Commit ec6aaec
chore: upgrade @grpc/grpc-js to ^1.14.4 to address CVE-2026-48068, CVE-2026-48069
Refreshed the lockfile so all instances of @grpc/grpc-js resolve to
1.14.4, which patches a server crash via malformed HTTP/2 stream
(CVE-2026-48068) and CVE-2026-48069. Both existing version ranges
(^1.14.1 and ^1.12.6) already permit 1.14.4, so no package.json or
resolutions change was required.
Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1307/sourcebot-devsourcebot-cve-2026-48068-cve-2026-48068-grpcgrpc-js#agent-session-ddcdf1e5)
Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>1 parent 242fd2e commit ec6aaec
2 files changed
Lines changed: 7 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
10 | 13 | | |
11 | 14 | | |
12 | 15 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2492 | 2492 | | |
2493 | 2493 | | |
2494 | 2494 | | |
2495 | | - | |
2496 | | - | |
2497 | | - | |
2498 | | - | |
2499 | | - | |
2500 | | - | |
2501 | | - | |
2502 | | - | |
2503 | | - | |
2504 | | - | |
2505 | | - | |
2506 | | - | |
2507 | | - | |
| 2495 | + | |
| 2496 | + | |
| 2497 | + | |
2508 | 2498 | | |
2509 | 2499 | | |
2510 | 2500 | | |
2511 | | - | |
| 2501 | + | |
2512 | 2502 | | |
2513 | 2503 | | |
2514 | 2504 | | |
| |||
0 commit comments