chore(deps): update module github.com/lestrrat-go/jwx/v2 to v4 #10
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/github.com-lestrrat-go-jwx-v2-4.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v2.1.7→v4.5.0Release Notes
lestrrat-go/jwx (github.com/lestrrat-go/jwx/v2)
v4.5.0Compare Source
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
"could close its own member and add members the application never set.For example, calling
Setwith the namex":0,"adminproduced a signedtoken containing
"admin":true. Every name now yields exactly one member,and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0
v4.4.0Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.3.0...v4.4.0
v4.3.0Compare Source
For more detailed release notes, see Changes.
What's Changed
New Contributors
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.2.0...v4.3.0
v4.2.0Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.1.0...v4.2.0
v4.1.0Compare Source
For more detailed release notes, see Changes.
What's Changed
ed25519key by @lestrrat in #2201Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.0.2...v4.1.0
v4.0.2Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.0.1...v4.0.2
v4.0.1Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.0.0...v4.0.1
v4.0.0Compare Source
Changes
v4 has many incompatibilities with v3. To see the full list of differences between
v3 and v4, please read the Changes-v4.md file. Coding Agents should read MIGRATION.md
v4.0.0 - 19 Apr 2026
v3.3.0Compare Source
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
"could close its own member and add members the application never set.For example, calling
Setwith the namex":0,"adminproduced a signedtoken containing
"admin":true. Every name now yields exactly one member,and names that need no escaping serialize exactly as before.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.2.0...v3.3.0
v3.2.0Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.1.1...v3.2.0
v3.1.1Compare Source
For more detailed release notes, see Changes.
What's Changed
f245a91to7bf9d82by @dependabot[bot] in #2065Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.1.0...v3.1.1
v3.1.0Compare Source
See Changes file for curated list of changes
What's Changed
ce28e4bin examples by @lestrrat in #1621Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.13...v3.1.0
v3.0.13Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.12...v3.0.13
v3.0.12Compare Source
What's Changed
godoclintissues by @babakks in #1469"header") for flattened JSON serialization by @lestrrat in #1477New Contributors
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.11...v3.0.12
v3.0.11Compare Source
What's Changed
New Contributors
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.10...v3.0.11
v3.0.10Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.9...v3.0.10
v3.0.9Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.8...v3.0.9
v3.0.8Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.7...v3.0.8
v3.0.7Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.6...v3.0.7
v3.0.6Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.5...v3.0.6
v3.0.5Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.4...v3.0.5
v3.0.4Compare Source
v3.0.3Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.2...v3.0.3
v3.0.2Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.1...v3.0.2
v3.0.1Compare Source
What's Changed
Please read the Changes file and upgrade accordingly, especially if you are using the following combinations for JWE:
New Contributors
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.0.0...v3.0.1
v3.0.0Compare Source
What's Changed
New Contributors
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v2.1.0...v3.0.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.