• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zentralopensource / zentral / 36478110477
91%

Build:
DEFAULT BRANCH: main
Ran 28 Sep 2026 08:28PM UTC
Jobs 1
Files 1035
Run time 3min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 07:55PM UTC coverage: 90.908%. Remained the same
36478110477

push

github

np5
Bump PyJWT to 2.15.1

2.15.1 has one change (jpadilla/pyjwt#1216), in the base64url decoder of the
JWS segments. 2.15.0 rejected a segment that ends in "=" padding with
"Invalid crypto padding". 2.15.1 accepts the padding if it is correct: one or
two "=" characters that complete the last 4-character group. Padding that is
too long, and characters that are not in the alphabet, are still rejected, and
the decoded value must encode back to the same segment without its padding.

In Zentral, this affects zentral.utils.oidc.verify_jws: the OIDC API token
issuer auth view and the ID token of an OpenID Connect realm. An issuer that
pads the signature segment, as AWS ALB does, now gets a verified token instead
of a 400. A padded token with a correct signature and an unpadded token with a
correct signature decode to the same bytes, and the signature is calculated
on the header and payload segments as they are sent. Thus padding does not
let a token through that 2.15.0 would not verify without the padding.

The cost is that one token now has two string forms that both verify. No
Zentral code keeps or compares the token string, so this has no effect here.

The dependency metadata is the same for 2.15.0 and 2.15.1, so no other pin
moves.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

52830 of 58114 relevant lines covered (90.91%)

0.91 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36478110477.1 28 Sep 2026 08:28PM UTC 1035
90.91
GitHub Action Run
Source Files on build 36478110477
  • Tree
  • List 1035
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36478110477
  • b3704c5f on github
  • Prev Build on main (#36227682781)
  • Next Build on main (#36483798952)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc