Skip to content

fix(deps): update module github.com/auth0/go-jwt-middleware/v2 to v3 - #2120

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-auth0-go-jwt-middleware-v2-3.x
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-auth0-go-jwt-middleware-v2-3.x

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/auth0/go-jwt-middleware/v2 v2.3.0 → v3.3.0 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

auth0/go-jwt-middleware (github.com/auth0/go-jwt-middleware/v2)

v3.3.0

Compare Source

Full Changelog

Added

  • feat(validator): parse and expose On-Behalf-Of / Token Exchange claims per RFC 8693 #​407 (developerkunal)

Fixed

v3.2.0

Compare Source

Full Changelog

Added

v3.1.0

Compare Source

Full Changelog

Added

v3.0.0

Compare Source

Full Changelog

BEFORE YOU UPGRADE

  • This is a major release that includes breaking changes. Please see MIGRATION_GUIDE.md before upgrading. This release will require changes to your application.
Added
  • Pure options pattern for validator, middleware, and JWKS provider (#​357, #​358, #​360)
  • DPoP (Demonstrating Proof-of-Possession) support per RFC 9449 (#​363)
  • Framework-agnostic core package for reusable validation logic (#​356)
  • Type-safe claims retrieval with generics (GetClaims[T](), MustGetClaims[T](), HasClaims())
  • Structured logging support compatible with log/slog
  • Support for 14 signature algorithms (HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512, ES256K, EdDSA)
  • Enhanced error responses with RFC 6750 compliance
  • Trusted proxy configuration for DPoP behind reverse proxies
  • Multiple issuer and audience support with new APIs
  • Documentation and linting configuration (#​361)
Changed
  • Migrated from square/go-jose to lestrrat-go/jwx v3 (#​358)
  • Module path updated to github.com/auth0/go-jwt-middleware/v3 (#​355)
  • Minimum Go version updated to 1.24 (#​355)
  • Update examples for v3 module path and new APIs
Breaking
  • Pure options pattern: All constructors (New()) now require functional options instead of positional parameters
  • Context key: ContextKey{} is no longer exported - use GetClaims[T]() helper function
  • Custom claims now use generics for type safety
  • TokenExtractor returns ExtractedToken (with scheme) instead of string
  • Type naming: ExclusionUrlHandler renamed to ExclusionURLHandler
Migration Example

v2:

// Validator with positional parameters
jwtValidator, err := validator.New(
    keyFunc,
    validator.RS256,
    "https://issuer.example.com/",
    []string{"my-api"},
)

// Middleware
middleware := jwtmiddleware.New(jwtValidator.ValidateToken)

// Claims access via context key
claims := r.Context().Value(jwtmiddleware.ContextKey{}).(*validator.ValidatedClaims)

v3:

// Validator with pure options
jwtValidator, err := validator.New(
    validator.WithKeyFunc(keyFunc),
    validator.WithAlgorithm(validator.RS256),
    validator.WithIssuer("https://issuer.example.com/"),
    validator.WithAudience("my-api"),
)

// Middleware with options
middleware, err := jwtmiddleware.New(
    jwtmiddleware.WithValidator(jwtValidator),
)

// Type-safe claims with generics
claims, err := jwtmiddleware.GetClaims[*validator.ValidatedClaims](r.Context())

See MIGRATION_GUIDE.md for complete migration instructions.


v2.3.1

Compare Source

Full Changelog

Security


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@github-actions

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: src/invocation-plane-services/ratelimiter/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated

Details:

Package Change
google.golang.org/grpc v1.79.3 -> v1.82.1
golang.org/x/crypto v0.51.0 -> v0.52.0
google.golang.org/genproto/googleapis/api v0.0.0-20260209200024-4cfbd4190f57 -> v0.0.0-20260414002931-afd174a4e478
google.golang.org/genproto/googleapis/rpc v0.0.0-20260209200024-4cfbd4190f57 -> v0.0.0-20260414002931-afd174a4e478

@github-actions
github-actions Bot requested a review from a team as a code owner September 28, 2026 09:50
@github-actions
github-actions Bot requested a review from sparve-nv September 28, 2026 09:50
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: NVIDIA/nvcf/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 8af512f6-6ffb-44db-8722-9b5ce72d8819

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot force-pushed the renovate/github.com-auth0-go-jwt-middleware-v2-3.x branch 2 times, most recently from af3cdd1 to e8e35b9 Compare September 30, 2026 09:32
@github-actions
github-actions Bot force-pushed the renovate/github.com-auth0-go-jwt-middleware-v2-3.x branch from e8e35b9 to a6e1d30 Compare October 1, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants