Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade swagger-ui from 3.25.3 to 3.27.0 #2

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade swagger-ui from 3.25.3 to 3.27.0.

merge advice

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 6 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2020-06-18.

The recommended version fixes:

Severity Issue Exploit Maturity
Insecure Defaults
SNYK-JS-SWAGGERUI-572012
No Known Exploit
Denial of Service (DoS)
SNYK-JS-AUTOLINKER-73494
No Known Exploit
Cross-site Scripting (XSS)
SNYK-JS-AUTOLINKER-564438
Proof of Concept
Release notes
Package name: swagger-ui
  • 3.27.0 - 2020-06-18

    3.27.0 (2020-06-18)

    Features

    • model view: hide applicable readOnly and writeOnly properties (#5832) (f8dd4e6)
    • model view Added onLoad()s and tweaker onToggle() to support ScrollTo functionality for Models (#5237)
    • Copy response to clipboard #4300 (#5278) (973e1f7)
    • Display example value in Swagger ReadOnly documentation mode (#4422) (ca1b19a)
    • swagger-ui-react: add displayOperationId config support (#5795) (bd1b297)

    Bug Fixes

    • remove clipboard inline svg from a file with SASS (#6148) (eeb0b73)
    • curlify agnostic to order of header values (#6152) (b86e8e9), closes #6082
    • Docker: case where SWAGGER_ROOT in conjunction with BASE_URL does not work (#6147)
    • Call DomPurify.addHook only if it exists (#5428)

    Docs

    • Docs: Demonstrate a simple Webpack setup (#5185)
  • 3.26.2 - 2020-06-12

    3.26.2 (2020-06-12)

    Bug Fixes

    • update corrupted swagger-client from v3.10.6 to v3.10.7
  • 3.26.1 - 2020-06-11

    3.26.1 (2020-06-11)

    ⚠️ This release includes a security update with Markdown render.

    Features

    • New OAUTH_SCOPES configuration property to select all/none/user_list to OAuth scopes popup (#6037) (275c8f2)
    • Docker New SWAGGER_JSON_URL option to allow remote urls from Docker (#6122)
    • Docker VALIDATOR_URL now has options to disable the validation badge (#5994)
    • Various style improvements (#6014) (#5578) (#5478)

    Bug Fixes

    • Markdown: render markdown in more secure way (a616cb4)
    • Docker allow local ref's to be served by nginx (#5565) (f353974)
    • Docker support variables in auth urls (#5913) (21f5149)
  • 3.26.0 - 2020-06-05

    3.26.0 (2020-06-05)

    Features

    • Allow to skip submitting empty values in form data (#5830) (b9b32c9)
    • Add empty data param to cURL if no POST request body was given (#6017)

    Bug Fixes

    • set default supportedSubmitMethods (#6030) (3b6942c)
    • OAS3 upload file when array items are type=string format=binary (#6040)
    • support generated curl for PUT and PATCH requests (#5960)
    • flaky test: bugs/4641 use wait on route alias (#6048) (5bbd3e7)

    Housekeeping

    • SwaggerClient version 3.10.6
    • dependency updates
  • 3.25.5 - 2020-05-28

    3.25.5 (2020-05-28)

    Bug Fixes

    • entries can now be generally used again as a key name. special handling of non-FormData entries removed (#6036) (68185dd), closes #6033
  • 3.25.4 - 2020-05-21

    3.25.4 (2020-05-21)

    Bug Fixes

    • bump swagger-client to version 3.10.4 and return back compatibility with node.js >= 4
    • allow entries as property name (#6025) (3a65070)
  • 3.25.3 - 2020-05-14

    3.25.3 (2020-05-14)

    Changelog

    • housekeeping: update release-it config
    • housekeeping: bump swagger-client version with package-lock (#6008)
    • housekeeping: update dev-e2e-cypress-open script name (#6005)

    Bug Fixes

from swagger-ui GitHub release notes
Commit messages
Package name: swagger-ui

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant