| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
As a key component in the implementation of API clients and servers, oapi-codegen is in an critical position to keep secure.
Only oapi-codegen's latest minor version is generally supported.
Related: oapi-codegen's support model (SUPPORT.md)
However, depending on the severity of a given security vulnerability, there may be case(s) where this would lead to a backport of the patch on a currently unsupported version.
If you believe you have found a security vulnerability in oapi-codegen or any of the related projects in the oapi-codegen GitHub organisation, please report it to us through coordinated disclosure.
Important
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Please report the vulnerability through the GitHub security advisories page.
For instance, for the core oapi-codegen CLI, you would report it on this page.
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
This information will help us triage your report more quickly.
If a dependency that oapi-codegen (or its child projects) contains a CVE, we will look to patch that dependency in the following cases:
Note
Given the Go ecosystem allows projects to override dependency updates, this allows consumers of oapi-codegen to upgrade dependencies separate to oapi-codegen making changes upstream.
We will strive to make sure that we do update these dependencies on a regular basis, but until a fix or release is made, it is possible to override the version in your go.mod.
| Back | FazBrowse Home | New Git URL |