You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Aug 4, 2023. It is now read-only.
Hi Team,
we are using swagger-tools and now our security team has raised a License issue with it as Swagger is using json-refs which inturn is using Slash.
Slash is flagged as vulnerable with GPL license.
Our current version is:
Swagger-tools : 0.10.1
→ json-refs : 2.1.7
→slash : 1.0.0 (Vulnerable)
we can upgrade it but slash vulnerability still remains and slash not in development from 2006.
Could you please let us know if we have any alternative here. It is very critical as our production release will be stuck.
The text was updated successfully, but these errors were encountered:
I'll take a peek. Development on swagger-tools is halted, with only high impact bug fixes being implemented at this time. Please see #335 for more details.
@whitlockjc is swagger-tools being deprecated? I would like to understand if vulnerabilities will be fixed.
Also, sway-connect doesn't seems to be a recent project and active mantained.
What is the alternative to swagger-tools that is being maintained?
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Hi Team,
we are using swagger-tools and now our security team has raised a License issue with it as Swagger is using json-refs which inturn is using Slash.
Slash is flagged as vulnerable with GPL license.
Our current version is:
Swagger-tools : 0.10.1
→ json-refs : 2.1.7
→slash : 1.0.0 (Vulnerable)
we can upgrade it but slash vulnerability still remains and slash not in development from 2006.
Could you please let us know if we have any alternative here. It is very critical as our production release will be stuck.
The text was updated successfully, but these errors were encountered: