-
Notifications
You must be signed in to change notification settings - Fork 21
Closed
Labels
priority: p2Moderately-important priority. Fix may not be included in next release.Moderately-important priority. Fix may not be included in next release.type: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Description
In version 3.6.1 of this library (gax-nodejs) in the changelog it was reported that you bumped the version of protobufjs to 7.2.4 to fix a security vulnerability in that library.
According to the CVE report of that vulnerability, it was only fixed in version 7.2.5 of protobufjs.
Can you please create a release of 3.x.x with an updated version of protobufjs without the security vulnerability ?
Thanks.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
priority: p2Moderately-important priority. Fix may not be included in next release.Moderately-important priority. Fix may not be included in next release.type: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.