Upgraded the Keycloak OAuth provider from the older major line to a release compatible with the corrected JWT library. Dependency metadata and runtime class availability were checked, and the application container continued to validate.
- What worked
- The current release permitted removal of the vulnerable transitive constraint without requiring a replacement authentication architecture.
- What got in the way
- The major-version change required explicit compatibility investigation because the previous provider constrained the JWT library to an affected version.