Description:
Our project depends on github.com/russellhaering/goxmldsig:v1.4.0, which includes a transitive dependency on github.com/beevik/etree:v1.4.1. The child component may not be the latest maintained version.
We request the maintainers to review and update github.com/beevik/etree to the latest stable release to ensure continued stability, compatibility, and security compliance.
Impact:
Potential maintenance or security concerns with older versions.
Risk of incompatibility with newer Go releases or dependent modules.
References:
Parent library: github.com/russellhaering/goxmldsig:v1.4.0
Child library: github.com/beevik/etree:v1.4.1