deps): bump anchore/sbom-action from 0.22.1 to 0.22.2 (#4510)
dependabot[bot] Feb 9, 2026
4c94d8a
build(deps): bump golang.org/x/oauth2 from 0.34.0 to 0.35.0 in /examp…
dependabot[bot] Feb 9, 2026
b09a9e7
build(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 (#4518)
dependabot[bot] Feb 10, 2026
79e28f5
build(deps): bump golang.org/x/net from 0.49.0 to 0.50.0 (#4519)
dependabot[bot] Feb 10, 2026
56958b1
feat: Add Vault signer for JWT (#4512)
nabokihms Feb 10, 2026
2f6a185
test: Add conformance tests for Vault signer integration (#4520)
nabokihms Feb 12, 2026
c016300
build(deps): bump google.golang.org/api from 0.265.0 to 0.266.0 (#4523)
dependabot[bot] Feb 12, 2026
9e37771
feat: add name and emailVerified fields for static passwords (#4526)
Jabejixo Feb 12, 2026
27b5f29
build(deps): bump docker/build-push-action from 6.18.0 to 6.19.1 (#4530)
dependabot[bot] Feb 12, 2026
52c243f
build(deps): bump golang from 1.25.7-alpine3.22 to 1.26.0-alpine3.22 …
dependabot[bot] Feb 12, 2026
5c32fad
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.33 to 1.14.34…
dependabot[bot] Feb 12, 2026
1855a9a
build(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 (#4525)
dependabot[bot] Feb 12, 2026
9bee0b0
build(deps): bump google.golang.org/grpc in /examples (#4537)
dependabot[bot] Feb 13, 2026
f2c2526
build(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.0 (#4534)
dependabot[bot] Feb 13, 2026
4955d43
build(deps): bump docker/build-push-action from 6.19.1 to 6.19.2 (#4535)
dependabot[bot] Feb 13, 2026
76d7ed4
build(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0 (#4…
dependabot[bot] Feb 13, 2026
489e37d
fix: suppress deprecation warning for userAttr when not set (#4539)
nabokihms Feb 13, 2026
d90827c
fix: use correct id value for label (#4541)
loganripplinger Feb 15, 2026
7850337
feat: refactor signer configuration with local and vault options (#4532)
nabokihms Feb 15, 2026
ad3a83e
build(gomplate): update gomplate version to v5.0.0 and add update scr…
nabokihms Feb 15, 2026
9bee809
feat(crd): add CRD handling behavior and configuration options (#4543)
nabokihms Feb 15, 2026
a5f4956
Add permissions section to trivydb-cache workflow (#4544)
nabokihms Feb 15, 2026
7c74dd8
build(deps): bump distroless/static-debian13 from `f9f84bd` to `01e55…
dependabot[bot] Feb 16, 2026
2976b23
build(deps): bump google.golang.org/grpc in /examples (#4551)
dependabot[bot] Feb 16, 2026
e640a40
build(deps): bump google.golang.org/grpc from 1.79.0 to 1.79.1 (#4549)
dependabot[bot] Feb 16, 2026
c331bb9
build(deps): bump the etcd group with 2 updates (#4548)
dependabot[bot] Feb 16, 2026
5593fb7
build(deps): bump github/codeql-action from 4.32.2 to 4.32.3 (#4547)
dependabot[bot] Feb 16, 2026
eb9f04b
Debug trivy scans (#4545)
nabokihms Feb 16, 2026
adec8b4
Add steps to fetch and extract OCI image tarball (#4552)
nabokihms Feb 16, 2026
955142b
feat: enhance git-version script to generate pseudo-versions with tim…
nabokihms Feb 16, 2026
dce4638
build(deps): update gRPC to v1.79.1 and other dependencies (#4554)
nabokihms Feb 17, 2026
be13b1f
build(deps): bump helm/kind-action from 1.13.0 to 1.14.0 (#4557)
dependabot[bot] Feb 18, 2026
69f9b7e
build(deps): bump google.golang.org/api from 0.266.0 to 0.267.0 (#4558)
dependabot[bot] Feb 18, 2026
29c7b6f
feat: validate redirect URIs and safely append parameters (#4559)
nabokihms Feb 18, 2026
548b0f5
build(deps): bump filippo.io/edwards25519 from 1.1.0 to 1.1.1 (#4562)
dependabot[bot] Feb 19, 2026
0108be9
feat: add skopeo copy command to transfer image from OCI layout (#4564)
nabokihms Feb 20, 2026
49c8228
build(deps): bump actions/dependency-review-action from 4.8.2 to 4.8.…
dependabot[bot] Feb 20, 2026
0807930
feat: add debug step to check image metadata in workflow (#4566)
nabokihms Feb 20, 2026
5d27abc
feat: refactor example-app with a new config (#4569)
nabokihms Feb 21, 2026
25591ee
Add support to PKCE in OIDC connector (#3777)
johnvan7 Feb 22, 2026
83697b0
fix(server): respond with forbidden if failed to authenticate (#4200)
aljoshare Feb 22, 2026
cf17fc6
test: update HandleCallback after merging OIDC PKCE (#4572)
nabokihms Feb 22, 2026
8db7699
feat: implement device code flow in example-app (#4570)
nabokihms Feb 22, 2026
51c66d2
build(deps): bump aquasecurity/trivy-action from 0.34.0 to 0.34.1 (#4…
dependabot[bot] Feb 23, 2026
ec26e19
build(deps): bump github/codeql-action from 4.32.3 to 4.32.4 (#4573)
dependabot[bot] Feb 23, 2026
bcc2283
feat: enhance test commands to support GitHub Actions formatting (#4575)
nabokihms Feb 23, 2026
0963bbe
build(deps): bump google.golang.org/api from 0.267.0 to 0.268.0 (#4577)
dependabot[bot] Feb 24, 2026
a6962a8
fix(mysql): quote `groups` reserved word in query replacer (#4580)
backkem Feb 24, 2026
2ecf64e
build(deps): bump google.golang.org/api from 0.268.0 to 0.269.0 (#4582)
dependabot[bot] Feb 25, 2026
4c3dffd
build(deps): bump actions/setup-go from 6.2.0 to 6.3.0 (#4584)
dependabot[bot] Feb 26, 2026
9cd6668
build(deps): bump anchore/sbom-action from 0.22.2 to 0.23.0 (#4587)
dependabot[bot] Feb 26, 2026
c0daa71
build(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#4586)
dependabot[bot] Feb 26, 2026
3295c72
build(deps): bump actions/attest-build-provenance from 3.2.0 to 4.0.0…
dependabot[bot] Feb 26, 2026
49dcb4d
fix: clean up in-memory connector before create (#4529)
loafoe Feb 26, 2026
d78d744
feat: Disallow unknown config fields (#4531)
nabokihms Feb 26, 2026
4311931
feat: saml support refresh tokens (#4565)
Jabejixo Feb 26, 2026
44e2749
fix(connector): update authproxy and oauth to match CallbackConnector…
matzegebbe Feb 26, 2026
47e84db
feat(connector): add compile-time checks for connector interfaces (#4…
nabokihms Feb 26, 2026
8ab16cf
build(deps): bump actions/attest-build-provenance from 4.0.0 to 4.1.0…
dependabot[bot] Feb 27, 2026
e5e64c6
build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 (#4594)
dependabot[bot] Feb 27, 2026
e5c14f1
build(deps): bump distroless/static-debian13 from `01e550f` to `f512d…
dependabot[bot] Feb 27, 2026
e1d6c38
fix: Invert condition for unknown fields in config unmarshaller (#4596)
nabokihms Feb 27, 2026
99c4233
fix: fix typo in grpc listener error message (#4598)
kanywst Feb 28, 2026
91e985e
fix: correct error message for device request expiry (#4599)
kanywst Mar 2, 2026
a70f592
fix(deviceflow): update redirect URIs to use absolute paths for non-r…
nabokihms Mar 2, 2026
044dcd5
build(deps): bump aquasecurity/trivy-action from 0.34.1 to 0.34.2 (#4…
dependabot[bot] Mar 3, 2026
e79638d
build(deps): bump github/codeql-action from 4.32.4 to 4.32.5 (#4603)
dependabot[bot] Mar 3, 2026
fec4f53
feat(oauth2): add client credentials flow with opt-in config flag (#4…
matzegebbe Mar 3, 2026
57a601f
build(deps): bump actions/dependency-review-action from 4.8.3 to 4.9.…
dependabot[bot] Mar 4, 2026
fb57055
build(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0 (#4608)
dependabot[bot] Mar 5, 2026
3ab0947
build(deps): bump docker/login-action from 3.7.0 to 4.0.0 (#4609)
dependabot[bot] Mar 5, 2026
a11b3cd
feat(gitlab): implement TokenIdentity method (#4606)
nabokihms Mar 5, 2026
7870871
build(deps): bump golang from 1.26.0-alpine3.22 to 1.26.1-alpine3.22 …
dependabot[bot] Mar 6, 2026
91bf627
build(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0 (#4…
dependabot[bot] Mar 6, 2026
8dce952
build(deps): bump docker/build-push-action from 6.19.2 to 7.0.0 (#4613)
dependabot[bot] Mar 6, 2026
976e45e
build(deps): bump docker/metadata-action from 5.10.0 to 6.0.0 (#4614)
dependabot[bot] Mar 6, 2026
f4c3102
build(deps): bump github/codeql-action from 4.32.5 to 4.32.6 (#4615)
dependabot[bot] Mar 6, 2026
591a201
feat(tests): add MySQL 8 support in CI and tests (#4617)
nabokihms Mar 6, 2026
c03a687
fix(server): handle double-submit on approval endpoint (#4620)
mark-liu Mar 8, 2026
e2462a2
build(deps): bump golang.org/x/oauth2 from 0.35.0 to 0.36.0 in /examp…
dependabot[bot] Mar 9, 2026
9ba3c3f
build(deps): bump aquasecurity/trivy-action from 0.34.2 to 0.35.0 (#4…
dependabot[bot] Mar 9, 2026
74dd7ee
build(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.2 (#4623)
dependabot[bot] Mar 9, 2026
e67c47c
build(deps): bump golang.org/x/oauth2 from 0.35.0 to 0.36.0 (#4624)
dependabot[bot] Mar 9, 2026
01b6822
build(deps): bump google.golang.org/grpc in /examples (#4626)
dependabot[bot] Mar 9, 2026
a4136db
build(deps): bump google.golang.org/grpc in /api/v2 (#4625)
dependabot[bot] Mar 9, 2026
35c0b56
build(deps): bump sigstore/cosign-installer from 4.0.0 to 4.1.0 (#4628)
dependabot[bot] Mar 10, 2026
7bd3c2a
build(deps): bump google.golang.org/api from 0.269.0 to 0.270.0 (#4630)
dependabot[bot] Mar 10, 2026
ae8c5af
build(deps): bump anchore/sbom-action from 0.23.0 to 0.23.1 (#4629)
dependabot[bot] Mar 10, 2026
3d97c59
test: add concurrency tests for storage implementations (#4631)
nabokihms Mar 10, 2026
47b6454
build(deps): bump google.golang.org/api from 0.270.0 to 0.271.0 (#4633)
dependabot[bot] Mar 11, 2026
7777773
feat(connector): connectors for grants (#4619)
nabokihms Mar 11, 2026
f80a89d
feat(client): add allowed connectors field to client configuration (#…
nabokihms Mar 11, 2026
80d297b
feat: update CSS for improved theming and button styles (#4634)
nabokihms Mar 12, 2026
734d60f
build(deps): bump golang.org/x/crypto from 0.48.0 to 0.49.0 (#4636)
dependabot[bot] Mar 12, 2026
13f012f
build(deps): bump golang.org/x/net from 0.51.0 to 0.52.0 (#4635)
dependabot[bot] Mar 12, 2026
2bda646
test: fix token introspection tests to use consistent timestamps (#4639)
nabokihms Mar 13, 2026
5bbfbbe
feat: add PKCE (Proof Key for Code Exchange) configuration to OAuth2 …
nabokihms Mar 13, 2026
0568abe
DEP: CEL integration (#4601)
nabokihms Mar 13, 2026
175dc57
feat(cel): implement CEL compiler with library (#4607)
nabokihms Mar 13, 2026
e8f79fe
DEP: Auth Sessions - Introduce (#4561)
nabokihms Mar 14, 2026
5a4395f
feat: add UserIdentity entity and CRUD operations (#4643)
nabokihms Mar 14, 2026
4fb3e78
feat(logger): add excludeFields config for PII redaction (#4621)
mark-liu Mar 15, 2026
fe79863
build(deps): bump mheap/github-action-required-labels (#4649)
dependabot[bot] Mar 16, 2026
4433b36
build(deps): bump distroless/static-debian13 from `f512d81` to `e3f94…
dependabot[bot] Mar 16, 2026
93985de
fix: increase lock acquisition attempts from 60 to 200 for better rel…
nabokihms Mar 16, 2026
0f9b7eb
Pin GitHub API version in requests (#4647)
utafrali Mar 16, 2026
12339f2
feat: implement user identity creation and persisting consent (#4645)
nabokihms Mar 16, 2026
6b9ce00
feat: implement AuthSession CRUD operations (#4646)
nabokihms Mar 16, 2026
de1e85a
build(deps): bump github/codeql-action from 4.32.6 to 4.33.0 (#4651)
dependabot[bot] Mar 17, 2026
72e63fa
build(deps): bump google.golang.org/api from 0.271.0 to 0.272.0 (#4652)
dependabot[bot] Mar 17, 2026
d31ed97
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.34 to 1.14.37…
dependabot[bot] Mar 17, 2026
90fd51b
feat(ldap): allow specifying multiple attributes on username input (#…
yardenshoham Mar 17, 2026
1e65dda
fix(localSigner): simplify Algorithm method to always return RSA algo…
nabokihms Mar 17, 2026
285d83b
build(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3 (#4658)
dependabot[bot] Mar 18, 2026
7f4a5a7
build(deps): bump github.com/go-ldap/ldap/v3 from 3.4.12 to 3.4.13 (#…
dependabot[bot] Mar 18, 2026
8af6d3c
build(deps): bump google.golang.org/grpc in /examples (#4661)
dependabot[bot] Mar 18, 2026
cbd7dd7
feat: Create AuthSessions and set cookies (#4650)
nabokihms Mar 18, 2026
503ddca
DEP for Identity Assertion JWT Authorization Grant (ID-JAG) / request…
kanywst Mar 18, 2026
86abd33
Two-Factor authentication (TOTP) (#3712)
nabokihms Mar 18, 2026
8938c98
build(deps): bump github.com/russellhaering/goxmldsig (#4664)
dependabot[bot] Mar 18, 2026
56914a8
build(deps): bump github.com/lib/pq from 1.11.2 to 1.12.0 (#4666)
dependabot[bot] Mar 19, 2026
ff5bc7c
build(deps): bump actions/cache from 5.0.3 to 5.0.4 (#4665)
dependabot[bot] Mar 19, 2026
7ec1760
feat: Add OIDC conformance testing scripts and configuration (#4663)
nabokihms Mar 19, 2026
c3bc1d7
feat: add auth_time, prompt, and max_age fields (#4662)
nabokihms Mar 19, 2026
92f51f9
fix non-constant format string in call to newRedirectedErr (#4671)
taylorsilva Mar 20, 2026
3b5be6a
Disable MFA configuration in config-dev.yaml (#4672)
nabokihms Mar 20, 2026
5bbc400
feat: implement id_token_hint (#4670)
nabokihms Mar 20, 2026
449f664
feat: Add AuthSession GC (#4667)
nabokihms Mar 20, 2026
3c7e159
chore: update Go and gRPC dependencies to latest versions (#4673)
nabokihms Mar 20, 2026
363e9d5
feat: use protobuf for session cookie (#4675)
nabokihms Mar 20, 2026
9d22748
build(deps): bump github/codeql-action from 4.33.0 to 4.34.1 (#4679)
dependabot[bot] Mar 24, 2026
2e41d5b
build(deps): bump anchore/sbom-action from 0.23.1 to 0.24.0 (#4681)
dependabot[bot] Mar 24, 2026
894f87d
build(deps): bump the etcd group with 2 updates (#4680)
dependabot[bot] Mar 24, 2026
cf2c017
build(deps): update entgo.io/ent to v0.14.6 and ariga.io/atlas to v0.…
nabokihms Mar 24, 2026
08dc8ee
docs: add CONTRIBUTING.md (#4685)
nabokihms Mar 25, 2026
098ab60
feat: support ES256 local signer (#4682)
space-arens Mar 25, 2026
896c695
build(deps): bump google.golang.org/api from 0.272.0 to 0.273.0 (#4689)
dependabot[bot] Mar 26, 2026
58e387a
build(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.1 (#4692)
dependabot[bot] Mar 27, 2026
9f92c71
feat: cookies encryption support (#4676)
nabokihms Mar 27, 2026
9caf0f1
feat: prompt select_login (#4678)
nabokihms Mar 27, 2026
1558aac
fix: fix handler tests after merging cookie enc (#4693)
nabokihms Mar 27, 2026
31cf652
feat: add a jti per default (#4695)
bufferoverflow Mar 28, 2026
89f4321
Updating the maintainers list (#4696)
nabokihms Mar 29, 2026
bf323d3
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.37 to 1.14.38…
dependabot[bot] Mar 30, 2026
6e695a6
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#4700)
dependabot[bot] Mar 30, 2026
2fa7d80
build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 (#4698)
dependabot[bot] Mar 30, 2026
f90a36c
docs: mention LDAP recursionGroupAttr in config.yaml.dist (#4697)
space-arens Mar 30, 2026
780cbe1
feat: disconnect upstream refreshing
nabokihms Mar 30, 2026
8031f5b
feat: add home page with user session info (#4677)
nabokihms Mar 30, 2026
bc8f045
feat: include prompt=select_account in back link for multiple connect…
nabokihms Mar 30, 2026
d4807b6
fix: update parseSession callas after merging home page (#4701)
nabokihms Mar 30, 2026
830fca9
fix: migrate Bitbucket Cloud connector to current workspace API (#4687)
nicknikolakakis Mar 31, 2026
06c5233
build(deps): bump github.com/lib/pq from 1.12.0 to 1.12.1 (#4702)
dependabot[bot] Mar 31, 2026
142d776
build(deps): bump google.golang.org/api from 0.273.0 to 0.273.1 (#4707)
dependabot[bot] Apr 1, 2026
486320d
build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (…
dependabot[bot] Apr 1, 2026
58f148d
feat: implement OIDC RP-Initiated logout (#4674)
nabokihms Apr 1, 2026
546e66c
feat: add WebAuthn support (#4704)
nabokihms Apr 2, 2026
3bf25fd
feat: add SSO sharing policy (#4705)
nabokihms Apr 2, 2026
6f2e233
feat: example app session refactoring (#4712)
nabokihms Apr 2, 2026
ed88652
build(deps): bump google.golang.org/grpc in /examples (#4710)
dependabot[bot] Apr 2, 2026
61635a6
build(deps): bump google.golang.org/grpc from 1.79.3 to 1.80.0 (#4709)
dependabot[bot] Apr 2, 2026
6511fb9
build(deps): bump the etcd group with 2 updates (#4708)
dependabot[bot] Apr 2, 2026
5b5b467
build(deps): bump github.com/go-jose/go-jose/v4 (#4718)
dependabot[bot] Apr 3, 2026
7bd2f57
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.38 to 1.14.39…
dependabot[bot] Apr 3, 2026
af47557
build(deps): bump github.com/go-webauthn/webauthn from 0.16.1 to 0.16…
dependabot[bot] Apr 3, 2026
503e461
build(deps): bump github.com/lib/pq from 1.12.1 to 1.12.2 (#4716)
dependabot[bot] Apr 3, 2026
6e7a983
build(deps): bump docker/login-action from 4.0.0 to 4.1.0 (#4713)
dependabot[bot] Apr 3, 2026
a10dd9b
build(deps): bump google.golang.org/api from 0.273.1 to 0.274.0 (#4714)
dependabot[bot] Apr 3, 2026
a90912e
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.39 to 1.14.40…
dependabot[bot] Apr 6, 2026
a0f1231
build(deps): bump github.com/go-webauthn/webauthn from 0.16.2 to 0.16…
dependabot[bot] Apr 6, 2026
ea243dd
build(deps): bump github.com/lib/pq from 1.12.2 to 1.12.3 (#4720)
dependabot[bot] Apr 6, 2026
0977c87
docs: update README and remove gitpod (#4719)
nabokihms Apr 6, 2026
4d4c58d
Use the C approach
nabokihms Apr 6, 2026
90bb8eb
Fixes according to codereview comments
nabokihms Apr 6, 2026
832caae
build(deps): bump oras-project/setup-oras from 1.2.4 to 2.0.0 (#4723)
dependabot[bot] Apr 7, 2026
cda5c37
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.40 to 1.14.41…
dependabot[bot] Apr 7, 2026
9c138ef
fix: mfa not enforced on session validation (#4726)
jnfrati Apr 8, 2026
52ef42f
build(deps): bump golang from 1.26.1-alpine3.22 to 1.26.2-alpine3.22 …
dependabot[bot] Apr 8, 2026
d11dbd2
build(deps): bump google.golang.org/api from 0.274.0 to 0.275.0 (#4729)
dependabot[bot] Apr 8, 2026
05c23bd
build(deps): bump github.com/coreos/go-oidc/v3 from 3.17.0 to 3.18.0 …
dependabot[bot] Apr 8, 2026
95fefb4
build(deps): bump github.com/coreos/go-oidc/v3 in /examples (#4730)
dependabot[bot] Apr 8, 2026
2fb5d78
feat: Add more tests for sessions and edge case
nabokihms Apr 8, 2026
6189b20
Fix nonce comparison to prevent timing
nabokihms Apr 8, 2026
ae0c5c0
Fix linter
nabokihms Apr 8, 2026
683d1ee
feat: Add more tests for sessions and edge cases (#4731)
nabokihms Apr 8, 2026
066f34c
build(deps): bump github.com/google/cel-go from 0.27.0 to 0.28.0 (#4733)
dependabot[bot] Apr 9, 2026
0e0b936
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.41 to 1.14.42…
dependabot[bot] Apr 9, 2026
f49dddc
build(deps): bump golang.org/x/net from 0.52.0 to 0.53.0 (#4738)
dependabot[bot] Apr 10, 2026
eec8f76
feat(microsoft): map userPrincipalName to preferred_username claim (#…
matzegebbe Apr 10, 2026
410a58f
build(deps): bump github.com/go-webauthn/webauthn from 0.16.3 to 0.16…
dependabot[bot] Apr 10, 2026
bdfac38
build(deps): bump docker/build-push-action from 7.0.0 to 7.1.0 (#4740)
dependabot[bot] Apr 13, 2026
6f78bb6
build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#4741)
dependabot[bot] Apr 13, 2026
acd853b
build(deps): bump actions/cache from 5.0.4 to 5.0.5 (#4744)
dependabot[bot] Apr 14, 2026
6f68a40
feat(oauth2): populate groups claim in client_credentials tokens (#4691)
carlesarnal Apr 14, 2026
5d33f94
build(deps): bump alpine from 3.23.3 to 3.23.4 (#4746)
dependabot[bot] Apr 16, 2026
2d12818
build(deps): bump google.golang.org/api from 0.275.0 to 0.276.0 (#4745)
dependabot[bot] Apr 16, 2026
5f9ad5c
build(deps): bump github/codeql-action from 4.35.1 to 4.35.2 (#4747)
dependabot[bot] Apr 16, 2026
75934f3
Add OpenSSF Best Practices badge (#4748)
nabokihms Apr 16, 2026
6cf5b52
Add LFX Health Score badge (#4749)
nabokihms Apr 16, 2026
ec003f5
Read User Identity once
nabokihms Apr 17, 2026
ed65360
feat: disconnect upstream refreshing (#4703)
nabokihms Apr 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 0 additions & 2 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1,4 +1,2 @@
.github/
.gitpod.yml
bin/
tmp/
3 changes: 3 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,6 @@ indent_style = tab

[{config.yaml.dist,config.dev.yaml}]
indent_size = 2

[.golangci.yaml]
indent_size = 2
6 changes: 3 additions & 3 deletions .envrc
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
if ! has nix_direnv_version || ! nix_direnv_version 1.5.0; then
source_url "https://raw.githubusercontent.com/nix-community/nix-direnv/1.5.0/direnvrc" "sha256-carKk9aUFHMuHt+IWh74hFj58nY4K3uywpZbwXX0BTI="
if ! has nix_direnv_version || ! nix_direnv_version 3.0.6; then
source_url "https://raw.githubusercontent.com/nix-community/nix-direnv/3.0.6/direnvrc" "sha256-RYcUJaRMf8oF5LznDrlCXbkOQrywm0HDv1VjYGaJGdM="
fi
use flake
use flake . --impure

dotenv_if_exists
6 changes: 5 additions & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
blank_issues_enabled: false
contact_links:
- name: 📖 Documentation enhancement
url: https://github.com/dexidp/website/issues
about: Suggest an improvement to the documentation

- name: ❓ Ask a question
url: https://github.com/dexidp/dex/discussions/new?category=q-a
about: Ask and discuss questions with other Dex community members
Expand All @@ -13,5 +17,5 @@ contact_links:
about: Please ask and answer questions here

- name: 💡 Dex Enhancement Proposal
url: https://github.com/dexidp/dex/tree/master/enhancements/README.md
url: https://github.com/dexidp/dex/tree/master/docs/enhancements/README.md
about: Open a proposal for significant architectural change
12 changes: 0 additions & 12 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,15 +21,3 @@ Thank you for sending a pull request! Here are some tips for contributors:
-->

#### Special notes for your reviewer

#### Does this PR introduce a user-facing change?

<!--
If no, just write "NONE" in the release-note block below.
If yes, a release note is required:
Enter your extended release note in the block below. If the PR requires additional action from users switching to the new release, include the string "action required".
-->

```release-note
```
4 changes: 2 additions & 2 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,10 @@ to confirm receipt of the issue.
## Review Process

Once a maintainer has confirmed the relevance of the report, a draft security
advisory will be created on Github. The draft advisory will be used to discuss
advisory will be created on GitHub. The draft advisory will be used to discuss
the issue with maintainers, the reporter(s).
If the reporter(s) wishes to participate in this discussion, then provide
reporter Github username(s) to be invited to the discussion. If the reporter(s)
reporter GitHub username(s) to be invited to the discussion. If the reporter(s)
does not wish to participate directly in the discussion, then the reporter(s)
can request to be updated regularly via email.

Expand Down
11 changes: 11 additions & 0 deletions .github/dependabot.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,10 @@ updates:
- "area/dependencies"
schedule:
interval: "daily"
groups:
etcd:
patterns:
- "go.etcd.io/*"

- package-ecosystem: "gomod"
directory: "/api/v2"
Expand All @@ -15,6 +19,13 @@ updates:
schedule:
interval: "daily"

- package-ecosystem: "gomod"
directory: "/examples"
labels:
- "area/dependencies"
schedule:
interval: "daily"

- package-ecosystem: "docker"
directory: "/"
labels:
Expand Down
47 changes: 47 additions & 0 deletions .github/workflows/analysis-scorecard.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: OpenSSF Scorecard

on:
branch_protection_rule:
push:
branches: [ main ]
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scorecard workflow targets main instead of master

Low Severity

The new analysis-scorecard.yaml workflow triggers on pushes to branches: [ main ], but this fork's default branch is master (as seen in ci.yaml). The scorecard push trigger will never fire. The workflow only runs on the weekly schedule and branch_protection_rule events, which may not be the intent.

Fix in Cursor Fix in Web

schedule:
- cron: '30 0 * * 5'

permissions:
contents: read

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest

permissions:
actions: read
contents: read
id-token: write
security-events: write

steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- name: Run analysis
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif
publish_results: true

- name: Upload results as artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: OpenSSF Scorecard results
path: results.sarif
retention-days: 5

- name: Upload results to GitHub Security tab
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v3.29.5
with:
sarif_file: results.sarif
Loading