bcgov / nr-forests-access-management

Authorization solution for BC natural resource sector
Apache License 2.0
8 stars 2 forks source link

Dependabot Security Vulnerability: Switch Outdated Python Package "python-jose" #1398

Open ianliuwk1019 opened 1 month ago

ianliuwk1019 commented 1 month ago

Describe the task Dependabot has several security alerts for Python package: "python-jose" on version 3.3.0 or lower. (reported created 3 weeks ago from May 17, 2024) image

As of today, version 3.3.0 is the latest, but seems old (it was released Jun 4, 2021), and FAM is using this version. image

Unless there will be a coming fix version for this "python-jose", we probably need to replace this package with alternative.

Acceptance Criteria

Additional context

ianliuwk1019 commented 3 weeks ago

man... the replacement might not be easy and pretty....

ianliuwk1019 commented 2 weeks ago

Create a new ticket to separately address the complexity for replacing "python-jose" on BCSC part #1454 .