NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2796 most downloaded on npm
[](http://badge.fury.io/js/swagger-ui-dist)
Last release 3 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
9 years old
371 releases · first in 2017
handle virtualization with path item references
One column per quarter.
a11y: add accessible names for buttons
Huge thanks to our contributors who made this release happen: @moskvin, @tstarling, and @yogeshwaran-c
ci: fix Trivy security scan and add dependency vulnerability scan
Huge thanks to our contributors who made this release happen: @bmatar, @yogeshwaran-c, @jonnyjackson26, @rkdfx, and @adrianodpdiaz
deps: bump swagger-client to v3.37.8
spec: avoid crash when requestBody has no content field
avoid filling parameter input with invalid array initial values
deps: bump dompurify from 3.4.0 to 3.4.9
deps: bump swagger-client to v3.37.3
docker: bump libpng and zlib versions to fix CVE-2026-33416, CVE-2026-33636 and CVE-2026-22184
oas32: add basic OpenAPI 3.2.0 support
core: remove mistakenly put condition
deps: update vulnerable dependencies
deps: update vulnerable @release-it/conventional-changelog to 10.0.2
deps: bump react-syntax-highlighter to 16.0.0
prevent webook from crashing in case of openapi 3.0
deps: update ApiDOM to v1.0.0-rc.1
core: handle complex value stringification in Property component (#10604) (0422415), closes #10535
update vulnerable libxml2 to 2.13.9-r0
auth: ensure schema is immutable when persisting authorization (#10588) (9124f59), closes #10569
include oauth2-redirect.js in npm package distribution (#10585) (443c011), closes #10574
security: update Axios to non-vulnerable 1.12.2 version
oauth2-redirect: externalize inline script for CSP compliance
provide polyfill for buffer in build (#10554) (bbb1282), closes #10553
add initial support for React 19 (#10551) (7a13771), closes #10243
use open-cli instead of require('open') for Node 20+ compatibility
permissions of files to allow running as non-root
style: restore paragraph spacing in parameter and response descriptions
oas3: reset request body values in try it out
release Swagger UI to Packagist
docker: bump nginx image to version 1.29.0-alpine to fix CVE-2025-48174
fix opened model schema resolving issue on spec change
dist: provide correct npm token for swagger-ui-dist release
align expanded content inside expand collapse button
oas3: show the schema tab in the Try it Out mode
mitigate ReDoS when generating examples from pattern
docker: address CVE-2025-32414/CVE-2025-32415
align OpenAPI 3.x.y file uploads with specification (#10409) (c29e712), closes #9278
docker: address multiple HIGH security vulnerabilities
style: prevent operationId from wrapping when space is available
json-schema-2020-12-samples: use zero as default example value for int32 and int64
utils: fix error messages for range validation of number parameters
json-schema-2020-12-samples: fix examples for nullable primitive types defined as list of types
json-schema-2020-12: avoid accessing properties of null schemas
fix definition resolving being affected by the order of schemas (#10386) (28f77cb), closes #10096
docker: fix security issues CVE-2024-56171, CVE-2025-24928
security: update axios to address CVE-2024-39338
@char0n @glowcloud @robert-hebel-sb
# 5.19.0 (2025-02-17) ### Features * add support for OpenAPI 3.0.4
docker: document new SwaggerUI docker registry usage
update Scarf.js to v1.4.0 to avoid breaking Vitest (#10204) (adc1c3c), closes #10197
docker: return explicit Node.js installation (#10198) (3e3dfc6), closes #10195
analytics: use Scarf.js to provide anonymized installation analytics
SwaggerUI uses Scarf to collect anonymized installation analytics. These analytics help support the maintainers of this library and ONLY run during installation. To opt out, you can set the scarfSettings.enabled field to false in your project's package.json:
// package.json
{
// ...
"scarfSettings": {
"enabled": false
}
// ...
}
Alternatively, you can set the environment variable SCARF_ANALYTICS to false as part of the environment that installs your npm packages, e.g., SCARF_ANALYTICS=false npm install.
Your coding agent can read these notes before it upgrades. Set up the MCP server →