Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update grpc/grpc dependency to avoid vulnerability #525

Merged
merged 1 commit into from
May 7, 2024

Conversation

snake14
Copy link
Contributor

@snake14 snake14 commented May 6, 2024

Description:

It was pointed out that the plugin was locked on v1.42.0 of the grpc/grpc dependency, which is before a patch for the CVE-2023-32731 vulnerability was patched. This PR is to address that. Composer only allowed me to update to v1.57.0, but that appears to contain the patch for the vulnerability.
Fixes: #524

Review

Copy link
Contributor

@AltamashShaikh AltamashShaikh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Both GA3 and GA4 imports works as expected 👍

@snake14 snake14 merged commit 9e1385d into 5.x-dev May 7, 2024
5 checks passed
@snake14 snake14 deleted the PG-3461-update-dependency branch May 7, 2024 01:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Security: Using insecure release of grpc?
2 participants