Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump up libraries to the latest version #426

Merged
merged 1 commit into from
Oct 10, 2022
Merged

Bump up libraries to the latest version #426

merged 1 commit into from
Oct 10, 2022

Conversation

hackerwins
Copy link
Member

@hackerwins hackerwins commented Oct 10, 2022

What this PR does / why we need it:

Bump up libraries to the latest version

Replace github.com/dgrijalva/jwt-go with github.com/golang-jwt/jwt
https://nvd.nist.gov/vuln/detail/CVE-2020-26160

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?:


Additional documentation:


Checklist:

  • Added relevant tests or not required
  • Didn't break anything

Replace github.com/dgrijalva/jwt-go with github.com/golang-jwt/jwt
https://nvd.nist.gov/vuln/detail/CVE-2020-26160
@hackerwins hackerwins marked this pull request as ready for review October 10, 2022 14:21
@hackerwins hackerwins merged commit 002962d into main Oct 10, 2022
@hackerwins hackerwins deleted the bumpup-libs branch October 10, 2022 14:21
@jongwooo jongwooo mentioned this pull request Oct 19, 2023
hackerwins pushed a commit that referenced this pull request Nov 22, 2023
Updating manually, like in #426, #641, requires checking for
dependency updates every time. Automating this with Dependabot will
save us a lot of work.

If we set open-pull-requests-limit to 0, we can only get security
updates. Dependabot will check updates every Monday if
`schedule.interval` is set to weekly.
hackerwins pushed a commit that referenced this pull request Nov 23, 2023
Updating manually, like in #426, #641, requires checking for
dependency updates every time. Automating this with Dependabot will
save us a lot of work.

If we set open-pull-requests-limit to 0, we can only get security
updates. Dependabot will check updates every Monday if
`schedule.interval` is set to weekly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant