request for security bugfix release
Open
- Dominant language
- Rust
- Stars
- 1.4k
- Forks
- 567
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 93
Description
jsonwebtoken < v10.3.0 have a security vuln of Medium severity [CVE-2026-25537](https://github.com/advisories/GHSA-h395-gr6q-cpjc)
It is transitive dependency of opendal 55. We migrated to opendal 56 in #2401
It would be nice to have a bugfix release with those changes ( and possibly other RUSTSEC fixes? )
thanks!
Contributor guide
Research direction
Start by reviewing the opendal 56 migration in issue #2401 and the repository's release process. Confirm that a bugfix release includes the dependency update addressing CVE-2026-25537; whether to include other RUSTSEC fixes remains an open question.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100