Skip to content

Conversation

@roman-sainchuk
Copy link
Contributor

@roman-sainchuk roman-sainchuk commented Apr 15, 2025

What/Why/How?

Update redoc to 2.5.0 to fix vulnerabilities related to dompurify < 3.2.4 (CVE-2025-26791)

Also, run npm audit fix to fix 3 moderate severity vulnerabilities.

Reference

Testing

Screenshots (optional)

Check yourself

  • Code changed? - Tested with redoc/reference-docs/workflows (internal)
  • All new/updated code is covered with tests
  • New package installed? - Tested in different environments (browser/node)

Security

  • Security impact of change has been considered
  • Code follows company security practices and guidelines

@roman-sainchuk roman-sainchuk requested review from a team as code owners April 15, 2025 14:23
@changeset-bot
Copy link

changeset-bot bot commented Apr 15, 2025

🦋 Changeset detected

Latest commit: 47019e8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
Name Type
@redocly/cli Patch
@redocly/openapi-core Patch
@redocly/respect-core Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@roman-sainchuk roman-sainchuk changed the title chore: (v1) update redoc to 2.5.0 chore(v1): update redoc to 2.5.0 Apr 15, 2025
@roman-sainchuk roman-sainchuk changed the base branch from main to v1 April 15, 2025 14:26
@github-actions
Copy link
Contributor

github-actions bot commented Apr 15, 2025

Coverage report

St.
Category Percentage Covered / Total
🟡 Statements 79.48% 7069/8894
🟡 Branches 68.53% 2947/4300
🟡 Functions 75.18% 1154/1535
🟡 Lines 79.87% 6744/8444

Test suite run success

1344 tests passing in 194 suites.

Report generated by 🧪jest coverage report action from 7787bc8

@github-actions
Copy link
Contributor

github-actions bot commented Apr 16, 2025

Command Mean [ms] Min [ms] Max [ms] Relative
redocly lint packages/core/src/benchmark/benches/rebilly.yaml 976.5 ± 19.9 962.0 1028.7 1.00
redocly-next lint packages/core/src/benchmark/benches/rebilly.yaml 988.3 ± 15.3 973.3 1023.9 1.01 ± 0.03

@github-actions
Copy link
Contributor

📦 A new experimental 🧪 version v0.0.0-snapshot.1744801622 of Redocly CLI has been published for testing.

Install with NPM:

npm install @redocly/[email protected]
# or
npm install @redocly/[email protected]
# or
npm install @redocly/[email protected]

⚠️ Note: This is a development build and may contain unstable features.

@tatomyr tatomyr merged commit 8d0d7a1 into v1 Apr 22, 2025
8 checks passed
@tatomyr tatomyr deleted the chore/v1/update-redoc branch April 22, 2025 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

snapshot Create experimental release PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants