Update dependency pyjwt to v2.15.1 #97
No reviewers
Labels
No labels
TUI
bug
docs
duplicate
enhancement
help wanted
invalid
major
question
secrets
wontfix
bug
docs
duplicate
enhancement
help wanted
invalid
major
minor
patch
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
oeng/smol-k8s-lab!97
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/pyjwt-2.x-lockfile"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
2.13.0→2.15.1Release Notes
jpadilla/pyjwt (pyjwt)
v2.15.1Compare Source
v2.15.0Compare Source
Fixed
DecodeErrorinstead of exposing a raw
RecursionError.Added
JWKSetCachenow stores the parsedPyJWKSetrather than the raw JWKSpayload, so a cache hit no longer re-parses every key.
JWKSetCache.put()accepts either form and raises
PyJWKSetErrorfor anything else. As aresult,
PyJWKClient.get_jwk_set()returns the samePyJWKSetinstancefor as long as it stays cached, rather than a freshly built one per call in
#​1208 <https://github.com/jpadilla/pyjwt/pull/1208>__PyJWKClient.fetch_data()now raisesPyJWKClientError("The JWKS endpoint did not return a JSON object")whenthe endpoint response is not a JSON object, instead of returning it for
get_jwk_set()to reject. Callers reaching the JWKS throughget_jwk_set()see the same error as before in#​1208 <https://github.com/jpadilla/pyjwt/pull/1208>__Fixed
JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>,GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>,GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>,and
GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>.PyJWKClientfetches a JWKS, preventingredirected destinations from being treated as trusted key sources. See
GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>__.normal key-rotation behavior. See
GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>__.errors or whole-set parsing failures. See
GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>__and
GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>__.GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>__.@xclow3n <https://github.com/xclow3n>__ for reporting this behavior; fixed in commit37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>__.Fixed
HMACAlgorithm.prepare_keyto close an algorithm-confusion gap thatthe existing PEM/SSH guard did not cover. Reported by @aradona91 in
GHSA-xgmm-8j9v-c9wx <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx>__.algtoPyJWK.algorithm_nameduringverification so the caller's
algorithms=[...]allow-list cannot bebypassed when decoding with a
PyJWK/PyJWKClientkey. Reportedby @sushi-gif in
GHSA-jq35-7prp-9v3f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f>__.http(s)URI schemes inPyJWKClientso attacker-influenced URIs cannot read local files or reach unintended schemes via
urllib's default
file:///ftp:///data:handlers. Reportedby @KEIJOT in
GHSA-993g-76c3-p5m4 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4>__.PyJWKClient.fetch_data.The previous
finally-blockput(None)pattern cleared the cacheon any transient outage, turning one bad JWKS request into application-
wide auth failure. Reported by @eddieran in
GHSA-fhv5-28vv-h8m8 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8>__.when
b64=falseis set in the protected header, and require thatsegment to be empty (RFC 7515 Appendix F detached form). Closes an
unauthenticated DoS amplifier. Reported by @thesmartshadow in
GHSA-w7vc-732c-9m39 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39>__.Fixed
dev,docs, andtestspackage extras to dependency groups by @kurtmckee in#​1152 <https://github.com/jpadilla/pyjwt/pull/1152>__v2.14.0Compare Source
See the 2.14.0 changelog for the complete release details and related security advisories.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
ce0e70ad898f21e94aceUpdate dependency pyjwt to v2.14.0to Update dependency pyjwt to v2.15.08f21e94ace2ec41825cdUpdate dependency pyjwt to v2.15.0to Update dependency pyjwt to v2.15.12ec41825cde94b4b6cddView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.