Skip to content

chore(deps): Bump github.com/grokify/goauth from 0.24.0 to 0.25.0 - #55

Merged
grokify merged 1 commit into
mainfrom
dependabot/go_modules/github.com/grokify/goauth-0.25.0
Oct 3, 2026
Merged

grokify merged 1 commit into
mainfrom
dependabot/go_modules/github.com/grokify/goauth-0.25.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/grokify/goauth from 0.24.0 to 0.25.0.

Release notes

Sourced from github.com/grokify/goauth's releases.

v0.25.0

Release Notes: v0.25.0

Full Changelog: grokify/goauth@v0.24.0...v0.25.0

Changelog

Sourced from github.com/grokify/goauth's changelog.

[v0.25.0] - 2026-09-26

Highlights

  • New providers package: exchange an OAuth 2.0 authorization code for a normalized OAuthUser across Google and GitHub, for "Sign in with ..." login flows

Added

  • providers.FetchGoogleUser / providers.FetchGitHubUser: exchange an authorization code and return a provider-neutral OAuthUser (ID, email, name, avatar, access and refresh tokens). GitHub users with a private profile email fall back to the primary verified address from the emails endpoint (requires the user:email scope) (674e3b2)
  • providers.FetchGoogleUserWithToken / providers.FetchGitHubUserWithToken: fetch provider-native profiles with an existing access token, using a client bounded by providers.DefaultTimeout (674e3b2)
  • providers.PrimaryVerifiedEmail and providers.ErrNoVerifiedEmail: select a GitHub user's primary verified email, falling back to any verified email (674e3b2)
  • cmd/jwt_parse: print a JWT's claims as JSON without verifying its signature, reading the token from the JWT_PARSE environment variable (8596ad9)
  • google/cmd/oauth2web and google/cmd/serviceaccount: runnable examples that load credentials from a credentials set file and fetch the Google userinfo profile, printing only token metadata, never credentials or tokens (6660d4e)

Dependencies

  • 6 dependency updates

Documentation

  • Structured changelog (CHANGELOG.json / CHANGELOG.md) covering the full release history (8f3664a)
  • v0.24.0 release notes for the dpop package (bb60265)
  • MkDocs site with a DPoP user guide (eb8be46)

Tests

  • providers coverage using an httptest server as token endpoint and provider API: code exchange, Bearer auth, GitHub email and name fallbacks, missing verified email, token-based fetches, and non-200 error reporting (8546b9c)

Infrastructure

  • Ignore the locally built cmd/goauth/goauth binary (89d3160)
Commits
  • ab2990b Merge pull request #510 from grokify/feat/providers-and-examples
  • 0580ccc docs(changelog): add v0.25.0 entry and release notes
  • ecf2fbe docs: add Sign in with Google or GitHub guide and update README
  • cc6e6b0 docs(changelog): update commit links to current history
  • 89d3160 chore: ignore locally built goauth CLI binary
  • 6660d4e feat(google): add oauth2web and serviceaccount examples
  • 8596ad9 feat(cmd): add jwt_parse to decode JWT claims without verification
  • 8546b9c test(providers): cover code exchange, email fallback, and error paths
  • 674e3b2 feat(providers): add normalized OAuth user fetch for Google and GitHub
  • 2c158cc chore(deps): go mod: update dependencies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/grokify/goauth](https://github.com/grokify/goauth) from 0.24.0 to 0.25.0.
- [Release notes](https://github.com/grokify/goauth/releases)
- [Changelog](https://github.com/grokify/goauth/blob/main/CHANGELOG.md)
- [Commits](grokify/goauth@v0.24.0...v0.25.0)

---
updated-dependencies:
- dependency-name: github.com/grokify/goauth
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d96bbbf4-0de0-4a12-a859-edfe8aa84d86

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@grokify
grokify merged commit 829f438 into main Oct 3, 2026
6 of 7 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/grokify/goauth-0.25.0 branch October 3, 2026 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant