Skip to content

security: upgrade @apollo/protobufjs to v1.2.8 to resolve Snyk vulnerability #8203

@ork-acro

Description

@ork-acro

A security vulnerability has been identified in the current version of @apollo/protobufjs used by this library. Currently, the project depends on v1.2.7, which has been flagged by Snyk for security risks.

Details
Vulnerable Package: @apollo/protobufjs

Current Version: 1.2.7

Fixed Version: 1.2.8

Security Tool: Snyk

Reason for Upgrade
The upgrade to v1.2.8 contains critical security patches that resolve known vulnerabilities in the protobuf parser/generator. Upgrading will ensure the library remains compliant with security best practices and protects downstream users from potential exploits.

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions