Conversation
Bumps the pip group with 2 updates in the /issue_credential directory: [cryptography](https://github.com/pyca/cryptography) and [jwcrypto](https://github.com/latchset/jwcrypto). Bumps the pip group with 5 updates in the /oid4vc directory: | Package | From | To | | --- | --- | --- | | [jwcrypto](https://github.com/latchset/jwcrypto) | `1.5.6` | `1.5.7` | | [urllib3](https://github.com/urllib3/urllib3) | `2.5.0` | `2.6.3` | | [cbor2](https://github.com/agronholm/cbor2) | `5.7.0` | `5.9.0` | | [filelock](https://github.com/tox-dev/py-filelock) | `3.19.1` | `3.20.3` | | [ecdsa](https://github.com/tlsfuzzer/python-ecdsa) | `0.19.1` | `0.19.2` | Bumps the pip group with 3 updates in the /oid4vc/auth_server directory: [cryptography](https://github.com/pyca/cryptography), [orjson](https://github.com/ijl/orjson) and [authlib](https://github.com/authlib/authlib). Bumps the pip group with 1 update in the /oid4vc/integration directory: [black](https://github.com/psf/black). Bumps the pip group with 2 updates in the /present_proof directory: [cryptography](https://github.com/pyca/cryptography) and [jwcrypto](https://github.com/latchset/jwcrypto). Bumps the pip group with 2 updates in the /status_list directory: [cryptography](https://github.com/pyca/cryptography) and [jwcrypto](https://github.com/latchset/jwcrypto). Bumps the pip group with 1 update in the /status_list/integration directory: [black](https://github.com/psf/black). Updates `cryptography` from 46.0.6 to 46.0.7 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) Updates `jwcrypto` from 1.5.6 to 1.5.7 - [Release notes](https://github.com/latchset/jwcrypto/releases) - [Commits](latchset/jwcrypto@v1.5.6...v1.5.7) Updates `jwcrypto` from 1.5.6 to 1.5.7 - [Release notes](https://github.com/latchset/jwcrypto/releases) - [Commits](latchset/jwcrypto@v1.5.6...v1.5.7) Updates `urllib3` from 2.5.0 to 2.6.3 - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.5.0...2.6.3) Updates `cbor2` from 5.7.0 to 5.9.0 - [Release notes](https://github.com/agronholm/cbor2/releases) - [Commits](agronholm/cbor2@5.7.0...5.9.0) Updates `filelock` from 3.19.1 to 3.20.3 - [Release notes](https://github.com/tox-dev/py-filelock/releases) - [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst) - [Commits](tox-dev/filelock@3.19.1...3.20.3) Updates `ecdsa` from 0.19.1 to 0.19.2 - [Release notes](https://github.com/tlsfuzzer/python-ecdsa/releases) - [Changelog](https://github.com/tlsfuzzer/python-ecdsa/blob/master/NEWS) - [Commits](tlsfuzzer/python-ecdsa@python-ecdsa-0.19.1...python-ecdsa-0.19.2) Updates `cryptography` from 46.0.6 to 46.0.7 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) Updates `orjson` from 3.11.5 to 3.11.6 - [Release notes](https://github.com/ijl/orjson/releases) - [Changelog](https://github.com/ijl/orjson/blob/master/CHANGELOG.md) - [Commits](ijl/orjson@3.11.5...3.11.6) Updates `authlib` from 1.6.7 to 1.6.9 - [Release notes](https://github.com/authlib/authlib/releases) - [Commits](authlib/authlib@v1.6.7...v1.6.9) Updates `black` from 24.10.0 to 26.3.1 - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@24.10.0...26.3.1) Updates `cryptography` from 46.0.6 to 46.0.7 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) Updates `jwcrypto` from 1.5.6 to 1.5.7 - [Release notes](https://github.com/latchset/jwcrypto/releases) - [Commits](latchset/jwcrypto@v1.5.6...v1.5.7) Updates `cryptography` from 46.0.6 to 46.0.7 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) Updates `jwcrypto` from 1.5.6 to 1.5.7 - [Release notes](https://github.com/latchset/jwcrypto/releases) - [Commits](latchset/jwcrypto@v1.5.6...v1.5.7) Updates `black` from 24.10.0 to 26.3.1 - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@24.10.0...26.3.1) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect dependency-group: pip - dependency-name: jwcrypto dependency-version: 1.5.7 dependency-type: indirect dependency-group: pip - dependency-name: jwcrypto dependency-version: 1.5.7 dependency-type: indirect dependency-group: pip - dependency-name: urllib3 dependency-version: 2.6.3 dependency-type: indirect dependency-group: pip - dependency-name: cbor2 dependency-version: 5.9.0 dependency-type: direct:production dependency-group: pip - dependency-name: filelock dependency-version: 3.20.3 dependency-type: direct:production dependency-group: pip - dependency-name: ecdsa dependency-version: 0.19.2 dependency-type: indirect dependency-group: pip - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect dependency-group: pip - dependency-name: orjson dependency-version: 3.11.6 dependency-type: direct:production dependency-group: pip - dependency-name: authlib dependency-version: 1.6.9 dependency-type: direct:production dependency-group: pip - dependency-name: black dependency-version: 26.3.1 dependency-type: direct:development dependency-group: pip - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect dependency-group: pip - dependency-name: jwcrypto dependency-version: 1.5.7 dependency-type: indirect dependency-group: pip - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect dependency-group: pip - dependency-name: jwcrypto dependency-version: 1.5.7 dependency-type: indirect dependency-group: pip - dependency-name: black dependency-version: 26.3.1 dependency-type: direct:development dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
jamshale
approved these changes
Apr 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the pip group with 2 updates in the /issue_credential directory: cryptography and jwcrypto.
Bumps the pip group with 5 updates in the /oid4vc directory:
1.5.61.5.72.5.02.6.35.7.05.9.03.19.13.20.30.19.10.19.2Bumps the pip group with 3 updates in the /oid4vc/auth_server directory: cryptography, orjson and authlib.
Bumps the pip group with 1 update in the /oid4vc/integration directory: black.
Bumps the pip group with 2 updates in the /present_proof directory: cryptography and jwcrypto.
Bumps the pip group with 2 updates in the /status_list directory: cryptography and jwcrypto.
Bumps the pip group with 1 update in the /status_list/integration directory: black.
Updates
cryptographyfrom 46.0.6 to 46.0.7Changelog
Sourced from cryptography's changelog.
Commits
622d67246.0.7 release (#14602)Updates
jwcryptofrom 1.5.6 to 1.5.7Release notes
Sourced from jwcrypto's releases.
Commits
63a78e7Version 1.5.725db861Limit max plaintext size for JWE decompressiona0fa2eaMigrate to Hatch build backend and dynamic versioning Add pyproject.toml64f93ccAdd Ed25519 and Ed448 signature algorithmsf2921cdUpdate tox for CI tests625ac5dDocument JWA module and update theme9de81ecMake HMAC key length enforcement optional54550deEnforce minimum HMAC key size per RFC 7518255d5daSet default kid when importing keys from pyca.f105494Add support for 'scope' claim with multiple scopesUpdates
jwcryptofrom 1.5.6 to 1.5.7Release notes
Sourced from jwcrypto's releases.
Commits
63a78e7Version 1.5.725db861Limit max plaintext size for JWE decompressiona0fa2eaMigrate to Hatch build backend and dynamic versioning Add pyproject.toml64f93ccAdd Ed25519 and Ed448 signature algorithmsf2921cdUpdate tox for CI tests625ac5dDocument JWA module and update theme9de81ecMake HMAC key length enforcement optional54550deEnforce minimum HMAC key size per RFC 7518255d5daSet default kid when importing keys from pyca.f105494Add support for 'scope' claim with multiple scopesUpdates
urllib3from 2.5.0 to 2.6.3Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
0248277Release 2.6.38864ac4Merge commit from fork70cecb2Fix Scorecard issues related to vulnerable dev dependencies (#3755)41f249aMove "v2.0 Migration Guide" to the end of the table of contents (#3747)fd4dffdPatchVerifiedHTTPSConnectionfor Emscripten (#3752)13f0bfdHandle massive values in Retry-After when calculating time to sleep for (#3743)8c480bfBump actions/upload-artifact from 5.0.0 to 6.0.0 (#3748)4b40616Bump actions/cache from 4.3.0 to 5.0.1 (#3750)82b8479Bump actions/download-artifact from 6.0.0 to 7.0.0 (#3749)34284cbMention experimental features in the security policy (#3746)Updates
cbor2from 5.7.0 to 5.9.0Release notes
Sourced from cbor2's releases.
Commits
93c5988Bumped up the versiond903d62Updated the max_depth default value in the C function signature2b53b28Stack allocate small strings (#270)a7ac10dUpped the max_depth value to 40054c8ed5Fixed reference/memory leaks in decode_definite_long_string (#290)a8d92dc[pre-commit.ci] pre-commit autoupdate (#289)c91aa00[pre-commit.ci] pre-commit autoupdate (#288)53521e7Fixed ssize_t to Py_ssize_t94e0d21Added missing Python counterpart for max_depthbcb6ceaAdded the max_depth decoder parameterUpdates
filelockfrom 3.19.1 to 3.20.3Release notes
Sourced from filelock's releases.
Changelog
Sourced from filelock's changelog.
... (truncated)
Commits
41b42ddFix TOCTOU symlink vulnerability in SoftFileLock (#465)f2e7d40[pre-commit.ci] pre-commit autoupdate (#464)5088854Support Unix systems without O_NOFOLLOW (#463)377f622[pre-commit.ci] pre-commit autoupdate (#460)4724d7fFix TOCTOU symlink vulnerability in lock file creation (#461)cb69414Bump actions/upload-artifact from 5 to 6 (#459)0769294Bump actions/download-artifact from 6 to 7 (#458)414193a[pre-commit.ci] pre-commit autoupdate (#457)1456797[pre-commit.ci] pre-commit autoupdate (#456)8d6bf90Bump actions/checkout from 5 to 6 (#455)Updates
ecdsafrom 0.19.1 to 0.19.2Release notes
Sourced from ecdsa's releases.
Changelog
Sourced from ecdsa's changelog.
... (truncated)
Commits
bd66899Merge commit from fork9c046eetests: reject truncated DER lengthsacc40fdder: reject truncated lengths in octet/implicit/constructed55aca78Merge pull request #363 from gstarovo/ubuntu20-deprecationc4f0df1chore: change to ubuntu-22 since u-20 is deprecatedUpdates
cryptographyfrom 46.0.6 to 46.0.7Changelog
Sourced from cryptography's changelog.
Commits
622d67246.0.7 release (#14602)Updates
orjsonfrom 3.11.5 to 3.11.6Release notes
Sourced from orjson's releases.
Changelog
Sourced from orjson's changelog.
Commits
ec020243.11.6d581687build, clippy misc4105b29writer::num62bb185Fix sporadic crash on serializing object closed860078PyRef idiom refactors343ae2fDeserializer, Utf8Buffer7835f58PyBytesRef and other input refactor71e0516PyStrRef1096df4MSRV 1.89b718e75Drop support for python3.9Updates
authlibfrom 1.6.7 to 1.6.9Release notes
Sourced from authlib's releases.
Commits
9266eaachore: release 1.6.9b9bb2b2fix(oidc): fail close at validating c_hash and at_hash1b0a1d9fix(jose): generate random cek when cek length doesn't match5be3c51fix(jose): add ES256K into default jwt algorithms48b345ffix(jose): remove deprecated algorithm from default registrya5d4b2dfix(jose): do not use header's jwk automaticallya769f34chore: release 1.6.884f3fa2fix: add EdDSA to default jwt algorithmsUpdates
blackfrom 24.10.0 to 26.3.1Release notes
Sourced from black's releases.
... (truncated)
Changelog
Sourced from black's changelog.
... (truncated)
Commits
c6755bbPrepare release 26.3.1 (#5046)69973fdHarden blackd browser-facing request handling (#5039)4937fe6Fix some shenanigans with the cache file and IPython (#5038)2e641d1docs: remove outdated Black Playground references (#5044)c014b22Remove unused internal code (#5041)0dae20bAdd new changelog (#5036)c5c1cbdMinor release patches (#5035)7e5a828docs: clarify relationship between Black style and PEP 8 (#5025)69705dedocs: add clearer pyproject configuration guidance (#5026)35ea679Prepare release 26.3.0 (#5032)Updates
cryptographyfrom 46.0.6 to 46.0.7Changelog
Sourced from cryptography's changelog.
Commits
622d67246.0.7 release (#14602)Updates
jwcryptofrom 1.5.6 to 1.5.7Release notes
Sourced from jwcrypto's releases.
Commits
63a78e7Version 1.5.725db861Limit max plaintext size for JWE decompressiona0fa2eaMigrate to Hatch build backend and dynamic versioning Add pyproject.toml64f93ccAdd Ed25519 and Ed448 signature algorithmsf2921cdUpdate tox for CI tests625ac5dDocument JWA module and update theme9de81ecMake HMAC key length enforcement optional54550deEnforce minimum HMAC key size per RFC 7518255d5daSet default kid when importing keys from pyca.f105494Add support for 'scope' claim with multiple scopesUpdates
cryptographyfrom 46.0.6 to 46.0.7Changelog
Sourced from cryptography's changelog.
Commits
622d67246.0.7 release (#14602)Updates
jwcryptofrom 1.5.6 to 1.5.7Release notes
Sourced from jwcrypto's releases.