-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
cve-2020-26160 vulnerability in dgrijalva/jwt-go #1003
Comments
I ran
@HadwaAbdelhalem do you think we can bump the Azure dependencies in terratest to latest version? Do you know if this is addressed in the newer versions of the SDK? |
Hi @yorinasub17 investigating it now |
Some dependencies have been updated to remove reliance on this, but others still need to be updated. |
Ok I went through the dependency graph using I think we made a best effort attempt between #1008 and #1009 to avoid this reporting, but I don't see how it is practically feasible to avoid this. FWIW, I don't see this as a huge issue given that:
Going to close this as something we won't address directly. Happy to reconsider reopening if someone can comment on the relevance of the vulnerability in relation to terratest as a testing library. |
Just reopening this since that whole project is archived now : dgrijalva/jwt-go#462 |
There is a CVE (cve-2020-26160) detected in the library dgrijalva/jwt-go used by one of required library that you use (present in the go.sum file).
warning from github:
The text was updated successfully, but these errors were encountered: