Skip to content

fix: update core/* and packages/* protobufjs versions to address vulnerbility#8651

Open
pearigee wants to merge 2 commits into
mainfrom
pearigee-protobugjs-vuln
Open

fix: update core/* and packages/* protobufjs versions to address vulnerbility#8651
pearigee wants to merge 2 commits into
mainfrom
pearigee-protobugjs-vuln

Conversation

@pearigee

Copy link
Copy Markdown
Contributor

A handful of new vulnerabilities in protobufjs were discovered in May:
https://github.com/advisories?query=protobufjs

New versions of this package have been released (as recently as last week). This PR explicitly bumps each package to its most recent minor version.

@pearigee pearigee requested a review from a team as a code owner June 15, 2026 20:30

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the 'protobufjs' dependency to version '^7.6.4' and the 'protobufjs-cli' dependency to version '^1.3.3' across multiple package.json files in the repository. I have no feedback to provide as these are standard dependency updates.

@pearigee pearigee added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Jun 15, 2026
@yoshi-kokoro yoshi-kokoro removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Jun 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants