GoogleCloud - prismacloud raising a vulnerability due to JWT-GO dependency on old version

We are currently using google-cloud NPM package in our applications, however, we use prismacloud to scan our containers to find vulnerabilities.

Prismacloud is complaining that we are using an indirect reference to JWT-GO package 3.2.0, however, we should be referencing 4.0.0-preview1

It seems google cloud npm package is referencing the old versions yet. Any plans to upgrade it? Or any directions?

0 0 83
0 REPLIES 0