Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in dependency (google-gax > protobufjs) #1498

Open
scaryguy opened this issue Apr 15, 2024 · 1 comment
Open

Vulnerability in dependency (google-gax > protobufjs) #1498

scaryguy opened this issue Apr 15, 2024 · 1 comment
Assignees
Labels
api: logging Issues related to the googleapis/nodejs-logging API. priority: p2 Moderately-important priority. Fix may not be included in next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.

Comments

@scaryguy
Copy link

There is a critical vulnerability in protobujs. It's causing npm audit to fail and causing many CI/CD pipelines to fail. When should we expect a new version with the fixed dependency?

Could someone help with accelerating this internally at Google? 🙄

googleapis/gax-nodejs#1586

@scaryguy scaryguy added priority: p2 Moderately-important priority. Fix may not be included in next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Apr 15, 2024
@product-auto-label product-auto-label bot added the api: logging Issues related to the googleapis/nodejs-logging API. label Apr 15, 2024
@cindy-peng
Copy link
Contributor

cindy-peng commented May 7, 2024

Thanks for opening this issue! @scaryguy Is this issue for @google-cloud/logging-min or @google-cloud/logging?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: logging Issues related to the googleapis/nodejs-logging API. priority: p2 Moderately-important priority. Fix may not be included in next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Projects
None yet
Development

No branches or pull requests

2 participants