Closed dependabot[bot] closed 2 years ago
@henri-hulski Do you still use this library? We have a security issue with pyjwt
, see https://github.com/morepath/more.jwtauth/security
Updating the library breaks this library. I do not have the resources to dig deeper.
This leads us back to the question - do you still use this library and do you have the time to make this library safe again?
If not we should discuss what we could do to prevent harm - maybe adding a big red note on the readme? Maybe archiving this library as unmaintained?
Actually just reading about it exactly in this moment. Just take a look at the changes in pyjwt. I think I will fix it, as this was the first python plug-in I created so I want it to be fixed.
May 25, 2022 07:16:23 Jürgen Gmach @.***>:
@henri-hulski[https://github.com/henri-hulski] Do you still use this library? We have a security issue with pyjwt, see https://github.com/morepath/more.jwtauth/security
Updating the library breaks this library. I do not have the resources to dig deeper.
This leads us back to the question - do you still use this library and do you have the time to make this library safe again?
If not we should discuss what we could do to prevent harm - maybe adding a big red note on the readme? Maybe archiving this library as unmaintained?
— Reply to this email directly, view it on GitHub[https://github.com/morepath/more.jwtauth/pull/18#issuecomment-1136735880], or unsubscribe[https://github.com/notifications/unsubscribe-auth/AB2EJ4A26FZLUNQ7LBI7LYDVLWZSPANCNFSM5W3J6HRA]. You are receiving this because you were mentioned.[Tracking image][https://github.com/notifications/beacon/AB2EJ4HMFZJ36ZE37KDW7RDVLWZSPA5CNFSM5W3J6HRKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOIPATNCA.gif]
Looks like pyjwt is up-to-date now, so this is no longer needed.
Bumps pyjwt from 1.7.1 to 2.4.0.
Release notes
Sourced from pyjwt's releases.
... (truncated)
Changelog
Sourced from pyjwt's changelog.