Skip to content
This repository has been archived by the owner on Oct 5, 2021. It is now read-only.

[Snyk] Upgrade swagger-parser from 4.0.0-beta.2 to 4.1.0 #83

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade swagger-parser from 4.0.0-beta.2 to 4.1.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 4 versions ahead of your current version.
  • The recommended version was released 3 years ago, on 2018-04-11.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Arbitrary Code Execution
SNYK-JS-JSYAML-174129
619/1000
Why? Has a fix available, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JS-JSYAML-173999
619/1000
Why? Has a fix available, CVSS 8.1
No Known Exploit
Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
619/1000
Why? Has a fix available, CVSS 8.1
No Known Exploit
Regular Expression Denial of Service (ReDoS)
npm:validator:20180218
619/1000
Why? Has a fix available, CVSS 8.1
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: swagger-parser from swagger-parser GitHub release notes
Commit messages
Package name: swagger-parser
  • 07575d7 release v4.1.0
  • 47d1baa updated dependencies
  • 5c5eea6 Removed `Array.find()` from test code, since it isn't supported by IE
  • e87a254 re-generated the github-pages content
  • bbf1c79 either run the Mocha (Node.js) tests OR the Karma (web browser) tests on each CI instance, not both
  • e62c75f some of the "real world" APIs fail validation on web browsers (other than Chrome) due to unsupported RegExp syntax
  • 72398ed removed some "known API errors" that are no longer valid
  • 1b73447 Merge branch 'marcelstoer-master'
  • e92ad70 fixed a typo
  • f7b55d0 Merge branch 'master' of https://github.com/marcelstoer/swagger-parser into marcelstoer-master
  • 20f7cfc modified test fixtures to use karma-host-environment, so they work in Node and browsers
  • 88badf8 added karma-host-environment to simplify testing across Node and browsers
  • 6ba7a1a give up after 3 retries, rather than throwing an error
  • 2bcbdad fixed a bug in the retry logic
  • fad3d45 added retry logic to the "real world" tests, to handle download failures
  • fc1b558 handled invalid regular expressions in some AWS APIs
  • f40a30a updated dependencies
  • 08db4e3 Run IE 11 tests on Windows 10
  • 13137c6 Added Node v9 to the CI matrix
  • 9368f37 fixed the Codacy badge in the ReadMe
  • 98c0746 fixed some minor bugs in `validateRequiredPropertiesExist()`
  • 764bd60 Refactored the "real world" tests to make the error-handling logic more tolerant to problematic API definitions
  • 26d8804 excluded an API that was causing erroneous test failures
  • 086fc2b Refactored tests to account for a recent bug fix in json-schema-ref-parser (see https://github.com/BigstickCarpet/json-schema-ref-parser/commit/a95cf50fdf16c864cc1c18d2021d9ce3ec35f5de)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant