Skip to content

Update dependency oauth2-proxy to v7.15.2#16

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/oauth2-proxy-7.x
Apr 16, 2026
Merged

Update dependency oauth2-proxy to v7.15.2#16
renovate[bot] merged 1 commit intomainfrom
renovate/oauth2-proxy-7.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 15, 2026

This PR contains the following updates:

Package Update Change
oauth2-proxy patch 7.15.17.15.2

Release Notes

oauth2-proxy/oauth2-proxy (oauth2-proxy)

v7.15.2

Compare Source

Release Highlights

Important Notes

We have had security audits performed on OAuth2 Proxy in the past couple of weeks and as a result we have fixed
several CRITICAL vulnerabilities.

The security vulnerabilities include multiple authentication bypasses and a potential session fixation attack.
For more details and to identify if you are effects, we urge all users of OAuth2 Proxy to read the security
disclosures.

Furthermore, for improving the security of OAuth2 Proxy we introduced a new flag --trusted-proxy-ip that allows users
to explicitly specify trusted reverse proxy IPs for the X-Forwarded-* headers. This is an important step to prevent
potential header spoofing attacks and to ensure that OAuth2 Proxy only trusts headers from known and trusted sources.
We highly recommend users to review their deployment architecture and consider using this flag to enhance the security
of their OAuth2 Proxy instances. Check the docs for more details: https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview#proxy-options

Furthermore, we want to thank everyone who contributed to the audits and reported potential issues to make open source
software like OAuth2 Proxy more secure for everyone.

Breaking Changes

Changes since v7.15.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot merged commit 2dd25ea into main Apr 16, 2026
7 checks passed
@renovate renovate Bot deleted the renovate/oauth2-proxy-7.x branch April 16, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants