Skip to content

updates to swagger-parser 2.0.28#10819

Closed
benzvan wants to merge 2 commits into
OpenAPITools:masterfrom
benzvan:master
Closed

updates to swagger-parser 2.0.28#10819
benzvan wants to merge 2 commits into
OpenAPITools:masterfrom
benzvan:master

Conversation

@benzvan

@benzvan benzvan commented Nov 9, 2021

Copy link
Copy Markdown
Contributor

Updates swagger parser to mitigate vulnerability in dependent httpclient library.
#10818

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package 
    ./bin/generate-samples.sh
    ./bin/utils/export_docs_generators.sh
    
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    For Windows users, please run the script in Git BASH.
  • File the PR against the correct branch: master (5.3.0), 6.0.x
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

@benzvan

benzvan commented Nov 9, 2021

Copy link
Copy Markdown
Contributor Author

I believe the build failure to be transient network issues but don't have permission to re-run it.

nullable: true
type: string
nullableWithNullDefault:
default: "null"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@benzvan thanks for the PR. Is this a regression? Did the changelog mention anything related to this change?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That must have crept in when I ran the generator scripts. I didn't notice any output related to it.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Though reading it maybe it's just being more explicit? Seems like it's reasonable for a nullableWithNullDefault to have a default of null

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not familiar enough with the upstream project to speak intelligently to the change though. I just know it used to use a 4-year-old version of httpclient. :-D

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@wing328 any followup thoughts? The only line I manually changed was the version number for swagger-parser.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Poking around the swagger-parser notes I see this could be related but I don't know enough about the code to be sure.
https://github.com/swagger-api/swagger-parser/pull/1600/files

@wing328

wing328 commented Jan 24, 2022

Copy link
Copy Markdown
Member

@benzvan thanks again for the PR. I've filed #11388 to upgrade to 2.0.29 instead so closing this one.

@wing328 wing328 closed this Jan 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants