Skip to content

Issue: Suggest Updating golang-jwt/jwt Dependency to v4/v5 for Security & Compatibility #1

@heqingpro

Description

@heqingpro

The current version of core-go appears to depend on github.com/golang-jwt/jwt v3.x (marked as v3.2.1+incompatible), which has known security vulnerabilities:
rhtpa(osv-github) vulnerability info:
Known security vulnerabilities: 1
Highest severity: HIGH

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions