Skip to content

deps: bridge lock pins PyJWT 2.15.1 - #299

Merged
virtualsteve-exa merged 1 commit into
devfrom
deps/pyjwt-2.15
Sep 30, 2026
Merged

virtualsteve-exa merged 1 commit into
devfrom
deps/pyjwt-2.15

Conversation

@virtualsteve-exa

Copy link
Copy Markdown
Collaborator

Updates the one package in the bridge's lock: PyJWT 2.13.0 → 2.15.1. This clears the required dependency audit, which has failed on every PR since eleven PyJWT advisories were published on 2026-09-28 (fixed in 2.14.0).

  • PyJWT comes in through mcp. The bridge imports only the MCP client and the stdio server and never decodes or verifies a token, so the advisories, all about token verification and key-set fetching, don't reach a code path it uses.
  • SBOM and AI BOM regenerated. pip-audit --strict on the exported lock: no known vulnerabilities.
  • The bridge boot-check against staging passes: OK — connected … 27 Exabeam tools available.
  • The full suite passes (1035), and the identity, docs and BOM checks pass.
  • No version bump: the plugin's behavior doesn't change. There's a CHANGELOG line under 1.0.0.

This unblocks #298.

🤖 Generated with Claude Code

https://claude.ai/code/session_016Q9UohWfy2scPhr4pavhqd

Clears the dependency audit on the eleven PyJWT advisories published 2026-09-28 (fixed in 2.14.0).
PyJWT is a transitive dependency of mcp; the bridge never decodes or verifies a token. The SBOM and
AI BOM are regenerated. No version bump: nothing about the plugin's behavior changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016Q9UohWfy2scPhr4pavhqd
Signed-off-by: Steve Wilson <steve.wilson@exabeam.com>
@virtualsteve-exa
virtualsteve-exa merged commit 41a017e into dev Sep 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant