bump jwt from 2.10.3 to 3.2.0 - #8039
Merged
Merged
Conversation
Collaborator
Coverage Report for CI Build 28621447237Coverage remained the same at 90.251%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsNo coverage regressions found. Coverage Stats💛 - Coveralls |
Naragod
approved these changes
Jul 3, 2026
david-yz-liu
approved these changes
Jul 3, 2026
david-yz-liu
left a comment
Collaborator
There was a problem hiding this comment.
Thanks @donny-wong!
Naragod
added a commit
that referenced
this pull request
Jul 27, 2026
* Implement GET and PATCH /overall_comment API routes (#7963) Closes #7708 * build(deps): bump puma from 7.2.0 to 7.2.1 (#7994) Bumps [puma](https://github.com/puma/puma) from 7.2.0 to 7.2.1. - [Release notes](https://github.com/puma/puma/releases) - [Changelog](https://github.com/puma/puma/blob/main/History.md) - [Commits](puma/puma@v7.2.0...v7.2.1) --- updated-dependencies: - dependency-name: puma dependency-version: 7.2.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump dompurify from 3.4.0 to 3.4.9 (#8005) Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.0 to 3.4.9. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.0...3.4.9) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.9 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Refactored SubmissionFilePanel subcomponents into functional style (#7969) * build(deps): bump net-imap from 0.6.4 to 0.6.4.1 (#7995) Bumps [net-imap](https://github.com/ruby/net-imap) from 0.6.4 to 0.6.4.1. - [Release notes](https://github.com/ruby/net-imap/releases) - [Commits](ruby/net-imap@v0.6.4...v0.6.4.1) --- updated-dependencies: - dependency-name: net-imap dependency-version: 0.6.4.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump dompurify from 3.4.9 to 3.4.11 (#8009) Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.9 to 3.4.11. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.9...3.4.11) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.11 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Added missing NOT NULL db constraints and presence validations (#7965) Issues detected by active_record_doctor * build(deps): bump nokogiri from 1.19.3 to 1.19.4 (#8010) Bumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.19.3 to 1.19.4. - [Release notes](https://github.com/sparklemotion/nokogiri/releases) - [Changelog](https://github.com/sparklemotion/nokogiri/blob/main/CHANGELOG.md) - [Commits](sparklemotion/nokogiri@v1.19.3...v1.19.4) --- updated-dependencies: - dependency-name: nokogiri dependency-version: 1.19.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump ws from 8.18.3 to 8.21.1 (#8058) Bumps [ws](https://github.com/websockets/ws) from 8.18.3 to 8.21.1. - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.18.3...8.21.1) --- updated-dependencies: - dependency-name: ws dependency-version: 8.21.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Added case sensitivity to group search (#7938) This adds a new caseSensitiveTextFilter table component for doing case-sensitive search. * build(deps): bump concurrent-ruby from 1.3.6 to 1.3.7 (#8011) Bumps [concurrent-ruby](https://github.com/ruby-concurrency/concurrent-ruby) from 1.3.6 to 1.3.7. - [Release notes](https://github.com/ruby-concurrency/concurrent-ruby/releases) - [Changelog](https://github.com/ruby-concurrency/concurrent-ruby/blob/master/CHANGELOG.md) - [Commits](ruby-concurrency/concurrent-ruby@v1.3.6...v1.3.7) --- updated-dependencies: - dependency-name: concurrent-ruby dependency-version: 1.3.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Refactored group creation to set group_name and repo_name pre-validation (#7975) Also add NOT NULL constraint to groups.group_name column * Simplified Chart.js usage (#7987) * Migrated MarkingSchemesTable to React Table v8 (#7985) * Fixed merge commits being incorrectly attributed as latest submission (#7988) When an instructor cloned a student repo, made a local commit, then merged and pushed, the merge commit was treated as the latest submission for the student's files. This inflated late penalties and showed the instructor's name as author. `entry_changed?` returned true for a merge commit whenever the file differed from *any* parent — including the instructor's branch that simply didn't have the file yet. The fix: for merge commits (2+ parents), only return true when the result differs from *all* parents. If the merged content matches at least one parent the merge was trivial for that path and should not be counted as a new modification. Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> * Refactored criterion keyboard navigation (#7989) * Moved criterion and level keyboard handlers into React components (MarksPanel and RubricCrtierionInput) * Fixed keyboard criterion navigation when flexible/checkbox inputs were focused * Ensured criterion navigation causes selected criterion to scroll into view --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> * Fixed navbar MarkUs logo link URL on mobile (#7990) * Added confirmation when uploading scans for a template with no divisions (#7993) * Fixed tester spec upload when spec contains non-existent criterion (#7998) Closes #7528 * Migrated SummaryPanel marks chart modal to use react-modal (#7996) * Added release process automation scripts (#7914) * Fixed SVG rendering by converting base64 SVG data URIs to inline <svg> (#8001) * Added pagination to Admin Users table for performance (#7997) * Added confirm dialog when a student submits during late period (#8003) * Reorganized locale strings from config/locales/en.yml (#8012) * Used native HTML required validation on modal upload inputs (#8016) * Refactored group creation job updates to use websockets (#8020) * Updated database indexes (#8018) - Enforce model uniqueness validations - Remove redundant indexes These were detected by active_record_doctor:missing_unique_indexes and active_record_doctor:extraneous_indexes. * Migrated graders_manager.jsx tables to react-table v8 (#8014) * Support all annotation types in add_annotations API route (#8007) * Fixed result annotation links to display correct file (#8017) * Updated PDFViewer to persist PDF scroll across submissions (#8004) * Added assignment grades upload feature (#8008) * bump jwt from 2.10.3 to 3.2.0 (#8039) * Fix LTI test JWK fixture to use 2048-bit key for jwt 3.0 compatibility * Fixed selection column header checkbox in v8 tables (#8037) * Added migrations to add missing timestamp columns and foreign key constraints (#8040) * Fixed assignment dropdown menu redirection from Assignments#index (#8043) * Fixed escaping of HTML annotation start_node and end_node attributes (#8064) * update changelog with new release v2.10.1 [ci skip] * update markus version * Fix rubocop ArrayIntersect and spec path offenses * [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci * Install postgresql-client-17 for CI pg_dump compatibility --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: philipkukulak <philip.kukulak@utoronto.ca> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: David Liu <david@cs.toronto.edu> Co-authored-by: Yanzhen Chen <yanzhenchen123@gmail.com> Co-authored-by: Muhammad <rafie.muhammad2007@gmail.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Daniel Rafailov <74218740+danielrafailov1@users.noreply.github.com> Co-authored-by: donny-wong <141858744+donny-wong@users.noreply.github.com> Co-authored-by: Aayush Karki <147123757+akarki2005@users.noreply.github.com> Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed Changes
(Describe your changes here. Also describe the motivation for your changes: what problem do they solve, or how do they improve the application or codebase? If this pull request fixes an open issue, use a keyword to link this pull request to the issue.)
Manually bump
jwtgem from 2.10.3 → 3.2.0. Sincejwtis unpinned in theGemfile, this is aGemfile.lock-only change.3.2.0 is the current latest release. Relevant points from its changelog:
nil/empty HMAC keys when signing and verifying. As assessed in the Dependabot bump build(deps): bump jwt from 2.10.1 to 2.10.3 #7959, this is an HMAC vulnerability, and MarkUs signs and verifies exclusively with RSA/RS256, so the vulnerable path was never reachable - but moving to the patched release keeps us current.opensslgem (it is absent fromGemfile.lock) and instead relies on Ruby's stdlib OpenSSL. RSA/RS256 was confirmed working at runtime.enforce_hmac_key_length), CI-only (Ruby 4.0 test matrix), or defensive hardening (type error on non-JSON token headers) - none affect the RSA/RS256/JWKS paths MarkUs uses.Major version (3.0) breaking-change review
rails markus:lti_keyhardcodesOpenSSL::PKey::RSA.new(2048).Tests:
Screenshots of your changes (if applicable)
Type of Change
(Write an
Xor a brief description next to the type or types that best describe your changes.)Checklist
(Complete each of the following items for your pull request. Indicate that you have completed an item by changing the
[ ]into a[x]in the raw text, or by clicking on the checkbox in the rendered description on GitHub.)Before opening your pull request:
After opening your pull request:
Questions and Comments
(Include any questions or comments you have regarding your changes.)