Skip to content

chore(deps): bump the python-dependencies group with 4 updates - #235

Merged
github-actions[bot] merged 2 commits into
masterfrom
dependabot/pip/master/python-dependencies-ca6250ebd2
Oct 1, 2026
Merged

github-actions[bot] merged 2 commits into
masterfrom
dependabot/pip/master/python-dependencies-ca6250ebd2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 4 updates: pyjwt, boto3, botocore and pylint.

Updates pyjwt from 2.14.0 to 2.15.0

Release notes

Sourced from pyjwt's releases.

2.15.0

See the 2.15.0 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>__

Security


- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
  instead of exposing a raw ``RecursionError``.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__
  • PyJWKClient.fetch_data() now raises PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;) when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON
  object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a> chore: prepare 2.15.0 release</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a> fix: make recursive payload tests deterministic</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a> fix: normalize recursive JWT payload errors</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

Updates boto3 from 1.43.97 to 1.43.102

Commits

Updates botocore from 1.43.97 to 1.43.102

Commits
  • 60d28e5 Merge branch 'release-1.43.102'
  • 06efcdb Bumping version to 1.43.102
  • d199c72 Update endpoints model
  • c98a4cd Update to latest models
  • 75ed8fe Merge customizations for CloudWatch
  • 93a35be Merge branch 'release-1.43.101'
  • d5ed435 Merge branch 'release-1.43.101' into develop
  • a9ac948 Bumping version to 1.43.101
  • 42ec6e0 Update endpoints model
  • a07e400 Update to latest models
  • Additional commits viewable in compare view

Updates pylint from 4.0.8 to 4.0.9

Release notes

Sourced from pylint's releases.

v4.0.9

What's new in Pylint 4.0.9?

Release date: 2026-09-23

Security Fixes

  • Someone without access to the configuration or linted code, but with access to the cache directory (predictable PYLINT_HOME on a multi-user host) can no longer write a crafted pickle that will runs arbitrary code when pylint access its stat cache. The result cache is now stored as JSON instead of pickle, preventing code-execution. The workaround is upgrading or not pointing PYLINT_HOME to an untrusted, shared, or group-writable directory. The default value, ~/.cache/pylint, is writable only by the user running pylint. (CVE with the same information pending)

False Positives Fixed

  • Fixed a false positive for no-self-use on a method that only uses self before a locally defined class (or other nested method), because the checker's could-be-a-function tracking state was not restored after visiting the nested method.

    Closes #3705

  • Fix a false positive for :ref:not-callable when calling functions constructed with types.FunctionType or types.LambdaType.

    Closes #7500

  • Fix a false positive for unnecessary-direct-lambda-call when a directly called lambda in a class body wraps a comprehension containing an assignment expression. PEP 572 makes that a SyntaxError without the lambda's scope, so following the message produced code that would not compile.

    Closes #9294

  • Fix a false positive for :ref:unnecessary-ellipsis when an ellipsis is the sole body statement of a method defined on a Protocol.

    Closes #9319

  • Fix a false positive for :ref:bad-exception-cause when the bases of the class being raised from cannot be inferred, such as an exception deriving from a C extension class. :ref:raising-non-exception and :ref:catching-non-exception already guard the same inherit_from_std_ex

... (truncated)

Commits
  • 303703f Bump pylint to 4.0.9, update changelog (#11448)
  • b342384 Fix block-scoped disable leaking into sibling elif/else blocks (#11429) (#11445)
  • 58c87cf Store the results cache as JSON instead of pickle
  • e3f4942 [Backport maintenance/4.0.x] Fix crash on failed attribute inference (#11443)
  • faf47f9 [Backport maintenance/4.0.x] Fix false positive no-self-use when a method con...
  • 20c7bb9 [Backport maintenance/4.0.x] Fix a crash in method-hidden for methods named a...
  • 47e6757 [Backport maintenance/4.0.x] Fix bad-exception-cause false positive when the ...
  • ae3ee53 [Backport maintenance/4.0.x] Fix not-callable false positive for types.Functi...
  • 3e444be [Backport maintenance/4.0.x] Fix a crash in unnecessary-default-type-args for...
  • 8f2dd4f [Backport maintenance/4.0.x] Fix declare-non-slot false positives for ClassVa...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated the versions of supporting packages used in development and application integrations.
    • These maintenance updates do not change the app’s user-facing features or behavior.

Bumps the python-dependencies group with 4 updates: [pyjwt](https://github.com/jpadilla/pyjwt), [boto3](https://github.com/boto/boto3), [botocore](https://github.com/boto/botocore) and [pylint](https://github.com/pylint-dev/pylint).


Updates `pyjwt` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.0)

Updates `boto3` from 1.43.97 to 1.43.102
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.97...1.43.102)

Updates `botocore` from 1.43.97 to 1.43.102
- [Commits](boto/botocore@1.43.97...1.43.102)

Updates `pylint` from 4.0.8 to 4.0.9
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v4.0.8...v4.0.9)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: boto3
  dependency-version: 1.43.102
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: botocore
  dependency-version: 1.43.102
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pylint
  dependency-version: 4.0.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added auto update Changes by automated library update tool infrastructure Project setup and deployment no RN No release notes required labels Sep 27, 2026
@dependabot dependabot Bot added infrastructure Project setup and deployment auto update Changes by automated library update tool no RN No release notes required labels Sep 27, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 27, 2026 23:53
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a6e4c097-9c2a-4137-a509-0401cd4635e2

📥 Commits

Reviewing files that changed from the base of the PR and between 6c4ab92 and 77bf10e.

📒 Files selected for processing (2)
  • requirements-dev.txt
  • requirements.txt

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


Walkthrough

The pull request updates the pinned versions of pylint, PyJWT, boto3, and botocore. The requests pin remains unchanged.

Changes

Dependency Pin Updates

Layer / File(s) Summary
Update dependency pins
requirements-dev.txt, requirements.txt
pylint changes from 4.0.8 to 4.0.9. PyJWT changes from 2.14.0 to 2.15.0. boto3 and botocore change from 1.43.97 to 1.43.102.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 77bf1

No regression is established in the supplied dependency updates or their described authentication path; no merge-blocking impact is identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 77bf1

The token-verification dependency is being updated, but the application retains its signature check and authorization gates. No new bypass was established. The exact behavior of the new library version has not been fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A change in token-verification outcomes could affect protected topic posts and, for newly accepted requests that pass subsequent controls, their configured writers. The available evidence does not establish a broader tenant or deployment-wide scope.

Trust Boundaries and Controls

  • observed — Request-supplied bearer tokens cross the identity boundary only after RS256 verification against loaded public keys. Verification errors produce a 401; the resulting subject is separately checked against topic access configuration and message permissions.

Hardening Proposals

  • proposed — Compare acceptance and rejection of valid, expired, malformed, and deeply nested tokens under both PyJWT pins to establish whether the dependency update changes the protected POST’s authentication outcomes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies a dependency maintenance change and accurately states that four Python dependencies are updated.
Description check ✅ Passed The description provides detailed, relevant information for all four dependency updates and includes release details. It does not use the template headings or provide a related issue, but the content …
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

A rabbit checks the pins in place
New versions hop into the list
The unchanged request stays as it was
A quiet patch, a tidy trace
Then off I go with carrots kissed

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot merged commit b191098 into master Oct 1, 2026
9 of 10 checks passed
auto-merge was automatically disabled October 1, 2026 09:41

Pull Request is not mergeable

@github-actions
github-actions Bot deleted the dependabot/pip/master/python-dependencies-ca6250ebd2 branch October 1, 2026 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto update Changes by automated library update tool infrastructure Project setup and deployment no RN No release notes required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant