Skip to content

Update jwt to 3.2.0 for CVE-2026-45363#124

Open
Fryguy wants to merge 1 commit into
ManageIQ:masterfrom
Fryguy:update_jwt
Open

Update jwt to 3.2.0 for CVE-2026-45363#124
Fryguy wants to merge 1 commit into
ManageIQ:masterfrom
Fryguy:update_jwt

Conversation

@Fryguy
Copy link
Copy Markdown
Member

@Fryguy Fryguy commented May 18, 2026

@agrare Please review.

Here's the information about upgrading to 3.x: https://github.com/jwt/ruby-jwt/blob/main/UPGRADING.md, however I don't think it affects anything in this repo.

The bigger problem is that the oci gem also depends on 2.x, so we;re going to have to find a way to upgrade that one.

Could not find compatible versions

Because every version of manageiq-providers-oracle_cloud depends on oci ~> 2.22
  and oci >= 2.0.6 depends on jwt ~> 2.1,
  every version of manageiq-providers-oracle_cloud requires jwt ~> 2.1.
And because every version of manageiq-providers-embedded_terraform depends on jwt ~> 3.2,
  every version of manageiq-providers-oracle_cloud is incompatible with manageiq-providers-embedded_terraform >= 0.
So, because Gemfile depends on manageiq-providers-embedded_terraform >= 0
  and Gemfile depends on manageiq-providers-oracle_cloud >= 0,
  version solving has failed.

@agrare
Copy link
Copy Markdown
Member

agrare commented May 18, 2026

RbNaCl/libsodium is used by the google provider, but indirectly so as long as the google api gems support jwt >= 3 we should be good.

@miq-bot
Copy link
Copy Markdown
Member

miq-bot commented May 18, 2026

Checked commit Fryguy@1f148ed with ruby 3.3.10, rubocop 1.86.0, haml-lint 0.73.0, and yamllint 1.37.1
0 files checked, 0 offenses detected
Everything looks fine. 👍

@agrare
Copy link
Copy Markdown
Member

agrare commented May 18, 2026

Embedded Terraform specs pass locally with an overridden oci gem

@agrare
Copy link
Copy Markdown
Member

agrare commented May 18, 2026

@miq-bot cross-repo-test IBM/ruby-sdk-core#47, agrare/oci-ruby-sdk@bump_jwt

@agrare
Copy link
Copy Markdown
Member

agrare commented May 18, 2026

@miq-bot cross-repo-test manageiq-providers-ibm_cloud, manageiq-providers-google, including IBM/ruby-sdk-core#47, agrare/oci-ruby-sdk@bump_jwt

@agrare
Copy link
Copy Markdown
Member

agrare commented May 19, 2026

@miq-bot cross-repo-test manageiq-providers-ibm_cloud, manageiq-providers-google, manageiq-providers-oracle_cloud including IBM/ruby-sdk-core#47, agrare/oci-ruby-sdk@bump_jwt

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants