OpenAPITools / OpenAPITools/openapi-generator

[BUG] [python] Python client expects vulnerable urllib3

Open
#18,993 6 comments 5 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Issue: Bug
Dominant language
Java
Stars
26.8k
Forks
7.7k
PR merge metrics
PR metrics pending

Description

Bug Report Checklist
  • Have you provided a full/minimal spec to reproduce the issue?
  • Have you validated the input using an OpenAPI validator (example)?
  • Have you tested with the latest master to confirm the issue still exists?
  • Have you searched for related issues/PRs?
  • What's the actual output vs expected output?
  • [Optional] Sponsorship to speed up the bug fix or feature request (example)
Description

After #15810 the generated Python client expects urllib3 >= 1.25.3, < 2.1.0.

Except 1.26.19 all these urllib3 have some security vulnerability: https://security.snyk.io/package/pip/urllib3

openapi-generator version

7.5.0

OpenAPI declaration file content or url

N/A

Generation Details

java -jar openapi-generator-cli-7.5.0.jar generate -i .../some/swagger/service.yaml -g python

Steps to reproduce

Generate a Python client.

Related issues/PRs

#15810

Suggest a fix

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by generating the Python client with the command and OpenAPI input described in the issue, then inspect where the generated client declares its urllib3 version range. Update the dependency constraint to avoid the reported vulnerable versions and verify the generated requirement against urllib3 1.26.19.

Written by the indexing model from the issue text.

Assessment

Tech stack
openapi, python
Domain
api, security, tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.