Security vulnerability caused by jws@3.1.4
envgap__auth0__node-jsonwebtoken-465
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
cd33cc81f06068b9df6c224d300dc6f70d8904ab- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
auth0/node-jsonwebtoken #465 · read the original issue
In our project, Snyk reported `jws@3.1.4` as a dependency with a known security vulnerability, because it depends on `jwa@1.1.5`. The latest version of `jws` (3.1.5), no longer depends on the vulnerable dependency of `base64url@2.0.0`. More info about the high severity vulnerability in `jws@3.1.4` can be found at https://snyk.io/vuln/npm:base64url:20180511
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]