Skip to content

Commit 8bcf672

Browse files
authored
Merge branch 'main' into deps/version-bump-nginx-1.29.0
2 parents e61ec03 + 4ef38ae commit 8bcf672

File tree

4 files changed

+15
-5
lines changed

4 files changed

+15
-5
lines changed

.github/workflows/image-promotion.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,7 @@ jobs:
158158
fi
159159
160160
- name: Upload SARIF file
161-
uses: github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6
161+
uses: github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
162162
if: steps.check-sarif.outputs.sarif_has_results == 'true'
163163
with:
164164
sarif_file: govulncheck.sarif
@@ -494,7 +494,7 @@ jobs:
494494
overwrite: true
495495

496496
- name: Upload Scan results to GitHub Security tab
497-
uses: github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6
497+
uses: github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
498498
with:
499499
sarif_file: "${{ steps.directory.outputs.directory }}/"
500500

@@ -583,7 +583,7 @@ jobs:
583583
overwrite: true
584584

585585
- name: Upload Scan results to GitHub Security tab
586-
uses: github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6
586+
uses: github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
587587
with:
588588
sarif_file: "${{ steps.directory.outputs.directory }}/"
589589

@@ -679,7 +679,7 @@ jobs:
679679
overwrite: true
680680

681681
- name: Upload Scan results to GitHub Security tab
682-
uses: github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6
682+
uses: github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
683683
with:
684684
sarif_file: "${{ steps.directory.outputs.directory }}/"
685685
continue-on-error: true

.github/workflows/scorecards.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,6 @@ jobs:
5757

5858
# Upload the results to GitHub's code scanning dashboard.
5959
- name: "Upload to code-scanning"
60-
uses: github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6
60+
uses: github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
6161
with:
6262
sarif_file: results.sarif

internal/configs/version2/__snapshots__/templates_test.snap

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1117,6 +1117,8 @@ server {
11171117
proxy_cache_valid 200 12h;
11181118
proxy_ssl_server_name on;
11191119
proxy_ssl_name sni.idp.spec.example.com;
1120+
proxy_pass_request_headers off;
1121+
proxy_pass_request_body off;
11201122
proxy_set_header Host idp.spec.example.com;
11211123
set $idp_backend idp.spec.example.com;
11221124
proxy_pass https://$idp_backend:443/spec-keys;
@@ -1129,6 +1131,8 @@ server {
11291131
proxy_cache_valid 200 12h;
11301132
proxy_ssl_server_name on;
11311133
proxy_ssl_name sni.idp.spec.example.com;
1134+
proxy_pass_request_headers off;
1135+
proxy_pass_request_body off;
11321136
proxy_set_header Host idp.route.example.com;
11331137
set $idp_backend idp.route.example.com;
11341138
proxy_pass http://$idp_backend:80/route-keys;
@@ -1239,6 +1243,8 @@ server {
12391243
proxy_set_header Content-Length "";
12401244
proxy_cache jwks_uri_cafe;
12411245
proxy_cache_valid 200 12h;
1246+
proxy_pass_request_headers off;
1247+
proxy_pass_request_body off;
12421248
proxy_set_header Host idp.spec.example.com;
12431249
set $idp_backend idp.spec.example.com;
12441250
proxy_pass https://$idp_backend:443/spec-keys;
@@ -1249,6 +1255,8 @@ server {
12491255
proxy_set_header Content-Length "";
12501256
proxy_cache jwks_uri_cafe;
12511257
proxy_cache_valid 200 12h;
1258+
proxy_pass_request_headers off;
1259+
proxy_pass_request_body off;
12521260
proxy_set_header Host idp.route.example.com;
12531261
set $idp_backend idp.route.example.com;
12541262
proxy_pass http://$idp_backend:80/route-keys;

internal/configs/version2/nginx-plus.virtualserver.tmpl

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -243,6 +243,8 @@ server {
243243
proxy_ssl_name {{ .JwksSNIName }};
244244
{{- end }}
245245
{{- end }}
246+
proxy_pass_request_headers off;
247+
proxy_pass_request_body off;
246248
proxy_set_header Host {{ .JwksHost }};
247249
set $idp_backend {{ .JwksHost }};
248250
proxy_pass {{ .JwksScheme}}://$idp_backend{{ if .JwksPort }}:{{ .JwksPort }}{{ end }}{{ .JwksPath }};

0 commit comments

Comments
 (0)