Skip to content

build(deps-dev): bump protobufjs from 7.5.4 to 7.5.6 in /rest-gateway#1515

Merged
wajda merged 1 commit into
developfrom
dependabot/npm_and_yarn/rest-gateway/protobufjs-7.5.5
May 7, 2026
Merged

build(deps-dev): bump protobufjs from 7.5.4 to 7.5.6 in /rest-gateway#1515
wajda merged 1 commit into
developfrom
dependabot/npm_and_yarn/rest-gateway/protobufjs-7.5.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps protobufjs from 7.5.4 to 7.5.6.

Release notes

Sourced from protobufjs's releases.

protobufjs: v7.5.6

7.5.6 (2026-04-27)

Bug Fixes

  • Backport input hardening and CLI fixes to 7.x (#2173) (75392ea)

v7.5.5

This release backports two reported security issues to 7.x branch.

  • fix: do not allow setting __proto__ in Message constructor (#2126)
  • fix: filter invalid characters from the type name (#2127)

Full Changelog: protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.5

Changelog

Sourced from protobufjs's changelog.

7.5.6 (2026-04-27)

Bug Fixes

  • Backport input hardening and CLI fixes to 7.x (#2173) (75392ea)
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for protobufjs since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 17, 2026
@dependabot dependabot Bot requested a review from wajda as a code owner April 17, 2026 05:34
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Apr 17, 2026
@dependabot dependabot Bot requested a review from cerveada as a code owner April 17, 2026 05:34
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Apr 17, 2026
@wajda
Copy link
Copy Markdown
Contributor

wajda commented Apr 17, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@wajda
Copy link
Copy Markdown
Contributor

wajda commented May 6, 2026

@dependabot rebase

Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 7.5.4 to 7.5.6.
- [Release notes](https://github.com/protobufjs/protobuf.js/releases)
- [Changelog](https://github.com/protobufjs/protobuf.js/blob/protobufjs-v7.5.6/CHANGELOG.md)
- [Commits](protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.6)

---
updated-dependencies:
- dependency-name: protobufjs
  dependency-version: 7.5.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps-dev): bump protobufjs from 7.5.4 to 7.5.5 in /rest-gateway build(deps-dev): bump protobufjs from 7.5.4 to 7.5.6 in /rest-gateway May 6, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/rest-gateway/protobufjs-7.5.5 branch from 8dd43b6 to ff23617 Compare May 6, 2026 15:09
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented May 6, 2026

@wajda wajda merged commit ab410bb into develop May 7, 2026
7 of 8 checks passed
@wajda wajda deleted the dependabot/npm_and_yarn/rest-gateway/protobufjs-7.5.5 branch May 7, 2026 07:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant