Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Any plans on fixing protobufjs Prototype Pollution vulnerability (GHSA-h755-8qp9-cq85) please? #245

Open
huxingyi opened this issue Jul 10, 2023 · 1 comment

Comments

@huxingyi
Copy link

Hi, looks like this hasn't been raised as an issue, and not sure if this has been brought to maintainers' attention.

There is a new vulnerability published 5 days ago, please check the details here:
GHSA-h755-8qp9-cq85

I have seen multiple pull requests created by Dependabot, but not found the one containing the recent vulnerability fixing. Maybe there is a limit on how many pull requests created by bots?

I forked this repo just for the purpose to verify the Dependabot, and it's able to raise a fixing pull request for this vulnerability (Enabled it in the Security tab of the forked repo): huxingyi#1

If you could have a look on this vulnerability issue, that would be much appreciated, thanks!

@jrm86
Copy link

jrm86 commented Jul 11, 2023

This looks like a pretty cut and dry fix (or, should have already been fixed by dependabot). It would be wonderful to see this resolved ASAP if someone is still maintaining this repo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants