Bump pyjwt from 2.11.0 to 2.12.0
Open
Number: #182
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Unknown
Comments: 2
Association: Unknown
Comments: 2
Created:
March 13, 2026 at 12:33 AM UTC
(3 months ago)
(3 months ago)
Updated:
March 13, 2026 at 12:33 AM UTC
(3 months ago)
(3 months ago)
Labels:
dependencies python
dependencies python
Description:
Bumps pyjwt from 2.11.0 to 2.12.0.
Release notes
Sourced from pyjwt's releases.
2.12.0
Security
- Validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by
@dmbs335in GHSA-752w-5fwx-jx9fWhat's Changed
- [pre-commit.ci] pre-commit autoupdate by
@pre-commit-ci[bot] in jpadilla/pyjwt#1132- chore(docs): fix docs build by
@tamirdin jpadilla/pyjwt#1137- Annotate PyJWKSet.keys for pyright by
@tamirdin jpadilla/pyjwt#1134- fix: close HTTPError to prevent ResourceWarning on Python 3.14 by
@veeceeyin jpadilla/pyjwt#1133- chore: remove superfluous constants by
@tamirdin jpadilla/pyjwt#1136- [pre-commit.ci] pre-commit autoupdate by
@pre-commit-ci[bot] in jpadilla/pyjwt#1135- chore(tests): enable mypy by
@tamirdin jpadilla/pyjwt#1138- Bump actions/download-artifact from 7 to 8 by
@dependabot[bot] in jpadilla/pyjwt#1142- [pre-commit.ci] pre-commit autoupdate by
@pre-commit-ci[bot] in jpadilla/pyjwt#1141- [pre-commit.ci] pre-commit autoupdate by
@pre-commit-ci[bot] in jpadilla/pyjwt#1145- fix: do not store reference to algorithms dict on PyJWK by
@akxin jpadilla/pyjwt#1143- Use PyJWK algorithm when encoding without explicit algorithm by
@jpadillain jpadilla/pyjwt#1148New Contributors
@tamirdmade their first contribution in jpadilla/pyjwt#1137@veeceeymade their first contribution in jpadilla/pyjwt#1133Full Changelog: https://github.com/jpadilla/pyjwt/compare/2.11.0...2.12.0
Changelog
Sourced from pyjwt's changelog.
v2.12.0 <https://github.com/jpadilla/pyjwt/compare/2.11.0...2.12.0>__Fixed
- Annotate PyJWKSet.keys for pyright by @tamird in `[#1134](https://github.com/jpadilla/pyjwt/issues/1134) <https://github.com/jpadilla/pyjwt/pull/1134>`__ - Close ``HTTPError`` response to prevent ``ResourceWarning`` on Python 3.14 by @veeceey in `[#1133](https://github.com/jpadilla/pyjwt/issues/1133) <https://github.com/jpadilla/pyjwt/pull/1133>`__ - Do not keep ``algorithms`` dict in PyJWK instances by @akx in `[#1143](https://github.com/jpadilla/pyjwt/issues/1143) <https://github.com/jpadilla/pyjwt/pull/1143>`__ - Validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by @dmbs335 in `GHSA-752w-5fwx-jx9f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f>`__ - Use PyJWK algorithm when encoding without explicit algorithm in `[#1148](https://github.com/jpadilla/pyjwt/issues/1148) <https://github.com/jpadilla/pyjwt/pull/1148>`__Added
- Docs: Add
PyJWKClientAPI reference and document the two-tier caching system (JWK Set cache and signing key LRU cache).
Commits
bd9700cUse PyJWK algorithm when encoding without explicit algorithm (#1148)051ea34Merge commit from fork1451d70fix: do not store reference to algorithms dict on PyJWK (#1143)f3ba74c[pre-commit.ci] pre-commit autoupdate (#1145)0318ffa[pre-commit.ci] pre-commit autoupdate (#1141)a52753dBump actions/download-artifact from 7 to 8 (#1142)b85050fchore(tests): enable mypy (#1138)1272b26[pre-commit.ci] pre-commit autoupdate (#1135)99a8728chore: remove superfluous constants (#1136)412cb67fix: close HTTPError to prevent ResourceWarning on Python 3.14 (#1133)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Technical Details
| ID: | 14566116 |
| UUID: | 4068048441 |
| Node ID: | PR_kwDOFYH3Ss7KNZnj |
| Host: | GitHub |
| Repository: | NHSDigital/shared-flow-testing |