dependabot[bot] opened a new pull request, #25918:
URL: https://github.com/apache/datafusion/pull/25918

   Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/jpadilla/pyjwt/releases";>pyjwt's releases</a>.</em></p>
   <blockquote>
   <h2>2.15.0</h2>
   <p>See the <a 
href="https://github.com/jpadilla/pyjwt/blob/2.15.0/CHANGELOG.rst";>2.15.0 
changelog</a> for complete release details.</p>
   <h2>2.14.0</h2>
   <p>See the <a 
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst";>2.14.0 
changelog</a> for the complete release details and related security 
advisories.</p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst";>pyjwt's 
changelog</a>.</em></p>
   <blockquote>
   <h2><code>v2.15.0 
&lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;</code>__</h2>
   <p>Security</p>
   <pre><code>
   - Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
     instead of exposing a raw ``RecursionError``.
   <p>Added</p>
   <pre><code>
   - Support Python 3.15 by @kytta in 
`[#1202](https://github.com/jpadilla/pyjwt/issues/1202) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1202&amp;gt;`__
   
   Changed
   </code></pre>
   <ul>
   <li><code>JWKSetCache</code> now stores the parsed <code>PyJWKSet</code> 
rather than the raw JWKS
   payload, so a cache hit no longer re-parses every key. 
<code>JWKSetCache.put()</code>
   accepts either form and raises <code>PyJWKSetError</code> for anything else. 
As a
   result, <code>PyJWKClient.get_jwk_set()</code> returns the same 
<code>PyJWKSet</code> instance
   for as long as it stays cached, rather than a freshly built one per call in
   <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
   <li><code>PyJWKClient.fetch_data()</code> now raises
   <code>PyJWKClientError(&amp;quot;The JWKS endpoint did not return a JSON 
object&amp;quot;)</code> when
   the endpoint response is not a JSON object, instead of returning it for
   <code>get_jwk_set()</code> to reject. Callers reaching the JWKS through
   <code>get_jwk_set()</code> see the same error as before in
   <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
   </ul>
   <p>Fixed</p>
   <pre><code>
   - Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` 
instead
     of raising ``PyJWKClientError(&amp;quot;The JWKS endpoint did not return a 
JSON
     object&amp;quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the 
cached value,
     so callers pre-populating the cache to avoid a network round-trip could not
     read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) 
&amp;lt;https://github.com/jpadilla/pyjwt/issues/914&amp;gt;`__ and
     `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
   - ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
     ``fetch_data()`` override that filters or transforms the JWKS is no longer
     undone by the next cache hit in
     `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
   - Raise the documented ``PyJWTError`` subclass instead of leaking a
     ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
     non-numeric, non-string value such as a list, dict, or ``null``.
   - Reject OKP JWK private keys when their public ``x`` component does not
     match the private ``d`` component.
   - Treat malformed JWK Set members as unusable keys rather than letting
     ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is 
not
   &amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt; 
   &lt;/code&gt;&lt;/pre&gt;
   &lt;/blockquote&gt;
   &lt;p&gt;... (truncated)&lt;/p&gt;
   &lt;/details&gt;
   &lt;details&gt;
   &lt;summary&gt;Commits&lt;/summary&gt;
   
   &lt;ul&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a&gt;
 chore: prepare 2.15.0 release&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a&gt;
 fix: make recursive payload tests deterministic&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a&gt;
 fix: normalize recursive JWT payload errors&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a&gt;
 utils: mention bytes in force_bytes type error (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a&gt;
 docs/conf: drop duplicate 'and' from read() docstring (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a&gt;
 Add support for Python 3.15 (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a&gt;
 Catch http.client.HTTPException in PyJWKClient.fetch_data (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a&gt;
 fix: correct docstring typo in _validate_jti (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a&gt;
 docs: clarify JWK certificate member handling (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a&gt;
 [pre-commit.ci] pre-commit autoupdate (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;Additional commits viewable in &lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0&quot;&gt;compare
 view&lt;/a&gt;&lt;/li&gt;
   &lt;/ul&gt;
   &lt;/details&gt;
   
   &lt;br /&gt;</code></pre>
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.13.0&new-version=2.15.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/datafusion/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to