Skip to content

fix: replace vulnerable JWT dependency - #11

Merged
flpksh merged 1 commit into
mainfrom
codex/replace-vulnerable-jwt
Aug 12, 2026
Merged

fix: replace vulnerable JWT dependency#11
flpksh merged 1 commit into
mainfrom
codex/replace-vulnerable-jwt

Conversation

@flpksh

@flpksh flpksh commented Aug 12, 2026

Copy link
Copy Markdown
Owner

Remove ecdsa and python-jose, migrate HS256 token handling to PyJWT 2.13.0, update idna to 3.15, and preserve token validation behavior. Local validation: 76 tests passed, 94.22% coverage, formatting, lint, types, Docker checks, and migrations approved.

@flpksh
flpksh merged commit 755c7c5 into main Aug 12, 2026
3 checks passed
@flpksh
flpksh deleted the codex/replace-vulnerable-jwt branch August 12, 2026 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant