Bump jose from 5.10.0 to 6.1.0 #116

Closed
dependabot[bot] wants to merge 1 commits from dependabot/npm_and_yarn/jose-6.1.0 into main
dependabot[bot] commented 2025-08-28 07:08:01 +00:00 (Migrated from github.com)

Bumps jose from 5.10.0 to 6.1.0.

Release notes

Sourced from jose's releases.

v6.1.0

Features

  • support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri (cf2092a)
  • support for the ML-DSA PQC Algorithm Identifiers (25ddce4)

v6.0.13

Refactor

  • more readability in ecdhes.ts (84da9de)
  • update asn1.ts helpers (b4f8fb3)

v6.0.12

Documentation

  • add known caveats to customFetch (02e1f1e)
  • mention the apu/apv parameter names in setKeyManagementParameters (6274d5a)
  • update compact setKeyManagementParameters (2f44381)
  • use GitHub Flavored Markdown for notes and warnings (f6b4ffc)

Refactor

  • createPublicKey is not a constructor (61ded78)
  • update asn1.ts helper functions (b2b611c)

v6.0.11

Fixes

  • typ checking edge-cases when it contains a slash (/) character (31e4baf)

v6.0.10

Refactor

  • removed unused claims methods (74719cf)
  • reorganize jwt claim set utils (1f12d88)

v6.0.9

Documentation

  • add more symbol document, ignore ts-private fields (8b73687)
  • bump typedoc (6163a8b)
  • drop cdnjs links in README (a910038)
  • drop denoland/x links in README and add jsr (3662b9e)
  • fix key export links from docs/README.md (c8edfc2)

Refactor

  • always assume structuredClone is present (f7898a9)

... (truncated)

Changelog

Sourced from jose's changelog.

6.1.0 (2025-08-27)

Features

  • support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri (cf2092a)
  • support for the ML-DSA PQC Algorithm Identifiers (25ddce4)

6.0.13 (2025-08-21)

Refactor

  • more readability in ecdhes.ts (84da9de)
  • update asn1.ts helpers (b4f8fb3)

6.0.12 (2025-07-15)

Documentation

  • add known caveats to customFetch (02e1f1e)
  • mention the apu/apv parameter names in setKeyManagementParameters (6274d5a)
  • update compact setKeyManagementParameters (2f44381)
  • use GitHub Flavored Markdown for notes and warnings (f6b4ffc)

Refactor

  • createPublicKey is not a constructor (61ded78)
  • update asn1.ts helper functions (b2b611c)

6.0.11 (2025-05-05)

Fixes

  • typ checking edge-cases when it contains a slash (/) character (31e4baf)

6.0.10 (2025-03-12)

Refactor

  • removed unused claims methods (74719cf)
  • reorganize jwt claim set utils (1f12d88)

6.0.9 (2025-03-11)

... (truncated)

Commits
  • 6f3e004 chore(release): 6.1.0
  • 25ddce4 feat: support for the ML-DSA PQC Algorithm Identifiers
  • cf2092a feat: support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri
  • 2c519cc chore: cleanup after release
  • 1e36dd2 chore(release): 6.0.13
  • b4f8fb3 refactor: update asn1.ts helpers
  • 413fa45 chore: bump packages
  • 84da9de refactor: more readability in ecdhes.ts
  • 475a3ed chore: npm run format
  • b59c547 chore: bump packages
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [jose](https://github.com/panva/jose) from 5.10.0 to 6.1.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/panva/jose/releases">jose's releases</a>.</em></p> <blockquote> <h2>v6.1.0</h2> <h3>Features</h3> <ul> <li>support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri (<a href="https://github.com/panva/jose/commit/cf2092a2b51c9fb67049e96ee22d551ad34c0b2c">cf2092a</a>)</li> <li>support for the ML-DSA PQC Algorithm Identifiers (<a href="https://github.com/panva/jose/commit/25ddce491ba3968e8802db5913e49a52224246be">25ddce4</a>)</li> </ul> <h2>v6.0.13</h2> <h3>Refactor</h3> <ul> <li>more readability in ecdhes.ts (<a href="https://github.com/panva/jose/commit/84da9decd8b2f266a343a507b6b79197f2da11e8">84da9de</a>)</li> <li>update asn1.ts helpers (<a href="https://github.com/panva/jose/commit/b4f8fb372689b5b38074aa45c9921a6a997a9142">b4f8fb3</a>)</li> </ul> <h2>v6.0.12</h2> <h3>Documentation</h3> <ul> <li>add known caveats to customFetch (<a href="https://github.com/panva/jose/commit/02e1f1e87c764885121590aa2af80c831a9320ab">02e1f1e</a>)</li> <li>mention the apu/apv parameter names in setKeyManagementParameters (<a href="https://github.com/panva/jose/commit/6274d5abca3d3882d3d722415f064fee5c44d0e4">6274d5a</a>)</li> <li>update compact setKeyManagementParameters (<a href="https://github.com/panva/jose/commit/2f44381b6b0e30cf538ea2edb0d42b76a61de1f8">2f44381</a>)</li> <li>use GitHub Flavored Markdown for notes and warnings (<a href="https://github.com/panva/jose/commit/f6b4ffcd82d9645d9b818ece09a09b5a636b69c9">f6b4ffc</a>)</li> </ul> <h3>Refactor</h3> <ul> <li>createPublicKey is not a constructor (<a href="https://github.com/panva/jose/commit/61ded787150c6ae13eeb65b6680f857d6657465f">61ded78</a>)</li> <li>update asn1.ts helper functions (<a href="https://github.com/panva/jose/commit/b2b611c426eeed3c40c3a1423d8a02dd46f3f7e8">b2b611c</a>)</li> </ul> <h2>v6.0.11</h2> <h3>Fixes</h3> <ul> <li>typ checking edge-cases when it contains a slash (/) character (<a href="https://github.com/panva/jose/commit/31e4bafc0a908cac044bbe34c7024f4eac9c974f">31e4baf</a>)</li> </ul> <h2>v6.0.10</h2> <h3>Refactor</h3> <ul> <li>removed unused claims methods (<a href="https://github.com/panva/jose/commit/74719cfcfba1920b87740245da08bb70b68e7cd1">74719cf</a>)</li> <li>reorganize jwt claim set utils (<a href="https://github.com/panva/jose/commit/1f12d88ee8cfa328126934a7020396f9a8dd8932">1f12d88</a>)</li> </ul> <h2>v6.0.9</h2> <h3>Documentation</h3> <ul> <li>add more symbol document, ignore ts-private fields (<a href="https://github.com/panva/jose/commit/8b73687595a7ca608aa1b78870b6b165ad5249f2">8b73687</a>)</li> <li>bump typedoc (<a href="https://github.com/panva/jose/commit/6163a8b6a773100ed31d207b598db1259a7e13a8">6163a8b</a>)</li> <li>drop cdnjs links in README (<a href="https://github.com/panva/jose/commit/a9100383ab16cb62c375401fac08a77f3c6c528d">a910038</a>)</li> <li>drop denoland/x links in README and add jsr (<a href="https://github.com/panva/jose/commit/3662b9ec44403bd501fc895bea4ded623d23e7e1">3662b9e</a>)</li> <li>fix key export links from docs/README.md (<a href="https://github.com/panva/jose/commit/c8edfc29416d3339f6c78fdc42bdfdfadaa5cf7e">c8edfc2</a>)</li> </ul> <h3>Refactor</h3> <ul> <li>always assume structuredClone is present (<a href="https://github.com/panva/jose/commit/f7898a9487508684dbbeba990e0cc96d344b1ff6">f7898a9</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/panva/jose/blob/main/CHANGELOG.md">jose's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/panva/jose/compare/v6.0.13...v6.1.0">6.1.0</a> (2025-08-27)</h2> <h3>Features</h3> <ul> <li>support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri (<a href="https://github.com/panva/jose/commit/cf2092a2b51c9fb67049e96ee22d551ad34c0b2c">cf2092a</a>)</li> <li>support for the ML-DSA PQC Algorithm Identifiers (<a href="https://github.com/panva/jose/commit/25ddce491ba3968e8802db5913e49a52224246be">25ddce4</a>)</li> </ul> <h2><a href="https://github.com/panva/jose/compare/v6.0.12...v6.0.13">6.0.13</a> (2025-08-21)</h2> <h3>Refactor</h3> <ul> <li>more readability in ecdhes.ts (<a href="https://github.com/panva/jose/commit/84da9decd8b2f266a343a507b6b79197f2da11e8">84da9de</a>)</li> <li>update asn1.ts helpers (<a href="https://github.com/panva/jose/commit/b4f8fb372689b5b38074aa45c9921a6a997a9142">b4f8fb3</a>)</li> </ul> <h2><a href="https://github.com/panva/jose/compare/v6.0.11...v6.0.12">6.0.12</a> (2025-07-15)</h2> <h3>Documentation</h3> <ul> <li>add known caveats to customFetch (<a href="https://github.com/panva/jose/commit/02e1f1e87c764885121590aa2af80c831a9320ab">02e1f1e</a>)</li> <li>mention the apu/apv parameter names in setKeyManagementParameters (<a href="https://github.com/panva/jose/commit/6274d5abca3d3882d3d722415f064fee5c44d0e4">6274d5a</a>)</li> <li>update compact setKeyManagementParameters (<a href="https://github.com/panva/jose/commit/2f44381b6b0e30cf538ea2edb0d42b76a61de1f8">2f44381</a>)</li> <li>use GitHub Flavored Markdown for notes and warnings (<a href="https://github.com/panva/jose/commit/f6b4ffcd82d9645d9b818ece09a09b5a636b69c9">f6b4ffc</a>)</li> </ul> <h3>Refactor</h3> <ul> <li>createPublicKey is not a constructor (<a href="https://github.com/panva/jose/commit/61ded787150c6ae13eeb65b6680f857d6657465f">61ded78</a>)</li> <li>update asn1.ts helper functions (<a href="https://github.com/panva/jose/commit/b2b611c426eeed3c40c3a1423d8a02dd46f3f7e8">b2b611c</a>)</li> </ul> <h2><a href="https://github.com/panva/jose/compare/v6.0.10...v6.0.11">6.0.11</a> (2025-05-05)</h2> <h3>Fixes</h3> <ul> <li>typ checking edge-cases when it contains a slash (/) character (<a href="https://github.com/panva/jose/commit/31e4bafc0a908cac044bbe34c7024f4eac9c974f">31e4baf</a>)</li> </ul> <h2><a href="https://github.com/panva/jose/compare/v6.0.9...v6.0.10">6.0.10</a> (2025-03-12)</h2> <h3>Refactor</h3> <ul> <li>removed unused claims methods (<a href="https://github.com/panva/jose/commit/74719cfcfba1920b87740245da08bb70b68e7cd1">74719cf</a>)</li> <li>reorganize jwt claim set utils (<a href="https://github.com/panva/jose/commit/1f12d88ee8cfa328126934a7020396f9a8dd8932">1f12d88</a>)</li> </ul> <h2><a href="https://github.com/panva/jose/compare/v6.0.8...v6.0.9">6.0.9</a> (2025-03-11)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/panva/jose/commit/6f3e0045f189891801f27717b6d76ea1f9ee5fc2"><code>6f3e004</code></a> chore(release): 6.1.0</li> <li><a href="https://github.com/panva/jose/commit/25ddce491ba3968e8802db5913e49a52224246be"><code>25ddce4</code></a> feat: support for the ML-DSA PQC Algorithm Identifiers</li> <li><a href="https://github.com/panva/jose/commit/cf2092a2b51c9fb67049e96ee22d551ad34c0b2c"><code>cf2092a</code></a> feat: support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri</li> <li><a href="https://github.com/panva/jose/commit/2c519cce22b73983a00a0da24f4e319050598749"><code>2c519cc</code></a> chore: cleanup after release</li> <li><a href="https://github.com/panva/jose/commit/1e36dd29e76511e06737e5d5d500d81e01a9c3d2"><code>1e36dd2</code></a> chore(release): 6.0.13</li> <li><a href="https://github.com/panva/jose/commit/b4f8fb372689b5b38074aa45c9921a6a997a9142"><code>b4f8fb3</code></a> refactor: update asn1.ts helpers</li> <li><a href="https://github.com/panva/jose/commit/413fa4504c63a7f84f47df8bb7ea310eddfa6451"><code>413fa45</code></a> chore: bump packages</li> <li><a href="https://github.com/panva/jose/commit/84da9decd8b2f266a343a507b6b79197f2da11e8"><code>84da9de</code></a> refactor: more readability in ecdhes.ts</li> <li><a href="https://github.com/panva/jose/commit/475a3ed35f54deb3a078165bee627637cbcec8c4"><code>475a3ed</code></a> chore: npm run format</li> <li><a href="https://github.com/panva/jose/commit/b59c5475afc5d4ed127ba22356a4cee58e802ad0"><code>b59c547</code></a> chore: bump packages</li> <li>Additional commits viewable in <a href="https://github.com/panva/jose/compare/v5.10.0...v6.1.0">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=jose&package-manager=npm_and_yarn&previous-version=5.10.0&new-version=6.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
dependabot[bot] commented 2025-08-30 04:24:44 +00:00 (Migrated from github.com)

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting `@dependabot ignore this major version` or `@dependabot ignore this minor version`. You can also ignore all major, minor, or patch releases for a dependency by adding an [`ignore` condition](https://docs.github.com/en/code-security/supply-chain-security/configuration-options-for-dependency-updates#ignore) with the desired `update_types` to your config file. If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Pull request closed

Sign in to join this conversation.