Upgrade security posture of grpc_json_transcoder #15576
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Commit Message:
Upgrade security posture of grpc_json_transcoder
Additional Description:
Follow-up on #9334 to upgrade the security posture of the filter to
robust_to_untrusted_downstream
.Since the last discussion, we have:
Note the filter depends on the external library https://github.com/grpc-ecosystem/grpc-httpjson-transcoding. We followed the external dependency policy to add CI, add SECURITY.md, improve fuzz coverage, and update the library's dependencies.
Risk Level: N/A
Testing: None
Docs Changes: None
Release Notes: None
Platform Specific Features: None
Signed-off-by: Teju Nareddy [email protected]