NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2796 most downloaded on npm
[](http://badge.fury.io/js/swagger-ui-dist)
Last release today
01 Oct 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 59 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
9 years old
371 releases · first in 2017
Models: onLoad should check this.props.layoutSelectors method (#6307) (168d0ae), closes #6305
prismjs@1.21.0 (#6312)Additional dependency updates via #6317, #6316, #6313, #6310
One column per quarter.
This release should properly include swagger-ui-es-bundle and swagger-ui-es-bundle-core in the /dist directory. There are no other source code changes
build: SwaggerUI now also has an es2015 bundle artifact
specPath for isShownKey to toggle models (#6200) (084b236)$ in curl request bodies and headers (#6245) (225a915), closes #5390swagger-ui-react: updated babel config file target
try-it-out: Better tooltips for min/max validations
Remove LodashModuleReplacementPlugin that made v3.30.1 unusable (#6255). Fixes #6249.
LodashModuleReplacementPlugin that made v3.30.1 unusable (#6255). Fixes #6249.Webpack optimizations to reduce bundle size to <1 MiB.
This build was reduced to 963 KiB
syntax highlighting of code section
RequestBody: set default true for 'send empty value' (#6228) (b68942c), closes #6203
avoid mapping Immutable.Map as React children
model view: hide applicable readOnly and writeOnly properties
displayOperationId config support (#5795) (bd1b297)DomPurify.addHook only if it exists (#5428)update corrupted swagger-client from v3.10.6 to v3.10.7
⚠️ This release includes a security update with Markdown render.
⚠️ This release includes a security update with Markdown render.
OAUTH_SCOPES configuration property to select all/none/user_list to OAuth scopes popup (#6037) (275c8f2)SWAGGER_JSON_URL option to allow remote urls from Docker (#6122)VALIDATOR_URL now has options to disable the validation badge (#5994)Allow to skip submitting empty values in form data
entries can now be generally used again as a key name. special handling of non-FormData entries removed (#6036) (68185dd), closes #6033
bump swagger-client to version 3.10.4 and return back compatibility with node.js >= 4
housekeeping: update release-it config
feature: JsonSchema components are now ImmutableJS compliant
improvement: render OAS3 parameter type formats
No release summary included.
showCommonExtensions support for OAS3 parameters (#5901)feature(swagger-ui-react): defaultModelExpandDepth and plugins props
No release summary included.
defaultModelExpandDepth and plugins props (#5594)npm run lint and npm test on Windows (#5737)npm audit fix (#5718, #5772, #5805)### Changelog * housekeeping: npm audit fix
npm audit fix (#5718)This release reverts Swagger UI's upgrade to redux@^4 (via #5569), which was causing test failures in downstream projects.
This release reverts Swagger UI's upgrade to redux@^4 (via #5569), which was causing test failures in downstream projects.
…which mitigates our exposure to dompurify's mXSS vulnerability that was disclosed earlier this week.
⚠️ This release includes security updates. You should upgrade to this version if you use Swagger UI to render untrusted documents.
Specifically, this version updates Swagger UI's dompurify dependency to ^2.0.7, which mitigates our exposure to dompurify's mXSS vulnerability that was disclosed earlier this week.
pre.microlight (#5673)feature: add PKCE support for OAuth2 Authorization Code flows
⚠️ This release contains a security fix that addresses a CSS-based input field value exfiltration vulnerability. If you use Swagger UI to display untr…
⚠️ This release contains a security fix that addresses a CSS-based input field value exfiltration vulnerability. If you use Swagger UI to display untrusted OpenAPI documents, you should upgrade to this version ASAP.
@import chaining" vulnerability (via #5616)This release fixes two bugs: one visual issue within static documentation, and another within runtime validation for Array-typed parameters.
This release fixes two bugs: one visual issue within static documentation, and another within runtime validation for Array-typed parameters.
<Select disabled> for type: string + enum schemas (#5601)This release changes the default value for the validatorUrl configuration option from https://online.swagger.io/validator to https://validator.swagger
This release changes the default value for the validatorUrl configuration option from https://online.swagger.io/validator to https://validator.swagger.io/validator.
This release fixes an issue with Swagger 2.0 required body parameter runtime validation (#5583) that was introduced in v3.23.7.
This release fixes an issue with Swagger 2.0 required body parameter runtime validation (#5583) that was introduced in v3.23.7.
This release includes new support for display and Try-It-Out functionality of OAS 3.0 Parameter.content values.
This release includes new support for display and Try-It-Out functionality of OAS 3.0 Parameter.content values.
Parameter.content (#5571)This release fixes a React warning originating in Swagger UI and a CSS class name collision with Bootstrap 4.0.
This release fixes a React warning originating in Swagger UI and a CSS class name collision with Bootstrap 4.0.
It also includes several in-range updates to minimum dependency versions.
.col class that causes collision with Bootstrap (via #5541)This release includes a fix to our Markdown parsing implementation that should resolve display issues with certain Markdown strings.
This release includes a fix to our Markdown parsing implementation that should resolve display issues with certain Markdown strings.
housekeeping: @kyleshockey/js-yaml -> js-yaml (via #5511)
@kyleshockey/js-yaml -> js-yaml (via #5511)npm audit resolutions (via #5509)This release resolves an undeclared dependency issue visible in swagger-ui-react@3.23.3 due to usage of @babel/runtime-corejs2. No source changes were
This release resolves an undeclared dependency issue visible in swagger-ui-react@3.23.3 due to usage of @babel/runtime-corejs2. No source changes were made.
See #5505 for more information.
This release includes improvements to our Docker container permissions, bug fixes for OpenAPI 3.0 rendering of Responses and Request Bodies, and resol
This release includes improvements to our Docker container permissions, bug fixes for OpenAPI 3.0 rendering of Responses and Request Bodies, and resolution of most npm audit warnings visible to consumers.
This release fixes a couple of minor regressions introduced in v3.23.0, and also includes improvements to our module sizes and sourcemap quality.
This release fixes a couple of minor regressions introduced in v3.23.0, and also includes improvements to our module sizes and sourcemap quality.
Response.examples (via #5464 + #5465)Note: swagger-ui-react@3.23.1 was unpublished due to a bad build being pushed to npm. It will be updated again with the next release of Swagger UI.
This release includes support for OpenAPI 3.0's Examples Object within Parameter, Request Body, and Response Objects.
This release includes support for OpenAPI 3.0's Examples Object within Parameter, Request Body, and Response Objects.
Several things have moved around internally.
If you make heavy use of the Plugin API, this may be of concern to you:
Parameterscomponent no longer has a wrapComponent in OpenAPI 3.0. Version-specific logic is now contained within one component.ParameterRow now needs oas3Actions and oas3Selectors as props.Response now needs path and method as props.Responses' shouldComponentUpdate check has been removed, it now re-renders as the Redux store changes.RequestBodyEditor has been heavily modified. It is no longer aware of the underlying request body or schema, and only concerns itself with the string value being edited. It will now also update its own internal state if the value prop given to it changes.This release moves Swagger UI to `swagger-client@3.9.0`.
No source changes.
This release moves Swagger UI to swagger-client@3.9.0.
security: CVE-2018-20834 (non-user-facing, via #5368)
isShown check to <ModelCollapse />'s prop expanded logic (via #5331)swagger-ui-react@3.22.0 lacked the changes that were advertised for it in that version - specifically, docExpansion support was missing.
swagger-ui-react@3.22.0 lacked the changes that were advertised for it in that version - specifically, docExpansion support was missing.
swagger-ui-react@3.22.1 is now available with the new changes. See #5294 for more information.
This release introduces a new configuration option (withCredentials) which allows control of Swagger UI's underlying Fetch/XHR instance's credential i
This release introduces a new configuration option (withCredentials) which allows control of Swagger UI's underlying Fetch/XHR instance's credential inclusion mode. You may find this option helpful if your API requires an authentication/authorization scheme that Swagger UI doesn't directly support, but can be handled out-of-band by your browser.
Also notable: GitHub Flavored Markdown table syntax is now supported in our OpenAPI 3 Markdown parser, swagger-ui-react's underlying UI system object is now exposed in the onComplete prop callback, react-addons-perf is removed from our dependencies to avoid BSD+Patents licensing, and we've improved how Markdown is rendered across Swagger UI.
withCredentials configuration key (via #5149)This release marks the introduction of a new flavor of Swagger UI: `swagger-ui-react`.
This release marks the introduction of a new flavor of Swagger UI: swagger-ui-react.
This new module exports a component for use in React applications, and allows you to use any React version you'd like, without fear of colliding with Swagger UI's internal React version.
We recommend that anyone using Swagger UI within a React application migrate to this module, instead of continuing to mount Swagger UI onto a React-created DOM node by ID.
This release also includes some fixes that improve Swagger UI's handling of rare edge cases in the resolver engine.
Note: this release was also erroneously pushed out as v3.20.10 - both versions' contents are identical.
swagger-ui-react module (via #5207)Nothing published for this version
This release contains a security fix that addresses a cross-site scripting vulnerability. If you use Swagger UI to display untrusted OpenAPI documents…
This release contains a security fix that addresses a cross-site scripting vulnerability. If you use Swagger UI to display untrusted OpenAPI documents, you should upgrade to this version ASAP.
This release also changes Swagger UI's OperationSummary component to better tolerate badly-formed (i.e., non-string) summary fields.
Changelog:
…request properties, and non-material security fixes from upstream modules.
This release contains styling fixes, support for x-www-form-urlencoded bodies without explicitly-defined request properties, and non-material security fixes from upstream modules.
In order to take advantage of the new X-Requested-With header in OAuth2 token requests, cross-origin APIs (which require CORS configuration) needs to send Access-Control-Allow-Headers: X-Requested-With as part of the OPTIONS response for your token endpoint. A CORS library will handle this for you - visit https://enable-cors.org for more guidance.
X-Requested-With to prevent browser authentication dialog (via #4934)improvement: generate non-smart Markdown quotes (via #5162)
Interface changes: none.
Changelog:
url remote document load if urls is provided (via #5161)improvement(docker): avoid caching mounted json/yml/yaml assets (via #5151)
Interface changes: none.
Changelog:
allowEmptyValue + required interactions (via #5142)improvement: support Markdown in header descriptions (via #5120)
Interface changes: None.
Changelog:
fix: urls.primaryName functionality regression (via #5097)
Interface changes: none.
Changelog:
urls.primaryName functionality regression (via #5097)improvement: generate default oauth2RedirectUrl based on page location (via #5085)
Interface changes: none.
Changelog:
improvement: OAuth2 UI and test suite (via #5066)
Interface changes: none.
Changelog:
Schemas in OpenAPI 3 (via #5065)specSelectors.operationConsumes was removed in favor of the new specSelectors.consumesOptionsFor selector.
Private interface changes:
specSelectors.operationConsumes was removed in favor of the new specSelectors.consumesOptionsFor selector.Changelog:
feature: sample value generation for uuid, hostname, ipv4, & ipv6 formats (via #5033)
Interface changes: none.
Changelog:
.js -> .jsx file extensions (via #5014)Interface changes: A handful of Docker environment variables were added and deprecated, see #4965 and #4987 for more information.
Interface changes: A handful of Docker environment variables were added and deprecated, see #4965 and #4987 for more information.
Changelog:
xml fork (via #4985)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →