chore(deps): update dependency pyjwt to v2 [security] - autoclosed#5360
Closed
renovate[bot] wants to merge 1 commit intomasterfrom
Closed
chore(deps): update dependency pyjwt to v2 [security] - autoclosed#5360renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
5420421 to
693acf5
Compare
c481f58 to
d4b915a
Compare
6323a2f to
a52e271
Compare
a52e271 to
c4eeea6
Compare
c4eeea6 to
c52de0c
Compare
8e1df5a to
c23c097
Compare
5f0cdaa to
fb62e88
Compare
fb62e88 to
7bd7eeb
Compare
cdbe00b to
babd7a9
Compare
babd7a9 to
c58e693
Compare
014a4b2 to
6aeb59b
Compare
e020815 to
5c089ba
Compare
5c089ba to
9823fdd
Compare
9823fdd to
6eaeb46
Compare
4163d88 to
3269416
Compare
3269416 to
120d2dd
Compare
7ea817a to
a58e8a2
Compare
45f120d to
249c084
Compare
249c084 to
079500d
Compare
079500d to
a18a7c1
Compare
a18a7c1 to
9fc53b8
Compare
aa22392 to
7440a91
Compare
7440a91 to
a01ae41
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==1.5.2→==2.4.0GitHub Vulnerability Alerts
CVE-2022-29217
Impact
What kind of vulnerability is it? Who is impacted?
Disclosed by Aapo Oksman (Senior Security Specialist, Nixu Corporation).
Patches
Users should upgrade to v2.4.0.
Workarounds
Always be explicit with the algorithms that are accepted and expected when decoding.
References
Are there any links users can visit to find out more?
For more information
If you have any questions or comments about this advisory:
Release Notes
jpadilla/pyjwt (pyjwt)
v2.4.0Compare Source
Changed
v2.3.0Compare Source
Security
v2.2.0Compare Source
Fixed
#​702 <https://github.com/jpadilla/pyjwt/pull/702>__v2.1.0Compare Source
Changed
v2.0.1Compare Source
Changed
v2.0.0Compare Source
Changed
v1.7.1Compare Source
Changed
(#441) by @jdufresne
@jdufresne
Ed25519/ EdDSA, with unit tests (#455) by@Someguy123
python_requires(#478) by @michael-k@dimaqq
tox -e lintwarnings and errors (#490) by @jdufresne(#491) by @jdufresne
(#492) by @jdufresne
@GeoffRichards
@jdufresne
@michael-k
default_backend()(#523) by @rohitkg98@jdufresne
@jdufresne
@jdufresne
by @jdufresne
@jdufresne
(#543) by @jdufresne
@jdufresne
by @jdufresne
@jdufresne
(#555) by @jdufresne
@jdufresne
(#558) by @jdufresne
@jdufresne
(#562) by @jdufresne
by @jdufresne
(#571) by @jdufresne
(#574) by @jdufresne
v1.7.0Compare Source
Fixed
v1.6.4Compare Source
Fixed
#​340 <https://github.com/jpadilla/pyjwt/pull/340>__Added
InvalidAudienceErrorwhen applicationdoes not specify an audience, but the token does.
#​336 <https://github.com/jpadilla/pyjwt/pull/336>__v1.6.3Compare Source
Fixed
#​340 <https://github.com/jpadilla/pyjwt/pull/340>__Added
InvalidAudienceErrorwhen applicationdoes not specify an audience, but the token does.
#​336 <https://github.com/jpadilla/pyjwt/pull/336>__v1.6.1Compare Source
Fixed
InvalidAudienceErrorwhen application does not specify an audience, but the token does. #336v1.6.0Compare Source
Changed
Fixed
7c1e61d <https://github.com/jpadilla/pyjwt/commit/7c1e61dde27bafe16e7d1bb6e35199e778962742>__v1.5.3Compare Source
Changed
Fixed
7c1e61d <https://github.com/jpadilla/pyjwt/commit/7c1e61dde27bafe16e7d1bb6e35199e778962742>__Configuration
📅 Schedule: Branch creation - "" in timezone US/Eastern, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.