Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to jsonwebtoken 9.0.0 #31

Closed
fabge opened this issue Jan 2, 2023 · 1 comment
Closed

Upgrade to jsonwebtoken 9.0.0 #31

fabge opened this issue Jan 2, 2023 · 1 comment

Comments

@fabge
Copy link

fabge commented Jan 2, 2023

Hello,
any chance, the package will be updated to use jsonwebtoken 9.0.0 in the near future?
The current version shows a critical vulnerarbility regarding jwt.verify()

Dependabot has already created a PR with the proposed changes. A test fails though as unverified verify() calls are forbidden since 9.0.0.

Thank you!

@MarioArnt
Copy link
Owner

MarioArnt commented Aug 8, 2023

Hi,

Thanks for reporting this :)

The issue was solved with #32

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants