swagger-api / swagger-api/swagger-core

[Feature]: Drop commons-lang3 dependency and replace its usages with core Java

Open
#5,011 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

backlog Feature
Dominant language
Java
Stars
7.5k
Forks
2.3k
Avg merge
18h 1m
Merged PRs (30d)
10

Description

Feature Description

It would be great if swagger-core would not depend on commons-lang3.

Use Case

Currently swagger-core uses only a few classes from commons-lang3, and it would probably be worth dropping the dependency for the following reasons:

  • Better security. commons-* follows "all features in a single jar" pattern, so a CVE in one of the classes would impact swagger-core
  • Fewer bytes to ship with binary distribution for the end-users: commons-lang3 is ~690K

I have raised a suggestion to make commons-lang3 modular and extract modules like commons-stringutils, commons-arrayutils, however, Commons team does not seem to like the idea.
Commons PMC members often suggest that users should clone the code or shade commons-lang, see

Suggested Solution (optional)

Use modern Java approaches and remove the use of commons-lang completely.

Alternatives Considered

Ship a micro-module library to replace commons-lang3.

Additional Context

Checklist

  • I have searched the existing issues to ensure this is not a duplicate.
  • This feature would be useful to more than just my use case.
  • I have provided enough detail for the maintainers to understand the scope of the request.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the commons-lang3 dependency declaration and every commons-lang3 usage in swagger-core. Read the surrounding code to identify suitable core Java replacements, then run the project's test suite and verify that the dependency is no longer included.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
backend
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.