chore(deps): bump protobufjs from 7.5.4 to 7.5.8 in /ui by dependabot[bot] · Pull Request #6426 · feast-dev/feast
Conversation
Contributor
Bumps protobufjs from 7.5.4 to 7.5.8.
Release notes
Sourced from protobufjs's releases.
protobufjs: v7.5.8
7.5.8 (2026-05-12)
Bug Fixes
protobufjs: v7.5.7
7.5.7 (2026-05-09)
Bug Fixes
protobufjs: v7.5.6
7.5.6 (2026-04-27)
Bug Fixes
v7.5.5
This release backports two reported security issues to 7.x branch.
- fix: do not allow setting
__proto__in Message constructor (#2126)- fix: filter invalid characters from the type name (#2127)
Full Changelog: protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.5
Changelog
Sourced from protobufjs's changelog.
7.5.8 (2026-05-12)
Bug Fixes
7.5.7 (2026-05-09)
Bug Fixes
7.5.6 (2026-04-27)
Bug Fixes
Commits
d7035f9chore: release protobufjs-v7.x (#2248)54b593ffix: Backport parser hardening to 7.x (#2245)e88fceachore: release protobufjs-v7.x (#2239)cc7d595fix: Restore first-match namespace lookup (#2236)3abc9b5chore: release protobufjs-v7.x (#2190)a0bf2dffix: Update CLI peer dependency (7.x) (#2189)2189e5bchore: release protobufjs-v7.x (#2174)75392eafix: Backport input hardening and CLI fixes to 7.x (#2173)8af8d7cchore(ci): Fix 7.x release please configuration (#2169)e92ca42chore(ci): Enable release-please for 7.x (#2166)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for protobufjs since your current version.
dependabot
Bot
added
dependencies
labels
dependabot
Bot
requested a review
from a team
as a code owner
dependabot
Bot
added
dependencies
labels
dependabot
Bot
mentioned this pull request
Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 7.5.4 to 7.5.8. - [Release notes](https://github.com/protobufjs/protobuf.js/releases) - [Changelog](https://github.com/protobufjs/protobuf.js/blob/protobufjs-v7.5.8/CHANGELOG.md) - [Commits](protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.8) --- updated-dependencies: - dependency-name: protobufjs dependency-version: 7.5.8 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
changed the title
chore(deps): Bump protobufjs from 7.5.4 to 7.5.8 in /ui
chore(deps): bump protobufjs from 7.5.4 to 7.5.8 in /ui
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/ui/protobufjs-7.5.8
branch
from
864794d to
7149c17
Compare
dependabot
Bot
commented
on behalf of github
Jun 15, 2026
dependabot Bot commented on behalf of github
Contributor Author
Superseded by #6523.
dependabot
Bot
closed this
dependabot
Bot
deleted the
dependabot/npm_and_yarn/ui/protobufjs-7.5.8
branch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment