Ensures that after successful JWS signature verification, an application-configured Base64Url Decoder output is
used to construct a Jws instance (instead of JJWT's default decoder). See jwtk/jjwt#947.
Fixes a decompression memory leak in concurrent/multi-threaded environments introduced in 0.12.0 when decompressing JWTs with a zip header of GZIP. See jwtk/jjwt#949.
Ensures that after successful JWS signature verification, an application-configured Base64Url Decoder output is
used to construct a Jws instance (instead of JJWT's default decoder). See
Issue 947.
Fixes a decompression memory leak in concurrent/multi-threaded environments introduced in 0.12.0 when decompressing JWTs with a zip header of GZIP. See Issue 949.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps io.jsonwebtoken:jjwt-impl from 0.12.5 to 0.12.6.
Release notes
Sourced from io.jsonwebtoken:jjwt-impl's releases.
Changelog
Sourced from io.jsonwebtoken:jjwt-impl's changelog.
Commits
0df9756
[maven-release-plugin] prepare release 0.12.6aacdfdc
- Updated README.adoc:project-version:
to be0.12.6
.d14f27b
Bump org.bouncycastle:bcprov-jdk18on from 1.76 to 1.78 (#941)0c2d96c
Fixes #949 (#950)a7de554
Fixes #947 (#948)7543248
Bump org.bouncycastle:bcpkix-jdk18on from 1.76 to 1.78 (#943)3489fdb
JWE arbitrary content compression (#937)23d9a33
Allow using GenericSecret for HmacSHA* (#935)c673b76
Update SECURITY.md2694861
Use Acsiidoc as README format (#777)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show