Skip to content

Update module github.com/golang-jwt/jwt/v4 to v4.5.2#103

Open
red-hat-konflux[bot] wants to merge 1 commit intokonflux-pocfrom
konflux/mintmaker/konflux-poc/github.com-golang-jwt-jwt-v4-4.x
Open

Update module github.com/golang-jwt/jwt/v4 to v4.5.2#103
red-hat-konflux[bot] wants to merge 1 commit intokonflux-pocfrom
konflux/mintmaker/konflux-poc/github.com-golang-jwt-jwt-v4-4.x

Conversation

@red-hat-konflux
Copy link
Copy Markdown

@red-hat-konflux red-hat-konflux Bot commented Dec 12, 2025

This PR contains the following updates:

Package Change Age Confidence
github.com/golang-jwt/jwt/v4 v4.5.0v4.5.2 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

golang-jwt/jwt (github.com/golang-jwt/jwt/v4)

v4.5.2

Compare Source

See GHSA-mh63-6h87-95cp

Full Changelog: golang-jwt/jwt@v4.5.1...v4.5.2

v4.5.1

Compare Source

Security

Unclear documentation of the error behavior in ParseWithClaims in <= 4.5.0 could lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by ParseWithClaims return both error codes. If users only check for the jwt.ErrTokenExpired using error.Is, they will ignore the embedded jwt.ErrTokenSignatureInvalid and thus potentially accept invalid tokens.

This issue was documented in GHSA-29wx-vh33-7x7r and fixed in this release.

Note: v5 was not affected by this issue. So upgrading to this release version is also recommended.

What's Changed

  • Back-ported error-handling logic in ParseWithClaims from v5 branch. This fixes GHSA-29wx-vh33-7x7r.

Full Changelog: golang-jwt/jwt@v4.5.0...v4.5.1


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Dec 12, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Dec 14, 2025
@red-hat-konflux
Copy link
Copy Markdown
Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Dec 14, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Dec 18, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Dec 18, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Dec 18, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Dec 19, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Dec 19, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Dec 19, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Dec 20, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Dec 20, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Dec 27, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Dec 27, 2025
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Jan 1, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Jan 1, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Jan 13, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Jan 13, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Jan 14, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Jan 15, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Jan 25, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Jan 25, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Feb 5, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Feb 6, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Feb 19, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Feb 20, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Mar 5, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Mar 5, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Mar 25, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Mar 25, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Apr 9, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Apr 9, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Apr 11, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Apr 11, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Apr 21, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Apr 21, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Apr 24, 2026
@red-hat-konflux red-hat-konflux Bot changed the title Update module github.com/golang-jwt/jwt/v4 to v4.5.2 - abandoned Update module github.com/golang-jwt/jwt/v4 to v4.5.2 Apr 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants