Skip to content

build(deps): bump pyjwt from 2.13.0 to 2.14.0 - #2533

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pyjwt-2.14.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pyjwt-2.14.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps pyjwt from 2.13.0 to 2.14.0.

Release notes

Sourced from pyjwt's releases.

2.14.0

See the 2.14.0 changelog for the complete release details and related security advisories.

Changelog

Sourced from pyjwt's changelog.

v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0>__

Security


- Harden HMAC key validation against public-key material supplied as JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
  `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__,
  `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__,
  `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__,
  and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing
  redirected destinations from being treated as trusted key sources. See
  `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while preserving
  normal key-rotation behavior. See
  `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught recursion
  errors or whole-set parsing failures. See
  `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__
  and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__.
- Enforce compact JWS encoding rules during decoding. See
  `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n
  <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit
  `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__.

Fixed


- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
  `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__.
- Reject empty HMAC keys when represented as JWKs.
  See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__.
</code></pre>
</blockquote>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df&quot;&gt;&lt;code&gt;c6fe464&lt;/code&gt;&lt;/a> release: prepare v2.14.0</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42&quot;&gt;&lt;code&gt;f541302&lt;/code&gt;&lt;/a> style: apply Ruff formatting</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95&quot;&gt;&lt;code&gt;801cd12&lt;/code&gt;&lt;/a> fix: reject public JWK container HMAC keys</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb&quot;&gt;&lt;code&gt;af8181c&lt;/code&gt;&lt;/a> fix: reject empty HMAC keys from JWKs</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1&quot;&gt;&lt;code&gt;ba4853a&lt;/code&gt;&lt;/a> Throttle repeated PyJWKClient refreshes</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499&quot;&gt;&lt;code&gt;2798504&lt;/code&gt;&lt;/a> fix: reject DER public keys as HMAC secrets</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07&quot;&gt;&lt;code&gt;8b4e233&lt;/code&gt;&lt;/a> fix: reject loader-accepted PEM variants</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258&quot;&gt;&lt;code&gt;1f8180a&lt;/code&gt;&lt;/a> fix: format JWS tests</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab&quot;&gt;&lt;code&gt;cff1ac5&lt;/code&gt;&lt;/a> Fix redirect handler return annotation</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56&quot;&gt;&lt;code&gt;0a795b8&lt;/code&gt;&lt;/a> Reject redirects in PyJWKClient fetches</li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.14.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.14.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.14.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 30, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 30, 2026 04:55
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: dcea270e-5c8c-4837-ac4b-f0266223a709

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for c1291bd96fc48b4746ac8ad2e21e15f88a15690f against protected main@37b10243cec3d160ecc9c1be75c71428b160a703.

Reviewed the complete one-path delta and checked the upstream PyJWT 2.14.0 tag changelog. The release is a security hardening update (HMAC/JWK validation, JWKS redirect and refresh boundaries, malformed/nested input handling, and compact/detached JWS validation). This PR changes only the MCP-transitive hash lock from 2.13.0 to 2.14.0 with both replacement hashes and introduces no source, workflow, provider-routing, or policy change. Repository search found no direct PyJWT/PyJWKClient call site requiring an accompanying contract migration. I found no source-backed Critical, Important, or Minor defect in this delta.

Ready is review admission only. Exact-head Python Security 36671082841, Security Scan 36671082876, CodeQL PR 36671082868, and SAST Semgrep 36671082910 are queued and are not passing evidence. Terminal hosted Checks, zero unresolved threads, and a qualifying independent approval remain merge gates; this COMMENT is not approval.

@seonghobae seonghobae added area: security Security boundary, hardening, or vulnerability prevention maintenance priority: high High-priority or P1 work status: needs-review Open pull request requiring current-head review or checks labels Sep 30, 2026 — with ChatGPT Codex Connector
@seonghobae
seonghobae marked this pull request as draft September 30, 2026 14:51

Copy link
Copy Markdown
Contributor

Ready is review admission only. Exact head c1291bd96fc48b4746ac8ad2e21e15f88a15690f has terminal non-GREEN evidence: CodeQL PR run 36671082868 = failure; Security Scan run 36671082876 = failure. I moved the PR back to Draft. Return to Ready only on a new exact head with applicable terminal GREEN checks, zero substantive unresolved threads, and qualifying independent review. No rerun, status synthesis, bypass, force push, destructive rebase, merge, or closure was used.

Copy link
Copy Markdown
Contributor

Verified complete successor transfer

This Draft predecessor at exact head c1291bd96fc48b4746ac8ad2e21e15f88a15690f changes only requirements-strix-ci-hashes.txt, advancing PyJWT from 2.13.0 to 2.14.0 to leave CVE-2026-102274's affected range.

Canonical owner #2531 exact head 516471fbe7d4e93a50c7bbba20402447f06f8d8b carries that complete security requirement and supersedes it with PyJWT 2.15.0 after 2.14.0 was itself rejected for GHSA-42vr-xj54-vc7v / CVE-2026-101918. The owner binds both the source input and generated hash lock, tests normalized duplicate pins including extras, and has exact-head Security Scan, Python Security, SAST, and runtime-quality success.

Every valid delta in this one-file predecessor is therefore present in the live canonical successor at a later patched release with stronger source/lock contracts. Closing records verified successor carryover; it is not a merge or release claim. #2531 remains subject to authenticated CodeQL evidence, independent approval, and ordinary protected merge.

@seonghobae seonghobae closed this Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/pyjwt-2.14.0 branch September 30, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: security Security boundary, hardening, or vulnerability prevention dependencies Pull requests that update a dependency file maintenance priority: high High-priority or P1 work python Pull requests that update python code status: needs-review Open pull request requiring current-head review or checks

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant