Skip to content

Conversation

@NickY-SC
Copy link

@NickY-SC NickY-SC commented Aug 22, 2024

Describe the PR
Bumps github.com/go-openapi/spec from 0.20.4 to 0.20.15.

We added swag as a vendored dependency, that pulled 0.20.4 of go-openapi/spec as an inderect dep. And this file triggered alerts due to exposed secrets:

https://github.com/go-openapi/spec/blob/v0.20.4/appveyor.yml

go-openapi/spec already addressed it in this ticket:

go-openapi/spec#161

This PR proposes to bump go-openapi/spec to the latest minor version.

Tests are green.

Relation issue
go-openapi/spec related ticket

Additional context
Add any other context about the problem here.

Bumps github.com/go-openapi/spec from 0.20.4 to 0.20.15.

We added swag as a vendored dependency, that pulled 0.20.4 of go-openapi/spec as an inderect dep.
And this file triggered alerts due to exposed secrets:

> https://github.com/go-openapi/spec/blob/v0.20.4/appveyor.yml

go-openapi/spec already addressed it in this ticket:

> go-openapi/spec#161

This PR proposes to bump go-openapi/spec to the latest minor version of `go-openapi/spec`.

Tests are green.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant