Skip to content

chore(deps): bump uuid to the latest#10907

Open
cka121 wants to merge 1 commit into
masterfrom
fix/uuid-missing-buffer-bounds-check
Open

chore(deps): bump uuid to the latest#10907
cka121 wants to merge 1 commit into
masterfrom
fix/uuid-missing-buffer-bounds-check

Conversation

@cka121
Copy link
Copy Markdown
Contributor

@cka121 cka121 commented May 26, 2026

This PR bumps uuid to the latest version
https://github.com/swagger-api/swagger-ui/security/dependabot/239

Description

Motivation and Context

How Has This Been Tested?

Screenshots (if appropriate):

Checklist

My PR contains...

  • No code changes (src/ is unmodified: changes to documentation, CI, metadata, etc.)
  • Dependency changes (any modification to dependencies in package.json)
  • Bug fixes (non-breaking change which fixes an issue)
  • Improvements (misc. changes to existing features)
  • Features (non-breaking change which adds functionality)

My changes...

  • are breaking changes to a public API (config options, System API, major UI change, etc).
  • are breaking changes to a private API (Redux, component props, utility functions, etc.).
  • are breaking changes to a developer API (npm script behavior changes, new dev system dependencies, etc).
  • are not breaking changes.

Documentation

  • My changes do not require a change to the project documentation.
  • My changes require a change to the project documentation.
  • If yes to above: I have updated the documentation accordingly.

Automated tests

  • My changes can not or do not need to be tested.
  • My changes can and should be tested by unit and/or integration tests.
  • If yes to above: I have added tests to cover my changes.
  • If yes to above: I have taken care to cover edge cases in my tests.
  • All new and existing tests passed.

Copy link
Copy Markdown
Contributor

@glowcloud glowcloud left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems fine to me for now, we could try updating cypress to the latest, as it was addressed in its dependency, but sockjs hasn't released the fix yet 😕

Comment thread package-lock.json
"arm64"
],
"dev": true,
"libc": [
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can't do anything about these being added and then removed depending on which system we install the packages? 😓

Comment thread package.json
"cheerio": "=1.0.0-rc.12"
}
},
"uuid": "^11.1.1"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good enough for now, we can remove it once we migrate to playwright & vite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants