-
Notifications
You must be signed in to change notification settings - Fork 101
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix the vulnerability caused by swagger-ui #254
Comments
Cross-posting #250 (comment) Upgrading to The following issue is the biggest blocker:
The pull request also says:
I think this is no longer relevant, we are successfully using https://www.npmjs.com/package/swagger-ui-dist in LB4. |
Proposed by @bajtos:
|
It seems like the files where the vulnerability exists in Edit: if there are no objections, I'll close the issue but we can reopen it if needed. |
I was able to reproduce the issue on a LoopBack 3 application using |
Closing this issue as no vulnerabilities are reported when creating a new LoopBack 3 app or when doing |
Description
See PR #253, the vulnerability report requires an upgrade from
[email protected]
to[email protected]
.There is breaking change in [email protected] to support OpenAPI 3.0.0. We need to
swagger-ui
from 2 to 3.The text was updated successfully, but these errors were encountered: