← All tasks
javascriptgrpc/grpc-node #2495Not a task: already works

Upgrade `protobufjs` to fix security vulnerability `CVE-2023-36665`

envgap__grpc__grpc-node-2495

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
1cc36e8df81c3972fb29a30aced678acee32680a
Manifest
packages/proto-loader/package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

grpc/grpc-node #2495 · read the original issue
### Problem description

`proto-loader` [requires](https://github.com/grpc/grpc-node/blob/1cc36e8df81c3972fb29a30aced678acee32680a/packages/proto-loader/package.json#L51) `protobufjs` with version `^7.0.0` with those version before `7.2.4` containing [CVE-2023-36665](https://www.tenable.com/cve/CVE-2023-36665)



### Additional context

https://www.tenable.com/cve/CVE-2023-36665

Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]