Repository navigation
chore(deps): bump pyjwt from 2.12.0 to 2.13.0 in /apps/api/requirements - #30
Merged
github-actions[bot] merged 1 commit intoJul 28, 2026
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Owner
|
@dependabot rebase |
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.12.0 to 2.13.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.12.0...2.13.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.13.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/pip/apps/api/requirements/pyjwt-2.13.0
branch
from
July 28, 2026 05:54
4bf7dae to
99a0b93
Compare
dependabot
Bot
deleted the
dependabot/pip/apps/api/requirements/pyjwt-2.13.0
branch
July 28, 2026 05:56
1 task done
aRustyDev
added a commit
that referenced
this pull request
Jul 28, 2026
…d base images) (#36) Triaging the baseline (plane-7fn.4.22) showed the trivy/grype gate was ~95% inherited base-image OS packages (Alpine) + the inherited proxy Go binary (Caddy/stdlib/grpc/golang.org/x/*) — none of which our deps control, so the strict all-package gate would block every release on upstream base-image churn. Re-scope per the chosen posture (gate on OUR code, report the rest): - Trivy is the gate, scoped to LIBRARY packages (TRIVY_PKG_TYPES=library): fails only on fixable HIGH/CRITICAL in our pnpm-workspace + apps/api pip deps. Verified locally: frontend library-only = 0 (was 37 OS), proxy library-only = 46 (inherited Go binary). - matrix `gate` flag makes the proxy (a pure inherited image) report-only. - Grype flips to full report-only over the SBOM (OS + library) so the inherited backlog stays visible in the Security tab; base-image refresh tracked in plane-7fn.4.23, accept-via-VEX in 4.18. Backend's only library vulns (PyJWT, cryptography) are fixed by Dependabot #30/#29. Refs: plane-7fn.4.22 Co-authored-by: adam <asmith@dashboard152.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps pyjwt from 2.12.0 to 2.13.0.
Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.
... (truncated)
Commits
7144e45Apply ruff formatd2f4becRestorecast()calls with cross-versiontype: ignoreforprepare_key22f478cRemove redundant casts inRSAAlgorithm.prepare_keyand `ECAlgorithm.prepare...95791b1Bundle security fixes and hardening into 2.13.0dcc27a9[pre-commit.ci] pre-commit autoupdate (#1155)9d08a9a[pre-commit.ci] pre-commit autoupdate (#1146)b87c100Bump codecov/codecov-action from 5 to 6 (#1154)40e3147Migrate development extras to dependency groups (#1152)a4e1a3dAdd typing_extensions dependency for Python < 3.11 (#1151)