fix(deps): bump pyjwt from 2.13.0 to 2.14.0 - #5241
dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 53db401c4d
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| [[package]] | ||
| name = "pyjwt" | ||
| version = "2.13.0" | ||
| version = "2.14.0" |
There was a problem hiding this comment.
Raise the published PyJWT security floor
The changed lockfile only protects uv-managed installs: the package metadata still declares pyjwt>=2.13.0 (in the project's security-floor group), so a consumer resolution that validly selects 2.13.0—for example, because another dependency constrains PyJWT below 2.14—will continue to install the vulnerable version this update is intended to replace. Raise the declared lower bound and regenerate the lockfile so distributed SDK installs inherit the security fix.
AGENTS.md reference: AGENTS.md:L19-L19
Useful? React with 👍 / 👎.
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.14.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.14.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.14.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
53db401 to
a6a3f41
Compare
Bumps pyjwt from 2.13.0 to 2.14.0.
Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.