build(deps): bump pyjwt from 2.13.0 to 2.14.0 - #2533
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.14.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.14.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.14.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for c1291bd96fc48b4746ac8ad2e21e15f88a15690f against protected main@37b10243cec3d160ecc9c1be75c71428b160a703.
Reviewed the complete one-path delta and checked the upstream PyJWT 2.14.0 tag changelog. The release is a security hardening update (HMAC/JWK validation, JWKS redirect and refresh boundaries, malformed/nested input handling, and compact/detached JWS validation). This PR changes only the MCP-transitive hash lock from 2.13.0 to 2.14.0 with both replacement hashes and introduces no source, workflow, provider-routing, or policy change. Repository search found no direct PyJWT/PyJWKClient call site requiring an accompanying contract migration. I found no source-backed Critical, Important, or Minor defect in this delta.
Ready is review admission only. Exact-head Python Security 36671082841, Security Scan 36671082876, CodeQL PR 36671082868, and SAST Semgrep 36671082910 are queued and are not passing evidence. Terminal hosted Checks, zero unresolved threads, and a qualifying independent approval remain merge gates; this COMMENT is not approval.
|
Ready is review admission only. Exact head |
Verified complete successor transferThis Draft predecessor at exact head Canonical owner #2531 exact head Every valid delta in this one-file predecessor is therefore present in the live canonical successor at a later patched release with stronger source/lock contracts. Closing records verified successor carryover; it is not a merge or release claim. #2531 remains subject to authenticated CodeQL evidence, independent approval, and ordinary protected merge. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps pyjwt from 2.13.0 to 2.14.0.
Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.