The repository already pinned python-jose for HS256 decoding. I installed it only to run the baseline test suite, then removed it in favour of PyJWT because the pinned release has known published CVEs and the project appears unmaintained. It did its old job fine, but it was not a library I wanted to build new JWKS-based verification on.
- What got in the way
- Pinned version carries published security advisories and the project has been slow to release fixes, which made it unsuitable as the foundation for a new auth integration.