aboutcode-org / aboutcode-org/vulnerablecode
Incorrect types for `related_ssvc_trees` and `fixed_by_packages` in OpenAPI schema
- Dominant language
- Python
- Stars
- 702
- Forks
- 328
- Avg merge
- 3d 8h
- Merged PRs (30d)
- 3
Description
Hi! I noticed another deficiency in the OpenAPI schema, for the `AdvisoryV3` and `AffectedByAdvisoryV3` schemas the `related_ssvc_trees` and `fixed_by_packages` properties are defined as string-type fields
```json
"related_ssvc_trees": {
"type": "string",
"readOnly": true
},
"fixed_by_packages": {
"type": "string",
"readOnly": true
}
```
though `related_ssvc_trees` is an array of objects, and `fixed_by_packages` is an array of strings, so should be something like
```json
"related_ssvc_trees": {
"type": "array",
"items": {
"$ref": "#/components/schemas/RelatedSSVCTree"
},
"readOnly": true
},
"fixed_by_packages": {
"type": "array",
"items": {
"type": "string"
},
"readOnly": true
}
```
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.