Skip to content

chore(deps): bump pyjwt to 2.15.1 (CVE-2026-102274) - #53

Merged
fedorov merged 1 commit into
mainfrom
chore/bump-pyjwt
Sep 30, 2026
Merged

fedorov merged 1 commit into
mainfrom
chore/bump-pyjwt

Conversation

@fedorov

@fedorov fedorov commented Sep 29, 2026

Copy link
Copy Markdown
Member

pip-audit flags pyjwt 2.13.0 (CVE-2026-102274, fixed in 2.14.0), failing the vulnerability scan on every PR (e.g. #52).

pyjwt is transitive via mcp[crypto], so this is a lockfile-only change (uv lock --upgrade-package pyjwt), resolving to the current 2.15.1. No CHANGELOG entry (dependency bump, not user-visible).

Verified locally: pip-audit reports no known vulnerabilities; test suite passes (95 passed).

🤖 Generated with Claude Code

Transitive via mcp[crypto]; lockfile-only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 19:50

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@fedorov
fedorov merged commit db0f4df into main Sep 30, 2026
6 checks passed
@fedorov
fedorov deleted the chore/bump-pyjwt branch September 30, 2026 02:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants