Skip to content

fix(deps): update module github.com/coreos/go-oidc/v3 to v3.18.0#3814

Open
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/github.com-coreos-go-oidc-v3-3.x
Open

fix(deps): update module github.com/coreos/go-oidc/v3 to v3.18.0#3814
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/github.com-coreos-go-oidc-v3-3.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 29, 2026

This PR contains the following updates:

Package Change Age Confidence
github.com/coreos/go-oidc/v3 v3.17.0v3.18.0 age confidence

Release Notes

coreos/go-oidc (github.com/coreos/go-oidc/v3)

v3.18.0

Compare Source

What's Changed

Full Changelog: coreos/go-oidc@v3.17.0...v3.18.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Apr 29, 2026

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.24.6 -> 1.25.0
golang.org/x/oauth2 v0.35.0 -> v0.36.0

Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review (automation)

Outcome: No medium, high, or critical security issues were identified in this PR’s changes.

Scope reviewed: go.mod / go.sum only — go 1.24.61.25.0, github.com/coreos/go-oidc/v3 v3.17.0v3.18.0, golang.org/x/oauth2 v0.35.0v0.36.0. No application code was modified, so there is no new auth, injection, or deserialization surface in Semaphore’s own logic.

Dependency note: Upstream v3.18.0 is primarily dependency alignment (e.g. go-jose / oauth2 bumps per upstream release notes). That is consistent with maintenance and patch-level crypto/JWT handling rather than introducing a new exploitable weakness for this bump alone.

Slack summary (copy/paste): PR #3814 (go-oidc → v3.18.0): security pass — diff is toolchain + OIDC/oauth2 bumps only, no app code changes; no actionable medium+ findings.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants