θΏ™ζ˜―indexlocζδΎ›ηš„ζœεŠ‘οΌŒδΈθ¦θΎ“ε…₯任何密码
Skip to content

Conversation

@timothycarambat
Copy link
Member

Pull Request Type

  • ✨ feat
  • πŸ› fix
  • ♻️ refactor
  • πŸ’„ style
  • πŸ”¨ chore
  • πŸ“ docs

Relevant Issues

connect #1969

What is in this change?

Resolves Reported CVE from GHSA-8cf7-32gw-wr33
The current impact is unaffected as we use JWT and HS256 for signing and verification of tokens.

Bumping this package should make the image compliant and have no impact on user tokens or instances with passwords/multi-user already set.

Additional Information

Developer Validations

  • I ran yarn lint from the root of the repo & committed changes
  • Relevant documentation has been updated
  • I have tested my code functionality
  • Docker build succeeds locally

@timothycarambat timothycarambat merged commit 88e2209 into master Jul 25, 2024
@timothycarambat timothycarambat deleted the jwt-bump branch July 25, 2024 18:03
cabwds pushed a commit to cabwds/anything-llm that referenced this pull request Jul 3, 2025
* bump `jsonwebtoken` version

* update dev build branch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants