Files
oidc/go.mod
dependabot[bot] 8138813929 chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.9.1 to 4.9.2 (#832)
Bumps
[github.com/bmatcuk/doublestar/v4](https://github.com/bmatcuk/doublestar)
from 4.9.1 to 4.9.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/bmatcuk/doublestar/releases">github.com/bmatcuk/doublestar/v4's
releases</a>.</em></p>
<blockquote>
<h2>Fixed Handling of Paths With Meta Chars Using Alts</h2>
<p><a href="https://github.com/toga4"><code>@​toga4</code></a> submitted
a PR that fixed a small bug with the way paths were handled when the
pattern used <code>{alts}</code>: if some part of the on-disk path that
came before the <code>{alt}</code> included meta characters (say, a
directory name that included the character <code>?</code>), these meta
characters were not escaped when they were passed back through the
globbing routines. This caused doublestar to interpret them as actual
meta characters, rather than a fixed-string path as it should have. Nice
find, <a href="https://github.com/toga4"><code>@​toga4</code></a> !</p>
<h2>What's Changed</h2>
<ul>
<li>fix: escape meta characters in paths during brace expansion by <a
href="https://github.com/toga4"><code>@​toga4</code></a> in <a
href="https://redirect.github.com/bmatcuk/doublestar/pull/108">bmatcuk/doublestar#108</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/toga4"><code>@​toga4</code></a> made
their first contribution in <a
href="https://redirect.github.com/bmatcuk/doublestar/pull/108">bmatcuk/doublestar#108</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/bmatcuk/doublestar/compare/v4.9.1...v4.9.2">https://github.com/bmatcuk/doublestar/compare/v4.9.1...v4.9.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="3dc83064cf"><code>3dc8306</code></a>
Merge branch 'toga4-fix-brace-exp-with-meta'</li>
<li><a
href="4db19e22da"><code>4db19e2</code></a>
fix tests</li>
<li><a
href="4ef2b00391"><code>4ef2b00</code></a>
fix: escape meta characters in paths during brace expansion</li>
<li><a
href="b191bb9ad1"><code>b191bb9</code></a>
test: add failing tests for brace expansion with meta char
directories</li>
<li><a
href="9fded312dd"><code>9fded31</code></a>
notes about globbing</li>
<li>See full diff in <a
href="https://github.com/bmatcuk/doublestar/compare/v4.9.1...v4.9.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/bmatcuk/doublestar/v4&package-manager=go_modules&previous-version=4.9.1&new-version=4.9.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-12 06:49:18 +00:00

41 lines
1.3 KiB
Modula-2

module github.com/zitadel/oidc/v3
go 1.24.0
require (
github.com/bmatcuk/doublestar/v4 v4.9.2
github.com/go-chi/chi/v5 v5.2.3
github.com/go-jose/go-jose/v4 v4.0.5
github.com/golang/mock v1.6.0
github.com/google/go-github/v31 v31.0.0
github.com/google/uuid v1.6.0
github.com/gorilla/securecookie v1.1.2
github.com/jeremija/gosubmit v0.2.8
github.com/muhlemmer/gu v0.3.1
github.com/muhlemmer/httpforwarded v0.1.0
github.com/rs/cors v1.11.1
github.com/sirupsen/logrus v1.9.3
github.com/stretchr/testify v1.11.1
github.com/zitadel/logging v0.6.2
github.com/zitadel/schema v1.3.2
go.opentelemetry.io/otel v1.39.0
go.opentelemetry.io/otel/trace v1.39.0
golang.org/x/oauth2 v0.34.0
golang.org/x/text v0.33.0
)
require (
github.com/cespare/xxhash/v2 v2.3.0 // indirect
github.com/davecgh/go-spew v1.1.1 // indirect
github.com/go-logr/logr v1.4.3 // indirect
github.com/go-logr/stdr v1.2.2 // indirect
github.com/google/go-querystring v1.1.0 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
go.opentelemetry.io/otel/metric v1.39.0 // indirect
golang.org/x/crypto v0.45.0 // indirect
golang.org/x/net v0.47.0 // indirect
golang.org/x/sys v0.38.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
)