Ensures that after successful JWS signature verification, an application-configured Base64Url Decoder output is
used to construct a Jws instance (instead of JJWT's default decoder). See jwtk/jjwt#947.
Fixes a decompression memory leak in concurrent/multi-threaded environments introduced in 0.12.0 when decompressing JWTs with a zip header of GZIP. See jwtk/jjwt#949.
Ensures that after successful JWS signature verification, an application-configured Base64Url Decoder output is
used to construct a Jws instance (instead of JJWT's default decoder). See
Issue 947.
Fixes a decompression memory leak in concurrent/multi-threaded environments introduced in 0.12.0 when decompressing JWTs with a zip header of GZIP. See Issue 949.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the dependencies group with 3 updates in the / directory: io.jsonwebtoken:jjwt, org.apache.maven.plugins:maven-release-plugin and org.owasp:dependency-check-maven.
Updates
io.jsonwebtoken:jjwt
from 0.12.5 to 0.12.6Release notes
Sourced from io.jsonwebtoken:jjwt's releases.
Changelog
Sourced from io.jsonwebtoken:jjwt's changelog.
Commits
0df9756
[maven-release-plugin] prepare release 0.12.6aacdfdc
- Updated README.adoc:project-version:
to be0.12.6
.d14f27b
Bump org.bouncycastle:bcprov-jdk18on from 1.76 to 1.78 (#941)0c2d96c
Fixes #949 (#950)a7de554
Fixes #947 (#948)7543248
Bump org.bouncycastle:bcpkix-jdk18on from 1.76 to 1.78 (#943)3489fdb
JWE arbitrary content compression (#937)23d9a33
Allow using GenericSecret for HmacSHA* (#935)c673b76
Update SECURITY.md2694861
Use Acsiidoc as README format (#777)Updates
org.apache.maven.plugins:maven-release-plugin
from 3.0.1 to 3.1.0Release notes
Sourced from org.apache.maven.plugins:maven-release-plugin's releases.
Commits
f2f9f4e
[maven-release-plugin] prepare release maven-release-3.1.0e109d3b
Bump scmVersion from 2.0.1 to 2.1.05f794a1
Bump org.apache.maven.shared:maven-invoker from 3.2.0 to 3.3.028201bb
Bump org.codehaus.plexus:plexus-interactivity-api from 1.2 to 1.38547606
Bump org.codehaus.plexus:plexus-interpolation from 1.26 to 1.27adf6aaf
Bump org.xmlunit:xmlunit-core from 2.9.1 to 2.10.0f3bbb77
[MRELEASE-1064] [REGRESSION] release:branch uses@releaseLabel
instead of@br
...fa6c3db
[MRELEASE-1145] Upgrade to Maven 3.6.3167db81
[MRELEASE-1147]@junitVersion
@ never replaced in UTs (make explicit)7249d1f
[MRELEASE-1148] Release Manager pulls in transitive dependenciesUpdates
org.owasp:dependency-check-maven
from 9.2.0 to 10.0.1Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
Commits
4d47fb9
build: prepare release v10.0.1934a307
docs: release 10.0.1763fe31
fix: postgresql error (#6773)cab586e
build(deps): bump open-vulnerability-client (#6772)a8128a4
docs: update supported versions (#6771)8c731cd
fix: remove debug logging (#6770)214bdd9
fix: Fix column name and version (#6761)c0da58e
Update initialize_mssql.sql1d6bd7a
build: Release 10.0.0 (#6759)e31d456
Update CHANGELOG.mdDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show