Skip to content

chore(deps): bump com.nimbusds:nimbus-jose-jwt from 10.9.1 to 10.10 - #2765

Merged
acoburn merged 1 commit into
1.3from
dependabot/maven/1.3/com.nimbusds-nimbus-jose-jwt-10.10
Oct 1, 2026
Merged

acoburn merged 1 commit into
1.3from
dependabot/maven/1.3/com.nimbusds-nimbus-jose-jwt-10.10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps com.nimbusds:nimbus-jose-jwt from 10.9.1 to 10.10.

Changelog

Sourced from com.nimbusds:nimbus-jose-jwt's changelog.

10.9.1 (2026-05-31) * Fixes health status reporting when RefreshAheadCachingJWKSetSource, JWKSetSourceWithHealthStatusReporting and OutageTolerantJWKSetSource are used together. A failed refresh-ahead background update could previously cause JWKSetSourceWithHealthStatusReporting to mark the JWK set source as UNHEALTHY, even though OutageTolerantJWKSetSource was still within its configured outage tolerance window and regular JWT validation could continue using the cached JWK set. Refresh-ahead failures that are covered by outage tolerance no longer cause the health status to become unhealthy before the outage tolerance period has been exceeded (iss #619).

10.10 (2026-09-17) * Adds JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH for the default maximum allowed length of decompressed plain text, in bytes. Used to establish an active (dynamic) safety limit against zip-bomb attacks. Set to 1 mio bytes (iss #611). * Adds MaxDecompressedPlainTextLength implementing JWEDecrypterOption, to enable applications to override the default JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH (iss #611). * Adds explicit non-null checks to DeflateUtils (iss #611). * Fixes potential native memory resource leak in DeflateUtils when Deflater or Inflater instances were not guaranteed to call .end() if stream closing or processing threw an exception (iss #611). * Optimizes DeflateUtils resource management and memory allocation by guaranteeing native stream cleanup, validating inputs, and pre-allocating decompression buffers (iss #611). * Updates to com.google.code.gson:gson:2.14.0 * Updates to com.google.crypto.tink:tink:1.23.0 * Updates to BouncyCastle 1.86

11.0 (2026-09-xx) * Compile source and target bumped from Java 7 to Java 8. * Optimises JWS input composition for unencoded payloads (RFC 7797) to conserve memory and CPU cycles. Introduces a helper JWSInput interface with a ByteArrayJWSInput and ComposedJWSInput implementations for the JWS input composition when the payloaded is encoded and when not (iss #613). * Adds JWTClaimsSet.getInstantClaims, getExpirationInstant, getNotBeforeInstant and getIssueInstant methods. Adds JWTClaimsSet.Builder.expirationInstant, notBeforeInstant and issueInstant methods. * Adds JSONObjectUtils.getEpochSecondAsInstant static method. * Overrides equals and hashCode in Payload. * Fixes health status reporting when RefreshAheadCachingJWKSetSource, JWKSetSourceWithHealthStatusReporting and OutageTolerantJWKSetSource are used together. A failed refresh-ahead background update could previously cause JWKSetSourceWithHealthStatusReporting to mark the JWK set source as UNHEALTHY, even though OutageTolerantJWKSetSource was still within its configured outage tolerance window and regular JWT validation could continue using the cached JWK set. Refresh-ahead failures that are

... (truncated)

Commits
  • e055b3b [maven-release-plugin] prepare for next development iteration
  • c06d769 Adds JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH - 10.x WIP (iss #611)
  • a427513 Adds explicit non-null checks to DeflateUtils (iss #611)
  • 3302e15 Fixes potential native memory resource leak in DeflateUtils when Deflater or ...
  • d004e79 Optimizes DeflateUtils resource management and memory allocation by guarantee...
  • 98ed6ba Adjusts JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH to 1 mio bytes (iss #611)
  • 0350144 Adds MaxDecompressedPlainTextLength implementing JWEDecrypterOption (iss #611)
  • 218575f Wires MaxDecompressedPlainTextLength (iss #611)
  • 3fcb8f5 Adds MaxDecompressedPlainTextLength tests for each JWEDecrypter (iss #611)
  • 14ae7ac Adds CHANGELOG.txt entries (iss #611)
  • Additional commits viewable in compare view

Bumps [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) from 10.9.1 to 10.10.
- [Changelog](https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt)
- [Commits](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/10.10..10.9.1)

---
updated-dependencies:
- dependency-name: com.nimbusds:nimbus-jose-jwt
  dependency-version: '10.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/maven/1.3/com.nimbusds-nimbus-jose-jwt-10.10 branch from ee829a6 to 963a90f Compare October 1, 2026 13:04
@acoburn
acoburn merged commit e3b9a6b into 1.3 Oct 1, 2026
7 checks passed
@acoburn
acoburn deleted the dependabot/maven/1.3/com.nimbusds-nimbus-jose-jwt-10.10 branch October 1, 2026 13:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant