-
Notifications
You must be signed in to change notification settings - Fork 27
Closed
Description
There is a CVE in go-jose v2.6.3
Our project depends on openziti sdk-golang, so this dependency is included
Line 87 in d060e6e
gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect |
Please see more details from the dependabot security adviosry
https://www.mend.io/vulnerability-database/CVE-2025-27144?utm_source=JetBrains
Please see if you can upgrade to the latest go-jose lib in v4
https://github.com/go-jose/go-jose
Metadata
Metadata
Assignees
Labels
No labels