pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/textproc/py-JWT
Module Name: pkgsrc
Committed By: wiz
Date: Mon Sep 28 14:40:37 UTC 2026
Modified Files:
pkgsrc/textproc/py-JWT: Makefile distinfo
Log Message:
py-JWT: update to 2.15.0.
v2.15.0
-------
Security
~~~~~~~~
- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
instead of exposing a raw ``RecursionError``.
Added
~~~~~
- Support Python 3.15 by @kytta in `#1202 <https://github.com/jpadilla/pyjwt/pull/1202>`__
Changed
~~~~~~~
- ``JWKSetCache`` now stores the parsed ``PyJWKSet`` rather than the raw JWKS
payload, so a cache hit no longer re-parses every key. ``JWKSetCache.put()``
accepts either form and raises ``PyJWKSetError`` for anything else. As a
result, ``PyJWKClient.get_jwk_set()`` returns the same ``PyJWKSet`` instance
for as long as it stays cached, rather than a freshly built one per call in
`#1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- ``PyJWKClient.fetch_data()`` now raises
``PyJWKClientError("The JWKS endpoint did not return a JSON object")`` when
the endpoint response is not a JSON object, instead of returning it for
``get_jwk_set()`` to reject. Callers reaching the JWKS through
``get_jwk_set()`` see the same error as before in
`#1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
Fixed
~~~~~
- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
of raising ``PyJWKClientError("The JWKS endpoint did not return a JSON
object")``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
so callers pre-populating the cache to avoid a network round-trip could not
read it back in `#914 <https://github.com/jpadilla/pyjwt/issues/914>`__ and
`#1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
``fetch_data()`` override that filters or transforms the JWKS is no longer
undone by the next cache hit in
`#1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
a JSON object is skipped, a key whose components have the wrong type raises
``InvalidKeyError`` and is skipped, and a set left with no usable keys raises
``PyJWKSetError``. A single bad entry no longer fails an otherwise usable
JWK Set in `#1208 <https://github.com/jpadilla/pyjwt/pull/1208>`__
- Wrap ``http.client.HTTPException`` (e.g. ``IncompleteRead`` from a
truncated response) in ``PyJWKClient.fetch_data`` as
``PyJWKClientConnectionError``, matching the other network failure
modes the method already documents.
To generate a diff of this commit:
cvs rdiff -u -r1.35 -r1.36 pkgsrc/textproc/py-JWT/Makefile
cvs rdiff -u -r1.29 -r1.30 pkgsrc/textproc/py-JWT/distinfo
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/textproc/py-JWT/Makefile
diff -u pkgsrc/textproc/py-JWT/Makefile:1.35 pkgsrc/textproc/py-JWT/Makefile:1.36
--- pkgsrc/textproc/py-JWT/Makefile:1.35 Sun Sep 13 12:56:50 2026
+++ pkgsrc/textproc/py-JWT/Makefile Mon Sep 28 14:40:37 2026
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.35 2026/09/13 12:56:50 wiz Exp $
+# $NetBSD: Makefile,v 1.36 2026/09/28 14:40:37 wiz Exp $
-DISTNAME= pyjwt-2.14.0
+DISTNAME= pyjwt-2.15.0
PKGNAME= ${PYPKGPREFIX}-${DISTNAME:S/pyjwt/JWT/}
CATEGORIES= textproc python
MASTER_SITES= ${MASTER_SITE_PYPI:=P/PyJWT/}
Index: pkgsrc/textproc/py-JWT/distinfo
diff -u pkgsrc/textproc/py-JWT/distinfo:1.29 pkgsrc/textproc/py-JWT/distinfo:1.30
--- pkgsrc/textproc/py-JWT/distinfo:1.29 Sun Sep 13 12:56:50 2026
+++ pkgsrc/textproc/py-JWT/distinfo Mon Sep 28 14:40:37 2026
@@ -1,5 +1,5 @@
-$NetBSD: distinfo,v 1.29 2026/09/13 12:56:50 wiz Exp $
+$NetBSD: distinfo,v 1.30 2026/09/28 14:40:37 wiz Exp $
-BLAKE2s (pyjwt-2.14.0.tar.gz) = db0c5b3faedbe47055a9187e9a4adc67fc65952e25e3112fb0b3f4cbdb16fca2
-SHA512 (pyjwt-2.14.0.tar.gz) = 33b5ea83edb24fd4d73cc471c1d5ecbd0be45eef1d19c873a0a9a5615d2d52d8401176c71287a466c05f1086479dabeded203910c5815927574b8ebd07428936
-Size (pyjwt-2.14.0.tar.gz) = 113177 bytes
+BLAKE2s (pyjwt-2.15.0.tar.gz) = 150f167863b57e9ce647de7f5b76506a851b06640cb052ce0ad9552f8d62e23a
+SHA512 (pyjwt-2.15.0.tar.gz) = ede90c35e667924a2749083d726e9f8af6fa86c215d64433819b36d14a28059d68ba062d3a6b04a1aaac94505362e52a888d92adf8ce0b80599a223de5850692
+Size (pyjwt-2.15.0.tar.gz) = 120513 bytes
Home |
Main Index |
Thread Index |
Old Index