-
Hi, we're dependent on a library that uses Jose 2.0.6, and security scanning software is popping these three CVEs. The version flag is <3.11.4, which will defacto include all of 2.x.x, so I'm thinking this is a false positive given 2.0.6 was published after 3.11.4, but wanted to check and get it sorted out. |
Beta Was this translation helpful? Give feedback.
Answered by
panva
Mar 16, 2023
Replies: 1 comment 5 replies
-
Your security scanning is wrong. Those three CVEs are not for the "jose" library but for runtime specific packages. 2.0.6 is fine. |
Beta Was this translation helpful? Give feedback.
5 replies
Answer selected by
Lomilar
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Your security scanning is wrong. Those three CVEs are not for the "jose" library but for runtime specific packages. 2.0.6 is fine.