Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
e64b092
doc: announced new discord channel
fredbi Dec 19, 2025
90efd45
doc: updated contributors file
bot-go-openapi[bot] Dec 20, 2025
3b2ff60
fix: fixed key escaping in OrderedItems marshaling
fredbi Dec 24, 2025
5fc39a0
doc: updated contributors file
bot-go-openapi[bot] Dec 27, 2025
22037ac
build(deps): bump the development-dependencies group with 7 updates
dependabot[bot] Jan 9, 2026
02c28f2
build(deps): bump github.com/go-openapi/testify/v2
dependabot[bot] Jan 16, 2026
d181245
build(deps): bump the development-dependencies group with 7 updates
dependabot[bot] Jan 30, 2026
d708159
build(deps): bump github.com/go-openapi/testify/v2
dependabot[bot] Feb 6, 2026
71eebab
build(deps): bump github.com/go-openapi/testify/v2
dependabot[bot] Feb 13, 2026
7ca5d97
build(deps): bump the development-dependencies group with 7 updates
dependabot[bot] Feb 20, 2026
0c2d5d4
build(deps): bump github.com/go-openapi/testify/v2
dependabot[bot] Feb 27, 2026
d6177ef
chore: doc, tests, lint (#255)
fredbi Mar 3, 2026
fb0c59e
build(deps): bump the development-dependencies group with 7 updates
dependabot[bot] Mar 6, 2026
cb33f35
doc: updated contributors file
bot-go-openapi[bot] Mar 7, 2026
6bf1996
build(deps): bump the go-openapi-dependencies group with 2 updates
dependabot[bot] Mar 13, 2026
b2867e8
doc: update discord link (#260)
fredbi Mar 15, 2026
b7c0c19
doc: add portable agentic instructions (#261)
fredbi Mar 15, 2026
1505803
chore: bump go directive to 1.25.0 (#262)
fredbi Mar 15, 2026
2e5142b
build(deps): bump the development-dependencies group with 7 updates
dependabot[bot] Mar 15, 2026
2b49290
build(deps): bump the go-openapi-dependencies group with 2 updates
dependabot[bot] Mar 20, 2026
c5c7103
doc: updated contributors file
bot-go-openapi[bot] Mar 21, 2026
1d7d651
build(deps): bump the go-openapi-dependencies group with 6 updates
dependabot[bot] Apr 17, 2026
a2d9c41
build(deps): bump github.com/go-openapi/jsonpointer
dependabot[bot] Apr 24, 2026
a5d0895
build(deps): bump the go-openapi-dependencies group with 2 updates
dependabot[bot] May 1, 2026
596087b
build(deps): bump the development-dependencies group across 1 directo…
dependabot[bot] May 8, 2026
5c73b50
build(deps): bump the go-openapi-dependencies group with 2 updates
dependabot[bot] May 22, 2026
9715006
build(deps): bump the development-dependencies group across 1 directo…
dependabot[bot] May 29, 2026
45b7fe1
feat(ci): added shared workflow for bot-pr monitoring
fredbi May 31, 2026
0741160
build(deps): bump the development-dependencies group with 8 updates
dependabot[bot] Jun 5, 2026
9a2db11
doc: aligned with org docs (#273)
fredbi Jun 5, 2026
1ab4532
doc: updated contributors file
bot-go-openapi[bot] Jun 6, 2026
e935605
build(deps): bump the go-openapi-dependencies group across 1 director…
dependabot[bot] Jun 10, 2026
536d375
build(deps): bump the development-dependencies group with 8 updates
dependabot[bot] Jun 12, 2026
e41b4fd
fix(header): header extension should correctly marshal as JSON
fredbi Jun 14, 2026
49846cb
chore: relint
fredbi Jun 14, 2026
1b69857
Merge pull request #278 from fredbi/fix/277-header-ext
fredbi Jun 14, 2026
dc55c96
build(deps): bump go-openapi/ci-workflows/.github/workflows/monitor-b…
dependabot[bot] Jun 19, 2026
eb04d47
doc: updated contributors file
bot-go-openapi[bot] Jun 20, 2026
1754e05
chore(ci): run contributors workflow monthly instead of weekly (#281)
fredbi Jun 21, 2026
da6a6cf
ci: post README announcements to discord + bump ci-workflows to v0.4.…
fredbi Jun 22, 2026
bac1bee
build(deps): bump the go-openapi-dependencies group with 2 updates
dependabot[bot] Jun 26, 2026
8e7a0e6
doc: updated contributors file
bot-go-openapi[bot] Jul 1, 2026
9b21ccd
build(deps): bump the go-openapi-dependencies group with 6 updates
dependabot[bot] Jul 3, 2026
1688f14
build(deps): bump the go-openapi-dependencies group with 2 updates (#…
dependabot[bot] Jul 12, 2026
d76a1a4
fix(expander): cap $ref expansion node count to prevent amplification…
fredbi Jul 20, 2026
5ae1e0d
chore: upgrade dependencies ; fix deprecated jsonname
fredbi Jul 20, 2026
64655f3
feat(expander): accept an option-aware document loader
fredbi Jul 20, 2026
4e073e1
fix(ref): stop performing a network request in IsValidURI
fredbi Jul 20, 2026
7229152
docs(security): warn that the default $ref loader is not sandboxed
fredbi Jul 20, 2026
75e4859
build(deps): bump swag/loading to v0.27.2 for confined $ref loading
fredbi Jul 20, 2026
fe9f8bd
test(expander): validate the SSRF posture of an injected loader
fredbi Jul 20, 2026
497d583
build(deps): bump swag modules to v0.27.3
fredbi Jul 20, 2026
5173965
Merge pull request #290 from fredbi/fix/vuln-reports
fredbi Jul 20, 2026
9bfe732
feat(expander): add ExpandSchemaWithOptions for confined schema expan…
fredbi Jul 20, 2026
e682f66
feat(expander): add ExpandParameterWithOptions and ExpandResponseWith…
fredbi Jul 20, 2026
29d6c85
Keep extensions data on expand schema
ademidoff Aug 3, 2026
61fbd55
Merge branch 'master' into percona-expand-extensions-v0.22.9
ademidoff Aug 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .claude/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
plans/
skills/
commands/
agents/
hooks/
85 changes: 85 additions & 0 deletions .claude/CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

Go types modeling the [Swagger 2.0 / OpenAPI 2.0](https://swagger.io/specification/v2/)
specification. Every object in the spec --- `Swagger`, `Info`, `PathItem`, `Operation`,
`Parameter`, `Schema`, `Response`, `Header`, `SecurityScheme`, etc. --- has a corresponding
Go struct with JSON serialization (`encoding/json`) that round-trips through the spec's
JSON representation.

This package is the **foundational data model** for the
[go-swagger](https://github.com/go-swagger/go-swagger) ecosystem. Higher-level packages
(`analysis`, `loads`, `validate`, `runtime`) consume these types to load, analyze, validate,
and serve Swagger specifications. Because it sits at the bottom of the dependency graph,
changes here ripple through the entire ecosystem.

Key capabilities beyond plain structs:

- **`$ref` resolution** --- the `Ref` type wraps JSON Reference pointers; the `expander`
resolves `$ref` nodes (local, remote, circular) into fully expanded specs.
- **Schema composition** --- `Schema` supports `allOf`, `additionalProperties`,
`additionalItems`, and JSON Schema validations (`minimum`, `pattern`, `enum`, etc.).
- **URL normalization** --- cross-platform path/URL normalization for `$ref` targets.
- **Embedded spec** --- a copy of the Swagger 2.0 JSON Schema is embedded via `go:embed`
for offline use.

See [docs/MAINTAINERS.md](../docs/MAINTAINERS.md) for CI/CD, release process, and repo structure details.

### Package layout (single package)

| File | Contents |
|------|----------|
| `swagger.go` | Root `Swagger` type (top-level spec object) |
| `info.go` | `Info`, `ContactInfo`, `LicenseInfo` |
| `paths.go` | `Paths` (map of path patterns to `PathItem`) |
| `path_item.go` | `PathItem` (GET/PUT/POST/DELETE/... operations per path) |
| `operation.go` | `Operation` (single API operation) |
| `parameter.go` | `Parameter` (query, header, path, body, formData) |
| `header.go` | `Header` |
| `response.go`, `responses.go` | `Response`, `Responses` |
| `schema.go` | `Schema` (JSON Schema subset used by Swagger) |
| `security_scheme.go` | `SecurityScheme` |
| `items.go` | `Items` (non-body parameter schema) |
| `ref.go` | `Ref` type, JSON Reference (`$ref`) handling |
| `expander.go` | `$ref` expansion / resolution engine |
| `normalizer.go` | URL/path normalization (platform-specific variants) |
| `cache.go` | Resolution cache for expanded specs |
| `validations.go` | Common validation properties shared across types |
| `properties.go` | `SchemaProperties` ordered map |
| `embed.go` | Embedded Swagger 2.0 JSON Schema (`go:embed`) |
| `spec.go` | `MustLoadSwagger20Schema()` loader |
| `external_docs.go` | `ExternalDocumentation` |
| `tag.go` | `Tag` |
| `xml_object.go` | `XMLObject` |
| `debug.go` | Debug logging helpers |

### Key API

- `Swagger` --- root specification object; deserialize with `json.Unmarshal`
- `Schema` --- JSON Schema with Swagger extensions; supports `allOf`, `$ref`, validations
- `Ref` / `MustCreateRef(uri)` --- JSON Reference wrapper
- `ExpandSpec(spec, opts)` --- resolve all `$ref` nodes in a specification
- `ExpandSchema(schema, root, cache)` --- resolve `$ref` nodes in a single schema
- `ResolveRef(root, ref)` / `ResolveParameter` / `ResolveResponse` --- targeted resolution

### Dependencies

- `github.com/go-openapi/jsonpointer` --- JSON Pointer (RFC 6901) navigation
- `github.com/go-openapi/jsonreference` --- JSON Reference parsing
- `github.com/go-openapi/swag` --- JSON/YAML utilities, name mangling
- `github.com/go-openapi/testify/v2` --- test-only assertions (zero-dep testify fork)

### Notable historical design decisions

- **Mixin of spec types and `$ref`** --- many types embed both their data fields and a `Ref`
field. When `$ref` is present, the data fields are ignored per the Swagger specification.
This is modeled by custom `MarshalJSON`/`UnmarshalJSON` on each type.
- **`VendorExtensible`** --- most types embed `VendorExtensible` to capture `x-` extension
fields as `map[string]any`.
- **`SchemaProperties` as ordered slice** --- schema properties are stored as a slice of
key-value pairs (not a map) to preserve declaration order during round-trip serialization.
- **Platform-specific normalization** --- Windows path handling differs from Unix; separate
`normalizer_windows.go` / `normalizer_nonwindows.go` files handle this.
52 changes: 52 additions & 0 deletions .claude/rules/contributions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
---
paths:
- "**/*"
---

# Contribution rules (go-openapi)

Read `.github/CONTRIBUTING.md` before opening a pull request.

## Commit hygiene

- Every commit **must** be DCO signed-off (`git commit -s`) with a real email address.
PGP-signed commits are appreciated but not required.
- Agents may be listed as co-authors (`Co-Authored-By:`) but the commit **author must be the human sponsor**.
We do not accept commits solely authored by bots or agents.
- Squash commits into logical units of work before requesting review (`git rebase -i`).

## Linting

Before pushing, verify your changes pass linting against the base branch:

```sh
golangci-lint run --new-from-rev master
```

Install the latest version if you don't have it:

```sh
go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest
```

## Problem statement

- Clearly describe the problem the PR solves, or reference an existing issue.
- PR descriptions must not be vague ("fix bug", "improve code") — explain *what* was wrong and *why* the change is correct.

## Tests are mandatory

- Every bug fix or feature **must** include tests that demonstrate the problem and verify the fix.
- The only exceptions are documentation changes and typo fixes.
- Aim for at least 80% coverage of your patch.
- Run the full test suite before submitting:

For mono-repos:
```sh
go test work ./...
```

For single module repos:
```sh
go test ./...
```
Loading
Loading