microprofile-extensions / openapi-ext

Some extensions for MicroProfile OpenAPI
Apache License 2.0
22 stars 13 forks source link

Very old Swagger UI Version #47

Open LarsBrenker opened 1 year ago

LarsBrenker commented 1 year ago

Are you considering providing an update in the near future?

The current version uses Swagger UI 3.25.0 from January 2020, which in turn uses DOMPurify 2.0.7 from October 2019.

My OWASP Dependency Check tells me that there are at least seven security issues that have already been resolved (granted with a low severity).

It would be nice if there was an update to your library to bring Swagger UI and the JavaScript libraries used up to date.

phillip-kruger commented 1 year ago

Hi thanks for the issue, are you keen to do a PR?

simonst commented 3 months ago

are there any updates planned?

phillip-kruger commented 3 months ago

Nothing planned, but you are welcome to do a PR with the update and i'll do a release.