pingcap / tidb-tools

tidb-tools are some useful tool collections for TiDB.
Apache License 2.0
286 stars 191 forks source link

build(deps): bump github.com/lestrrat-go/jwx/v2 from 2.0.6 to 2.0.11 #732

Closed dependabot[bot] closed 10 months ago

dependabot[bot] commented 1 year ago

Bumps github.com/lestrrat-go/jwx/v2 from 2.0.6 to 2.0.11.

Release notes

Sourced from github.com/lestrrat-go/jwx/v2's releases.

[SECURITY] v2.0.11

v2.0.11 - 14 Jun 2023
[Security]
  * Potential Padding Oracle Attack Vulnerability and Timing Attack Vulnerability
    for JWE AES-CBC encrypted payloads affecting all v2 releases up to v2.0.10,
    all v1 releases up to v1.2.25, and all v0 releases up to v0.9.2 have been reported by
    @shogo82148.
Please note that v0 versions will NOT receive fixes.
This release fixes these vulnerabilities for the v2 series.

v2.0.10

v2.0.10 - 12 Jun 2023
[New Features]
  * [jwe] (EXPERIMENTAL) Added `jwe.KeyEncrypter` and `jwe.KeyDecrypter` interfaces
    that works in similar ways as how `crypto.Signer` works for signature
    generation and verification. It can act as the interface for your encryption/decryption
    keys that are for example stored in an hardware device.
This feature is labeled experimental because the API for the above interfaces have not
been battle tested, and may need to changed yet. Please be aware that until the API
is deemed stable, you may have to adapat our code to these possible changes,
_even_ during minor version upgrades of this library.

[Bug fixes]

  • Registering JWS signers/verifiers did not work since v2.0.0, because the way we handle algorithm names changed in 2aa98ce6884187180a7145b73da78c859dd46c84. (We previously thought that this would be checked by the example code, but it apparently failed to flag us properly)

    The logic behind managing the internal database has been fixed, and jws.RegisterSigner and jws.RegisterVerifier now properly hooks into the new jwa.RegisterSignatureAlgorithm to automatically register new algorithm names (#910, #911) [Miscellaneous]

  • Added limited support for github.com/segmentio/asm/base64. Compile your code with the jwx_asmbase64 build tag. This feature is EXPERIMENTAL.

    Through limited testing, the use of a faster base64 library provide 1~5% increase in throughput on average. It might make more difference if the input/output is large. If you care about this performance improvement, you should probably enable goccy JSON parser as well, by specifying jwx_goccy,jwx_asmbase64 in your build call.

  • Slightly changed the way global variables underneath jwk.Fetch are initialized and configured. jwk.Fetch creates an object that spawns wokers to fetch JWKS when it's first called. You can now also use jwk.SetGlobalFetcher() to set a fetcher object which you can control. </tr></table>

... (truncated)

Changelog

Sourced from github.com/lestrrat-go/jwx/v2's changelog.

v2.0.11 - 14 Jun 2023 [Security]

  • Potential Padding Oracle Attack Vulnerability and Timing Attack Vulnerability for JWE AES-CBC encrypted payloads affecting all v2 releases up to v2.0.10, all v1 releases up to v1.2.25, and all v0 releases up to v0.9.2 have been reported by @​shogo82148.

    Please note that v0 versions will NOT receive fixes. This release fixes these vulnerabilities for the v2 series.

v2.0.10 - 12 Jun 2023 [New Features]

  • [jwe] (EXPERIMENTAL) Added jwe.KeyEncrypter and jwe.KeyDecrypter interfaces that works in similar ways as how crypto.Signer works for signature generation and verification. It can act as the interface for your encryption/decryption keys that are for example stored in an hardware device.

    This feature is labeled experimental because the API for the above interfaces have not been battle tested, and may need to changed yet. Please be aware that until the API is deemed stable, you may have to adapat our code to these possible changes, even during minor version upgrades of this library.

[Bug fixes]

  • Registering JWS signers/verifiers did not work since v2.0.0, because the way we handle algorithm names changed in 2aa98ce6884187180a7145b73da78c859dd46c84. (We previously thought that this would be checked by the example code, but it apparently failed to flag us properly)

    The logic behind managing the internal database has been fixed, and jws.RegisterSigner and jws.RegisterVerifier now properly hooks into the new jwa.RegisterSignatureAlgorithm to automatically register new algorithm names (#910, #911) [Miscellaneous]

  • Added limited support for github.com/segmentio/asm/base64. Compile your code with the jwx_asmbase64 build tag. This feature is EXPERIMENTAL.

    Through limited testing, the use of a faster base64 library provide 1~5% increase in throughput on average. It might make more difference if the input/output is large. If you care about this performance improvement, you should probably enable goccy JSON parser as well, by specifying jwx_goccy,jwx_asmbase64 in your build call.

  • Slightly changed the way global variables underneath jwk.Fetch are initialized and configured. jwk.Fetch creates an object that spawns wokers to fetch JWKS when it's first called. You can now also use jwk.SetGlobalFetcher() to set a fetcher object which you can control.

v2.0.9 - 21 Mar 2023 [Security Fixes]

  • Updated use of golang.org/x/crypto to v0.7.0 [Bug fixes]

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pingcap/tidb-tools/network/alerts).
ti-chi-bot[bot] commented 1 year ago

Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.
ti-chi-bot[bot] commented 1 year ago

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Once this PR has been reviewed and has the lgtm label, please assign zanmato1984 for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files: - **[OWNERS](https://github.com/pingcap/tidb-tools/blob/master/OWNERS)** Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
CLAassistant commented 1 year ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

dveeden commented 10 months ago

@dependabot rebase

dependabot[bot] commented 10 months ago

Looks like github.com/lestrrat-go/jwx/v2 is up-to-date now, so this is no longer needed.

ti-chi-bot[bot] commented 10 months ago

[FORMAT CHECKER NOTIFICATION]

Notice: To remove the do-not-merge/needs-linked-issue label, please provide the linked issue number on one line in the PR body, for example: Issue Number: close #123 or Issue Number: ref #456.

:open_book: For more info, you can check the "Contribute Code" section in the development guide.