Bump pyjwt from 2.13.0 to 2.15.0 - #3608
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM, routine Dependabot lockfile bump of pyjwt 2.13.0 -> 2.15.0 with no source or constraint changes.
What was reviewed:
- The uv.lock diff: only the pyjwt entry's version, sdist/wheel URLs, hashes and sizes change; the typing-extensions marker and crypto extra are unchanged, and pyproject.toml still declares
pyjwt[crypto]>=2.10.1, consistent with the dependency policy of not raising floors for lockfile refreshes. - SDK call sites (
jwt.encodein client_credentials.py,jwt.decode/get_unverified_header/InvalidTokenErrorin the identity_assertion examples): all stable public APIs unaffected by the 2.14/2.15 changes, which target JWKSetCache/PyJWKClient and error wrapping the SDK does not use. - The crypto extra still resolves to the already-locked cryptography package, so RS256 signing is unaffected.
Extended reasoning...
The change is a single-file uv.lock update moving the locked pyjwt from 2.13.0 to 2.15.0, with updated sdist and wheel URLs, sha256 hashes, sizes and upload timestamps; no source, test, or pyproject.toml edits. It touches the lock entry for a JWT library used in the client_credentials private_key_jwt flow, but the SDK only calls jwt.encode with a key and algorithm, and the identity_assertion examples use jwt.decode, get_unverified_header and InvalidTokenError, none of which changed in 2.14 or 2.15 (those releases touched JWKSetCache/PyJWKClient internals and error normalization). The published requirement remains pyjwt[crypto]>=2.10.1 and the crypto extra still points at the already-locked cryptography package, so this only refreshes the tested version per the repository's dependency policy. The hunt ran dry, no CODEOWNERS file exists, and there are no third-party objections, which decided approve.
Bumps pyjwt from 2.13.0 to 2.15.0.
Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.