Skip to content

Backport of [NET-6617] security: Bump github.com/golang-jwt/jwt/v4 to 4.5.0 into release/1.15.x#19739

Merged
zalimeni merged 1 commit into
release/1.15.xfrom
backport/zalimeni/net-6617-bump-golang-jwt-prisma/openly-able-honeybee
Nov 27, 2023
Merged

Backport of [NET-6617] security: Bump github.com/golang-jwt/jwt/v4 to 4.5.0 into release/1.15.x#19739
zalimeni merged 1 commit into
release/1.15.xfrom
backport/zalimeni/net-6617-bump-golang-jwt-prisma/openly-able-honeybee

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #19705 to be assessed for backporting due to the inclusion of the label backport/1.15.

The below text is copied from the body of the original PR.


This version is accepted by Prisma/Twistlock, resolving scan results for issue PRISMA-2022-0270. Chosen over later versions to avoid a major version with breaking changes that is otherwise unnecessary.

Note that in practice this is a false positive (see golang-jwt/jwt#258), but we should update the version to aid customers relying on scanners that flag it.

Description

Resolves proprietary scanner reported vulnerability, and #19661.

I've reviewed the changelog from 4.2.0 to 4.5.0 and don't see any evidence of breaking changes.

Testing & Reproduction steps

Unit tests should continue to pass.

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/zalimeni/net-6617-bump-golang-jwt-prisma/openly-able-honeybee branch 2 times, most recently from 7ac7743 to 33840e1 Compare November 27, 2023 16:03
@github-actions github-actions Bot added the pr/dependencies PR specifically updates dependencies of project label Nov 27, 2023
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@zalimeni zalimeni enabled auto-merge (squash) November 27, 2023 16:04
@vercel vercel Bot temporarily deployed to Preview – consul November 27, 2023 16:09 Inactive
@zalimeni zalimeni merged commit 88227e4 into release/1.15.x Nov 27, 2023
@zalimeni zalimeni deleted the backport/zalimeni/net-6617-bump-golang-jwt-prisma/openly-able-honeybee branch November 27, 2023 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependencies PR specifically updates dependencies of project

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants