Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade swagger-ui from 5.11.0 to 5.15.1 #48

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dooman87
Copy link
Collaborator

@dooman87 dooman87 commented May 6, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade swagger-ui from 5.11.0 to 5.15.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 18 versions ahead of your current version.
  • The recommended version was released 25 days ago, on 2024-04-11.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Template Injection
SNYK-JS-DOMPURIFY-6474511
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Proof of Concept
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Proof of Concept
Permissive Cross-domain Policy with Untrusted Domains
SNYK-JS-UNDICI-6252336
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
No Known Exploit
Improper Access Control
SNYK-JS-UNDICI-6564963
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
No Known Exploit
Improper Authorization
SNYK-JS-UNDICI-6564964
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: swagger-ui from swagger-ui GitHub release notes
Commit messages
Package name: swagger-ui
  • 6160b10 refactor(json-schema-2020-12-samples): design formatAPI consistent with mediatypeAPI and encoderAPI (#9799)
  • 0f395c2 fix(spec): format validation errors for nested parameters (#9775)
  • 3b72ee1 refactor: consolidate all JSON Schema 5 rendering code into json-schema-5 plugin (#9798)
  • 46c849b docs(configuration): fix wrong syntaxHighlight option name (#9776)
  • 13aa3bf chore(release): cut the v5.15.0 release
  • 3bea389 fix(oas3): compensate for JSON Schemas left unresolved by swagger-client (#9794)
  • b6b0d28 fix(json-schema-2020-12-samples): apply string constraints sensibly (#9796)
  • 7db9c98 feat(json-schema-2020-12-sample): introduce option API (#9795)
  • 1267c04 chore(deps-dev): bump eslint-plugin-jest from 27.9.0 to 28.2.0 (#9793)
  • 6e91056 chore(deps): bump dompurify from 3.0.11 to 3.1.0 (#9789)
  • 111e420 fix(oas31): allow override names of top level schemas (#9787)
  • af538a3 chore(deps): bump dependabot/fetch-metadata from 1.6.0 to 2.0.0 (#9729)
  • 7bcf090 chore(release): cut the v5.14.0 release
  • a94dd28 fix(docker): fix CVE-2024-27983 related to Node.js (#9786)
  • ac0d2a3 refactor(syntax-highlighting): use component wrapping for syntax highlighting activation (#9784)
  • 7260005 feat: consolidate syntax highlighting code into standalone plugin (#9783)
  • f844319 chore(deps-dev): bump sass from 1.72.0 to 1.74.1 (#9781)
  • 4a5a879 chore(deps): bump swagger-client from 3.26.4 to 3.26.5 (#9780)
  • 086ffeb chore(deps-dev): bump @ babel/core from 7.24.3 to 7.24.4 (#9778)
  • 5e95ffa chore(deps): bump @ babel/runtime-corejs3 from 7.24.1 to 7.24.4 (#9779)
  • cf13000 chore(deps-dev): bump @ babel/preset-env from 7.24.3 to 7.24.4 (#9777)
  • 3110954 chore(deps-dev): bump postcss-preset-env from 9.5.3 to 9.5.4 (#9773)
  • a0b164b chore(deps-dev): bump cypress from 13.7.1 to 13.7.2 (#9772)
  • 1735ea8 chore(deps-dev): bump postcss-preset-env from 9.5.2 to 9.5.3 (#9770)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants