Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing " could close its own member and add members the application never set.
For example, calling Set with the name x":0,"admin produced a signed
token containing "admin":true. Every name now yields exactly one member,
and names that need no escaping serialize exactly as before.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx) | `v3.2.0` → `v3.3.0` |  |  |
---
### Release Notes
<details>
<summary>lestrrat-go/jwx (github.com/lestrrat-go/jwx/v3)</summary>
### [`v3.3.0`](https://github.com/lestrrat-go/jwx/releases/tag/v3.3.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v3.2.0...v3.3.0)
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
`"` could close its own member and add members the application never set.
For example, calling `Set` with the name `x":0,"admin` produced a signed
token containing `"admin":true`. Every name now yields exactly one member,
and names that need no escaping serialize exactly as before.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v3.3.0/Changes).
#### What's Changed
- build(deps): bump actions/stale from 10.4.0 to 11.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2280](https://github.com/lestrrat-go/jwx/pull/2280)
- build(deps): bump github/codeql-action from 4 to 4.37.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2283](https://github.com/lestrrat-go/jwx/pull/2283)
- build(deps): bump github/codeql-action from 4.37.3 to 4.37.4 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2287](https://github.com/lestrrat-go/jwx/pull/2287)
- build(deps): bump github/codeql-action from 4.37.4 to 4.37.5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2290](https://github.com/lestrrat-go/jwx/pull/2290)
- build(deps): bump github/codeql-action from 4.37.5 to 4.37.6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2293](https://github.com/lestrrat-go/jwx/pull/2293)
- build(deps): bump github/codeql-action from 4.37.6 to 4.37.7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2301](https://github.com/lestrrat-go/jwx/pull/2301)
- build(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2299](https://github.com/lestrrat-go/jwx/pull/2299)
- build(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2306](https://github.com/lestrrat-go/jwx/pull/2306)
- build(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2316](https://github.com/lestrrat-go/jwx/pull/2316)
- build(deps): bump github.com/lestrrat-go/dsig from 1.3.0 to 1.4.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2319](https://github.com/lestrrat-go/jwx/pull/2319)
- build(deps): bump github/codeql-action from 4.37.7 to 4.37.8 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2321](https://github.com/lestrrat-go/jwx/pull/2321)
- \[v3] deprecate AlgorithmsForKey, move to internal by [@​lestrrat](https://github.com/lestrrat) in [#​2326](https://github.com/lestrrat-go/jwx/pull/2326)
- \[v3] add jws.WithStrictECDSA sign option by [@​lestrrat](https://github.com/lestrrat) in [#​2328](https://github.com/lestrrat-go/jwx/pull/2328)
- \[v3] fix curve inference claim in docs by [@​lestrrat](https://github.com/lestrrat) in [#​2330](https://github.com/lestrrat-go/jwx/pull/2330)
- build(deps): bump github/codeql-action from 4.37.8 to 4.37.9 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2332](https://github.com/lestrrat-go/jwx/pull/2332)
- add example for bounded WithWaitReady wait by [@​lestrrat](https://github.com/lestrrat) in [#​2343](https://github.com/lestrrat-go/jwx/pull/2343)
- show fetch failure cause via error sink by [@​lestrrat](https://github.com/lestrrat) in [#​2344](https://github.com/lestrrat-go/jwx/pull/2344)
- \[v3] escape JSON object member names on output by [@​lestrrat](https://github.com/lestrrat) in [#​2349](https://github.com/lestrrat-go/jwx/pull/2349)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v3.2.0...v3.3.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4yIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v3.2.0→v3.3.0Release Notes
lestrrat-go/jwx (github.com/lestrrat-go/jwx/v3)
v3.3.0Compare Source
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
"could close its own member and add members the application never set.For example, calling
Setwith the namex":0,"adminproduced a signedtoken containing
"admin":true. Every name now yields exactly one member,and names that need no escaping serialize exactly as before.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v3.2.0...v3.3.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.