Skip to content

chore(deps): bump jsonwebtoken from 9.3.1 to 10.3.0 in the cargo group across 1 directory - #1

Merged
vheins merged 7 commits into
masterfrom
dependabot/cargo/cargo-faef625f8c
Sep 11, 2026
Merged

vheins merged 7 commits into
masterfrom
dependabot/cargo/cargo-faef625f8c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update in the / directory: jsonwebtoken.

Updates jsonwebtoken from 9.3.1 to 10.3.0

Changelog

Sourced from jsonwebtoken's changelog.

10.3.0 (2026-01-27)

  • Export everything needed to define your own CryptoProvider
  • Fix type confusion with exp/nbf when not required

10.2.0 (2025-11-06)

  • Remove Clone bound from decode functions

10.1.0 (2025-10-18)

  • add dangerous::insecure_decode
  • Implement TryFrom &Jwk for DecodingKey

10.0.0 (2025-09-29)

  • BREAKING: now using traits for crypto backends, you have to choose between aws_lc_rs and rust_crypto
  • Add Clone bound to decode
  • Support decoding byte slices
  • Support JWS
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 9, 2026
Bumps the cargo group with 1 update in the / directory: [jsonwebtoken](https://github.com/Keats/jsonwebtoken).


Updates `jsonwebtoken` from 9.3.1 to 10.3.0
- [Changelog](https://github.com/Keats/jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](Keats/jsonwebtoken@v9.3.1...v10.3.0)

---
updated-dependencies:
- dependency-name: jsonwebtoken
  dependency-version: 10.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/cargo-faef625f8c branch from 696c9b9 to 09a6276 Compare September 9, 2026 10:15
@vheins
vheins self-requested a review September 10, 2026 12:35
- Domain: dependency bump jsonwebtoken 9.3.1 -> 10.4.0 (rustasea-auth JWT guard)
- Findings: 1 CRITICAL, 0 HIGH, 1 MEDIUM, 0 LOW
- Blocker: jsonwebtoken 10 requires an explicit crypto backend; no rust_crypto/aws_lc_rs feature -> JWT encode/decode panic at runtime

@vheins vheins left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot[bot] 1 blocker + 1 compatibility violation, details in the inline comments.

  1. CRITICAL — jsonwebtoken 10 needs an explicit crypto backend; without rust_crypto/aws_lc_rs every JWT sign/verify panics at runtime. Fix: add features = ["rust_crypto"] on Cargo.toml:25.
  2. MEDIUM — jsonwebtoken 10.x is edition 2024 (MSRV 1.85; 10.4.0 requires 1.88), violating documented constraint C-01 (Rust 1.80+, edition 2021). Fix: raise MSRV in [workspace.package], update C-01/architecture docs, add ADR.

Comment thread Cargo.toml Outdated
Comment thread Cargo.toml Outdated
- Add sqlx 0.8 (postgres/mysql/sqlite) + config 0.14 workspace deps
- Introduce DbPool/DbRow/Database facade, DatabaseConfig/PoolConfig
- Bind pool into foundation container (DATABASE_BINDING); load config/database.toml
- Typed OrmError mapping incl. Connection (Io/Tls) and Value::Unsupported for non-null unmapped cells
- compile_error! guard when no driver feature enabled
- Tests: sqlite round-trip, typed DSN errors, container binding
- Replace stub_handler wiring with Handler/ActionFactory/BoundAction dispatch
- into_axum_router resolves explicit action -> controller registry -> stub
- Consume #[route] metadata at registration (macros: const -> pub const)
- Normalize HTTP methods; domain-aware resolution; Laravel {param} -> :param at axum boundary
- Tests: path/query/json extraction, 404/405, domain precedence, resource actions
…parity map

- Add docs/milestones.md: evidence-backed done/partial/missing per M0–M6 + P0 progress (GAP-001/002 done, GAP-003 backlog)
- Add docs/laravel-parity.md: Laravel 13.x namespace + interface/trait adoption mapping (5 api.laravel.com sources)
- README: link both docs; correct stale status (object_store wired, HttpClient::throw implemented, M4 driver state)
…rgo-faef625f8c

# Conflicts:
#	Cargo.lock
#	crates/rustasea-orm/Cargo.toml
#	crates/rustasea-orm/src/builder/ext.rs
#	crates/rustasea-orm/src/error.rs
#	crates/rustasea-orm/src/lib.rs
@github-actions
github-actions Bot requested a review from vheins September 11, 2026 13:16
@vheins
vheins merged commit aba8a5a into master Sep 11, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-faef625f8c branch September 11, 2026 13:17
@vheins

vheins commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

Resolved both review findings and merged.

Fix applied (f125709, merged as aba8a5a):

  • [CRITICAL] Cargo.toml → jsonwebtoken = { version = "10", default-features = false, features = ["rust_crypto"] }. Pure-Rust backend (no C toolchain / aws_lc_rs), sufficient for the HS256 usage in rustasea-auth/src/jwt.rs. JWT sign/verify tests now pass without panicking.
  • [MEDIUM] Workspace rust-version = "1.88"; C-01 / NFR-Com-01 updated in prd.md + architecture.md; decision recorded in docs/adr/ADR-0001-jsonwebtoken-10-msrv-bump.md.

Also in this branch: origin/master merged in (sqlx ORM backend, transactions, migrations, queue drivers) and the router controller-dispatch rewrite (GAP-002) kept.

Verification: cargo check --workspace --all-targets clean; scoped tests rustasea-auth + rustasea-router + rustasea-orm = 158 passed, 0 failed, 3 ignored.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant