Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release package with z-schema v5+ #177

Closed
wronrohn opened this issue Jul 20, 2021 · 4 comments
Closed

Release package with z-schema v5+ #177

wronrohn opened this issue Jul 20, 2021 · 4 comments

Comments

@wronrohn
Copy link

Currently, there are vulnerabilities in the validator package within the v4 of z-schema. Would it be possible to have a new release supporting z-schema v5+?

@jonrober-80
Copy link

It looks like the work has already been done as PR #166 was merged. It just hasn't been included in a release yet. @philsturgeon @JamesMessinger is this something that you're able help with?

@jonrober-80
Copy link

@JamesMessinger @philsturgeon are you able to release a new version of swagger-parser or share the plans for when the next release of will be available? As mentioned above, there is a security vulnerability in the z-schema library (which was already fixed by PR #166) that consumers are keen to pick up a fix for.

@philsturgeon
Copy link
Member

@jonrober-80 When #173 is unblocked through #178 or #175 or whichever PR makes the build pass we can release. Cannot release without tests passing.

@philsturgeon
Copy link
Member

Done, 10.0.3 has z-schema v5+. Sorry for the delay, I was in the middle of mountains/desert for quite some time. Back now.

The browser tests were failing but node tests are passing, so I'll look into that, get OAS 3.1 updated, and get circular dependencies fixed with #173 too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants