external
external copied to clipboard
Chore(deps): Bump firebase/php-jwt from 6.11.1 to 7.0.2
Bumps firebase/php-jwt from 6.11.1 to 7.0.2.
Release notes
Sourced from firebase/php-jwt's releases.
v7.0.2
7.0.2 (2025-12-16)
Bug Fixes
v7.0.1
Bug Fixes
- remove resource support (#612)
v7.0.0
7.0.0 (2025-12-15)
⚠️ ⚠️ ⚠️ Security Fixes ⚠️ ⚠️ ⚠️
- add key size validation (#613) (6b80341) NOTE: This fix will cause keys with a size below the minimally allowed size to break.
Features
- add SensitiveParameter attribute to security-critical parameters (#603) (4dbfac0)
- store timestamp in
ExpiredException(#604) (f174826)Bug Fixes
Changelog
Sourced from firebase/php-jwt's changelog.
7.0.2 (2025-12-16)
Bug Fixes
7.0.0 (2025-12-15)
⚠️ ⚠️ ⚠️ Security Fixes ⚠️ ⚠️ ⚠️
- add key size validation (#613) (6b80341) NOTE: This fix will cause keys with a size below the minimally allowed size to break.
Features
- add SensitiveParameter attribute to security-critical parameters (#603) (4dbfac0)
- store timestamp in
ExpiredException(#604) (f174826)Bug Fixes
Commits
5645b43chore(main): release 7.0.2 (#616)7044f9afix: add key length validation for ec keys (#615)81ed59eAdd key size validation (#612)c03036fchore(main): release 7.0.0 (#614)6b80341feat: add key size validation (#613)a3edb39chore: update release-please secret (#608)f174826feat: store timestamp inExpiredException(#604)4dbfac0feat: add SensitiveParameter attribute to security-critical parameters (#603)223d1b3chore: move release please from app to github action (#606)953b2c8fix: validate iat and nbf on payload (#568)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)