microprofile-extensions / openapi-ext

Some extensions for MicroProfile OpenAPI
Apache License 2.0
23 stars 13 forks source link

Very old Swagger UI Version #47

Open Lars5678 opened 2 years ago

Lars5678 commented 2 years ago

Are you considering providing an update in the near future?

The current version uses Swagger UI 3.25.0 from January 2020, which in turn uses DOMPurify 2.0.7 from October 2019.

My OWASP Dependency Check tells me that there are at least seven security issues that have already been resolved (granted with a low severity).

It would be nice if there was an update to your library to bring Swagger UI and the JavaScript libraries used up to date.

phillip-kruger commented 2 years ago

Hi thanks for the issue, are you keen to do a PR?

simonst commented 7 months ago

are there any updates planned?

phillip-kruger commented 7 months ago

Nothing planned, but you are welcome to do a PR with the update and i'll do a release.