Skip to content

fix(deps): bump oauth2-proxy to v7.15.5 for two critical auth bypasses - #206

Merged
catinspace-au merged 2 commits into
mainfrom
fix/ga-versions-deps
Oct 6, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/ga-versions-deps

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Security bump for the auth profile's oauth2-proxy, part of the GA /deps pass.

  • oauth2-proxy v7.15.4 -> v7.15.5 (released 2026-10-01) on all three auth-profile proxies, pinned as v7.15.5@sha256:8498b0d0ef0a7b29686414000a08aee467f02d0299c9ed1e006a8f33fc017916 (amd64 + arm64 in the index).
  • Fixes GHSA-63jm-59jj-478j and GHSA-wr5q-7wxw-x568, both CRITICAL auth bypasses.
  • The stricter skip-auth and trusted-proxy rules in 7.15.5 change nothing here: our proxies set no skip-auth routes and no reverse-proxy client-IP trust.
  • NOT in this PR: .env.example:198 still shows the old v7.15.4 pin in its commented-out override line. The file is write-protected for agents, so it needs a human edit to the same tag@digest.
  • The stack pins this repo takes from dfe-infra (Envoy v1.39.2, otel-collector 0.162.0, ClickHouse 26.3.42.3, Redpanda v26.2.3) move in the dfe-infra versions.yaml PR. config/proxy/envoy.yaml and config/proxy/hyperdx.yaml pass envoy --mode validate on v1.39.2, and config/otel-collector/config.yaml passes otelcol validate on 0.162.0.
  • make check-hardfail check-compose check-python check-tests: green (767 passed).

oauth2-proxy v7.15.5 fixes GHSA-63jm-59jj-478j (skip-auth path confusion) and GHSA-wr5q-7wxw-x568 (spoofed client-IP headers). The three auth-profile proxies take it as tag@sha256, multi-arch. Our proxies set no skip-auth routes and no trusted-proxy client-IP rules, so the stricter matching changes nothing for them.
@catinspace-au
catinspace-au merged commit 7970385 into main Oct 6, 2026
7 checks passed
@catinspace-au
catinspace-au deleted the fix/ga-versions-deps branch October 6, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant