GetShopTV / swagger2

Swagger 2.0 data model.
http://hackage.haskell.org/package/swagger2
BSD 3-Clause "New" or "Revised" License
74 stars 59 forks source link

Aeson security Issue (Servant dependency) #226

Closed akhesaCaro closed 3 years ago

akhesaCaro commented 3 years ago

Hi swagger2 maintainers,

I am a servant maintainer and I am trying to bump aeson following the security issue Servant has a dependency with swagger2 but aeson has been bounded below 1.6

Would it be possible to relax constraint for aeson (>= 2.0.0.0)?

fizruk commented 3 years ago

Hi, I'm sorry for a late reply, we haven't been very active on the open source front lately. However, @swamp-agr has volunteered to help with this :)