Skip to content

chore(deps): bump protobufjs from 7.5.4 to 7.6.5 - #4130

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/protobufjs-7.6.5
Open

chore(deps): bump protobufjs from 7.5.4 to 7.6.5#4130
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/protobufjs-7.6.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor

Bumps protobufjs from 7.5.4 to 7.6.5.

Release notes

Sourced from protobufjs's releases.

protobufjs: v7.6.5

7.6.5 (2026-07-04)

Bug Fixes

protobufjs: v7.6.4

7.6.4 (2026-06-12)

Bug Fixes

protobufjs: v7.6.3

7.6.3 (2026-06-09)

Bug Fixes

  • Avoid name collisions in generated code (#2311) (78a9576)
  • Preserve null conversion behavior for fieldless messages (#2312) (df91652)

protobufjs: v7.6.2

7.6.2 (2026-05-30)

Bug Fixes

  • Backport consistency and correctness fixes (#2294) (a92f72e)

protobufjs: v7.6.1

7.6.1 (2026-05-22)

Bug Fixes

protobufjs: v7.6.0

7.6.0 (2026-05-18)

Features

... (truncated)

Changelog

Sourced from protobufjs's changelog.

7.6.5 (2026-07-04)

Bug Fixes

7.6.4 (2026-06-12)

Bug Fixes

7.6.3 (2026-06-09)

Bug Fixes

  • Avoid name collisions in generated code (#2311) (78a9576)
  • Preserve null conversion behavior for fieldless messages (#2312) (df91652)

7.6.2 (2026-05-30)

Bug Fixes

  • Backport consistency and correctness fixes (#2294) (a92f72e)

7.6.1 (2026-05-22)

Bug Fixes

7.6.0 (2026-05-18)

Features

7.5.9 (2026-05-17)

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for protobufjs since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 7.5.4 to 7.6.5.
- [Release notes](https://github.com/protobufjs/protobuf.js/releases)
- [Changelog](https://github.com/protobufjs/protobuf.js/blob/protobufjs-v7.6.5/CHANGELOG.md)
- [Commits](protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.6.5)

---
updated-dependencies:
- dependency-name: protobufjs
  dependency-version: 7.6.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 21, 2026
@github-actions

Copy link
Copy Markdown

Overview

Image reference testlagoon/api:main lagoon/api:ci-latest
- digest ae2178b01fcd 8f0939f6a9b6
- tag main ci-latest
- vulnerabilities critical: 5 high: 74 medium: 70 low: 11 unspecified: 2 critical: 3 high: 61 medium: 61 low: 9 unspecified: 2
- platform linux/amd64 linux/amd64
- size 142 MB 171 MB (+29 MB)
- packages 1478 1482 (+4)
Base Image node:22-alpine
also known as:
22-alpine3.23
jod-alpine
jod-alpine3.23
node:22-alpine3.23
also known as:
22.23-alpine3.23
22.23.1-alpine3.23
jod-alpine3.23
- vulnerabilities critical: 1 high: 10 medium: 10 low: 2 unspecified: 11 critical: 0 high: 2 medium: 6 low: 0
Environment Variables (1 changes)
  • ± 1 changed
  • 16 unchanged
 BASH_ENV=/home/.bashrc
 ELASTICSEARCH_URL=http://logs-db-service:9200
 ENV=/home/.bashrc
 HOME=/home
 KEYCLOAK_ADMIN_API_CLIENT_SECRET=bb86d344-a52d-11ef-b872-4f4337ee24f0
 KEYCLOAK_API_CLIENT_SECRET=39d5282d-3684-4026-b4ed-04bbc034b61a
 LAGOON=node
 LAGOON_LOCALDEV_HTTP_PORT=3000
 LAGOON_VERSION=development
 LOGSDB_ADMIN_PASSWORD=admin
 NODE_ENV=production
-NODE_VERSION=22.22.3
+NODE_VERSION=22.23.1
 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
 REDIS_PASSWORD=admin
 TMP=/tmp
 TMPDIR=/tmp
 YARN_VERSION=1.22.22
Packages and Vulnerabilities (13 package changes and 15 vulnerability changes)
  • ♾️ 13 packages changed
  • 1255 packages unchanged
  • ✔️ 15 vulnerabilities removed
Changes for packages of type apk (7 changes)
Package Version
testlagoon/api:main
Version
lagoon/api:ci-latest
♾️ alpine-base 3.23.4-r0 3.23.5-r0
♾️ alpine-release 3.23.4-r0 3.23.5-r0
♾️ ca-certificates 20260413-r0 20260611-r0
♾️ ca-certificates-bundle 20260413-r0 20260611-r0
♾️ libcrypto3 3.5.6-r0 3.5.7-r0
♾️ libssl3 3.5.6-r0 3.5.7-r0
♾️ openssl 3.5.6-r0 3.5.7-r0
critical: 1 high: 8 medium: 0 low: 0
Removed vulnerabilities (9):
  • critical : CVE--2026--34182
  • high : CVE--2026--45447
  • high : CVE--2026--7383
  • high : CVE--2026--9076
  • high : CVE--2026--45445
  • high : CVE--2026--42764
  • high : CVE--2026--34183
  • high : CVE--2026--34180
  • high : CVE--2026--34181
Changes for packages of type github (1 changes)
Package Version
testlagoon/api:main
Version
lagoon/api:ci-latest
♾️ node 22.22.3 22.23.1
Changes for packages of type npm (5 changes)
Package Version
testlagoon/api:main
Version
lagoon/api:ci-latest
♾️ @protobufjs/codegen 2.0.4 2.0.5
♾️ @protobufjs/eventemitter 1.1.0 1.1.1
♾️ @protobufjs/fetch 1.1.0 1.1.1
♾️ @protobufjs/utf8 1.1.0 1.1.2
♾️ protobufjs 7.5.4 7.6.5
critical: 1 high: 5 medium: 0 low: 0
Removed vulnerabilities (6):
  • critical : CVE--2026--41242
  • high : CVE--2026--44291
  • high : CVE--2026--44293
  • high : CVE--2026--48712
  • high : CVE--2026--44290
  • high : CVE--2026--44289

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants