Upgrade org.json transitive dependency to latest
envgap__jwtk__jjwt-770
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
847ad1332cd0afe7460a9eecec582621f10e9ba1- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
jwtk/jjwt #770 · read the original issue
**Describe the bug** Vulnerability in org.json package. More details here https://nvd.nist.gov/vuln/detail/CVE-2022-45688 https://github.com/stleary/JSON-java/issues/708 They have released a new version yesterday, is it possible for you to upgrade and release a new version of jjwt ? https://github.com/stleary/JSON-java/releases/tag/20230227
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]