Commit 4313bd2
authored
fix(security): upgrade protobufjs to 7.5.5 to fix critical CVE (calcom#28941)
Pins protobufjs to 7.5.5 via resolutions to patch GHSA-xq3m-2v4x-88gg
(arbitrary code execution, <7.5.5). The vulnerable 7.4.0 was pulled in
transitively through @opentelemetry/otlp-transformer, causing the
Security Audit CI job to fail on all PRs.1 parent 9efd0e6 commit 4313bd2
2 files changed
Lines changed: 5 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
145 | 145 | | |
146 | 146 | | |
147 | 147 | | |
| 148 | + | |
148 | 149 | | |
149 | 150 | | |
150 | 151 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34681 | 34681 | | |
34682 | 34682 | | |
34683 | 34683 | | |
34684 | | - | |
34685 | | - | |
34686 | | - | |
| 34684 | + | |
| 34685 | + | |
| 34686 | + | |
34687 | 34687 | | |
34688 | 34688 | | |
34689 | 34689 | | |
| |||
34697 | 34697 | | |
34698 | 34698 | | |
34699 | 34699 | | |
34700 | | - | |
| 34700 | + | |
34701 | 34701 | | |
34702 | 34702 | | |
34703 | 34703 | | |
| |||
0 commit comments