Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[REQ] Release 7.2.0 #17371

Closed
geemanjs opened this issue Dec 11, 2023 · 3 comments
Closed

[REQ] Release 7.2.0 #17371

geemanjs opened this issue Dec 11, 2023 · 3 comments

Comments

@geemanjs
Copy link

geemanjs commented Dec 11, 2023

Hey,

Wasn't sure the best way to request this so apologies if this is incorrect.

Is your feature request related to a problem? Please describe.

Axios 0.27 has a high CVE associated with it. Version openapi-generator@7.1.0 uses that version of Axios.

I noticed that the day after the 7.1.0 release the Typescript projects Axios upgrade was merged in (to 1.6.1 which has no CVE associated with it):
#14517
#14518
a460b7e

I also noticed that there have been a couple of PRs to do the upgrade and a couple of previous requests to release this version in various comments across the issues / PRs - which suggest this might be wanted by multiple people/projects.

Describe the solution you'd like

Release the current master version as 7.2.0 with the already merged axios upgrade in it.

Describe alternatives you've considered

The library we pull in to our project is @ory/client which is an authentication based library.

I assume they are reluctant to use a SNAPSHOT version of the generator for a public facing library

Additional context

Happy to help resolve any issues blocking the 7.2.0 release currently.

@beanow-at-crabnebula
Copy link

🙏 hopefully not long now.
Looking at the planned release from https://github.com/OpenAPITools/openapi-generator/milestone/55

Note if you're stuck on v0 axum waiting for this release, backporting efforts are still under way too.
For instance axios/axios#6091

If you're feeling brave you can target these commits as a v0 alternative.
Though it looks like an actual patch release should be available before long.

@wing328
Copy link
Member

wing328 commented Dec 18, 2023

we should be able to cut a release (last release of 2023) this week.

@geemanjs
Copy link
Author

Thanks @beanow-at-crabnebula and @wing328 - I didn't realise there was a target milestone! Looking forwards to getting this resolved in the new year!

I'll close this ticket now as it looks as if the ball is rolling 👍

Happy holidays and new year!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants