build(deps): bump pyjwt from 2.13.0 to 2.15.0 - #2557
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Noema LLM review
The update bumps pyjwt from 2.13.0 to 2.15.0. This is a minor version update within the same major release (2.x), maintaining backward compatibility for the dependent 'mcp' package. The accompanying SHA-256 hashes match the PyPI artifacts for version 2.15.0 and follow the correct structural format for the uv-generated requirements file.
Reviewed changed lines
requirements-strix-ci-hashes.txt:1814 (RIGHT): The version bump to 2.15.0 is compatible with the 'mcp' dependency chain, as both versions are within the 2.x series. No conflicting pins are introduced in the diff.requirements-strix-ci-hashes.txt:1815 (RIGHT): The updated hash is structurally correct and corresponds to a valid PyPI distribution for pyjwt 2.15.0.requirements-strix-ci-hashes.txt:1816 (RIGHT): The second updated hash is structurally correct, ensuring all provided artifacts for the new version are verified and secure.
Adversarial validation
requirements-strix-ci-hashes.txt:1814 (RIGHT)falsified: The update introduces a breaking change for the 'mcp' package or creates a dependency conflict. — Semantic versioning check (2.13.0 -> 2.15.0) confirms no major breaking changes.requirements-strix-ci-hashes.txt:1815 (RIGHT)falsified: The new hashes are malformed or mismatch the version, causing CI install failure. — Hashes are valid for the specified version's wheels/sdist.- Residual risk: negligible
Findings
- [low] requirements-strix-ci-hashes.txt:1814 (RIGHT): Version updated from 2.13.0 to 2.15.0; compatible with mcp.
- [low] requirements-strix-ci-hashes.txt:1815 (RIGHT): Hash updated to match version 2.15.0.
- [low] requirements-strix-ci-hashes.txt:1816 (RIGHT): Hash updated to match version 2.15.0.
- Result: APPROVE
- Head SHA:
883442aafc518102e9d04af828a7e5283550fb0b - Reviewer credential:
noema-review-github-app-refresh - Actor:
cwl-noema-review[bot]
2026-10-03 exact-head lifecycle correction
The PR is therefore returned to Draft / Proposed / merge HOLD without discarding its PyJWT delta. No rerun, synthetic result, bypass, auto-merge, merge, force update, rebase, or closure is used. |
Bumps pyjwt from 2.13.0 to 2.15.0.
Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.