twilio / twilio-node

Node.js helper library
MIT License
1.37k stars 497 forks source link

Can you please update jsonwebtoken to version 9.0.0? #900

Closed salsabea closed 1 year ago

salsabea commented 1 year ago

Issue Summary

jsonwebtoken has 4 critical vulnerabilities as mentioned in https://github.com/auth0/node-jsonwebtoken/security/advisories and these are fixed in version 9.0.0

Technical details:

shrutiburman commented 1 year ago

Duplicate issue https://github.com/twilio/twilio-node/issues/846 Please refer that for details.

vetlevo commented 1 year ago

I think they were gonna release v4 soon (today as per last comment I saw). However, I'm not sure if that was a solid date or anything. It's a bit difficult to know when there is no public release schedule. jsonwebtoken is updated in v4 as far as I know.

childish-sambino commented 1 year ago

Yes, it's today in a few hours.