dependabot[bot] opened a new pull request, #265:
URL: https://github.com/apache/datafusion-sandbox/pull/265

   Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.12.0 to 2.15.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/jpadilla/pyjwt/releases";>pyjwt's releases</a>.</em></p>
   <blockquote>
   <h2>2.15.0</h2>
   <p>See the <a 
href="https://github.com/jpadilla/pyjwt/blob/2.15.0/CHANGELOG.rst";>2.15.0 
changelog</a> for complete release details.</p>
   <h2>2.14.0</h2>
   <p>See the <a 
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst";>2.14.0 
changelog</a> for the complete release details and related security 
advisories.</p>
   <h2>2.13.0</h2>
   <h1>PyJWT 2.13.0 — Security Release</h1>
   <p>This release bundles five security fixes plus three additional hardening 
/ spec-compliance changes. We recommend all users upgrade.</p>
   <h2>Security</h2>
   <ul>
   <li>
   <p><strong><a 
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx";><code>GHSA-xgmm-8j9v-c9wx</code></a>
 — JWK JSON accepted as HMAC secret (algorithm confusion).</strong> 
<code>HMACAlgorithm.prepare_key</code> previously rejected PEM- and 
SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON 
string. In a verifier configured with both symmetric and asymmetric algorithms 
in <code>algorithms=[…]</code> and a raw-JSON JWK as the key, an attacker could 
forge HS256 tokens using the JWK text as the HMAC secret. The guard has been 
extended to reject any JWK-shaped JSON. <em>Reported by <a 
href="https://github.com/aradona91";><code>@​aradona91</code></a>.</em></p>
   </li>
   <li>
   <p><strong><a 
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f";><code>GHSA-jq35-7prp-9v3f</code></a>
 — Algorithm allow-list bypass with <code>PyJWK</code> / 
<code>PyJWKClient</code>.</strong> When verifying with a <code>PyJWK</code>, 
the caller's <code>algorithms=[…]</code> allow-list was checked against the 
token header <code>alg</code> as a string only; actual verification used the 
algorithm bound to the <code>PyJWK</code>. An attacker who controlled a 
registered JWKS key could sign with one algorithm and advertise another on the 
header. PyJWT now requires the token header <code>alg</code> to match the 
<code>PyJWK</code>'s algorithm before verification. <em>Reported by <a 
href="https://github.com/sushi-gif";><code>@​sushi-gif</code></a>.</em></p>
   </li>
   <li>
   <p><strong><a 
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39";><code>GHSA-w7vc-732c-9m39</code></a>
 — DoS via base64 decode of unused payload segment when 
<code>b64=false</code>.</strong> For detached-payload JWS 
(<code>b64=false</code>), the compact-form payload segment was base64-decoded 
before being discarded in favor of the caller-supplied 
<code>detached_payload</code>. An attacker could inflate the unused segment to 
force CPU + memory cost without holding a valid signature. The segment is now 
required to be empty per RFC 7515 Appendix F, and is no longer decoded. 
<em>Reported by <a 
href="https://github.com/thesmartshadow";><code>@​thesmartshadow</code></a>.</em></p>
   </li>
   <li>
   <p><strong><a 
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4";><code>GHSA-993g-76c3-p5m4</code></a>
 — <code>PyJWKClient</code> accepts non-HTTP(S) URIs.</strong> 
<code>PyJWKClient.fetch_data</code> passed its URI to 
<code>urllib.request.urlopen</code>, which by default also handles 
<code>file://</code>, <code>ftp://</code>, and <code>data:</code> schemes. An 
application that fed an attacker-influenced URI into <code>PyJWKClient</code> 
could be coerced into reading local files or reaching other unintended schemes. 
<code>PyJWKClient</code> now rejects any URI whose scheme isn't 
<code>http</code> or <code>https</code>. <em>Reported by <a 
href="https://github.com/KEIJOT";><code>@​KEIJOT</code></a>.</em></p>
   </li>
   <li>
   <p><strong><a 
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8";><code>GHSA-fhv5-28vv-h8m8</code></a>
 — <code>PyJWKClient</code> cache wiped on fetch error.</strong> A 
<code>finally</code>-block <code>put(jwk_set=None)</code> cleared the JWK Set 
cache whenever a fetch raised, turning a transient JWKS-endpoint outage into 
application-wide auth failure. The cache write was moved into the success path; 
transient errors no longer evict valid cached keys. <em>Reported by <a 
href="https://github.com/eddieran";><code>@​eddieran</code></a>.</em></p>
   </li>
   </ul>
   <h2>Fixed</h2>
   <ul>
   <li>Reject empty HMAC keys outright in 
<code>HMACAlgorithm.prepare_key</code> with <code>InvalidKeyError</code> 
instead of accepting them with only a warning. Defends against the 
<code>os.getenv(&quot;JWT_SECRET&quot;, &quot;&quot;)</code> footgun. 
<em>Thanks to <a 
href="https://github.com/SnailSploit";><code>@​SnailSploit</code></a> and <a 
href="https://github.com/spartan8806";><code>@​spartan8806</code></a> for the 
reports.</em></li>
   <li>Forward per-call <code>options</code> (including 
<code>enforce_minimum_key_length</code>) from <code>PyJWT.decode</code> through 
to <code>PyJWS._verify_signature</code>. The option was previously silently 
dropped between the two layers, so it only took effect when set on the 
<code>PyJWT</code> instance. <em>Thanks to <a 
href="https://github.com/WLUB";><code>@​WLUB</code></a> for the report.</em></li>
   <li><strong>RFC 7797 §3 compliance for <code>b64=false</code>:</strong> the 
encoder now auto-adds <code>&quot;b64&quot;</code> to <code>crit</code>, and 
the decoder rejects tokens that set <code>b64=false</code> without listing it 
in <code>crit</code>. <em>Thanks to <a 
href="https://github.com/MachineLearning-Nerd";><code>@​MachineLearning-Nerd</code></a>
 for the report.</em></li>
   </ul>
   <h2>Changed</h2>
   <ul>
   <li>Migrate the <code>dev</code>, <code>docs</code>, and <code>tests</code> 
package extras to dependency groups, by <a 
href="https://github.com/kurtmckee";><code>@​kurtmckee</code></a> in <a 
href="https://redirect.github.com/jpadilla/pyjwt/pull/1152";>#1152</a>.</li>
   </ul>
   <h2>Upgrade notes</h2>
   <p>Most fixes are invisible to correctly-configured callers. A few 
behavioral changes you may encounter:</p>
   <ul>
   <li><strong>Empty HMAC keys now raise.</strong> If your app passed 
<code>&quot;&quot;</code> or <code>b&quot;&quot;</code> as a secret (often via 
a missing env var, e.g. <code>os.getenv(&quot;JWT_SECRET&quot;, 
&quot;&quot;)</code>), <code>encode</code>/<code>decode</code> will now raise 
<code>InvalidKeyError</code>. This is the intended behavior — fix the 
configuration.</li>
   <li><strong><code>PyJWK</code> decoding now requires the token's 
<code>alg</code> to match the JWK's algorithm.</strong> Previously a mismatch 
was silently honored if the header <code>alg</code> appeared in the allow-list. 
Tokens that relied on this mismatch will now fail with 
<code>InvalidAlgorithmError</code>.</li>
   <li><strong><code>PyJWKClient</code> now rejects non-HTTP(S) URIs at 
construction time.</strong> Tests or dev environments that fetched JWKS from 
<code>file://</code> URIs need to switch to a local HTTP server or load the 
JWKS by other means (e.g. construct <code>PyJWKSet.from_dict(...)</code> 
directly).</li>
   <li><strong><code>b64=false</code> tokens are now strictly RFC 7515 / 7797 
compliant.</strong> Tokens with a non-empty compact-form payload segment, or 
that omit <code>&quot;b64&quot;</code> from <code>crit</code>, will be 
rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips 
through PyJWT are unaffected.</li>
   <li><strong><code>enforce_minimum_key_length</code> set per-call now takes 
effect.</strong> Callers who passed 
<code>options={&quot;enforce_minimum_key_length&quot;: True}</code> to 
<code>jwt.decode()</code> previously got no enforcement; they will now get 
<code>InvalidKeyError</code> on undersized keys, as documented.</li>
   </ul>
   <p><strong>Full changelog:</strong> <a 
href="https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0";>https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0</a></p>
   <h2>2.12.1</h2>
   <h2>What's Changed</h2>
   <ul>
   <li>Add typing_extensions dependency for Python &lt; 3.11 by <a 
href="https://github.com/jpadilla";><code>@​jpadilla</code></a> in <a 
href="https://redirect.github.com/jpadilla/pyjwt/pull/1151";>jpadilla/pyjwt#1151</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst";>pyjwt's 
changelog</a>.</em></p>
   <blockquote>
   <h2><code>v2.15.0 
&lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;</code>__</h2>
   <p>Security</p>
   <pre><code>
   - Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
     instead of exposing a raw ``RecursionError``.
   <p>Added</p>
   <pre><code>
   - Support Python 3.15 by @kytta in 
`[#1202](https://github.com/jpadilla/pyjwt/issues/1202) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1202&amp;gt;`__
   
   Changed
   </code></pre>
   <ul>
   <li><code>JWKSetCache</code> now stores the parsed <code>PyJWKSet</code> 
rather than the raw JWKS
   payload, so a cache hit no longer re-parses every key. 
<code>JWKSetCache.put()</code>
   accepts either form and raises <code>PyJWKSetError</code> for anything else. 
As a
   result, <code>PyJWKClient.get_jwk_set()</code> returns the same 
<code>PyJWKSet</code> instance
   for as long as it stays cached, rather than a freshly built one per call in
   <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
   <li><code>PyJWKClient.fetch_data()</code> now raises
   <code>PyJWKClientError(&amp;quot;The JWKS endpoint did not return a JSON 
object&amp;quot;)</code> when
   the endpoint response is not a JSON object, instead of returning it for
   <code>get_jwk_set()</code> to reject. Callers reaching the JWKS through
   <code>get_jwk_set()</code> see the same error as before in
   <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
   </ul>
   <p>Fixed</p>
   <pre><code>
   - Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` 
instead
     of raising ``PyJWKClientError(&amp;quot;The JWKS endpoint did not return a 
JSON
     object&amp;quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the 
cached value,
     so callers pre-populating the cache to avoid a network round-trip could not
     read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) 
&amp;lt;https://github.com/jpadilla/pyjwt/issues/914&amp;gt;`__ and
     `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
   - ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
     ``fetch_data()`` override that filters or transforms the JWKS is no longer
     undone by the next cache hit in
     `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) 
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
   - Raise the documented ``PyJWTError`` subclass instead of leaking a
     ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
     non-numeric, non-string value such as a list, dict, or ``null``.
   - Reject OKP JWK private keys when their public ``x`` component does not
     match the private ``d`` component.
   - Treat malformed JWK Set members as unusable keys rather than letting
     ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is 
not
   &amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt; 
   &lt;/code&gt;&lt;/pre&gt;
   &lt;/blockquote&gt;
   &lt;p&gt;... (truncated)&lt;/p&gt;
   &lt;/details&gt;
   &lt;details&gt;
   &lt;summary&gt;Commits&lt;/summary&gt;
   
   &lt;ul&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a&gt;
 chore: prepare 2.15.0 release&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a&gt;
 fix: make recursive payload tests deterministic&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a&gt;
 fix: normalize recursive JWT payload errors&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a&gt;
 utils: mention bytes in force_bytes type error (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a&gt;
 docs/conf: drop duplicate 'and' from read() docstring (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a&gt;
 Add support for Python 3.15 (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a&gt;
 Catch http.client.HTTPException in PyJWKClient.fetch_data (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a&gt;
 fix: correct docstring typo in _validate_jti (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a&gt;
 docs: clarify JWK certificate member handling (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;&lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a&gt;
 [pre-commit.ci] pre-commit autoupdate (&lt;a 
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li&gt;
   &lt;li&gt;Additional commits viewable in &lt;a 
href=&quot;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.15.0&quot;&gt;compare
 view&lt;/a&gt;&lt;/li&gt;
   &lt;/ul&gt;
   &lt;/details&gt;
   
   &lt;br /&gt;</code></pre>
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.12.0&new-version=2.15.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/datafusion-sandbox/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to