Uh oh!
There was an error while loading. Please reload this page.
fix: override protobufjs to patch CVE GHSA-jvwf-75h9-cwgg - #121
Conversation
protobufjs <7.5.6 is vulnerable to process-wide denial of service through unsafe option paths. The vulnerable version (7.4.0) was pulled in transitively via @atproto/bsky -> etcd3 -> @grpc/proto-loader. Added a pnpm override to force protobufjs >=7.5.6 (resolved to 8.2.0).
✅ Deploy Preview for tsky ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Coverage Report for ./packages/client/
File CoverageNo changed files found. |
commit: |
MathurAditya724
commented
May 13, 2026
fix-ci: attempt 1 — the |
fix-ci: attempt 1 — the failing run was on |
Uh oh!
There was an error while loading. Please reload this page.
Summary
pnpm.overridesentry to forceprotobufjsto>=7.5.6, resolving GHSA-jvwf-75h9-cwgg (high severity — process-wide DoS through unsafe option paths)protobufjs@7.4.0was a transitive dependency via@atproto/bsky→etcd3→@grpc/proto-loader; resolved to8.2.0Closes https://github.com/tsky-dev/tsky/security/dependabot/135