ruby-auth0
ruby-auth0 copied to clipboard
chore(deps): bump jwt from 2.7.1 to 2.8.1
Bumps jwt from 2.7.1 to 2.8.1.
Changelog
Sourced from jwt's changelog.
v2.8.1 (2024-02-29)
Features:
Fixes and enhancements:
v2.8.0 (2024-02-17)
Features:
- Updated rubocop to 1.56 #573 (
@anakinj)- Run CI on Ruby 3.3 #577 (
@anakinj)- Deprecation warning added for the HMAC algorithm HS512256 (HMAC-SHA-512 truncated to 256-bits) #575 (
@anakinj)- Stop using RbNaCl for standard HMAC algorithms #575 (
@anakinj)Fixes and enhancements:
- Fix signature has expired error if payload is a string #555 (
@GobinathAL)- Fix key base equality and spaceship operators #569 (
@magneland)- Remove explicit base64 require from x5c_key_finder #580 (
@anakinj)- Performance improvements and cleanup of tests #581 (
@anakinj)- Repair EC x/y coordinates when importing JWK #585 (
@julik)- Explicit dependency to the base64 gem #582 (
@anakinj)- Deprecation warning for decoding content not compliant with RFC 4648 #582 (
@anakinj)- Algorithms moved under the
::JWT::JWAmodule (@anakinj)
Commits
ea1e441Version 2.8.1db99c67Configurabe base64 behaviour and log deprecations once by defaultbd3f80bNext iteration956fa1bVersion 2.8.0d9352e8Adjust to changed exception message13dd333Algorithm cleanup.39aa57aDeprecate the loose base64 decoding.9090e78Relocate changelog entry6af6de5Relocate into constant1ec2e7fUpdate changelog- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)