Version 9.0.0 of `jsonwebtoken` is affected by a high severity vulnerability: [CVE-2025-65945](https://github.com/advisories/GHSA-869p-cjfg-cm3x) I created [this PR](https://github.com/mikenicholson/passport-jwt/pull/263) to bump the dependency to version 9.0.3.