github.com/square/go-jose

govv2.6.0+incompatible

An implementation of JOSE standards (JWE, JWS, JWT) in Go

License Apache-2.0permissive31 versions55 maintainers0 deps1,959 weekly dl
square/go-jose
41
/ 100
Health
safe to use

github.com/square/[email protected]+incompatible is safe to use (health: 41/100)

Update to >= 4.0.5 to fix known vulnerabilities

Health breakdown0 – 100
0/25
maintenance
6/20
popularity
23/25
security
12/15
maturity
0/15
community
Vulnerabilities
4
1 medium3 low
Advisories (4)
SeverityIDSummaryFixed in
mediumGO-2023-2334Decryption of malicious PBES2 JWE objects can consume unbounded system resources2.6.2
unknownCVE-2016-9123Integer overflow in github.com/square/go-jose0.0.0-20160903044734-789a4c4bd4c1
unknownGHSA-2c7c-3mj9-8fqhDenial of service via decryption of malicious PBES2 JWE objects in github.com/go-jose/go-jose/v33.0.1
unknownCVE-2025-27144DoS in go-jose Parsing in github.com/go-jose/go-jose4.0.5

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/square/go-jose

Last updated · 2021-05-29T01:40:59Z