Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[MAINT]/[SECURITY]: bump go-jose to from gopkg.in/square/go-jose.v2 to github.com/go-jose/go-jose/v3 #2343

Merged

Commits on Aug 9, 2024

  1. [MAINT]: bump go-jose to from gopkg.in/square/go-jose.v2 to github.co…

    …m/go-jose/go-jose/v3
    
    square/go-jose is not maintained anymore. Release v3 is the release to migrate to when you migrate to go-jose/go-jose.
    https://github.com/go-jose/go-jose/releases/tag/v3.0.0
    Release 4 contains breaking changes
    
    We bump to 3.0.3 because this contains the sec fix:
    Limit decompression output size to prevent a DoS. Backport from v4.0.1.
    
    closes: integrations#2341
    AtzeDeVries committed Aug 9, 2024
    Configuration menu
    Copy the full SHA
    84c2429 View commit details
    Browse the repository at this point in the history