flowshield
flowshield copied to clipboard
chore(deps): bump github.com/spiffe/go-spiffe/v2 from 2.0.0-beta.4 to 2.3.0 in /ca
Bumps github.com/spiffe/go-spiffe/v2 from 2.0.0-beta.4 to 2.3.0.
Release notes
Sourced from github.com/spiffe/go-spiffe/v2's releases.
v2.3.0
Changed
- Empty bundles are now supported, in alignment with the SPIFFE specification (#288)
v2.2.0
Changed
- Upgraded to go-jose v4 which has a stronger security posture than v3. Go-spiffe was not impacted by the security weaknesses of v3 due to stringing algorithm checking that is now handled by go-jose v4 (#276)
Fixed
- Makefile invocation for Apple Silicon-based Macs (#275)
Added
- Support Ed25519 keys for Workload SVIDs (#248)
v2.1.7
Fixed
- Panic if the Workload API returned a malformed JWT-SVID (#233)
- Race that causes WaitForUpdate to return immediately after watcher is initialized even if there is no update (#260)
v2.1.6
Added
- Name convenience method to the spiffeid.TrustDomain type (#228)
v2.1.5
Added
- PeerIDFromConnectionState method for extracting the peer ID from TLS connection state (#225)
Changed
- The
tlsconfigto enforce a minimum TLS version of TLS1.2 (#226)Fixed
- Panic when failing to parse raw SVID response returned from the Workload API (#223)
v2.1.4
Added
- Support for the SVID hints obtained from the Workload API (#220)
v2.1.3
... (truncated)
Changelog
Sourced from github.com/spiffe/go-spiffe/v2's changelog.
[2.3.0] - 2024-06-17
Changed
- Empty bundles are now supported, in alignment with the SPIFFE specification (#288)
[2.2.0] - 2024-04-01
Changed
- Upgraded to go-jose v4 which has a stronger security posture than v3. Go-spiffe was not impacted by the security weaknesses of v3 due to stringing algorithm checking that is now handled by go-jose v4 (#276)
Fixed
- Makefile invocation for Apple Silicon-based Macs (#275)
Added
- Support Ed25519 keys for Workload SVIDs (#248)
[2.1.7] - 2024-01-17
Fixed
- Panic if the Workload API returned a malformed JWT-SVID (#233)
- Race that causes WaitForUpdate to return immediately after watcher is initialized even if there is no update (#260)
[2.1.6] - 2023-06-06
Added
- Name convenience method to the spiffeid.TrustDomain type (#228)
[2.1.5] - 2023-05-26
Added
- PeerIDFromConnectionState method for extracting the peer ID from TLS connection state (#225)
Changed
- The
tlsconfigto enforce a minimum TLS version of TLS1.2 (#226)Fixed
- Panic when failing to parse raw SVID response returned from the Workload API (#223)
[2.1.4] - 2023-03-31
... (truncated)
Commits
94335b2v2.3.0 changelog (#290)c1e1fafBump google.golang.org/protobuf from 1.33.0 to 1.34.2 in /v2 (#289)0e8e7f0Bump google.golang.org/grpc from 1.63.2 to 1.64.0 in /v2 (#287)ff0d21eBump github.com/go-jose/go-jose/v4 from 4.0.1 to 4.0.2 in /v2 (#286)5460476Allow empty x509 bundles to be sent in responses (#288)fb781b6Bump golang.org/x/net from 0.20.0 to 0.23.0 in /v2 (#282)d4e119dBump google.golang.org/grpc from 1.62.1 to 1.63.2 in /v2 (#280)fb89f07Bump github.com/Microsoft/go-winio from 0.6.1 to 0.6.2 in /v2 (#283)31d9835CHANGELOG for v2.2.0 (#278)bf6eecfUpdate to go-jose v4.0.1 (#276)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)