jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.
https://github.com/panva/jose/discussions/813
https://gist.github.com/ZupeiNie/705a606fbb99f3bb8c9b51e5bc13c91d