Skip to content

Add PyJWT HMAC fix references#8229

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8229from
cookesan:pyjwt-xgmm-fix-references
Open

Add PyJWT HMAC fix references#8229
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8229from
cookesan:pyjwt-xgmm-fix-references

Conversation

@cookesan

Copy link
Copy Markdown

Adds source-backed fix references for GHSA-xgmm-8j9v-c9wx:

Audit:

  • PyPI version 2.13.0 is published for PyJWT
  • The 2.12.1...2.13.0 compare contains bundled fix commit 95791b17
  • The fix rejects JWK JSON documents passed as raw HMAC secrets

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8229 June 29, 2026 04:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant