Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a new release containing jose 2.0.6 #325

Closed
hatzz opened this issue Sep 22, 2022 · 4 comments · Fixed by #330
Closed

Create a new release containing jose 2.0.6 #325

hatzz opened this issue Sep 22, 2022 · 4 comments · Fixed by #330
Labels

Comments

@hatzz
Copy link

hatzz commented Sep 22, 2022

Currently jose@2.0.6 is in the master branch in this repository but a new release has not yet come out. I am getting npm audit issues from jwks-rsa@2.1.4 which still depends on jose@2.0.5.

When will a new release come?

@adamjmcgrath
Copy link
Member

Hi @hatzz - We'll do a release shortly.

The jose version specified in the package for the current release is ^2.0.5 - which means you can install the latest 2.x jose release (eg 2.0.6) along with this package. So you should not be blocked by a release, updating your package-lock (by running npm audit --fix) will resolve your issue.

@hatzz
Copy link
Author

hatzz commented Sep 22, 2022

Alright i will do that in the mean time. Thanks!

@mboaventura
Copy link

mboaventura commented Oct 6, 2022

Hi @adamjmcgrath,
Is create a new release with >=3.11.4 which solve those vulns CVE-2021-29444, CVE-2021-29445, CVE-2021-29446 and CVE-2022-36083
Thanks in advance.

@adamjmcgrath
Copy link
Member

Hi @mboaventura - see #316 (comment) those CVE's are for other variants of jose. The variant of jose we use has been patched for the vulnerability you're specifying

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants