go-jose version 3.0.3 has a fix for another [security vulnerability](https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g), please upgrade. Is containers/ocicrypt not set up for dependabot?