Mermade / widdershins

OpenAPI / Swagger, AsyncAPI & Semoasa definitions to (re)Slate compatible markdown
https://mermade.github.io/reslate
MIT License
1.49k stars 322 forks source link

Vulnerability for package ajv@5.5.2 in widdershins #498

Open so-amuk opened 2 years ago

so-amuk commented 2 years ago

Discussed in https://github.com/Mermade/widdershins/discussions/497

ajv is dependent on widdershins and we are using the latest version of widdershins@4.0.1.

Originally posted by **so-amuk** February 21, 2022 https://snyk.io/test/npm/widdershins Please publish latest version of widdershins as we are getting vulnerability issue with this package ajv@5.5.2. Currently I have installed widdershins@4.0.1. ![image](https://user-images.githubusercontent.com/39334174/154898187-a5dbc296-ef64-4b7c-a51d-27b776e3c891.png) ``` [](https://snyk.io/test/npm/widdershins#SNYK-JS-AJV-584908)Prototype Pollution Vulnerable module: [ajv](https://www.npmjs.com/package/ajv) Introduced through: swagger2openapi@6.2.3 Detailed paths Introduced through: widdershins@4.0.1 › swagger2openapi@6.2.3 › oas-validator@4.0.8 › ajv@5.5.2 Remediation: Upgrade to swagger2openapi@7.0.0. ``` Please help us to resolve vulnerability issue with ajv package.