this package is using `python-jose` which in turns bring in `python-ecdsa` which has high CVE-2024-23342 see: https://github.com/advisories/GHSA-wj6h-64fc-37mp see discussion on `python-jose`: https://github.com/mpdavis/python-jose/issues/341