chore(deps): update dependency pomerium/ingress-controller to v0.26.1 #13
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.25.2
->v0.26.1
v0.25.2
->v0.26.1
Release Notes
pomerium/ingress-controller (pomerium/ingress-controller)
v0.26.1
Compare Source
Security
This release includes multiple security updates:
The Pomerium user info page (at
/.pomerium
) unintentionally included serialized OAuth2 access and ID tokens from the logged-in user's session. These tokens are not intended to be exposed to end users, and have now been removed. CVE-2024-39315Credit to Vadim Sheydaev, aka Enr1g for reporting this issue.
This release also includes an update from Envoy 1.30.1 to Envoy 1.30.3 to address multiple security issues:
The release also removes a transitive dependency on the gopkg.in/square/go-jose.v2 library which is vulnerable to GHSA-c5q2-7r4c-mv6g.
What's Changed
Changed
Full Changelog: pomerium/ingress-controller@v0.26.0...v0.26.1
v0.26.0
Compare Source
Upgrading
See docs for further details.
What's Changed
Breaking
New
Fixes
Changed
Dependency Updates
8548e30
to530b451
by @dependabot in https://github.com/pomerium/ingress-controller/pull/89908baf3b
to8aa9165
in the docker group by @dependabot in https://github.com/pomerium/ingress-controller/pull/949New Contributors
Full Changelog: pomerium/ingress-controller@v0.25.2...v0.26.0
Configuration
📅 Schedule: Branch creation - "before 6am" in timezone America/Los_Angeles, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.