Skip to content

chore(deps): Bump pyjwt from 2.13.0 to 2.15.0 - #1251

Merged
CasperGN merged 1 commit into
mainfrom
dependabot/uv/pyjwt-2.15.0
Oct 5, 2026
Merged

CasperGN merged 1 commit into
mainfrom
dependabot/uv/pyjwt-2.15.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps pyjwt from 2.13.0 to 2.15.0.

Release notes

Sourced from pyjwt's releases.

2.15.0

See the 2.15.0 changelog for complete release details.

2.14.0

See the 2.14.0 changelog for the complete release details and related security advisories.

Changelog

Sourced from pyjwt's changelog.

v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>__

Security


- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
  instead of exposing a raw ``RecursionError``.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__
  • PyJWKClient.fetch_data() now raises PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;) when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON
  object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a> chore: prepare 2.15.0 release</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a> fix: make recursive payload tests deterministic</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a> fix: normalize recursive JWT payload errors</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 07:02
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 07:02
@dependabot dependabot Bot added python:uv Pull requests that update python:uv code dependencies Pull requests that update a dependency file labels Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.51%. Comparing base (3c4cbef) to head (67b97f4).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1251   +/-   ##
=======================================
  Coverage   85.51%   85.51%           
=======================================
  Files         162      162           
  Lines       12594    12594           
=======================================
  Hits        10770    10770           
  Misses       1824     1824           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/pyjwt-2.15.0 branch from e2cf3eb to 67b97f4 Compare October 1, 2026 17:46

@CasperGN CasperGN left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude review · approved on Casper's behalf.

No findings: lockfile-only bump with all CI green. Moves pyjwt past 2.14.0, which fixes open alerts #86, #87 and #91.

Reviewed at 67b97f4.

Disagree, or want to talk it through? Reply /human and Casper will pick it up.

@CasperGN
CasperGN added this pull request to the merge queue Oct 5, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 5, 2026
@CasperGN
CasperGN added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit bc54f2e Oct 5, 2026
22 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/pyjwt-2.15.0 branch October 5, 2026 10:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant