Skip to content

build(deps): bump github.com/grokify/goauth from 0.24.0 to 0.25.0 - #51

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/grokify/goauth-0.25.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/grokify/goauth-0.25.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/grokify/goauth from 0.24.0 to 0.25.0.

Release notes

Sourced from github.com/grokify/goauth's releases.

v0.25.0

Release Notes: v0.25.0

Full Changelog: grokify/goauth@v0.24.0...v0.25.0

Changelog

Sourced from github.com/grokify/goauth's changelog.

[v0.25.0] - 2026-09-26

Highlights

  • New providers package: exchange an OAuth 2.0 authorization code for a normalized OAuthUser across Google and GitHub, for "Sign in with ..." login flows

Added

  • providers.FetchGoogleUser / providers.FetchGitHubUser: exchange an authorization code and return a provider-neutral OAuthUser (ID, email, name, avatar, access and refresh tokens). GitHub users with a private profile email fall back to the primary verified address from the emails endpoint (requires the user:email scope) (674e3b2)
  • providers.FetchGoogleUserWithToken / providers.FetchGitHubUserWithToken: fetch provider-native profiles with an existing access token, using a client bounded by providers.DefaultTimeout (674e3b2)
  • providers.PrimaryVerifiedEmail and providers.ErrNoVerifiedEmail: select a GitHub user's primary verified email, falling back to any verified email (674e3b2)
  • cmd/jwt_parse: print a JWT's claims as JSON without verifying its signature, reading the token from the JWT_PARSE environment variable (8596ad9)
  • google/cmd/oauth2web and google/cmd/serviceaccount: runnable examples that load credentials from a credentials set file and fetch the Google userinfo profile, printing only token metadata, never credentials or tokens (6660d4e)

Dependencies

  • 6 dependency updates

Documentation

  • Structured changelog (CHANGELOG.json / CHANGELOG.md) covering the full release history (8f3664a)
  • v0.24.0 release notes for the dpop package (bb60265)
  • MkDocs site with a DPoP user guide (eb8be46)

Tests

  • providers coverage using an httptest server as token endpoint and provider API: code exchange, Bearer auth, GitHub email and name fallbacks, missing verified email, token-based fetches, and non-200 error reporting (8546b9c)

Infrastructure

  • Ignore the locally built cmd/goauth/goauth binary (89d3160)
Commits
  • ab2990b Merge pull request #510 from grokify/feat/providers-and-examples
  • 0580ccc docs(changelog): add v0.25.0 entry and release notes
  • ecf2fbe docs: add Sign in with Google or GitHub guide and update README
  • cc6e6b0 docs(changelog): update commit links to current history
  • 89d3160 chore: ignore locally built goauth CLI binary
  • 6660d4e feat(google): add oauth2web and serviceaccount examples
  • 8596ad9 feat(cmd): add jwt_parse to decode JWT claims without verification
  • 8546b9c test(providers): cover code exchange, email fallback, and error paths
  • 674e3b2 feat(providers): add normalized OAuth user fetch for Google and GitHub
  • 2c158cc chore(deps): go mod: update dependencies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/grokify/goauth](https://github.com/grokify/goauth) from 0.24.0 to 0.25.0.
- [Release notes](https://github.com/grokify/goauth/releases)
- [Changelog](https://github.com/grokify/goauth/blob/main/CHANGELOG.md)
- [Commits](grokify/goauth@v0.24.0...v0.25.0)

---
updated-dependencies:
- dependency-name: github.com/grokify/goauth
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3ee4e45e-7125-47ad-9c24-c628d6c9a270

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants