Skip to content

Bump jose from 5.1.3 to 6.2.2#4227

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/jose-6.2.2
Open

Bump jose from 5.1.3 to 6.2.2#4227
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/jose-6.2.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 22, 2026

Bumps jose from 5.1.3 to 6.2.2.

Release notes

Sourced from jose's releases.

v6.2.2

Fixes

  • reject failed decompression with JWEInvalid error (043b181)

v6.2.1

Refactor

  • reorganize internals, less files, smaller footprint (d4231f9)

v6.2.0

Features

  • re-introduce JWE "zip" (Compression Algorithm) Header Parameter support (b13b446)

Documentation

  • clarify return of general jws and jwe (56682b4)

v6.1.3

Refactor

  • avoid export * as for google closure's compiler sake (6303d98), closes #832

v6.1.2

Refactor

v6.1.1

Documentation

  • add link to RFC9864 (767edde)
  • link to ML-DSA for JOSE (ed4252c)
  • remove mention of Edge Runtime from the readme (94fdde7)
  • update README.md (25098ef)

Refactor

  • eliminate named exports in the source code (f6ae30d)
  • expose setKeyManagementParameters also on a GeneralEncrypt Recipient (16e6b23)
  • faster path for symmetric key checks (a44c2ec)
  • improve en/decoding overheads (daee426)

v6.1.0

Features

  • support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri (cf2092a)

... (truncated)

Changelog

Sourced from jose's changelog.

6.2.2 (2026-03-18)

Fixes

  • reject failed decompression with JWEInvalid error (043b181)

6.2.1 (2026-03-09)

Refactor

  • reorganize internals, less files, smaller footprint (d4231f9)

6.2.0 (2026-03-05)

Features

  • re-introduce JWE "zip" (Compression Algorithm) Header Parameter support (b13b446)

Documentation

  • clarify return of general jws and jwe (56682b4)

6.1.3 (2025-12-02)

Refactor

  • avoid export * as for google closure's compiler sake (6303d98), closes #832

6.1.2 (2025-11-15)

Refactor

6.1.1 (2025-11-09)

Documentation

  • add link to RFC9864 (767edde)
  • link to ML-DSA for JOSE (ed4252c)
  • remove mention of Edge Runtime from the readme (94fdde7)
  • update README.md (25098ef)

... (truncated)

Commits
  • 9c86586 chore(release): 6.2.2
  • 4984b5c chore(deps): bump the actions group with 4 updates
  • 043b181 fix: reject failed decompression with JWEInvalid error
  • 867cc2c chore(deps-dev): bump undici
  • f4e20e7 chore(deps-dev): bump tar in the npm_and_yarn group across 1 directory
  • d0505bf chore: cleanup after release
  • d491aa9 chore(release): 6.2.1
  • d4231f9 refactor: reorganize internals, less files, smaller footprint
  • 7b22ba8 test: use playwright instead of testcafe
  • 00965b4 chore: bump packages
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for jose since your current version.


@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 22, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 22, 2026 13:44
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 22, 2026
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 22, 2026 13:44 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 22, 2026 13:44 Inactive
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/jose-6.2.2 branch from 8998b8b to f354a9d Compare March 25, 2026 02:26
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:26 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:29 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:29 Inactive
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/jose-6.2.2 branch from a585a33 to e052a46 Compare March 25, 2026 02:32
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 02:32 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 02:32 Inactive
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/jose-6.2.2 branch from e052a46 to f03210e Compare March 25, 2026 16:03
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS Release-2-3 March 25, 2026 16:04 Inactive
@dependabot dependabot bot temporarily deployed to ESS PodSpaces March 25, 2026 16:04 Inactive
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/jose-6.2.2 branch from f03210e to 68062ba Compare March 26, 2026 14:56
Bumps [jose](https://github.com/panva/jose) from 5.1.3 to 6.2.2.
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](panva/jose@v5.1.3...v6.2.2)

---
updated-dependencies:
- dependency-name: jose
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants