-
Notifications
You must be signed in to change notification settings - Fork 101
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update swagger-ui version #250
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Guessing 3.x has breaking changes?
Upgrading to The following issue is the biggest blocker:
The pull request also says:
I think this is no longer relevant, we are successfully using https://www.npmjs.com/package/swagger-ui-dist in LB4. |
@@ -39,6 +39,6 @@ | |||
"lodash": "^4.17.5", | |||
"loopback-swagger": "^5.0.0", | |||
"strong-globalize": "^4.1.1", | |||
"swagger-ui": "^2.2.5" | |||
"swagger-ui": "^2.2.10" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The pull request mentions upgrade to swagger-ui@3
, but this change is upgrading only to 2.2.10
. Since we are already using ^
version specifier, such change is not necessary at all - npm
is going to install 2.2.10
anyway.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The reason I submit this PR is to get rid of the vulnerabilities. I thought the warnings go away when I change the version number. Let me try that again. thanks!
Based on @bajtos' above comment and #254 is opened to investigate the work involved in upgrading |
Description
When running
npm i
in this module, I got the following warning:This PR will update swagger-ui version in package.json.