You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue has been fixed in the latest versions of @google-cloud/pubsub package. But firebase-tools project is still using @google-cloud/pubsub version 3.x.x even in its latest release.
The text was updated successfully, but these errors were encountered:
Hey @sandeep-reddy-u, thanks for reporting this. Let me discuss this with our engineering team to see what we can do to address the vulnerability issue.
Project https://github.com/firebase/firebase-tools has dependency on @google-cloud/pubsub package, which has a critical security vulnerability.
Severity: critical
Title: protobufjs Prototype Pollution vulnerability
Package: protobufjs
Patched in protobufjs version: >=7.2.5
Path: firebase-tools > @google-cloud/pubsub > google-gax > protobufjs
More info: https://www.npmjs.com/advisories/1096964
This issue has been fixed in the latest versions of @google-cloud/pubsub package. But firebase-tools project is still using @google-cloud/pubsub version 3.x.x even in its latest release.
The text was updated successfully, but these errors were encountered: