Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-PyJWT for openSUSE:Factory 
checked in at 2026-10-03 20:12:27
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-PyJWT (Old)
 and      /work/SRC/openSUSE:Factory/.python-PyJWT.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-PyJWT"

Sat Oct  3 20:12:27 2026 rev:40 rq:1382058 version:2.15.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-PyJWT/python-PyJWT.changes        
2026-06-13 18:46:37.891669707 +0200
+++ /work/SRC/openSUSE:Factory/.python-PyJWT.new.1631729/python-PyJWT.changes   
2026-10-03 20:12:30.056009004 +0200
@@ -1,0 +2,77 @@
+Thu Oct  1 14:34:42 UTC 2026 - Nico Krapp <[email protected]>
+
+- Update to 2.15.1
+  * Accept trailing Base64URL = padding when decoding JWS segments,
+    so tokens issued by AWS ALB and similar systems verify instead
+    of raising DecodeError: Invalid crypto padding. Non-alphabet
+    junk such as !!!! remains rejected (#1209).
+- Update to 2.15.0 (fixes CVE-2026-101918 (bsc#1283061),
+  CVE-2026-102275 (bsc#1283072))
+  * Wrap recursion errors from deeply nested JWT payloads in
+    DecodeError instead of exposing a raw RecursionError.
+  * Support Python 3.15 by @kytta in #1202
+  * JWKSetCache now stores the parsed PyJWKSet rather than the raw
+    JWKS payload, so a cache hit no longer re-parses every key.
+    JWKSetCache.put() accepts either form and raises PyJWKSetError
+    for anything else. As a result, PyJWKClient.get_jwk_set()
+    returns the same PyJWKSet instance for as long as it stays
+    cached, rather than a freshly built one per call in #1208
+  * PyJWKClient.fetch_data() now raises PyJWKClientError("The JWKS
+    endpoint did not return a JSON object") when the endpoint
+    response is not a JSON object, instead of returning it for
+    get_jwk_set() to reject. Callers reaching the JWKS through
+    get_jwk_set() see the same error as before in #1208
+  * Return cached PyJWKSet values from PyJWKClient.get_jwk_set()
+    instead of raising PyJWKClientError("The JWKS endpoint did not
+    return a JSON object"). JWKSetCache.put() documents PyJWKSet
+    as the cached value, so callers pre-populating the cache to
+    avoid a network round-trip could not read it back in #914 and
+    #1208
+  * PyJWKClient.get_jwk_set() now caches the key set it returns,
+    so a fetch_data() override that filters or transforms the JWKS
+    is no longer undone by the next cache hit in #1208
+  * Raise the documented PyJWTError subclass instead of leaking a
+    TypeError when the exp, nbf, or iat claim decodes to a
+    non-numeric, non-string value such as a list, dict, or null.
+  * Reject OKP JWK private keys when their public x component does
+    not match the private d component.
+  * Treat malformed JWK Set members as unusable keys rather than
+    letting AttributeError or TypeError escape PyJWKSet. A member
+    that is not a JSON object is skipped, a key whose components
+    have the wrong type raises InvalidKeyError and is skipped, and
+    a set left with no usable keys raises PyJWKSetError. A single
+    bad entry no longer fails an otherwise usable JWK Set in #1208
+  * Wrap http.client.HTTPException (e.g. IncompleteRead from a
+    truncated response) in PyJWKClient.fetch_data as
+    PyJWKClientConnectionError, matching the other network failure
+    modes the method already documents.
+- Update to 2.14.0 (fixes CVE-2026-102270 (bsc#1283067),
+  CVE-2026-101917 (bsc#1283060), CVE-2026-102273 (bsc#1283070),
+  CVE-2026-102272 (bsc#1283069), CVE-2026-102271 (bsc#1283068),
+  CVE-2026-103001 (bsc#1283829), CVE-2026-102274 (bsc#1283071),
+  CVE-2026-102269 (bsc#1283066), CVE-2026-102265 (bsc#1283062),
+  CVE-2026-102268 (bsc#1283065), CVE-2026-102267 (bsc#1283064),
+  CVE-2026-102266 (bsc#1283063))
+  * Harden HMAC key validation against public-key material supplied
+    as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input.
+    See GHSA-r6x4-923q-g947, GHSA-ffc3-869f-jxw9,
+    GHSA-p4g4-x82p-q773, and GHSA-w2cx-738m-mc7w.
+  * Reject automatic redirects when PyJWKClient fetches a JWKS,
+    preventing redirected destinations from being treated as
+    trusted key sources. See GHSA-9v7f-9g4p-ffgj.
+  * Limit repeated JWKS refreshes caused by unknown key IDs while
+    preserving normal key-rotation behavior. See GHSA-2gx3-rcp4-g85q.
+  * Handle deeply nested and malformed JWS/JWK input without
+    uncaught recursion errors or whole-set parsing failures. See
+    GHSA-8wjv-2p76-3863 and GHSA-w6j9-cwv2-h6wq.
+  * Enforce compact JWS encoding rules during decoding. See
+    GHSA-hxm8-2xgr-2p9m.
+  * Reject detached-payload arguments for attached JWS inputs.
+    Thanks to @xclow3n for reporting this behavior; fixed in commit
+    37b54877.
+  * Apply HMAC key validation consistently when keys are loaded
+    through PyJWK and PyJWKClient. See GHSA-pxh4-856f-4h89.
+  * Reject empty HMAC keys when represented as JWKs. See
+    GHSA-pxh4-856f-4h89.
+
+-------------------------------------------------------------------

Old:
----
  pyjwt-2.13.0.tar.gz

New:
----
  pyjwt-2.15.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-PyJWT.spec ++++++
--- /var/tmp/diff_new_pack.kNqfB6/_old  2026-10-03 20:12:30.784039458 +0200
+++ /var/tmp/diff_new_pack.kNqfB6/_new  2026-10-03 20:12:30.795039918 +0200
@@ -18,7 +18,7 @@
 
 %{?sle15_python_module_pythons}
 Name:           python-PyJWT
-Version:        2.13.0
+Version:        2.15.1
 Release:        0
 Summary:        JSON Web Token implementation in Python
 License:        MIT

++++++ pyjwt-2.13.0.tar.gz -> pyjwt-2.15.1.tar.gz ++++++
++++ 2415 lines of diff (skipped)

Reply via email to