Highlights
Reflected XSS: 3 prior fixes. Scrutinize any change in this area.
swagger-ui: most-fixed (4 issues). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
DOM-Based XSS: The OAuth2 redirect handler in bundled Swagger UI assets allowed execution of arbitrary client-side script via window.opener manipulations, requiring an upgrade to at least v4.14.3.
Reflected XSS: Multiple historic versions of Swagger UI assets embedded in this repository contained Reflected XSS vulnerabilities within the core bundle assets, requiring repeated dependency upgrades to mitigate.