Skip to content

Commit 80ebe6f

Browse files
committed
Bump json schema ref parser version to fix security vulnerability allowing internal URL resolution in the http parser.
BREAKING CHANGE: Remove ability to request internal urls in the default http resolver - this is now behind a flag in the http resolver, safeUrlResolver
1 parent a4559a2 commit 80ebe6f

File tree

2 files changed

+228
-203
lines changed

2 files changed

+228
-203
lines changed

package.json

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -50,31 +50,31 @@
5050
"coverage:node": "cross-env QUICK_TEST=true nyc mocha"
5151
},
5252
"devDependencies": {
53-
"@eslint/compat": "^1.2.9",
54-
"@eslint/js": "^9.28.0",
53+
"@eslint/compat": "^1.3.0",
54+
"@eslint/js": "^9.29.0",
5555
"@jsdevtools/host-environment": "^2.1.2",
56-
"@types/node": "^22.15.30",
56+
"@types/node": "^24.0.3",
5757
"chai": "^5",
5858
"cross-env": "^7.0.3",
5959
"esbuild": "^0.25.5",
6060
"esbuild-plugin-polyfill-node": "^0.3.0",
61-
"eslint": "^9.28.0",
61+
"eslint": "^9.29.0",
6262
"eslint-config-prettier": "^10.1.5",
63-
"eslint-plugin-jsdoc": "^50.7.1",
63+
"eslint-plugin-jsdoc": "^51.0.1",
6464
"eslint-plugin-prettier": "^5.4.1",
6565
"eslint-plugin-unused-imports": "^4.1.4",
6666
"globals": "^16.2.0",
6767
"js-yaml": "^4.1.0",
68-
"mocha": "^11.5.0",
68+
"mocha": "^11.6.0",
6969
"nyc": "^17.1.0",
7070
"openapi-types": "^12.1.3",
7171
"prettier": "^3.5.3",
7272
"rimraf": "^6.0.1",
7373
"typescript": "^5.8.3",
74-
"typescript-eslint": "^8.33.1"
74+
"typescript-eslint": "^8.34.1"
7575
},
7676
"dependencies": {
77-
"@apidevtools/json-schema-ref-parser": "13.0.2",
77+
"@apidevtools/json-schema-ref-parser": "14.0.1",
7878
"@apidevtools/openapi-schemas": "^2.1.0",
7979
"@apidevtools/swagger-methods": "^3.0.2",
8080
"ajv": "^8.17.1",

0 commit comments

Comments
 (0)