swagger-api / swagger-api/swagger-parser

CVE-2020-8908 on swagger-compat-spec-parser, json-schema-validator replacement?

Open
#1,954 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Java
Stars
867
Forks
560
Avg merge
2d 21h
Merged PRs (30d)
7

Description

The last json-schema-validator release is from 2020 ( looks like it's no longer maintained 🤔 ).

  • CVE-2020-8908 vulnerability is now present on the project's Google/Guava dependency (28.2-android). 🎯

IMHO, It would be a good thing to replace it. ⭐ 😃

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing swagger-compat-spec-parser and its Google/Guava 28.2-android dependency, then compare the linked json-schema-validator release history. The issue does not name a replacement or files and has no tests or entry points; done would require selecting and integrating a replacement without leaving the reported CVE dependency.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.