-
Notifications
You must be signed in to change notification settings - Fork 32
Open
Description
This package is using an outdated version of firebase/php-jwt that has vulnerabilities.
Problem 1
- get-stream/stream is locked to version v7.1.0 and an update of this package was not requested.
- get-stream/stream v7.1.0 requires firebase/php-jwt ^v6.4.0 -> found firebase/php-jwt[v6.4.0, ..., v6.11.1] but these were not loaded, because they are affected by security advisories. To ignore the advisories, add ("PKSA-y2cr-5h3j-g3ys") to the audit "ignore" config. To turn the feature off entirely, you can set "block-insecure" to false in your "audit" config.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels