backport/1.16.x: bump deps to avoid old go-jose #176
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bump oidc to v3 and go-jose to v.3.0.3 to remove dependency on go-jose 2.6.0 and go-jose 3.0.0
If the major version bump in oidc sketches you out, we also made the change in a "chore" update into 0.18.0, and there's no go-oidc v2 without an old go-jose (i.e., go-oidc v2.2.1 is the latest v2)
If the
.go-version
bump sketches you out, this both fixes an issue with the test checks, and matches the version used in the release/1.16.x branch of vault.