Skip to content

Commit e626691

Browse files
chore: upgrade @grpc/grpc-js to ^1.14.4 to address CVE-2026-48068, CVE-2026-48069 (#1315)
Refreshed the lockfile so all instances of @grpc/grpc-js resolve to 1.14.4, which patches a server crash via malformed HTTP/2 stream (CVE-2026-48068) and CVE-2026-48069. Both existing version ranges (^1.14.1 and ^1.12.6) already permit 1.14.4, so no package.json or resolutions change was required. Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1307/sourcebot-devsourcebot-cve-2026-48068-cve-2026-48068-grpcgrpc-js#agent-session-ddcdf1e5) Co-authored-by: Brendan Kellam <10233483+brendan-kellam@users.noreply.github.com> Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
1 parent f5dab5f commit e626691

2 files changed

Lines changed: 5 additions & 14 deletions

File tree

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
88
## [Unreleased]
99

1010
### Fixed
11+
- Upgraded `@grpc/grpc-js` to `^1.14.4`. [#1315](https://github.com/sourcebot-dev/sourcebot/pull/1315)
1112
- Upgraded `vite` to `^8.0.16`. [#1313](https://github.com/sourcebot-dev/sourcebot/pull/1313)
1213

1314
## [5.0.3] - 2026-06-17

yarn.lock

Lines changed: 4 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -2492,23 +2492,13 @@ __metadata:
24922492
languageName: node
24932493
linkType: hard
24942494

2495-
"@grpc/grpc-js@npm:^1.12.6":
2496-
version: 1.14.0
2497-
resolution: "@grpc/grpc-js@npm:1.14.0"
2498-
dependencies:
2499-
"@grpc/proto-loader": "npm:^0.8.0"
2500-
"@js-sdsl/ordered-map": "npm:^4.4.2"
2501-
checksum: 10c0/51e0eb32f6dac68c49502b227e565c4244f53983d2efab8ef3fd2cc923999751c059f6c77fec4941a93c44eaa58cbc321ce1e9868e1ec226fba5a6c93722c3b1
2502-
languageName: node
2503-
linkType: hard
2504-
2505-
"@grpc/grpc-js@npm:^1.14.1":
2506-
version: 1.14.1
2507-
resolution: "@grpc/grpc-js@npm:1.14.1"
2495+
"@grpc/grpc-js@npm:^1.12.6, @grpc/grpc-js@npm:^1.14.1":
2496+
version: 1.14.4
2497+
resolution: "@grpc/grpc-js@npm:1.14.4"
25082498
dependencies:
25092499
"@grpc/proto-loader": "npm:^0.8.0"
25102500
"@js-sdsl/ordered-map": "npm:^4.4.2"
2511-
checksum: 10c0/a9a8fc7f4dfa374a34e37350b37ad2c092ed533b203fe16d45ba3220fe38195d17a87527dade2e5546afeeeccfcf68d3e914705d94e44e8df461321b0c02cc7a
2501+
checksum: 10c0/0ff6395e8112ad30e8f99dbb684b997ebc3264e770b8e354f23effeedf181a380e0ecef8bca466cbbf3e9141968656144851de1da50f840a1efd9314c9812449
25122502
languageName: node
25132503
linkType: hard
25142504

0 commit comments

Comments
 (0)