You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
first of all thank you a whole lot for maintaing this project! We're successfully using this library in Notify. However, yesterday dependabot threw a security alert about a flaw in github.com/dgrijalva/jwt-go. We were able to backtrace the dependency graph to this library here.
Not sure if you're aware of this yet, so I just quickly wanted to let you know and check if you plan to replace this with, as recommended, https://github.com/golang-jwt/jwt. Of course, depending on the required effort, I'd be willing to help out with this too!
Best regards
The text was updated successfully, but these errors were encountered:
We do not want to have worry about vulnerabilities in JWT. I am not
sure that this code was ever in wide use. Users who have a continued
need for JWT can integrate their own code with this library.
Fixes#95.
Hi @kevinburke,
first of all thank you a whole lot for maintaing this project! We're successfully using this library in Notify. However, yesterday dependabot threw a security alert about a flaw in github.com/dgrijalva/jwt-go. We were able to backtrace the dependency graph to this library here.
Not sure if you're aware of this yet, so I just quickly wanted to let you know and check if you plan to replace this with, as recommended, https://github.com/golang-jwt/jwt. Of course, depending on the required effort, I'd be willing to help out with this too!
Best regards
The text was updated successfully, but these errors were encountered: