Skip to content

Bump go-jose to v4.1.4#2439

Merged
jakubno merged 2 commits intobump-golang-versionfrom
upgrade-jose
Apr 19, 2026
Merged

Bump go-jose to v4.1.4#2439
jakubno merged 2 commits intobump-golang-versionfrom
upgrade-jose

Conversation

@djeebus
Copy link
Copy Markdown
Contributor

@djeebus djeebus commented Apr 18, 2026

No description provided.

@cursor
Copy link
Copy Markdown

cursor Bot commented Apr 18, 2026

PR Summary

Low Risk
Low risk dependency patch bump; main potential impact is subtle changes in JWT/JWE/JWS handling behavior or validation edge cases in upstream go-jose.

Overview
Bumps the indirect github.com/go-jose/go-jose/v4 dependency from v4.1.3 to v4.1.4 across packages/orchestrator and packages/shared, updating the corresponding go.sum entries.

Reviewed by Cursor Bugbot for commit ea9d522. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread packages/shared/go.sum
Comment thread packages/shared/go.sum
@jakubno jakubno merged commit 0656d9d into bump-golang-version Apr 19, 2026
41 checks passed
@jakubno jakubno deleted the upgrade-jose branch April 19, 2026 12:57
jakubno pushed a commit that referenced this pull request Apr 20, 2026
* bump golang from 1.25.4 to 1.25.9

this preps us for some other upgrades

* do a clearer job of pinning Dockerfile

* Bump go-jose to v4.1.4 (#2439)

* make dockerfile look like others
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants