Skip to content

chore(deps-dev): Bump protobufjs from 7.5.4 to 7.5.6#2784

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/protobufjs-7.5.5
Open

chore(deps-dev): Bump protobufjs from 7.5.4 to 7.5.6#2784
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/protobufjs-7.5.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

Bumps protobufjs from 7.5.4 to 7.5.6.

Release notes

Sourced from protobufjs's releases.

protobufjs: v7.5.6

7.5.6 (2026-04-27)

Bug Fixes

  • Backport input hardening and CLI fixes to 7.x (#2173) (75392ea)

v7.5.5

This release backports two reported security issues to 7.x branch.

  • fix: do not allow setting __proto__ in Message constructor (#2126)
  • fix: filter invalid characters from the type name (#2127)

Full Changelog: protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.5

Changelog

Sourced from protobufjs's changelog.

7.5.6 (2026-04-27)

Bug Fixes

  • Backport input hardening and CLI fixes to 7.x (#2173) (75392ea)
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for protobufjs since your current version.


@dependabot dependabot Bot added dependencies One or more dependencies are being bumped javascript Pull requests that update Javascript code labels Apr 17, 2026
@dependabot dependabot Bot requested a review from a team as a code owner April 17, 2026 05:33
@dependabot dependabot Bot added dependencies One or more dependencies are being bumped javascript Pull requests that update Javascript code labels Apr 17, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/protobufjs-7.5.5 branch from c1cefbb to 978bed2 Compare April 21, 2026 04:44
Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 7.5.4 to 7.5.6.
- [Release notes](https://github.com/protobufjs/protobuf.js/releases)
- [Changelog](https://github.com/protobufjs/protobuf.js/blob/protobufjs-v7.5.6/CHANGELOG.md)
- [Commits](protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.6)

---
updated-dependencies:
- dependency-name: protobufjs
  dependency-version: 7.5.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): Bump protobufjs from 7.5.4 to 7.5.5 chore(deps-dev): Bump protobufjs from 7.5.4 to 7.5.6 Apr 30, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/protobufjs-7.5.5 branch from 978bed2 to 0988528 Compare April 30, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies One or more dependencies are being bumped javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants