Skip to content

Add PyJWT detached JWS fix references#8230

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8230from
cookesan:pyjwt-w7vc-fix-references
Open

Add PyJWT detached JWS fix references#8230
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8230from
cookesan:pyjwt-w7vc-fix-references

Conversation

@cookesan

Copy link
Copy Markdown

Adds source-backed fix references for GHSA-w7vc-732c-9m39:

Audit:

  • PyPI version 2.13.0 is published for PyJWT
  • The 2.12.1...2.13.0 compare contains bundled fix commit 95791b17
  • The fix rejects non-empty compact payload segments when b64=false is used with detached JWS

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8230 June 29, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant