Skip to content

Conversation

@JoelLefkowitz
Copy link

@JoelLefkowitz JoelLefkowitz commented Mar 10, 2025

The swagger-ui-dist package before v4.1.3 has vulnerabilities: CVE-2023-52425, CVE-2023-52426, CVE-2024-27983, CVE-2023-32313, CVE-2023-32314.

The package drf-yasg was a consumer of swagger-ui-dist and was impacted by these vulnerabilities. In #4837 a fork was used to replace the package source.

The vulnerable dependencies have since been bumped in drf-yasg and the fixed version is available from release 1.21.10

To continue to receive future vulnerability fixes we can add drf-yasg back as the upstream for this repository.

@netlify
Copy link

netlify bot commented Mar 10, 2025

👷 Deploy request for heartex-docs pending review.

Visit the deploys page to approve it

Name Link
🔨 Latest commit 8770f67

@netlify
Copy link

netlify bot commented Mar 10, 2025

👷 Deploy request for label-studio-docs-new-theme pending review.

Visit the deploys page to approve it

Name Link
🔨 Latest commit 8770f67

@JoelLefkowitz JoelLefkowitz changed the title Revert to drf-yasg upstream now that CVE-2021-46708 is resolved fix: Revert to drf-yasg upstream now that CVE-2021-46708 is resolved Mar 10, 2025
@JoelLefkowitz JoelLefkowitz changed the title fix: Revert to drf-yasg upstream now that CVE-2021-46708 is resolved fix: Revert to drf-yasg upstream now that vulnerabilities are resolved Mar 13, 2025
@robot-ci-heartex
Copy link
Collaborator

This PR is stale because it has been open 45 days with no activity. Remove stale label or comment or this will be closed in 10 days.

@robot-ci-heartex
Copy link
Collaborator

This PR was closed because it has been stalled for 10 days with no activity.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants