Previously we did this split to avoid test dependencies have the CVE but it got recently reintroduced as part of this PR: https://github.com/nats-io/jwt/pull/165/files#diff-877327aee10f05ed1580cbd2b4ff4a7130b186a82c4044a5f9a1f4448abb7404R6
Getting reports that the project is being flagged for CVEs so I think we ought to release the v1.3.0 version without the CVE to prevent this further.