security: upgrade python-jose 3.3.0 → 3.4.0 (algorithm confusion CVE)

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
Agent-Logs-Url: https://github.com/christianlouis/pop_puller_to_gmail/sessions/c609ede7-b9d7-4ab1-acdb-8d29164066cc
This commit is contained in:
copilot-swe-agent[bot]
2026-03-25 23:04:22 +00:00
parent 5c40415590
commit dda768ff73
2 changed files with 4 additions and 1 deletions
+1 -1
View File
@@ -11,7 +11,7 @@ psycopg2-binary==2.9.11
asyncpg==0.31.0
# Authentication
python-jose[cryptography]==3.3.0
python-jose[cryptography]==3.4.0
bcrypt==4.3.0
python-multipart==0.0.22 # Updated: Fixed multiple vulnerabilities (was 0.0.6)
authlib==1.6.9 # Updated: Fixed OIDC hash binding, JWE RSA1_5 padding oracle, alg:none bypass, JWK header injection (was 1.6.6)