Skip to content

Bump pyjwt to 2.14.0 in the hermes lockfile - #253

Merged
GraemeF merged 1 commit into
mainfrom
worktree-pyjwt-bump-comms-74ke
Sep 30, 2026
Merged

GraemeF merged 1 commit into
mainfrom
worktree-pyjwt-bump-comms-74ke

Conversation

@GraemeF

@GraemeF GraemeF commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

The hermes lockfile resolved pyjwt 2.13.0, which carries GHSA-ffc3-869f-jxw9 (critical) and five high advisories. 2.14.0 fixes them. Only clients/hermes/uv.lock changes.

Clears GHSA-ffc3-869f-jxw9 (critical) and five high advisories in 2.13.0.
@GraemeF
GraemeF marked this pull request as ready for review September 30, 2026 07:56
@GraemeF
GraemeF merged commit cd39671 into main Sep 30, 2026
2 checks passed
@GraemeF
GraemeF deleted the worktree-pyjwt-bump-comms-74ke branch September 30, 2026 07:56
GraemeF added a commit that referenced this pull request Oct 2, 2026
Patch release, 0.24.2 → 0.24.3. It ships the fix that finds a newly
created user Zulip's cached user list has missed (#256), the fix that
stops an unsubscribe from one topic dropping the seat's other topics in
that channel (#257), and the PyJWT security bump in the Hermes lockfile
(#253).

Merge #256 first. The notes in `RELEASE-NOTES/0.24.3.md` become the
GitHub Release body. Merging fires the tag and npm publish.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant