pip-audit flagged 6 advisories: PyJWT 2.12.1 (PYSEC-2026-175/177/178/179, fixed in 2.13.0) and transitive certifi 2023.11.17 (PYSEC-2024-230, fixed in 2024.7.4). Bump PyJWT and pin certifi to its latest release to enforce the resolved version.