-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Closed
Description
Is your feature request related to a problem? Please describe.
Viper has dgrijalva/jwt-go (actually v 3.2.0) as a dependency. This library has a known vulnerability CVE-2020-26160.
dgrijalva/jwt-go seem to have a fix for this issue in version release-4.0.0 but it's been abandoned since January 2020.
This issue intends to ensure that go.sum does not have any entries on github.com/dgrijalva/jwt-go once spf13/viper#1115 is merged
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels