Hi Nobuhiro,
On Tue, Apr 21, 2020 at 11:09 AM Shengjing Zhu wrote:
[...]
> src:golang-github-dgrijalva-jwt-go/3.2.0-1 has been uploaded to archive
> for a long time. It's time to retire this
> golang-github-dgrijalva-jwt-go-v3 package.
>
> The following packages have direct build-depends on
>
On Tue, Apr 21, 2020 at 4:41 PM Pirate Praveen wrote:
[...]
> >Following packages may have patch to use github.com/dgrijalva/jwt-go-v3
> >import path.
> >
> ># https://codesearch.debian.net/search?q=jwt-go-v3=1=1
Seems this causes a lot of false positives.
On 2020, ഏപ്രിൽ 21 8:37:36 AM IST, Shengjing Zhu wrote:
>Source: golang-github-dgrijalva-jwt-go-v3
>Severity: normal
>Control: affects -1 go-cve-dictionary golang-github-go-kit-kit
>golang-github-azure-go-autorest golang-github-labstack-echo.v3 etcd
>goval-dictionary influxdb vuls
Source: golang-github-dgrijalva-jwt-go-v3
Severity: normal
Control: affects -1 go-cve-dictionary golang-github-go-kit-kit
golang-github-azure-go-autorest golang-github-labstack-echo.v3 etcd
goval-dictionary influxdb vuls golang-github-labstack-echo.v2
src:golang-github-dgrijalva-jwt-go/3.2.0-1