You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Sep 11, 2024. It is now read-only.
Not possibe. firebase/php-jwt:6.x made such changes it is impossible to use it without breaking BC. See discussion at: #217
I really do dislike CVE-2021-46743 because vulnerability scanners tag it has critical even though there is no vulnerability. Even the report itself says: "NOTE: this provides a straightforward way to use the PHP-JWT library unsafely, but might not be considered a vulnerability in the library itself."
With firebase/php-jwt version 5.5 it is possible to mitigate the issue.
I had to update the interface of my library to allow for the workaround, by introducing a Secret object, which mimics what firebase/php-jwt did in v5.5. Maybe this will help.
I was also forced to bump the major version in order to mitigate the issue by-default, as they did in firebase/php-jwt version 6.
Can you help me update the dependencies? Gitlab SAST show me an error and I need update to firebase/php-jwt ^6
Thank you.
The text was updated successfully, but these errors were encountered: