Skip to content

fix(deps): vuln protobufjs (patch → 7.6.6) [integration-tests/lambda/otlp-node/package.json] - #1347

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/lambda/0-1788172850
Draft

fix(deps): vuln protobufjs (patch → 7.6.6) [integration-tests/lambda/otlp-node/package.json]#1347
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/lambda/0-1788172850

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: Security update — 1 package upgraded (patch changes only)

Manifests changed:

  • integration-tests/lambda/otlp-node/package.json (npm)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
protobufjs 7.6.4 7.6.6 patch Transitive 2 MEDIUM

Security Details

ℹ️ Other Vulnerabilities (2)
Package CVE Severity Summary Unsafe Version Fixed In Case
protobufjs GHSA-j3f2-48v5-ccww MODERATE protobufjs: Denial of Service via infinite loop in .proto option parsing 7.6.4 7.6.5 -
protobufjs CVE-2026-59877 MODERATE protobufjs: Denial of Service via infinite loop in .proto option parsing 7.6.4 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-official

datadog-official Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Pipelines

Unblock PR with BitsAI

⚠️ Warnings

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 2 Pipeline jobs failed

DataDog/datadog-lambda-extension | e2e-test-status (amd64) — 🔧 Needs a code fix, caused by this PR

View more details · View in GitLab

DataDog/datadog-lambda-extension | e2e-test-status (amd64, fips)

View more details · View in GitLab

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 0e22606 | Docs | View more details | Give us feedback!

…node/package.json]

Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with main — rebased onto f32645c.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-aad58d
dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/minorpatch/npm/lambda/0-1788172850 branch from 063b788 to 0e22606 Compare September 1, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants