Skip to content

Upgrade babel packages for Javascript ES6 generator#3424

Merged
macjohnny merged 2 commits intoOpenAPITools:masterfrom
freemanchen:update-es6-generator-to-babel-7
Jul 25, 2019
Merged

Upgrade babel packages for Javascript ES6 generator#3424
macjohnny merged 2 commits intoOpenAPITools:masterfrom
freemanchen:update-es6-generator-to-babel-7

Conversation

@freemanchen
Copy link
Contributor

@freemanchen freemanchen commented Jul 22, 2019

PR checklist

  • Read the contribution guidelines.
  • Ran the shell script under ./bin/ to update Petstore sample so that CIs can verify the change. (For instance, only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the {LANG} (e.g. php, ruby, python, etc) code generator or {LANG} client's mustache templates). Windows batch files can be found in .\bin\windows\. If contributing template-only or documentation-only changes which will change sample output, be sure to build the project first.
  • Filed the PR against the correct branch: master, 4.1.x, 5.0.x. Default: master.
  • Copied the technical committee to review the pull request if your PR is targeting a particular programming language.

Description of the PR

(details of the change, additional tests that have been done, reference to the issue for tracking, etc)

This PR addresses the vulnerability described here: #3393

I ran npx babel-upgrade within the generated package and copied the changes into the ES6 mustache templates. I then ran the two relevant shell scripts: javascript-es6-petstore.sh and javascript-promise-es6-petstore.sh

Fixes #3393

@freemanchen
Copy link
Contributor Author

Not 100% sure what is meant by 'copied the technical committee' but assuming I should just @ them here. @CodeNinjai @frol @cliffano. Thanks.

Copy link
Member

@macjohnny macjohnny left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wing328
Copy link
Member

wing328 commented Aug 10, 2019

@freemanchen thanks for the PR, which has been included in the 4.1.0 release: https://twitter.com/oas_generator/status/1160000504455319553

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Babel CLI vulnerability in Javascript ES6 generator

3 participants

Comments