Skip to content

build(deps): bump web-token/jwt-library from 4.1.7 to 4.2.1 - #593

Open
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/composer/development/web-token/jwt-library-4.2.1
Open

build(deps): bump web-token/jwt-library from 4.1.7 to 4.2.1#593
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/composer/development/web-token/jwt-library-4.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps web-token/jwt-library from 4.1.7 to 4.2.1.

Commits
  • 43f7c7d Merge pull request #698 from web-token/fix/jwe-builder-shared-header-after-re...
  • 834bf3c fix(core): keep the cause of a load or verification failure
  • 443f6e7 fix(encryption): read the recipient header from the builder state
  • 0e0c0f4 Merge pull request #697 from web-token/fix/jwkset-duplicate-kid
  • 927c26c Merge pull request #696 from web-token/fix/jwe-builder-sender-key
  • b2af3ab fix(core): keep every key of a set sharing the same "kid"
  • d937168 fix(encryption): allow a sender key with a static key agreement
  • b241e68 fix(signature): apply the payload encoding to the clone, not the receiver
  • 5db62ca feat(signature): accept an already Base64Url encoded payload
  • 0dd57a7 feat(console): add a command to convert a key into PKCS#8
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [web-token/jwt-library](https://github.com/web-token/jwt-library) from 4.1.7 to 4.2.1.
- [Commits](web-token/jwt-library@4.1.7...4.2.1)

---
updated-dependencies:
- dependency-name: web-token/jwt-library
  dependency-version: 4.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/keepiq @ 7bf55da

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
format
check-l10n-js
check-schema-l10n
composer ✅ 111/111
npm ✅ 536/536
app:check-code ⏭️
info.xml
REUSE
PHPUnit
Newman
Playwright ⏭️ deferred — runs on the promotion into beta/main, not on a pull request into development
Hydra gates

Quality workflow — 2026-09-01 13:32 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants