Skip to content

Conversation

@jlorper
Copy link
Member

@jlorper jlorper commented Jul 24, 2025

Fixes

Downgrade google-cloud/datastore as 10.0.1 depends on vulnerable version of protobufjs
https://app.asana.com/1/27145998307022/project/183329416800305/task/1210233312389134

Change implications

  • includes or requires infrastructure changes? (tag 'infra-change')

@jlorper jlorper self-assigned this Jul 24, 2025
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR downgrades the @google-cloud/datastore package from version 10.0.1 to 9.2.1 to address a security vulnerability in a transitive dependency (protobufjs).

  • Downgrade @google-cloud/datastore from ^10.0.1 to ^9.2.1
Comments suppressed due to low confidence (1)

package.json:19

  • The version ^9.2.1 for @google-cloud/datastore may not exist. The latest version in the 9.x series was 9.0.3. Please verify this version exists before merging.
    "@google-cloud/datastore": "^9.2.1",

@jlorper jlorper added the dependencies Pull requests that update a dependency file label Jul 24, 2025
@jlorper jlorper merged commit f96e485 into main Jul 28, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants