OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.39.1
Update max length of Kubernetes object to fit Kubernetes policy by @RomanenkoDenys in https://github.com/dexidp/dex/pull/3439 (fix regression for Kubernetes storage)
Do not escape password for LDAP connectors by @nabokihms in https://github.com/dexidp/dex/pull/3470 (changes introduced in v2.39.0 were reverted)
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.39.0
[!WARNING] The validation of username and password in the LDAP connector is much more strict now. As of today, Dex uses the
EscapeFilter
function to check for special characters in credentials and prevent injections by denying such requests.
the special characters in the set
()*\
and those out of the range 0 < c < 0x80, as defined in RFC4515
3bd4475
to 3354c3a
by @dependabot in https://github.com/dexidp/dex/pull/3310
9be3fcc
to a43abc8
by @dependabot in https://github.com/dexidp/dex/pull/3350
a43abc8
to 072d78b
by @dependabot in https://github.com/dexidp/dex/pull/3374
072d78b
to 9235ad9
by @dependabot in https://github.com/dexidp/dex/pull/3381
9235ad9
to 7e5c6a2
by @dependabot in https://github.com/dexidp/dex/pull/3410
010f3b3
to ede158f
by @dependabot in https://github.com/dexidp/dex/pull/3421
Full Changelog: https://github.com/dexidp/dex/compare/v2.38.0...v2.39.0
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.38.0
869193e
to 3bd4475
by @dependabot in https://github.com/dexidp/dex/pull/3301
Full Changelog: https://github.com/dexidp/dex/compare/v2.37.0...v2.38.0
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.37.0
Full Changelog: https://github.com/dexidp/dex/compare/v2.36.0...v2.37.0
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.36.0
Full Changelog: https://github.com/dexidp/dex/compare/v2.35.3...v2.36.0
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.35.3
Full Changelog: https://github.com/dexidp/dex/compare/v2.35.2...v2.35.3
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.35.2
Full Changelog: https://github.com/dexidp/dex/compare/v2.35.1...v2.35.2
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.35.1
Full Changelog: https://github.com/dexidp/dex/compare/v2.35.0...v2.35.1
⚠️ This release fixes a major vulnerability in Dex. We advise everyone to upgrade as soon as possible! ⚠️
If you use the Google connector, please upgrade to 2.35.1 instead.
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.35.0
Full Changelog: https://github.com/dexidp/dex/compare/v2.34.0...v2.35.0
The official container image for this release can be pulled from
ghcr.io/dexidp/dex:v2.34.0
Full Changelog: https://github.com/dexidp/dex/compare/v2.33.0...v2.34.0