Is It Dead Yet? dependency vitals

github.com/dgrijalva/jwt-goGo

Signals · last 1 check

Commits 90d
0
Open issues
99
Unanswered
26
Contributors
0
What the project says about itself
  • Open milestones4.0.0 20/21 done; 4.1.0 1/4 done. Source: the repository's milestones.
  • OpenSSF Scorecard2.8 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-04 first verdict: abandoned
Where to go instead 1
  1. github.com/golang-jwt/jwt/v5 Drop-in replacement

    Community successor; the original is abandoned and carries a known CVE

    Change the import path and module requirement — the v5 API is source-compatible for common use.

    Checked by hand.

Badge

maintenance: abandoned

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/go/github.com/dgrijalva/jwt-go.svg)](https://isitdeadyet.dev/go/github.com/dgrijalva/jwt-go)

Watch it

Get told when github.com/dgrijalva/jwt-go changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.