Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update go-jose to 3.0.3 to resolve security issue #346

Closed
davidmytton opened this issue Oct 27, 2024 · 1 comment
Closed

Update go-jose to 3.0.3 to resolve security issue #346

davidmytton opened this issue Oct 27, 2024 · 1 comment

Comments

@davidmytton
Copy link

Do you plan to merge #300 and update go-jose from 3.0.1 to 3.0.3? Although v4 is the latest version, security fixes are still being backported and https://github.com/go-jose/go-jose/releases/tag/v3.0.3 includes a fix for GHSA-c5q2-7r4c-mv6g

@gkats
Copy link
Member

gkats commented Oct 30, 2024

Hi @davidmytton,

Thanks for the nudge. The PR is now merged and go-jose should be bumped to 3.0.3 now. The release tag is v2.1.0.

I guess we should look into upgrading to v4 at some point.

@gkats gkats closed this as completed Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants