dep: update golang-jwt to v4.5.1#2700
Conversation
Signed-off-by: inge4pres <fgualazzi@gmail.com>
|
Hi @inge4pres, Sorry the response is into #2699 |
|
Because there will be being stable and not breaking things is one of the most important feature of Go. In comparison to Javascript ecosystem Go is a bliss to maintain older applications. I very much want Echo to honor this tradition as much as we can - but CVEs pop up every other year with JWT. |
|
Superseded by #2701 |
Fixes #2699
We want to avoid a known vulnerability in golang-jwt library is flagged as a security concern when using echo as a framework in our applications.
Tests are passing locally with the new version.