Skip to content

fix(cli): remove unused got-fetch dependency - #352

Open
fujikky wants to merge 1 commit into
fabien0102:mainfrom
fujikky:fix/remove-unused-got-fetch
Open

fujikky wants to merge 1 commit into
fabien0102:mainfrom
fujikky:fix/remove-unused-got-fetch

Conversation

@fujikky

@fujikky fujikky commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Remove the unused got-fetch dependency from @openapi-codegen/cli.

Why

  • got-fetch is not imported anywhere in this repository (src, tests, docs). got itself is still used directly in getOpenAPISourceFile.ts and is kept.
  • got-fetch@5.1.11 and 5.1.12 are affected by GHSA-f29h-pxvx-f335 (malicious release, fixed in 6.0.0+).
  • cli/package.json declares "got-fetch": "^5.1.1", so an install without a lockfile (e.g. a consumer installing @openapi-codegen/cli) resolves to the compromised 5.1.12. The lockfile in this repository pins 5.1.10, which is not affected.

Removing the unused dependency eliminates that exposure.

Verification

  • pnpm install --frozen-lockfile
  • pnpm build
  • pnpm check (tsc / eslint / prettier)
  • pnpm test (27 files, 241 tests passed)

Follow-up: replacing got with native fetch

While looking into this, I noticed that got is only used in cli/src/core/getOpenAPISourceFile.ts (a plain GET/POST with headers, plus 401/404 handling for the GitHub source). This looks easy to replace with Node's native fetch (the repo already requires Node >= 20), which would also drop the whole got dependency tree.

A few things to take care of: fetch does not throw on non-2xx responses (so the HTTPError handling needs res.ok / res.status checks), got's default retry behavior goes away, and the URL tests would need nock v14+ (v13 cannot intercept native fetch).

I kept this PR focused on the security fix. If you are interested, I'm happy to open a separate PR for that.

got-fetch is not imported anywhere in the repository. Releases 5.1.11 and 5.1.12 are affected by GHSA-f29h-pxvx-f335, and the ^5.1.1 range resolves to 5.1.12 on installs without a lockfile.
@el-j el-j mentioned this pull request Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant