From e44b5410ae8d3cadc3390a38dbb7762a0961e1b5 Mon Sep 17 00:00:00 2001 From: Vrushank Vyas Date: Tue, 29 Sep 2026 12:24:16 +0530 Subject: [PATCH 1/2] ci: let the Swagger validator's browser launch Ubuntu 24.04 runners restrict unprivileged user namespaces via AppArmor, so the headless Chromium that char0n/swagger-editor-validate drives cannot start its sandbox and the check fails before validating anything. Lift the restriction on the ephemeral runner, and move checkout to v4. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/validate-openapi.yml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/validate-openapi.yml b/.github/workflows/validate-openapi.yml index b7cce206..15c4549a 100644 --- a/.github/workflows/validate-openapi.yml +++ b/.github/workflows/validate-openapi.yml @@ -19,7 +19,11 @@ jobs: - 80:8080 steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 + # Ubuntu 24.04 runners block the unprivileged user namespaces Chromium's + # sandbox needs, so the validator's headless browser fails to launch. + - name: Allow Chromium sandbox + run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 - name: Validate OpenAPI definition uses: char0n/swagger-editor-validate@v1 with: From a3ed747f5761c888e5db1cea6a42b456dad35669 Mon Sep 17 00:00:00 2001 From: Vrushank Vyas Date: Tue, 29 Sep 2026 12:29:19 +0530 Subject: [PATCH 2/2] ci: pin the Swagger Editor service to v4 swaggerapi/swagger-editor:latest moved to SwaggerEditor 5. Its nginx listens on 80, not 8080, so the validator got ERR_CONNECTION_RESET, and its UI lacks the .errors-wrapper panel char0n/swagger-editor-validate parses. v4.14.8 is the last v4 release. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/validate-openapi.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/validate-openapi.yml b/.github/workflows/validate-openapi.yml index 15c4549a..ecafcf84 100644 --- a/.github/workflows/validate-openapi.yml +++ b/.github/workflows/validate-openapi.yml @@ -12,8 +12,9 @@ jobs: services: # Label used to access the service container swagger-editor: - # Docker Hub image - image: swaggerapi/swagger-editor + # Docker Hub image. Pinned to v4: `latest` is now SwaggerEditor 5, which + # serves on port 80 and lacks the v4 error panel the validator reads. + image: swaggerapi/swagger-editor:v4.14.8 ports: # Maps port 8080 on service container to the host 80 - 80:8080