Update dependency pyjwt to v2.15.1 #97

Open
Owentje wants to merge 1 commit from renovate/pyjwt-2.x-lockfile into main
Owner

This PR contains the following updates:

Package Change Age Confidence
pyjwt 2.13.0 → 2.15.1 age confidence

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

jpadilla/pyjwt (pyjwt)

v2.15.1

Compare Source

v2.15.0

Compare Source

Fixed


- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
  ``!!!!`` remains rejected (`#&#8203;1209 <https://github.com/jpadilla/pyjwt/issues/1209>`__).

`v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>`__
-----------------------------------------------------------------------

Security
  • Wrap recursion errors from deeply nested JWT payloads in DecodeError
    instead of exposing a raw RecursionError.

Added


- Support Python 3.15 by @&#8203;kytta in `#&#8203;1202 <https://github.com/jpadilla/pyjwt/pull/1202>`__

Changed
  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS
    payload, so a cache hit no longer re-parses every key. JWKSetCache.put()
    accepts either form and raises PyJWKSetError for anything else. As a
    result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance
    for as long as it stays cached, rather than a freshly built one per call in
    #&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>__
  • PyJWKClient.fetch_data() now raises
    PyJWKClientError("The JWKS endpoint did not return a JSON object") when
    the endpoint response is not a JSON object, instead of returning it for
    get_jwk_set() to reject. Callers reaching the JWKS through
    get_jwk_set() see the same error as before in
    #&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError("The JWKS endpoint did not return a JSON
  object")``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `#&#8203;914 <https://github.com/jpadilla/pyjwt/issues/914>`__ and
  `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
  a JSON object is skipped, a key whose components have the wrong type raises
  ``InvalidKeyError`` and is skipped, and a set left with no usable keys raises
  ``PyJWKSetError``. A single bad entry no longer fails an otherwise usable
  JWK Set in `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- Wrap ``http.client.HTTPException`` (e.g. ``IncompleteRead`` from a
  truncated response) in ``PyJWKClient.fetch_data`` as
  ``PyJWKClientConnectionError``, matching the other network failure
  modes the method already documents.

`v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0>`__
-----------------------------------------------------------------------

Security
  • Harden HMAC key validation against public-key material supplied as JWK,
    JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
    GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>,
    GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>
    ,
    GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>,
    and GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>
    .
  • Reject automatic redirects when PyJWKClient fetches a JWKS, preventing
    redirected destinations from being treated as trusted key sources. See
    GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>__.
  • Limit repeated JWKS refreshes caused by unknown key IDs while preserving
    normal key-rotation behavior. See
    GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>__.
  • Handle deeply nested and malformed JWS/JWK input without uncaught recursion
    errors or whole-set parsing failures. See
    GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>__
    and GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>__.
  • Enforce compact JWS encoding rules during decoding. See
    GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>__.
  • Reject detached-payload arguments for attached JWS inputs. Thanks to @xclow3n <https://github.com/xclow3n>__ for reporting this behavior; fixed in commit
    37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>__.

Fixed


- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
  `GHSA-pxh4-856f-4h89 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89>`__.
- Reject empty HMAC keys when represented as JWKs.
  See `GHSA-pxh4-856f-4h89 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89>`__.

`v2.13.0 <https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0>`__
-----------------------------------------------------------------------

Security
  • Reject JWK JSON documents passed as raw HMAC secrets in
    HMACAlgorithm.prepare_key to close an algorithm-confusion gap that
    the existing PEM/SSH guard did not cover. Reported by @​aradona91 in
    GHSA-xgmm-8j9v-c9wx <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx>__.
  • Bind the JWT header alg to PyJWK.algorithm_name during
    verification so the caller's algorithms=[...] allow-list cannot be
    bypassed when decoding with a PyJWK / PyJWKClient key. Reported
    by @​sushi-gif in GHSA-jq35-7prp-9v3f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f>__.
  • Reject non-http(s) URI schemes in PyJWKClient so attacker-
    influenced URIs cannot read local files or reach unintended schemes via
    urllib's default file:// / ftp:// / data: handlers. Reported
    by @​KEIJOT in GHSA-993g-76c3-p5m4 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4>__.
  • Preserve the cached JWK Set on fetch errors in PyJWKClient.fetch_data.
    The previous finally-block put(None) pattern cleared the cache
    on any transient outage, turning one bad JWKS request into application-
    wide auth failure. Reported by @​eddieran in GHSA-fhv5-28vv-h8m8 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8>__.
  • Skip the unconditional base64 decode of the compact-form payload segment
    when b64=false is set in the protected header, and require that
    segment to be empty (RFC 7515 Appendix F detached form). Closes an
    unauthenticated DoS amplifier. Reported by @​thesmartshadow in
    GHSA-w7vc-732c-9m39 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39>__.

Fixed


- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with
  ``InvalidKeyError`` instead of accepting them with only a warning.
  Thanks to @&#8203;SnailSploit and @&#8203;spartan8806 for independently flagging the
  footgun.
- Forward per-call ``options`` (including ``enforce_minimum_key_length``)
  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the
  option actually takes effect when set at the call site rather than only
  on the ``PyJWT`` instance. Thanks to @&#8203;WLUB for the report.
- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds
  ``"b64"`` to the ``crit`` header parameter, and the decoder rejects
  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to
  @&#8203;MachineLearning-Nerd for the report.

Changed
  • Migrate the dev, docs, and tests package extras to dependency groups by @​kurtmckee in #&#8203;1152 <https://github.com/jpadilla/pyjwt/pull/1152>__

v2.14.0

Compare Source

See the 2.14.0 changelog for the complete release details and related security advisories.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` → `2.15.1` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/pyjwt/2.15.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/pyjwt/2.13.0/2.15.1?slim=true) | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/10) for more information. --- ### Release Notes <details> <summary>jpadilla/pyjwt (pyjwt)</summary> ### [`v2.15.1`](https://github.com/jpadilla/pyjwt/blob/HEAD/CHANGELOG.rst#Unreleased-httpsgithubcomjpadillapyjwtcompare2151HEAD) [Compare Source](https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1) ### [`v2.15.0`](https://github.com/jpadilla/pyjwt/blob/HEAD/CHANGELOG.rst#v2151-httpsgithubcomjpadillapyjwtcompare21502151) [Compare Source](https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0) Fixed ``` - Accept trailing Base64URL ``=`` padding when decoding JWS segments, so tokens issued by AWS ALB and similar systems verify instead of raising ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as ``!!!!`` remains rejected (`#&#8203;1209 <https://github.com/jpadilla/pyjwt/issues/1209>`__). `v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>`__ ----------------------------------------------------------------------- Security ``` - Wrap recursion errors from deeply nested JWT payloads in `DecodeError` instead of exposing a raw `RecursionError`. Added ``` - Support Python 3.15 by @&#8203;kytta in `#&#8203;1202 <https://github.com/jpadilla/pyjwt/pull/1202>`__ Changed ``` - `JWKSetCache` now stores the parsed `PyJWKSet` rather than the raw JWKS payload, so a cache hit no longer re-parses every key. `JWKSetCache.put()` accepts either form and raises `PyJWKSetError` for anything else. As a result, `PyJWKClient.get_jwk_set()` returns the same `PyJWKSet` instance for as long as it stays cached, rather than a freshly built one per call in `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`\_\_ - `PyJWKClient.fetch_data()` now raises `PyJWKClientError("The JWKS endpoint did not return a JSON object")` when the endpoint response is not a JSON object, instead of returning it for `get_jwk_set()` to reject. Callers reaching the JWKS through `get_jwk_set()` see the same error as before in `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`\_\_ Fixed ``` - Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead of raising ``PyJWKClientError("The JWKS endpoint did not return a JSON object")``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value, so callers pre-populating the cache to avoid a network round-trip could not read it back in `#&#8203;914 <https://github.com/jpadilla/pyjwt/issues/914>`__ and `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__ - ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a ``fetch_data()`` override that filters or transforms the JWKS is no longer undone by the next cache hit in `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__ - Raise the documented ``PyJWTError`` subclass instead of leaking a ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a non-numeric, non-string value such as a list, dict, or ``null``. - Reject OKP JWK private keys when their public ``x`` component does not match the private ``d`` component. - Treat malformed JWK Set members as unusable keys rather than letting ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not a JSON object is skipped, a key whose components have the wrong type raises ``InvalidKeyError`` and is skipped, and a set left with no usable keys raises ``PyJWKSetError``. A single bad entry no longer fails an otherwise usable JWK Set in `#&#8203;1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__ - Wrap ``http.client.HTTPException`` (e.g. ``IncompleteRead`` from a truncated response) in ``PyJWKClient.fetch_data`` as ``PyJWKClientConnectionError``, matching the other network failure modes the method already documents. `v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0>`__ ----------------------------------------------------------------------- Security ``` - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`**, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`**, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`**, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`**. - Reject automatic redirects when `PyJWKClient` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`\_\_. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`\_\_. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`\_\_ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`\_\_. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`\_\_. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`\_\_ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`\_\_. Fixed ``` - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89>`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89>`__. `v2.13.0 <https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0>`__ ----------------------------------------------------------------------- Security ``` - Reject JWK JSON documents passed as raw HMAC secrets in `HMACAlgorithm.prepare_key` to close an algorithm-confusion gap that the existing PEM/SSH guard did not cover. Reported by [@&#8203;aradona91](https://github.com/aradona91) in `GHSA-xgmm-8j9v-c9wx <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx>`\_\_. - Bind the JWT header `alg` to `PyJWK.algorithm_name` during verification so the caller's `algorithms=[...]` allow-list cannot be bypassed when decoding with a `PyJWK` / `PyJWKClient` key. Reported by [@&#8203;sushi-gif](https://github.com/sushi-gif) in `GHSA-jq35-7prp-9v3f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f>`\_\_. - Reject non-`http(s)` URI schemes in `PyJWKClient` so attacker- influenced URIs cannot read local files or reach unintended schemes via urllib's default `file://` / `ftp://` / `data:` handlers. Reported by [@&#8203;KEIJOT](https://github.com/KEIJOT) in `GHSA-993g-76c3-p5m4 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4>`\_\_. - Preserve the cached JWK Set on fetch errors in `PyJWKClient.fetch_data`. The previous `finally`-block `put(None)` pattern cleared the cache on any transient outage, turning one bad JWKS request into application- wide auth failure. Reported by [@&#8203;eddieran](https://github.com/eddieran) in `GHSA-fhv5-28vv-h8m8 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8>`\_\_. - Skip the unconditional base64 decode of the compact-form payload segment when `b64=false` is set in the protected header, and require that segment to be empty (RFC 7515 Appendix F detached form). Closes an unauthenticated DoS amplifier. Reported by [@&#8203;thesmartshadow](https://github.com/thesmartshadow) in `GHSA-w7vc-732c-9m39 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39>`\_\_. Fixed ``` - Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with ``InvalidKeyError`` instead of accepting them with only a warning. Thanks to @&#8203;SnailSploit and @&#8203;spartan8806 for independently flagging the footgun. - Forward per-call ``options`` (including ``enforce_minimum_key_length``) from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the option actually takes effect when set at the call site rather than only on the ``PyJWT`` instance. Thanks to @&#8203;WLUB for the report. - RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds ``"b64"`` to the ``crit`` header parameter, and the decoder rejects tokens that set ``b64=false`` without listing it in ``crit``. Thanks to @&#8203;MachineLearning-Nerd for the report. Changed ``` - Migrate the `dev`, `docs`, and `tests` package extras to dependency groups by [@&#8203;kurtmckee](https://github.com/kurtmckee) in `#&#8203;1152 <https://github.com/jpadilla/pyjwt/pull/1152>`\_\_ ### [`v2.14.0`](https://github.com/jpadilla/pyjwt/releases/tag/2.14.0) [Compare Source](https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0) See the [2.14.0 changelog](https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst) for the complete release details and related security advisories. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4OC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Update dependency pyjwt to v2.14.0
Some checks failed
Test smol-k8s-lab / test_kind (pull_request) Failing after 2s
Test smol-k8s-lab / test_k3s (pull_request) Failing after 2s
Test smol-k8s-lab / test_k3d (pull_request) Failing after 2s
ce0e70ad89
Owentje force-pushed renovate/pyjwt-2.x-lockfile from ce0e70ad89
Some checks failed
Test smol-k8s-lab / test_kind (pull_request) Failing after 2s
Test smol-k8s-lab / test_k3s (pull_request) Failing after 2s
Test smol-k8s-lab / test_k3d (pull_request) Failing after 2s
to 8f21e94ace
Some checks failed
Test smol-k8s-lab / test_k3s (pull_request) Failing after 2m6s
2026-09-24 03:57:10 +00:00
Compare
Owentje changed title from Update dependency pyjwt to v2.14.0 to Update dependency pyjwt to v2.15.0 2026-09-24 03:57:11 +00:00
Owentje force-pushed renovate/pyjwt-2.x-lockfile from 8f21e94ace
Some checks failed
Test smol-k8s-lab / test_k3s (pull_request) Failing after 2m6s
to 2ec41825cd
All checks were successful
Test smol-k8s-lab / test_k3s (pull_request) Successful in 7m58s
2026-09-29 03:57:56 +00:00
Compare
Owentje changed title from Update dependency pyjwt to v2.15.0 to Update dependency pyjwt to v2.15.1 2026-09-29 03:57:57 +00:00
Owentje force-pushed renovate/pyjwt-2.x-lockfile from 2ec41825cd
All checks were successful
Test smol-k8s-lab / test_k3s (pull_request) Successful in 7m58s
to e94b4b6cdd
All checks were successful
Test smol-k8s-lab / test_k3s (pull_request) Successful in 8m49s
2026-09-30 03:56:22 +00:00
Compare
All checks were successful
Test smol-k8s-lab / test_k3s (pull_request) Successful in 8m49s
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/pyjwt-2.x-lockfile:renovate/pyjwt-2.x-lockfile
git switch renovate/pyjwt-2.x-lockfile

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/pyjwt-2.x-lockfile
git switch renovate/pyjwt-2.x-lockfile
git rebase main
git switch main
git merge --ff-only renovate/pyjwt-2.x-lockfile
git switch renovate/pyjwt-2.x-lockfile
git rebase main
git switch main
git merge --no-ff renovate/pyjwt-2.x-lockfile
git switch main
git merge --squash renovate/pyjwt-2.x-lockfile
git switch main
git merge --ff-only renovate/pyjwt-2.x-lockfile
git switch main
git merge renovate/pyjwt-2.x-lockfile
git push origin main
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
oeng/smol-k8s-lab!97
No description provided.