Two weeks ago github.com/go-jose/go-jose released [v.4.0.1](https://github.com/go-jose/go-jose/releases/tag/v4.0.1) to fix a published vulnerability ([CVE-2024-28180](https://www.cve.org/CVERecord?id=CVE-2024-28180). This is issue is to bump the dependency from v3.0.1 to v4.0.1. (I can do a pull request with the bump)