Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
208 commits
Select commit Hold shift + click to select a range
bb6ff4e
chore(deps): update gitea/gitea docker tag to v1.23.7 (#3030)
renovate[bot] Apr 13, 2025
8abdbb5
Add --bearer-token-login-fallback option (#2924)
Apr 21, 2025
16e453e
chore(deps): update module golang.org/x/net to v0.38.0 [security] (#3…
renovate[bot] Apr 21, 2025
07b60b1
chore(deps): upgrade to latest golang v1.23.x release (#3041)
TheImplementer Apr 24, 2025
3afae76
chore(deps): update docker-compose (#3038)
renovate[bot] Apr 24, 2025
7d85c99
fix(entra-id): use federated credentials for refresh token (#3031)
Richard87 Apr 25, 2025
fc6ca1d
chore(deps): update ghcr.io/dexidp/dex docker tag to v2.42.1 (#3044)
renovate[bot] Apr 27, 2025
4237358
doc(entra-id): correct toml field in sample (#2946)
miniksa Apr 27, 2025
367183d
chore(build): refactoring makefile for better usability and introduci…
tuunit Apr 27, 2025
7b41c8e
fix: role extraction from access token in keycloak oidc (#1916)
Elektordi Apr 28, 2025
b7ff804
feat: ability to parse JWT encoded profile claims (#3014)
ikarius Apr 28, 2025
2ecb2c6
release: v7.9.0 (#3047)
github-actions[bot] Apr 28, 2025
bae509d
docs: clear up multiple-providers is unimplemented (#3046)
EvanCarroll Apr 28, 2025
14d5355
docs: add note about version obfuscation to footer option (#3051)
tuunit May 3, 2025
f82e904
chore(deps): update docker-compose (#3074)
renovate[bot] May 23, 2025
09f6252
chore(deps): drop golang.org/x/exp/{slices,maps} (#3065)
dolmen May 26, 2025
1225d61
chore(lint): fix staticcheck issues (#3061)
dolmen May 26, 2025
fb7e335
chores: major upgrade of golangci-lint from v1.64.8 to v2.1.6 (#3062)
dolmen May 26, 2025
7731437
feat: support for multiple github orgs (#3072)
daniel-mersch May 29, 2025
c8c160d
Create FUNDING.yml
tuunit Jul 11, 2025
1a03217
Merge pull request #3121 from oauth2-proxy/add-funding
JoelSpeed Jul 11, 2025
abb0a35
feat: bump to go1.24.5 and full dependency update (#3116)
wardviaene Jul 13, 2025
c4a02ec
chore(deps): update dependency golangci/golangci-lint to v2.2.2 (#3111)
renovate[bot] Jul 13, 2025
d390877
chore(deps): update dependency @easyops-cn/docusaurus-search-local to…
renovate[bot] Jul 13, 2025
40f3ef1
chore(deps): update example docker-compose files (#3096)
renovate[bot] Jul 13, 2025
b05bdc0
chore(deps): update helm examples (#2951)
renovate[bot] Jul 13, 2025
6c30a3c
chore(deps): update alpine base image to v3.22.0 (#3097)
renovate[bot] Jul 13, 2025
0e1dc9b
fix: return error for empty Redis URL list (#3101)
dgivens Jul 17, 2025
07a388d
add new docs version 7.10.x
github-actions[bot] Jul 17, 2025
5808f53
update to release version v7.10.0
github-actions[bot] Jul 17, 2025
e25f9ec
add changelog entry
tuunit Jul 17, 2025
78d2a36
Merge pull request #3128 from oauth2-proxy/release/v7.10.0
JoelSpeed Jul 17, 2025
313a2cb
chore(deps): update dependency @easyops-cn/docusaurus-search-local to…
renovate[bot] Jul 20, 2025
658256d
chore(deps): update gomod (#3132)
renovate[bot] Jul 20, 2025
c403d61
chore(deps): update helm release oauth2-proxy to v7.14.1 (#3133)
renovate[bot] Jul 20, 2025
20f561c
chore(deps): update docker-compose (#3130)
renovate[bot] Jul 20, 2025
d5f8507
chore(deps): update alpine docker tag to v3.22.1 (#3129)
renovate[bot] Jul 20, 2025
b57c821
feat(cookie) csrf per request limit (#3134)
tuunit Jul 20, 2025
5e7f14b
fix: show login page on broken session cookie (#2605)
Primexz Jul 20, 2025
3ac834d
Fix local-environment ports (#3136)
sim642 Jul 20, 2025
4d17bc1
feat: allow use more possible google admin-sdk api scopes (#2743)
BobDu Jul 21, 2025
a88306b
feat: add SourceHut (sr.ht) provider (#2359)
bitfehler Jul 22, 2025
137e59d
fix: regex substitution for $ signs in upstream path handling before …
dashkan Jul 22, 2025
dc8b162
feat(cookie): add feature support for cookie-secret-file (#3104)
sandy2008 Jul 22, 2025
b905f2c
feat: use non-default authorization request response mode in OIDC pro…
stieler-it Jul 23, 2025
e75a258
feat: make google-groups argument optional (#3138)
sourava01 Jul 24, 2025
f4b33b6
feat: differentiate between "no available key" and error for redis se…
nobletrout Jul 24, 2025
9ffafad
Merge commit from fork
tuunit Jul 30, 2025
c0a928e
release v7.11.0 (#3145)
github-actions[bot] Jul 30, 2025
4eaa1bc
fix: port for local-environment (#3148)
hunterboerner Aug 1, 2025
9667bce
feat(e2e): add workflow to trigger e2e test suite through PR comments…
tuunit Aug 12, 2025
4c86a4d
feat: add Cidaas provider (#2273)
Bibob7 Aug 12, 2025
744b31a
chore(dep): upgrade to latest golang 1.24.6 (#3166)
tuunit Aug 18, 2025
82e0169
chore(deps): update actions/checkout action to v5 (#3164)
renovate[bot] Aug 18, 2025
26813d3
chore(deps): update dependency golangci/golangci-lint to v2.4.0 (#3161)
renovate[bot] Aug 18, 2025
3978b2f
chore(deps): update docker-compose (#3160)
renovate[bot] Aug 18, 2025
f18a0b7
feat: allow disable-keep-alives configuration in upstream (#3156)
jet-go Aug 19, 2025
8c1b2b6
fix: Gitea team membership (#3150)
MagicRB Aug 19, 2025
413d4f6
add new docs version 7.12.x
github-actions[bot] Aug 19, 2025
b4b69a6
update to release version v7.12.0
github-actions[bot] Aug 19, 2025
7294eeb
add changelog entry for v7.12.0
tuunit Aug 19, 2025
5082db0
Merge pull request #3169 from oauth2-proxy/release/v7.12.0
tuunit Aug 19, 2025
8afb047
doc: SourceHut documentation fixes (#3170)
bitfehler Aug 20, 2025
f1c08a3
chore(deps): update actions/upload-pages-artifact action to v4 (#3194)
renovate[bot] Sep 25, 2025
66cdb9d
doc: update contribution guide to avoid a specific mention of the ver…
dsymonds Sep 25, 2025
9168731
fix(deps): revert actions/upload-pages-artifact action to v3 (#3211)
illrill Sep 28, 2025
a3349ad
chore(deps): update alpine docker tag to v3.22.2 (#3241)
renovate[bot] Oct 28, 2025
bccc988
chore(deps): update actions/setup-node action to v6 (#3242)
renovate[bot] Oct 28, 2025
65ef2ca
chore(deps): update actions/stale action to v10 (#3193)
renovate[bot] Oct 28, 2025
5539e59
chore(deps): update actions/setup-go action to v6 (#3191)
renovate[bot] Oct 28, 2025
e693f40
chore(deps): update actions/labeler action to v6 (#3190)
renovate[bot] Oct 28, 2025
dea0d0c
chore(deps): update helmv3 (#3189)
renovate[bot] Oct 28, 2025
a50bbcd
chore(deps): update docker-compose (#3188)
renovate[bot] Oct 28, 2025
4295f0c
chore(deps): update dependency golangci/golangci-lint to v2.5.0 (#3212)
renovate[bot] Oct 28, 2025
c0a087d
chore(deps): update actions/upload-artifact action to v5 (#3243)
renovate[bot] Oct 28, 2025
51e80f2
fix: use GetSecret() in ticket.go makeCookie to respect cookie-secret…
stagswtf Oct 28, 2025
ea1dc3f
Fix typo: diffrerent -> different (#3222)
vprivat-ads Oct 28, 2025
31b275f
docs: clarify ingress-nginx integration and remove Lua block example …
paulsc54 Oct 28, 2025
f950dc9
feat(makefile): simplify validate-go-version (#3147)
dolmen Oct 28, 2025
8f687e4
chore(deps): upgrade to latest go1.25.3 (#3244)
tuunit Oct 28, 2025
110d51d
test: replace mock pkg/clock with narrowly targeted stub clocks. (#3238)
dsymonds Oct 28, 2025
8782743
feat: added organizationId/employee id as preferred username (#3237)
pixeldrew Nov 7, 2025
5993067
Merge commit from fork
tuunit Nov 8, 2025
f3f30fa
Merge commit from fork
tuunit Nov 8, 2025
22053dc
fix: validation of refreshed sessions using the access_token in the O…
gysel Nov 8, 2025
fcc2db0
feat: add allowed_* constraint option to proxy endpoint query string…
jacobalberty Nov 8, 2025
082b49a
release: v7.13.0 (#3251)
github-actions[bot] Nov 8, 2025
fcf4e79
fix: hmacauth dependency licensing issue (#3253)
tuunit Nov 9, 2025
0107d6d
Add license scan report and status (#3248)
fossabot Nov 9, 2025
6a4255c
chore(deps): update docker-compose (#3255)
renovate[bot] Nov 11, 2025
e4becfd
chore(deps): update dependency node to v24 (#3256)
renovate[bot] Nov 11, 2025
7cf69b2
fix: NewRemoteKeySet is not using DefaultHTTPClient (#3197)
rsrdesarrollo Nov 11, 2025
7c20001
introduce mapstructure decoder for yaml parsing
tuunit May 4, 2024
676f56a
apply review suggestions
tuunit Feb 1, 2025
6720d8d
add duration test
tuunit Feb 9, 2025
c186d40
use official upstream yaml library v3
tuunit Feb 9, 2025
4c0dd28
fix alpha config example
tuunit Feb 9, 2025
18fc898
resolve cipher deprecation and update mapstructures v2
tuunit May 24, 2025
aaf1889
fix alpha config
tuunit May 24, 2025
810f629
revert: secrets as []byte instead of string
tuunit Jul 25, 2025
48bd2d7
fix merge problems and test cases
tuunit Jul 25, 2025
955ab6b
fix test setup and add local image build make target
tuunit Jul 26, 2025
5041435
return nil directly
tuunit Aug 19, 2025
9d70e04
feat: migrate all alpha config booleans to pointers
tuunit Aug 19, 2025
51b1fd0
chore(deps): replace with forked official yaml library
tuunit Oct 30, 2025
527c72f
feat: add ensure defaults to all migrated structs
tuunit Oct 30, 2025
ceb9a38
deref everything... but why?
tuunit Oct 31, 2025
638fba4
deref everything but now with default constants
tuunit Nov 7, 2025
137decb
adapting unit tests and fixing minor issues introduced with the derefing
tuunit Nov 7, 2025
0eec65e
refactor: ptr.Ptr to ptr.To
tuunit Nov 16, 2025
15041dd
feat: migrate google used organization id and header normalization bo…
tuunit Nov 16, 2025
aee540a
doc: fix mapstructure configuration comments
tuunit Nov 28, 2025
e27921e
Merge pull request #2628 from tuunit/use-mapstructures-for-parsing-an…
tuunit Nov 28, 2025
4956bab
chore(deps): update module golang.org/x/crypto to v0.45.0 [security] …
renovate[bot] Dec 24, 2025
699f367
chore(deps): upgrade gomod and bump to golang v1.25.5 (#3292)
tuunit Dec 24, 2025
12564e0
chore(deps): update docker-compose (#3272)
renovate[bot] Dec 24, 2025
6a0d821
chore(deps): update actions/checkout action to v6 (#3273)
renovate[bot] Dec 24, 2025
854a747
chore(deps): update dependency golangci/golangci-lint to v2.7.2 (#3254)
renovate[bot] Jan 4, 2026
0100ca9
chore(deps): update alpine docker tag to v3.23.2 (#3296)
renovate[bot] Jan 6, 2026
a2f2223
doc: improved clarity and correctness of proxy behaviour (#3305)
NirronCD Jan 14, 2026
a8e2084
docs: add Cisco Duo SSO provider documentation (#3306)
shri3016 Jan 14, 2026
3c37312
fix: added conditional so default is not always set and env vars are …
pixeldrew Jan 14, 2026
f3dcffe
chore(deps): update traefik docker tag to v2.11.35 (#3295)
renovate[bot] Jan 14, 2026
b4eb611
feat: more aggressively truncate logged access_token (#3264)
MartinNowak Jan 14, 2026
4953603
fix: session refresh handling in OIDC provider (#3267)
gysel Jan 14, 2026
3c22bc7
docs: split integration.md into separate integration guides (#3299)
pierluigilenoci Jan 16, 2026
1d6721f
fix: WebSocket proxy to respect PassHostHeader setting (#3290)
UnsignedLong Jan 16, 2026
86c2469
docs: clarify secret file format requirements (#3311)
shri3016 Jan 17, 2026
d16a0c4
add new docs version 7.14.x
github-actions[bot] Jan 15, 2026
3124bf7
update to release version v7.14.0
github-actions[bot] Jan 15, 2026
34c2712
doc: add changelog and migration guide for v7.14.0 alpha config changes
tuunit Jan 15, 2026
f46dcc7
doc: cncf onboarding and sponsor update
tuunit Jan 15, 2026
a360cb3
docs: backport integrations split to v7.14.x & v7.13.x
tuunit Jan 16, 2026
3bc1a53
doc: extend the alpha config changelog notice
tuunit Jan 16, 2026
1f29953
docs: add todo for revamping the usage / naming of PassHostHeader
tuunit Jan 16, 2026
707e6c4
Merge pull request #3308 from oauth2-proxy/release/v7.14.0
tuunit Jan 17, 2026
9c61c49
fix: skip provider button auth only redirect (#3309)
StefanMarkmann Jan 17, 2026
59f4e42
fix: static upstreams failing validation due to `passHostHeader` and …
sourava01 Jan 17, 2026
844e4e3
chore(deps): upgrade to go1.25.6; upgrade all go dependencies
tuunit Jan 17, 2026
cc0b48d
ci: fix linter warnings for preallocation
tuunit Jan 17, 2026
5020c33
ci: fix qlty coverage upload
tuunit Jan 17, 2026
56b5c08
Merge pull request #3312 from oauth2-proxy/chore/gomod
tuunit Jan 17, 2026
3ed3baf
update to release version v7.14.1
github-actions[bot] Jan 17, 2026
8f52b14
doc: changelog entry for v7.14.1
tuunit Jan 17, 2026
7bf586c
Merge pull request #3313 from oauth2-proxy/release/v7.14.1
tuunit Jan 17, 2026
cf5d34a
revert: "fix: skip provider button auth only redirect (#3309)" (#3314)
StefanMarkmann Jan 17, 2026
dcc7970
docs: fix how to use skip-provider-button with proper auth redirect h…
StefanMarkmann Jan 17, 2026
d5ea33b
ci: avoid running qlty coverage report for PRs (#3316)
tuunit Jan 18, 2026
3a55dad
release v7.14.2 (#3317)
github-actions[bot] Jan 18, 2026
e7724f3
ci: ensure release branches originate from the local repository and r…
tuunit Feb 12, 2026
1785327
fix: dont override parameters set in redis uri
Richard87 Sep 2, 2025
7747a88
fix: add tests for configure options and URL overrides when empty
Richard87 Feb 19, 2026
7822698
fix: update CHANGELOG to include new fix for URL parameters configura…
Richard87 Feb 19, 2026
a279fec
Merge pull request #3183 from Richard87/do-not-override-idle-timeout
JoelSpeed Feb 19, 2026
06f1234
ci: ensure we always use the latest patch version of golang (#3349)
tuunit Feb 26, 2026
788f3d0
ci: ensure we always use the latest patch version of golang (#3350)
tuunit Feb 26, 2026
b5c8df7
release v7.14.3 (#3351)
github-actions[bot] Feb 26, 2026
8807573
chore(deps): update alpine docker tag to v3.23.3 (#3329)
renovate[bot] Feb 27, 2026
75ff537
fix: backend logout URL call on sign out (#3172) (#3352)
vsejpal Mar 14, 2026
5f446c3
fix(devcontainer): bump Go version to 1.25 in devcontainer base image…
Br1an67 Mar 14, 2026
566b3aa
ci: distribute windows binary with .exe extension (#3332)
igitur Mar 14, 2026
6d27221
docs: fix plural typo in gitlab provider flag (#3363)
YMridul18 Mar 14, 2026
c6355ee
docs: add statusRewrites to Traefik Errors middleware example (#3360)
nicknikolakakis Mar 14, 2026
e59f7c1
feat: allow arbitrary claims from the IDToken and IdentityProvider Us…
vegetablest Mar 14, 2026
274d7de
ci: harden workflows; add trivy scanning; (#3372)
tuunit Mar 17, 2026
7e225ee
chore(deps): update dependency @easyops-cn/docusaurus-search-local to…
renovate[bot] Mar 17, 2026
8cb06b7
chore(deps): update docker-compose (#3320)
renovate[bot] Mar 17, 2026
3085309
feat: possibility to inject id_token in redirect url during sign out …
albanf Mar 18, 2026
7c96234
feat: add support for specifying allowed OIDC JWT signing algorithms …
andoks Mar 18, 2026
ff357da
fix: use CSRFExpire instead of Expire for CSRF cookie validation (#3369)
Br1an67 Mar 18, 2026
779cc5f
fix: filter empty strings from allowed groups (#3365)
Br1an67 Mar 18, 2026
fe5c6be
doc: add missing redis-ca-path documentation (#3341)
ganeshjp Mar 18, 2026
51ecc50
feat: add --config-test flag for validating configuration (#3338)
MayorFaj Mar 18, 2026
cdbdb11
feat: add same site option for csrf cookies (#3347)
jvnoije Mar 18, 2026
9ae0b32
feat: add support for setting a unix binding's socket file mode (#3376)
tuunit Mar 18, 2026
96c9ec6
release v7.15.0 (#3378)
github-actions[bot] Mar 18, 2026
0ecc35e
chore(deps): update gomod and golangci/golangci-lint to v2.11.4 (#3382)
tuunit Mar 23, 2026
9f09d54
chore(deps): update actions/upload-artifact action to v7 (#3358)
renovate[bot] Mar 23, 2026
a4d8903
fix: handle Unix socket RemoteAddr in IP resolution (#3374)
H1net Mar 23, 2026
44236f0
fix: do not log error for backend logout 204 (#3381)
artificiosus Mar 23, 2026
5ca3012
doc: update PR template with additional checklist items
tuunit Mar 23, 2026
e2682f7
fix: improve logging when session refresh token is missing (#3327)
yosri-brh Mar 23, 2026
46be69c
fix: propagate errors during route building (#3383)
tuunit Mar 23, 2026
848ec8b
release v7.15.1 (#3384)
github-actions[bot] Mar 23, 2026
7bc4b5e
doc: fix changelog for v7.15.0
tuunit Mar 23, 2026
da9123f
doc: fix config validation formatting (#3386)
tuunit Mar 23, 2026
761bf3b
build(deps): bump github.com/go-jose/go-jose/v4 to 4.1.4 (#3400)
Juqsi Apr 8, 2026
26de082
chore(deps): update gomod dependencies (#3411)
tuunit Apr 12, 2026
2e1261c
fix: invalidate session on fatal OAuth2 refresh errors (#3333)
frhack Apr 12, 2026
0337a95
Merge commit from fork
tuunit Apr 13, 2026
43596a7
Merge commit from fork
tuunit Apr 13, 2026
aff369d
Merge commit from fork
tuunit Apr 13, 2026
cc0e033
Merge commit from fork
tuunit Apr 13, 2026
bdfde72
Merge commit from fork
tuunit Apr 13, 2026
5961fd9
release v7.15.2 (#3413)
github-actions[bot] Apr 14, 2026
65037b0
change affiliation
tuunit Apr 17, 2026
9a14186
chore(goconsts): use proper constants for http methods
tuunit Jun 8, 2026
0de1882
chore(deps): bump Go to 1.26 and migrate upstream reverse proxies to …
tuunit Jun 8, 2026
61151b4
Merge pull request #3447 from oauth2-proxy/chore/bump-go-to-1.26-and-…
tuunit Jun 9, 2026
66b3a17
release v7.15.3 (#3450)
github-actions[bot] Jun 9, 2026
09979d4
docs: update slack reference for CNCF
tuunit Jun 9, 2026
2479410
chore(deps): update gomod
renovate[bot] Jun 13, 2026
807931c
Merge pull request #3424 from oauth2-proxy/renovate/gomod
JoelSpeed Jun 14, 2026
077cd9f
chore(deps): update docker-compose
renovate[bot] Jun 14, 2026
127f087
Merge pull request #3407 from oauth2-proxy/renovate/docker-compose
JoelSpeed Jun 14, 2026
3d011d9
chore(deps): update actions/upload-pages-artifact action to v5
renovate[bot] Jun 14, 2026
10b6871
Merge pull request #3425 from oauth2-proxy/renovate/actions-upload-pa…
JoelSpeed Jun 14, 2026
e8d9633
chore: merge upstream
thedadams Jul 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM mcr.microsoft.com/vscode/devcontainers/go:1-1.23
FROM mcr.microsoft.com/vscode/devcontainers/go:1-1.26

SHELL ["/bin/bash", "-o", "pipefail", "-c"]

Expand Down
15 changes: 15 additions & 0 deletions .github/FUNDING.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# These are supported funding model platforms

github: tuunit # Replace with up to 4 GitHub Sponsors-enabled usernames e.g., [user1, user2]
patreon: # Replace with a single Patreon username
open_collective: oauth2-proxy # Replace with a single Open Collective username
ko_fi: # Replace with a single Ko-fi username
tidelift: # Replace with a single Tidelift platform-name/package-name e.g., npm/babel
community_bridge: # Replace with a single Community Bridge project-name e.g., cloud-foundry
liberapay: # Replace with a single Liberapay username
issuehunt: # Replace with a single IssueHunt username
lfx_crowdfunding: # Replace with a single LFX Crowdfunding project-name e.g., cloud-foundry
polar: # Replace with a single Polar username
buy_me_a_coffee: # Replace with a single Buy Me a Coffee username
thanks_dev: # Replace with a single thanks.dev username
custom: # Replace with up to 4 custom sponsorship URLs e.g., ['link1', 'link2']
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
blank_issues_enabled: false
contact_links:
- name: OAuth2-Proxy Slack
url: https://gophers.slack.com/messages/CM2RSS25N
- name: OAuth2 Proxy Slack
url: https://cloud-native.slack.com/archives/C098Y5URZ2N
about: Feel free to ask any questions here.

5 changes: 3 additions & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,8 @@
<!--- Go over all the following points, and put an `x` in all the boxes that apply. -->
<!--- If you're unsure about any of these, don't hesitate to ask. We're here to help! -->

- [ ] My change requires a change to the documentation or CHANGELOG.
- [ ] I have updated the documentation/CHANGELOG accordingly.
- [ ] I have added an entry for my changes to the [CHANGELOG.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/CHANGELOG.md).
- [ ] I have [signed off](https://github.com/apps/dco) all my commits.
- [ ] I have created a feature (non-master) branch for my PR.
- [ ] I have used [conventional commits](https://www.conventionalcommits.org/en/v1.0.0/#examples) for the PR title.
- [ ] I have written tests for my code changes.
81 changes: 62 additions & 19 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,29 +7,39 @@ on:
pull_request:
branches:
- '**'
workflow_dispatch:

permissions:
contents: read
id-token: write
security-events: write

jobs:
build:
runs-on: ubuntu-latest
env:
COVER: true
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
fetch-depth: 0

- name: Get Go version
run: |
version=$(grep "^go " go.mod | cut -d' ' -f2 | cut -d. -f1,2)
echo "version=${version}" >> "$GITHUB_OUTPUT"
id: go-version

- name: Set up Go
uses: actions/setup-go@v5
uses: actions/setup-go@v6
with:
go-version-file: go.mod
id: go
go-version: ${{ steps.go-version.outputs.version }}
check-latest: true

- name: Get dependencies
env:
# renovate: datasource=github-tags depName=golangci/golangci-lint
GOLANGCI_LINT_VERSION: v1.64.8
run: |
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin ${GOLANGCI_LINT_VERSION}
curl -L https://codeclimate.com/downloads/test-reporter/test-reporter-latest-linux-amd64 > ./cc-test-reporter
chmod +x ./cc-test-reporter
- name: Install golangci-lint
uses: golangci/golangci-lint-action@v9
with:
install-only: true
version: v2.11.4 # renovate: datasource=github-tags depName=golangci/golangci-lint

- name: Verify Code Generation
run: |
Expand All @@ -52,15 +62,48 @@ jobs:

- name: Test
env:
CC_TEST_REPORTER_ID: ${{ secrets.CC_TEST_REPORTER_ID }}
COVER: true
run: |
make test

- name: Generate Coverage Report
if: github.event_name == 'push'
run: |
./.github/workflows/test.sh
go install github.com/jandelgado/gcov2lcov@25681830fb515e3d4c117e136b4f049e21efb4d0
gcov2lcov -infile=c.out -outfile=lcov.info

- name: Upload Coverage Report
if: github.event_name == 'push'
uses: qltysh/qlty-action/coverage@v2
with:
oidc: true
files: lcov.info

- name: Run Trivy vulnerability scanner
if: (!startsWith(github.head_ref, 'release'))
uses: aquasecurity/trivy-action@0.35.0
with:
scan-type: 'rootfs'
scan-ref: './oauth2-proxy'
severity: 'CRITICAL,HIGH'
hide-progress: true
format: 'sarif'
output: 'trivy-results.sarif'
exit-code: '0'

- name: Upload Trivy scan results
if: (!startsWith(github.head_ref, 'release'))
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: 'trivy-results.sarif'

docker:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
fetch-depth: 0

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
Expand All @@ -72,10 +115,10 @@ jobs:
- name: Docker Build
if: (!startsWith(github.head_ref, 'release'))
run: |
make docker
make build-docker

# For release testing
- name: Docker Build All
if: github.base_ref == 'master' && startsWith(github.head_ref, 'release')
run: |
make docker-all
make build-docker-all
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v6

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/create-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: master
fetch-depth: 0
Expand Down Expand Up @@ -54,7 +54,7 @@ jobs:
git config --local user.email "41898282+github-actions[bot]@users.noreply.github.com"

- name: Setup node
uses: actions/setup-node@v4
uses: actions/setup-node@v6
with:
node-version-file: docs/package.json

Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,16 +14,16 @@ jobs:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6

- name: Setup Pages
id: pages
uses: actions/configure-pages@v5

- uses: actions/setup-node@v4
- uses: actions/setup-node@v6
with:
# renovate: datasource=node-version depName=node
node-version: 22
node-version: 24

- name: Test Build
working-directory: ./docs
Expand All @@ -35,12 +35,12 @@ jobs:
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6

- uses: actions/setup-node@v4
- uses: actions/setup-node@v6
with:
# renovate: datasource=node-version depName=node
node-version: 22
node-version: 24

- name: Build docusaurus
working-directory: ./docs
Expand All @@ -49,7 +49,7 @@ jobs:
npm run build

- name: Upload artifact
uses: actions/upload-pages-artifact@v3
uses: actions/upload-pages-artifact@v5
with:
path: ./docs/build

Expand Down
14 changes: 14 additions & 0 deletions .github/workflows/e2e.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: E2E

on:
issue_comment:
types: [created]

jobs:
e2e:
uses: oauth2-proxy/e2e-suite/.github/workflows/e2e.yml@main
permissions:
contents: read
statuses: write
issues: write
pull-requests: write
2 changes: 1 addition & 1 deletion .github/workflows/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ jobs:
pull-requests: write
runs-on: ubuntu-latest
steps:
- uses: actions/labeler@v5
- uses: actions/labeler@v6
with:
sync-labels: true
dot: true
6 changes: 3 additions & 3 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
if: github.repository == 'oauth2-proxy/oauth2-proxy'
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: master
fetch-depth: 0
Expand All @@ -34,8 +34,8 @@ jobs:

- name: Build images
run: |
make docker-nightly-build
make nightly-build

- name: Push images
run: |
make docker-nightly-push
make nightly-push
48 changes: 27 additions & 21 deletions .github/workflows/publish-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,57 +14,63 @@ permissions:

jobs:
publish:
if: github.event.pull_request.merged && startsWith(github.event.pull_request.head.ref, 'release/')
if: github.event.pull_request.merged && startsWith(github.event.pull_request.head.ref, 'release/') && github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
outputs:
tag: ${{ steps.tag.outputs.version }}
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 0
fetch-tags: true

- name: Tag release
env:
BRANCH: ${{ github.event.pull_request.head.ref }}
run: |
# Set up github-actions[bot] user
git config --local user.name "github-actions[bot]"
git config --local user.email "41898282+github-actions[bot]@users.noreply.github.com"

# Get the version from the branch name
branch="${{ github.event.pull_request.head.ref }}"
version="${branch#release/}"
version="${BRANCH#release/}"
echo ${version}

# Tag and create release
git tag -a "${version}" -m "Release ${version}"
echo "version=${version}" >> $GITHUB_OUTPUT
id: tag

- name: Set up go
uses: actions/setup-go@v5
with:
go-version-file: go.mod

- name: Get dependencies
env:
# renovate: datasource=github-tags depName=golangci/golangci-lint
GOLANGCI_LINT_VERSION: v1.64.8
- name: Get Go version
run: |
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin ${GOLANGCI_LINT_VERSION}
curl -L https://codeclimate.com/downloads/test-reporter/test-reporter-latest-linux-amd64 > ./cc-test-reporter
chmod +x ./cc-test-reporter
version=$(grep "^go " go.mod | cut -d' ' -f2 | cut -d. -f1,2)
echo "version=${version}" >> "$GITHUB_OUTPUT"
id: go-version

# Install go dependencies
- name: Set up Go
uses: actions/setup-go@v6
with:
go-version: ${{ steps.go-version.outputs.version }}
check-latest: true

- name: Install golangci-lint
uses: golangci/golangci-lint-action@v9
with:
install-only: true
version: v2.11.4 # renovate: datasource=github-tags depName=golangci/golangci-lint

- name: Get go dependencies
run: |
go mod download

- name: Build Artifacts
run: make release

# Upload artifacts in case of workflow failure
- name: Upload Artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: oauth2-proxy-artifacts
path: |
Expand Down Expand Up @@ -100,7 +106,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: ${{ needs.publish.outputs.tag }}
fetch-depth: 0
Expand All @@ -122,8 +128,8 @@ jobs:

- name: Build images
run: |
make docker-all
make build-docker-all

- name: Push images
run: |
make docker-push-all
make push-docker-all
2 changes: 1 addition & 1 deletion .github/workflows/stale.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/stale@v9
- uses: actions/stale@v10
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
days-before-stale: 180
Expand Down
Loading
Loading