fix: Revert to drf-yasg upstream now that vulnerabilities are resolved #7195
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The
swagger-ui-dist
package beforev4.1.3
has vulnerabilities: CVE-2023-52425, CVE-2023-52426, CVE-2024-27983, CVE-2023-32313, CVE-2023-32314.The package
drf-yasg
was a consumer ofswagger-ui-dist
and was impacted by these vulnerabilities. In #4837 a fork was used to replace the package source.The vulnerable dependencies have since been bumped in
drf-yasg
and the fixed version is available from release 1.21.10To continue to receive future vulnerability fixes we can add
drf-yasg
back as the upstream for this repository.