Skip to content

Dependency Security risk on BlackDuck - docusaurus-plugin-openapi-docs #1320

@gregorysav

Description

@gregorysav

We have used docusaurus-plugin-openapi-docs package among others to create a UI project.
We have also set BlackDuck as a dependency analysis tool, which scans our code. Lately we have received a

Security risk on the following:

  • ajv 6.12.6, as part of docusaurus-plugin-openapi-docs 4.7.1
  • ajv 8.17.1, as part of docusaurus-plugin-openapi-docs 4.7.1

└─┬ docusaurus-plugin-openapi-docs@4.7.1
└─┬ openapi-to-postmanv2@5.8.0
└── ajv@8.18.0

  • minimatch 5.1.6, as part of docusaurus-plugin-openapi-docs 4.7.1

We would like to know if/when there will be a new version that will resolve this security issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions