Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing " could close its own member and add members the application never set.
For example, calling Set with the name x":0,"admin produced a signed
token containing "admin":true. Every name now yields exactly one member,
and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/lestrrat-go/jwx/v4](https://github.com/lestrrat-go/jwx) | `v4.4.0` → `v4.5.0` |  |  |
---
### Release Notes
<details>
<summary>lestrrat-go/jwx (github.com/lestrrat-go/jwx/v4)</summary>
### [`v4.5.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.5.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0)
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
`"` could close its own member and add members the application never set.
For example, calling `Set` with the name `x":0,"admin` produced a signed
token containing `"admin":true`. Every name now yields exactly one member,
and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.5.0/Changes).
#### What's Changed
- build(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2318](https://github.com/lestrrat-go/jwx/pull/2318)
- build(deps): bump github/codeql-action from 4.37.7 to 4.37.8 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2322](https://github.com/lestrrat-go/jwx/pull/2322)
- \[v4] deprecate AlgorithmsForKey, move to internal by [@​lestrrat](https://github.com/lestrrat) in [#​2325](https://github.com/lestrrat-go/jwx/pull/2325)
- \[v4] add jws.WithStrictECDSA sign option by [@​lestrrat](https://github.com/lestrrat) in [#​2327](https://github.com/lestrrat-go/jwx/pull/2327)
- \[v4] fix curve inference claim in docs by [@​lestrrat](https://github.com/lestrrat) in [#​2329](https://github.com/lestrrat-go/jwx/pull/2329)
- build(deps): bump github/codeql-action from 4.37.8 to 4.37.9 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2333](https://github.com/lestrrat-go/jwx/pull/2333)
- fix jwk.ParseKey generic guidance in guide skill by [@​lestrrat](https://github.com/lestrrat) in [#​2335](https://github.com/lestrrat-go/jwx/pull/2335)
- fix JWKS algorithm inference claim in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2336](https://github.com/lestrrat-go/jwx/pull/2336)
- document exact alg match rule in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2337](https://github.com/lestrrat-go/jwx/pull/2337)
- note RFC 9864 EdDSA deprecation in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2338](https://github.com/lestrrat-go/jwx/pull/2338)
- drop nonexistent v3 and v2 plugin pointers by [@​lestrrat](https://github.com/lestrrat) in [#​2339](https://github.com/lestrrat-go/jwx/pull/2339)
- correct ML-DSA import panic claim in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2340](https://github.com/lestrrat-go/jwx/pull/2340)
- add jwxfilter to guide companion table by [@​lestrrat](https://github.com/lestrrat) in [#​2341](https://github.com/lestrrat-go/jwx/pull/2341)
- build(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2347](https://github.com/lestrrat-go/jwx/pull/2347)
- \[v4] escape JSON object member names on output by [@​lestrrat](https://github.com/lestrrat) in [#​2348](https://github.com/lestrrat-go/jwx/pull/2348)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zOS4yIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):
1 additional dependency was updated
Details:
Package
Change
golang.org/x/crypto
v0.55.0 -> v0.56.0
### ℹ️ Artifact update notice
##### File name: go.mod
In order to perform the update(s) described in the table above, Renovate ran the `go get` command, which resulted in the following additional change(s):
- 1 additional dependency was updated
Details:
| **Package** | **Change** |
| :-------------------- | :--------------------- |
| `golang.org/x/crypto` | `v0.55.0` -> `v0.56.0` |
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v4.4.0→v4.5.0Release Notes
lestrrat-go/jwx (github.com/lestrrat-go/jwx/v4)
v4.5.0Compare Source
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
"could close its own member and add members the application never set.For example, calling
Setwith the namex":0,"adminproduced a signedtoken containing
"admin":true. Every name now yields exactly one member,and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
ℹ️ Artifact update notice
File name: go.mod
In order to perform the update(s) described in the table above, Renovate ran the
go getcommand, which resulted in the following additional change(s):Details:
golang.org/x/cryptov0.55.0->v0.56.067aac3b116to6917f33f836917f33f83to12509758951250975895toe8f5d41b59e8f5d41b59to2df9c5fce5View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.