-
-
Notifications
You must be signed in to change notification settings - Fork 472
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Replace issue.go dependency on archived project github.com/fatih/structs #413
Comments
Hi! Thank you for taking the time to create your first issue! Really cool to see you here for the first time. Please give us a bit of time to review it. |
Thanks for bringing this to our attention. I'll take a look this evening. |
@allisonsierra Is there a CVE associated with this issue that would require an update? If you would like to submit a PR to replace the use of the |
There's no current CVE I'm aware of with the |
Hey, I am very sorry that this issue has been open for a long time with no final solution. We work on this project in our spare time, and sometimes, other priorities take over. This is the typical open source dilemma. However, there is news: We are kicking off v2 of this library 🚀To provide visibility, we created the Road to v2 Milestone and calling for your feedback in #489 The development will take some time; however, I hope you can benefit from the changes. What does this mean for my issue?We will work on this issue indirectly. Final wordsThanks for using this library. |
Is your feature request related to a problem? Please describe.
issue.go currently imports the
github.com/fatih/structs
module which is an archived project no longer receiving maintenance updates. The last update to the project was over 3 years ago. This is causing dependency scanning software I am using (Sonatype IQ) to flag go-jira as a potential security risk.Describe the solution you'd like
Replace the dependency on
github.com/fatih/structs
using the standard library. I only see this dependency being used once here.Describe alternatives you've considered
Find an active project to use in place of
github.com/fatih/structs
that provides the same functionalityAdditional context
The text was updated successfully, but these errors were encountered: