Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump version of "github.com/golang-jwt/jwt/v4" to v4.4.3 #34292

Open
Bjyothi2023 opened this issue Nov 23, 2023 · 1 comment
Open

Bump version of "github.com/golang-jwt/jwt/v4" to v4.4.3 #34292

Bjyothi2023 opened this issue Nov 23, 2023 · 1 comment
Labels
bug new new issue not yet triaged v1.6 Issues (primarily bugs) reported against v1.6 releases

Comments

@Bjyothi2023
Copy link

Terraform Version

Terraform version 1.6.3

Terraform Configuration Files

NA

Debug Output

Security vulnerability "PRISMA-2022-0270" reported because of "github.com/golang-jwt/jwt/v4" version v4.4.2.
Fixed version available is v4.4.3
Requesting you to update "github.com/golang-jwt/jwt/v4" version from v4.4.2 to v4.4.3

Expected Behavior

Vulnerability scanner should not report PRISMA-2022-0270

Actual Behavior

Vulnerability scanner reporting PRISMA-2022-0270

Steps to Reproduce

By running twistlock security scanner over container installed with Terraform

Additional Context

No response

References

No response

@Bjyothi2023 Bjyothi2023 added bug new new issue not yet triaged labels Nov 23, 2023
@apparentlymart
Copy link
Member

Hi @Bjyothi2023,

According to the upstream issue golang-jwt/jwt#258, this vulnerability report is invalid. The upstream maintainers suggest that the new release does not change anything material about the code and instead they've just clarified the documentation to reflect correct vs. incorrect usage of the library, and so upgrading alone would not be sufficient if there was a problem here.

For our part, we will review our usage of this library to ensure we are not using it in the incorrect way that issue discusses.

@apparentlymart apparentlymart added the v1.6 Issues (primarily bugs) reported against v1.6 releases label Jan 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug new new issue not yet triaged v1.6 Issues (primarily bugs) reported against v1.6 releases
Projects
None yet
Development

No branches or pull requests

2 participants