Skip to content

Conversation

@lucas42
Copy link

@lucas42 lucas42 commented Jan 30, 2026

Updates

  • Affected products

Comments
Patched version has been released – see protocolbuffers/protobuf#25070 (comment)

@github-actions github-actions bot changed the base branch from main to lucas42/advisory-improvement-6746 January 30, 2026 11:23
@lucas42
Copy link
Author

lucas42 commented Jan 30, 2026

According to the thread, the team have plans to backport the patch to 6.29.x. I'm not entirely sure how you encode that in your advisory config.
But for now the only patched version is 6.33.5.

@helixplant
Copy link

Hi @lucas42,
We will update the advisory to reflect it as fixed in version 6.33.5. At this time, we cannot include the backported fix version as it does not exist, please feel free to open a PR when it is public and we will update the advisory appropriately.

@advisory-database advisory-database bot merged commit 7b11f9a into lucas42/advisory-improvement-6746 Jan 30, 2026
4 checks passed
@advisory-database
Copy link
Contributor

Hi @lucas42! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the lucas42-GHSA-7gcm-g887-7qv7 branch January 30, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants