Skip to content

Conversation

@scbizu
Copy link
Collaborator

@scbizu scbizu commented Mar 24, 2022

@scbizu scbizu requested review from cbuto and jdolitsky March 24, 2022 03:26
Copy link
Collaborator

@cbuto cbuto left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This lgtm but I don’t think it will resolve the issue linked.

The issue is about the CVE associated with github.com/dgrijalva/jwt-go

@scbizu
Copy link
Collaborator Author

scbizu commented Mar 25, 2022

github.com/golang-jwt/jwt is the community clone version of github.com/dgrijalva/jwt-go , their tag list are the same before v3.2.0 , and we do not depend on github.com/dgrijalva/jwt-go according to the mod graph .

@asgeirn
Copy link

asgeirn commented Nov 11, 2025

Any hope on merging this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chartMuseum binary contains High Vulnerable github.com/dgrijalva/jwt-go v3.2.0+incompatible library

4 participants