Skip to content

chore(deps): update jwt requirement from ~> 2 to >= 2, < 4 - #224

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/jwt-2.10.3
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/jwt-2.10.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 2, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on jwt to permit the latest version.

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Updates the requirements on [jwt](https://github.com/jwt/ruby-jwt) to permit the latest version.
- [Release notes](https://github.com/jwt/ruby-jwt/releases)
- [Changelog](https://github.com/jwt/ruby-jwt/blob/main/CHANGELOG.md)
- [Commits](jwt/ruby-jwt@v2.10.2...v2.10.3)

---
updated-dependencies:
- dependency-name: jwt
  dependency-version: 2.10.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Jun 2, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 2, 2026 22:31
@mdking

mdking commented Jun 9, 2026

Copy link
Copy Markdown

@arpit-jn could we get this merged? This is flagged as a vulnerability and potentially will impact our SOC 2 compliance.

@lukaselmer

Copy link
Copy Markdown

Can we merge this @arpit-jn please? We are affected by GHSA-c32j-vqhx-rx3x because this isn't merged and released 😬😬😬

@markaschneider

Copy link
Copy Markdown

It's now 3 months since the security advisory was published.

@lukaselmer

Copy link
Copy Markdown

It's now 3 months since the security advisory was published.

We've vendored it and fixed it ourselves. Additional benefit: we've thrown away about half of the implementation, because we didn't need it anyways. Not sure if that's a good strategy, but this here is moving too slow 👎

pull Bot pushed a commit to TheTechOddBug/onetimesecret that referenced this pull request Sep 23, 2026
omniauth-auth0 3.2.0 is the only gem in the bundle that pins jwt ~> 2.
Adding it moved the lock from jwt 3.2.0 to 2.10.3, a major-version
regression in a crypto library on the auth path that every other
consumer (oauth2, omniauth-entra-id, omniauth-google-oauth2,
safety_net_attestation) allows at < 4.0. Upstream has the relaxation
open (auth0/omniauth-auth0#224) but unreleased.

The provider never shipped (all AUTH0_* keys were "Since unreleased"),
and the gem's own claim validation never runs: its scope gate reads a
symbol key from a string-keyed hash, so iss/aud/exp/nonce go unchecked.
Auth0 is OIDC-compliant and is now documented through the generic oidc
provider, which validates those claims and is also tenant-capable.

Gemfile declares jwt ~> 3.2 so a future provider gem that pins jwt 2.x
fails resolution instead of silently downgrading. The lock resolves to
jwt 3.3.0.

:vars_valid stays: it is a generic registry field consumed by
AuthConfig#provider_active? and configure_provider. The Auth0-specific
examples that covered it are replaced by examples on a synthetic
definition, exercised through the public #sso_providers gate, and the
raising-strategy_options skip test now uses a raising Apple stub.

Verified: unit lane on the five touched spec files (344 examples), the
frontend features spec (208), bin/envref check, and jwt 3.3.0 loads
alongside omniauth-apple, omniauth-entra-id, omniauth-google-oauth2 and
webauthn.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants