← All tasks
javascriptauth0/node-jsonwebtoken #465Not a task: already works

Security vulnerability caused by jws@3.1.4

envgap__auth0__node-jsonwebtoken-465

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
cd33cc81f06068b9df6c224d300dc6f70d8904ab
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

auth0/node-jsonwebtoken #465 · read the original issue
In our project, Snyk reported `jws@3.1.4` as a dependency with a known security vulnerability, because it depends on `jwa@1.1.5`.



The latest version of `jws` (3.1.5), no longer depends on the vulnerable dependency of `base64url@2.0.0`.



More info about the high severity vulnerability in `jws@3.1.4` can be found at https://snyk.io/vuln/npm:base64url:20180511
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]