Skip to content

Commit a351656

Browse files
amitsi-bsclaude
andcommitted
LTS-2886: bump protobufjs to 7.6.4 to fix GHSA-xq3m-2v4x-88gg
protobufjs <7.5.5 is vulnerable to arbitrary code execution (GHSA-xq3m-2v4x-88gg). It is a dev-only transitive dependency whose parent ranges (^7.x) already permit the patched version, so this is a lockfile-only bump (7.5.4 -> 7.6.4) with no source or package.json changes. The remaining lockfile churn is npm deduping redundant entries. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 6dea233 commit a351656

1 file changed

Lines changed: 73 additions & 121 deletions

File tree

0 commit comments

Comments
 (0)