Skip to content

protobufjs Security vulnerability still exists in v3.6.1  #211

@gillyb

Description

@gillyb

In version 3.6.1 of this library (gax-nodejs) in the changelog it was reported that you bumped the version of protobufjs to 7.2.4 to fix a security vulnerability in that library.

According to the CVE report of that vulnerability, it was only fixed in version 7.2.5 of protobufjs.
Can you please create a release of 3.x.x with an updated version of protobufjs without the security vulnerability ?

Thanks.

Metadata

Metadata

Labels

priority: p2Moderately-important priority. Fix may not be included in next release.type: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions