Commit Graph

252 Commits

Author SHA1 Message Date
aswin-in-philips 46dbf695a1 test 2023-03-29 12:49:26 +05:30
aswin-in-philips ec796fd4c6 test 2023-03-29 12:40:20 +05:30
aswin-in-philips 86490c1478 test 2023-03-29 12:13:06 +05:30
aswin-in-philips 2b60fef2ae image tag output 2023-03-29 12:10:55 +05:30
aswin-in-philips 0b0141a7d9 test 2023-03-29 12:05:57 +05:30
aswin-in-philips d36889a9d9 test 2023-03-29 11:45:33 +05:30
aswin-in-philips fa6a5d4fe7 test 2023-03-29 11:45:03 +05:30
aswin-in-philips 033ed6058b blackduck test 2023-03-29 11:32:42 +05:30
aswin-in-philips 73024ea000 adding blackduck scan 2023-03-29 11:24:16 +05:30
aswin-in-philips 99075fba8f blackduck test 2023-03-29 11:15:36 +05:30
aswin-in-philips 29abc70b36 adding go path file 2023-03-29 10:39:28 +05:30
aswin-in-philips 7c65c05e60 blackduck test 2023-03-29 10:28:23 +05:30
aswin-in-philips a574e9df6b test 2023-03-29 10:14:30 +05:30
aswin-in-philips b93b48d2f7 blackduck test 2023-03-29 09:56:47 +05:30
aswin-in-philips 37479c277a adding go path 2023-03-29 09:46:43 +05:30
aswin-in-philips 781c8044ca blackduck test 2023-03-29 09:39:37 +05:30
aswin-in-philips 4148270258 blackduck test 2023-03-28 17:34:10 +05:30
aswin-in-philips a0e6c53c95 blackduck scan fix 2023-03-28 16:05:51 +05:30
aswin-in-philips 4cbf2ca4a9 blackduck test 2023-03-28 16:02:18 +05:30
aswin-in-philips cb04ec366f blackduck test 2023-03-28 14:48:08 +05:30
aswin-in-philips 837d2748eb adding blackduck scan 2023-03-28 14:41:17 +05:30
aswin-in-philips 45dbb96b94 docker test 2023-03-28 14:35:40 +05:30
aswin-in-philips 9413625878 blackduck test 2023-03-28 13:57:11 +05:30
aswin-in-philips 65dd81dd10 blackduck test 2023-03-28 13:50:49 +05:30
aswin-in-philips 1095a14cdd updating runner 2023-03-28 12:41:04 +05:30
aswin-in-philips bb66257a24 blackduck test 2023-03-28 12:26:30 +05:30
aswin-in-philips dab087ab22 adding java action 2023-03-28 12:15:21 +05:30
aswin-in-philips 87a423834c blackduck test 2023-03-28 11:54:50 +05:30
aswin-in-philips e245d75d80 test 2023-03-28 11:47:11 +05:30
aswin-in-philips 26196b3fcc test 2023-03-28 11:32:19 +05:30
aswin-in-philips ea9e1e2c80 java setup 2023-03-28 11:28:46 +05:30
aswin-in-philips a408e7a859 installing java 2023-03-28 11:24:47 +05:30
aswin-in-philips 4b938a9b0f test 2023-03-28 11:20:53 +05:30
aswin-in-philips f681b83e33 checking blackduck 2023-03-28 11:02:38 +05:30
aswin-in-philips ff784a422c blackduck test 2023-03-28 10:59:23 +05:30
aswin-in-philips 4be8f36049 commenting blackduck scan 2023-03-27 16:39:33 +05:30
Nuno Miguel Micaelo Borges e079c60dfe
Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is wri… (#2013)
* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Fixes CVE-2022-41721 (#1994)

See: https://avd.aquasec.com/nvd/2022/cve-2022-41717/

* update checkout actions (#1981)

* Fix a typo in oauthproxy.go (#2021)

* fix typo (#2001)

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

* Issue 1929: Oauth2-proxy v7.4.0 is not using alpine:3.16 as it is written in code & updates versions due to fixed CVEs

---------

Co-authored-by: Nuno Borges <Nuno.Borges@ctw.bmwgroup.com>
Co-authored-by: Jeroen Landheer <jlandheer@bintelligence.nl>
Co-authored-by: Ryuichi Watanabe <ryucrosskey@gmail.com>
Co-authored-by: Ho Kim <ho.kim@ulagbulag.io>
Co-authored-by: Terrell Russell <terrellrussell@gmail.com>
2023-03-05 17:12:55 +00:00
aswin-in-philips d116b068d3
Update ci.yaml 2023-02-18 13:19:03 +05:30
aswin-in-philips 7793caffa1
Update ci.yaml 2023-02-18 13:17:34 +05:30
aswin-in-philips c9e1955117 updating branch name 2023-02-17 14:07:14 +05:30
aswin-in-philips 6e0f60e783 updating job name 2023-02-17 13:32:59 +05:30
aswin-in-philips b63dd5bdc6 updating branch 2023-02-17 13:28:46 +05:30
aswin-in-philips 2b3f72d59c branch update 2023-02-17 13:11:56 +05:30
aswin-in-philips b42f53d174 coverage test 2023-02-17 13:10:52 +05:30
aswin-in-philips de4ca50d9b testing sonar 2023-02-17 13:01:04 +05:30
aswin-in-philips 642ccbef85 test 2023-02-17 12:57:48 +05:30
aswin-in-philips 6209272b46 test 2023-02-17 12:46:11 +05:30
aswin-in-philips 594175bd30 blackduck test 2023-02-17 12:30:36 +05:30
aswin-in-philips e63942f143 test 2023-02-17 12:19:50 +05:30
aswin-in-philips b9172cee05 blackduck test 2023-02-17 12:13:43 +05:30
aswin-in-philips 43b9edc4c0 adding secrets 2023-02-17 12:05:13 +05:30
aswin-in-philips 05731bac5d test 2023-02-17 11:56:37 +05:30
aswin-in-philips 4789f0b109 blackduck test 2023-02-17 11:52:43 +05:30
aswin-in-philips a9def5ea4d test 2023-02-17 11:40:11 +05:30
aswin-in-philips fd601df0f7 test 2023-02-17 11:25:33 +05:30
aswin-in-philips 52bdfa6a42 test 2023-02-17 11:06:20 +05:30
aswin-in-philips d3fd631fc0 adding blackduck and fortify 2023-02-17 11:05:17 +05:30
aswin-in-philips e8f4a5cb81 test run 2023-02-17 11:04:00 +05:30
Om Aximani cefeff5561
Chnages `checkout` version to `v3` 2023-01-27 22:53:05 +05:30
Adrian Aneci b3df9aecc2 Bump golang to 1.19 and min allowed version to 1.18 2022-10-21 20:40:58 +03:00
Adrian Aneci a5d918898c Add azure groups support and oauth2 v2.0 2022-10-21 20:23:21 +03:00
aswin-in-philips 254bd0e59b separating pr and main deployment 2022-10-21 19:17:23 +05:30
aswin-in-philips 0f8c26454b change 2022-07-11 20:00:15 +05:30
aswin-in-philips 252314532e changing base image 2022-07-11 16:49:22 +05:30
aswin-in-philips f94d8ebb76 file name change 2022-07-11 15:37:38 +05:30
aswin-in-philips 279a55126c change 2022-07-11 15:30:45 +05:30
aswin-in-philips 2d45db2d45 Merge branch 'release-version' of https://github.com/philips-forks/oauth2-proxy into release-version 2022-07-11 15:28:41 +05:30
aswin-in-philips d1e488daaa change 2022-07-11 15:28:38 +05:30
aswin-in-philips c6f52f2107
Update ci-integrated.yaml 2022-07-08 20:36:08 +05:30
aswin-in-philips dceaf6b295 changing workflow call file name 2022-07-08 09:24:01 +05:30
aswin-in-philips 564ebce538 change 2022-07-07 17:51:24 +05:30
aswin-in-philips b9d360cba1 change 2022-07-07 17:44:19 +05:30
aswin-in-philips 73a4850b12 removing Prometheus 2022-05-14 12:32:42 +05:30
aswin-in-philips d67b2a6555 adding workflow queue action 2022-05-13 17:36:48 +05:30
aswin-in-philips 31d247ea0c adding workflow queue 2022-05-12 17:42:56 +05:30
aswin-in-philips f9f561ab00 tag name change 2022-05-10 19:54:51 +05:30
aswin-in-philips 3cbdaa2ce1 adding condition 2022-05-09 23:45:57 +05:30
aswin-in-philips 6587a2137d removing pr 2022-05-09 23:32:41 +05:30
aswin-in-philips 7defb13357 change 2022-05-09 23:32:03 +05:30
aswin-in-philips d1916115f0 adding branch name 2022-05-09 22:13:20 +05:30
aswin-in-philips c890d329ff changing branch name 2022-05-09 21:55:44 +05:30
aswin-in-philips 02601f9eae changing branch name 2022-05-05 15:36:06 +05:30
aswin-in-philips 4181ec103e changing job names 2022-05-05 15:09:10 +05:30
aswin-in-philips fcfead835f adding trigger workflow 2022-05-05 15:07:14 +05:30
aswin-in-philips b9496e5a07 chaing docker 2022-05-05 14:40:49 +05:30
aswin-in-philips 35a32f1a66 adding sudo 2022-05-05 14:21:02 +05:30
aswin-in-philips 40e48af09d adding install command for bump version 2022-05-05 14:19:48 +05:30
aswin-in-philips 2d3e42c412 Adding init and bumpversion 2022-05-05 14:17:39 +05:30
aswin-in-philips 6815c22629 removing branch name 2022-05-05 14:09:13 +05:30
aswin-in-philips 3564847ff4 changing file names 2022-05-05 14:08:41 +05:30
aswin-in-philips e9c65f892c adding bump versions 2022-05-05 14:03:48 +05:30
aswin-in-philips d04a7e6ba2 changing branch name 2022-05-05 13:54:50 +05:30
aswin-in-philips 6fb580e6ef changing branch name 2022-05-05 13:50:46 +05:30
aswin-in-philips 8e32ad1315 adding secrets 2022-05-05 12:19:25 +05:30
aswin-in-philips 7da90dfe2a changing build label name 2022-05-05 10:53:56 +05:30
aswin-in-philips 5ab66803a3 changing branch name 2022-05-05 10:45:10 +05:30
aswin-in-philips d2836d08fc changing branch name 2022-05-05 10:39:55 +05:30
aswin-in-philips 941beae21c removing cd files 2022-05-03 13:19:12 +05:30
aswin-in-philips 076a4b8858 chaging runner label 2022-05-03 10:03:58 +05:30
aswin-in-philips f93cb82a0d adding gated sanity files with Automation tests 2022-05-03 09:57:04 +05:30
aswin-in-philips cb2a4ad850 changing branch name 2022-05-02 18:23:11 +05:30
aswin-in-philips 3740172ef2 adding terraform and terragrunt files 2022-05-02 18:22:08 +05:30
aswin-in-philips 39a36b8824 adding trigger workflow and release-candidate 2022-05-02 18:09:53 +05:30
aswin-in-philips f757a51211 Removing Fortify Old build 2022-04-04 14:06:57 +05:30
aswin-in-philips 11821d5a98 Adding Fortify and Blackduck scans 2022-04-04 12:43:56 +05:30
Joel Speed eb43b17750
Ensure docs release action has correct env 2022-02-20 14:07:56 +00:00
Joel Speed c232136196
Update docs github actions to Node 17 2022-02-19 18:45:07 +00:00
aswin-in-philips 3fbffa474e
Update Blackduck.yaml 2022-01-11 18:21:37 +05:30
aswin-in-philips 8b19f6162d
Update Blackduck.yaml 2022-01-11 18:16:37 +05:30
aswin-in-philips 6aed28ba8e
Update fortify.yaml 2022-01-10 17:25:05 +05:30
aswin-in-philips f0e785e10b
Update fortify.yaml 2022-01-10 17:12:50 +05:30
aswin-in-philips 4fff2eddea
Update fortify.yaml 2022-01-07 12:09:26 +05:30
aswin-in-philips b25d62f752
Update Blackduck.yaml 2022-01-07 12:08:04 +05:30
aswin-in-philips aeca2839a5 New commit 2022-01-05 17:11:15 +05:30
polarctos 7eaf98b5fe Update go version to 1.17
This includes the change to the pruned module graph with the converted go.mod for Go 1.17
https://go.dev/doc/go1.17#go-command
2021-12-17 16:51:13 +01:00
Ryan Hartje 05a4e77c4c
Multiarch builds (#1147)
* extract email from id_token for azure provider (#914)

* extract email from id_token for azure provider

this change fixes a bug when --resource is specified with non-Graph
api and the access token destined to --resource is used to call Graph
api

* fixed typo

* refactor GetEmailAddress to EnrichSessionState

* make getting email from idtoken best effort and fall back to previous behavior when it's absent

* refactor to use jwt package to extract claims

* fix lint

* refactor unit tests to use test table
refactor the get email logic from profile api

* addressing feedback

* added oidc verifier to azure provider and extract email from id_token if present

* fix lint and codeclimate

* refactor to use oidc verifier to verify id_token if oidc is configured

* fixed UT

* addressed comments

* minor refactor

* addressed feedback

* extract email from id_token first and fallback to access token

* fallback to access token as well when id_token doesn't have email claim

* address feedbacks

* updated change log!

* switch to docker buildx for multiarch builds

* add setup docker buildx action

* update docker push to push the multiarch image

* make multiarch image have parity with currently produced images by adding linux/armv6

* triaging issue with arm v6

* incorporating feedback

* fixing rebase disaster

* reset Makefile to blessed state

Co-authored-by: Weinong Wang <weinong@outlook.com>
2021-09-21 14:17:59 +01:00
praneethsandra 7029dfd0b6
Update pr.yaml 2021-05-03 15:29:27 +05:30
praneethsandra e3328281b9
Update pr.yaml 2021-05-03 14:52:57 +05:30
praneethsandra 17a4b2078c
Update ci.yaml 2021-05-03 12:20:08 +05:30
praneethsandra e2bfb84a9a
Update ci.yaml 2021-05-03 12:15:46 +05:30
praneethsandra ed55dbfe0e
Update pr.yaml 2021-05-03 11:52:29 +05:30
praneethsandra cbd4fc1da5
Update ci.yaml 2021-05-03 11:33:57 +05:30
praneethsandra 2f81c9102a
Update pr.yaml 2021-05-03 11:33:28 +05:30
praneethsandra d25d5b4a8c
Update ci.yaml 2021-05-03 11:30:57 +05:30
praneethsandra f3f865f191
Create pr.yaml 2021-05-03 11:22:06 +05:30
Joel Speed d1e7ae6f11
Don't download dependencies using go mod 2021-02-19 11:31:00 +00:00
Joel Speed 5fe947eb07
Update go version to 1.16
This includes a fix for our samesite cookie parsing. The behaviour
changed in 1.16 so that the default value now leaves it empty, so it's
equivalent to not setting it (as per spec)
2021-02-19 11:30:58 +00:00
Joel Speed 9cea4ea89b
Update golangci-lint version in CI workflow 2021-02-17 20:25:37 +00:00
Joel Speed eb129a342c
Ensure code is generated during CI 2021-01-18 09:56:07 +00:00
Joel Speed ef2628d5b2
Add github action to deploy docusaurus 2020-11-05 15:36:30 +00:00
Joel Speed 3ccf74746e
Remove basename from test coverage prefix (#892)
Co-authored-by: Nick Meves <nick.meves@greenhouse.io>
2020-11-04 19:40:40 +00:00
Joel Speed 70c585812e
Fix coverage file path recognition 2020-10-07 18:48:14 +01:00
Joel Speed b848663a3d
Move test script to workflows folder 2020-10-07 18:48:11 +01:00
Mitsuo Heijo f705d2b5d3
Improve CI (#819)
* simplify github actions workflow

no more GOPATH, update Go to 1.15.x

* add script to install golangci-lint

* drop support for Go 1.14

* check docker build in ci

* update alpine linux to 3.12

* update CHANGELOG

* fix golangci-lint installation

Co-authored-by: Joel Speed <Joel.speed@hotmail.co.uk>
2020-10-07 18:46:41 +01:00
Shinebayar G dc7dbc5d28
ci: migrate to Github Actions, close #546 (#750)
* ci: migrate to Github Actions

* ci: optimize on feedback

* ci: run gocov in correct dir

* ci: running after-build script always

* ci: giving test script execute permission

* ci: correct error handling on test script

* ci: more verbose test script

* ci: configure CC_TEST_REPORTER_ID env

* ci: check existence of CC_TEST_REPORT_ID variable, skip if unset

* ci: check existence of CC_TEST_REPORT_ID variable, skip if unset

* update changelog

* Update CHANGELOG.md

Co-authored-by: Joel Speed <Joel.speed@hotmail.co.uk>
2020-10-05 10:29:47 +01:00
Justin Hutchings 43189a7854
Add pull request events to CodeQL action
This will validate pull requests from forks to ensure that changes don't end up impacting you negatively.
2020-07-28 21:42:21 -07:00
Joel Speed 390d479d28
Update CODEOWNERS to request review from reviewers team (#613)
This means that we can keep the list of reviewers up to date based on team membership, rather than this file. Will make it easier to add and remove people going forward
2020-07-02 21:09:55 +01:00
Joel Speed 53d8e99f05
Remove Syscll as a maintainer (#540) 2020-05-10 11:51:15 +01:00
Grey Baker 842d764a5f
Add code scanning workflow (#507) 2020-04-29 16:29:30 +01:00
Joel Speed 802754caad
Migrate to oauth2-proxy/oauth2-proxy 2020-03-29 15:40:10 +01:00
Dan Bond d94cf45ea8
Update .github/workflows/stale.yml
Co-Authored-By: Theo Barber-Bany <theo.barberbany@pusher.com>
2020-03-02 10:09:58 +00:00
Dan Bond 8ee8bd8bc2
Update .github/workflows/stale.yml
Co-Authored-By: Theo Barber-Bany <theo.barberbany@pusher.com>
2020-03-02 10:09:52 +00:00
Joel Speed 85891a2261
Add GitHub Action to tidy stale issues 2020-03-01 15:59:52 +00:00
Joel Speed 14db073807
Add JoelSpeed to CODEOWNERS 2020-01-20 19:39:31 +00:00
Kamal Nasser eee4b55e0f DigitalOcean Auth Provider (#351)
* DigitalOcean provider

* documentation: digitalocean provider

* changelog: digitalocean provider

* codeowners: digitalocean provider
2020-01-15 11:09:34 +00:00
Casey Link 227ea5da44 Add Nextcloud provider (#179) 2019-11-25 18:47:21 +01:00
aledeganopix4d fa6c4792a1 Add Bitbucket provider. (#201)
Add a new provider for Bitbucket,
can be configured from the options
specifying team and/or repository
that the user must be part/have access
to in order to grant login.
2019-08-16 14:53:22 +01:00
Joel Speed 23309adc7c
Fix CODEOWNERS file 2019-07-24 09:21:08 +01:00
Joel Speed e48d28d1b9
Add MAINTAINERS and update CODEOWNERS 2019-07-23 16:20:45 +01:00
Tim Spencer 8cc5fbf859 add login.gov provider (#55)
* first stab at login.gov provider

* fixing bugs now that I think I understand things better

* fixing up dependencies

* remove some debug stuff

* Fixing all dependencies to point at my fork

* forgot to hit save on the github rehome here

* adding options for setting keys and so on, use JWT workflow instead of PKCE

* forgot comma

* was too aggressive with search/replace

* need JWTKey to be byte array

* removed custom refresh stuff

* do our own custom jwt claim and store it in the normal session store

* golang json types are strange

* I have much to learn about golang

* fix time and signing key

* add http lib

* fixed claims up since we don't need custom claims

* add libs

* forgot ioutil

* forgot ioutil

* moved back to pusher location

* changed proxy github location back so that it builds externally, fixed up []byte stuff, removed client_secret if we are using login.gov

* update dependencies

* do JWTs properly

* finished oidc flow, fixed up tests to work better

* updated comments, added test that we set expiresOn properly

* got confused with header and post vs get

* clean up debug and test dir

* add login.gov to README, remove references to my repo

* forgot to remove un-needed code

* can use sample_key* instead of generating your own

* updated changelog

* apparently golint wants comments like this

* linter wants non-standard libs in a separate grouping

* Update options.go

Co-Authored-By: timothy-spencer <timothy.spencer@gsa.gov>

* Update options.go

Co-Authored-By: timothy-spencer <timothy.spencer@gsa.gov>

* remove sample_key, improve comments related to client-secret, fix changelog related to PR feedback

* github doesn't seem to do gofmt when merging.  :-)

* update CODEOWNERS

* check the nonce

* validate the JWT fully

* forgot to add pubjwk-url to README

* unexport the struct

* fix up the err masking that travis found

* update nonce comment by request of @JoelSpeed

* argh.  Thought I'd formatted the merge properly, but apparently not.

* fixed test to not fail if the query time was greater than zero
2019-03-20 13:44:51 +00:00