Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update module github.com/coreos/go-oidc to v3.10.0 #2399

Merged
merged 1 commit into from
May 8, 2024

Conversation

Nagarei
Copy link
Contributor

@Nagarei Nagarei commented May 1, 2024

breaking changes はあまり無さそうなので多分動く... 多分
https://github.com/coreos/go-oidc?tab=readme-ov-file#updates-from-v2-to-v3

@Nagarei
Copy link
Contributor Author

Nagarei commented May 1, 2024

蛇足: PRを出した経緯

  1. Docker Desktop に脆弱性あるよと言われる
    1. docker pull ghcr.io/traptitech/traq:3.17.0
    2. Docker Desktop の Images から traq:3.17.0 をクリックして Image hierarchy を見る
    3. Vulnerabilities が表示される
    4. gopkg.in/square/go-jose.v2 2.6.0 に脆弱性があるらしい
  2.  $ go mod why gopkg.in/square/go-jose.v2
     # gopkg.in/square/go-jose.v2
     github.com/traPtitech/traQ/router/auth
     github.com/coreos/go-oidc
     gopkg.in/square/go-jose.v2
    
  3. github.com/coreos/go-oidc を更新する

Copy link
Member

@motoki317 motoki317 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ありがとうございます

@motoki317 motoki317 merged commit 33374c8 into traPtitech:master May 8, 2024
6 checks passed
@Nagarei Nagarei deleted the update/coreos-oidc branch May 8, 2024 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants