Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency grpc to v1.24.4 [SECURITY] #72

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
grpc (source) 1.20.0 -> 1.24.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-7768

"The package grpc before 1.24.4 and the package @​grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition."


Release Notes

grpc/grpc-node (grpc)

v1.24.4: Node gRPC v1.24.4

Compare Source

  • Add support for Electron 10 and newer minor versions of Electron 8 and 9 (#​1615)
  • Add a note in the README stating the latest supported versions of Node and Electron (#​1615)
  • Prevent prototype pollution in loadPackageDefinition (#​1606)
  • Add ResponseType to ServerWritableStream type definition for compatibility with @grpc/grpc-js (#​1590 contributed by @​badsyntax)
  • Add methodTypes enum to type definition (#​1496 contributed by @​jncr)

v1.24.3: grpc 1.24.3

Compare Source

Known Issues:

  • #​1407 may cause errors when running on Node 14

v1.24.2: Node gRPC v1.24.2

  • Publish some missing files to fix building from source (#​1060)
  • Add support for Node 13 and Electron 7 (#​1097)

C core release notes

v1.23.4: Node gRPC v1.23.4

Compare Source

C core release notes

v1.23.3: Node gRPC v1.23.3

Node gRPC v1.23.0

C core release notes

Node gRPC v1.23.1

  • Remove dependency on @types/protobufjs (#​999)

Node gRPC v1.23.2

  • Merge some changes from the 1.22 branch that got lost (#​1002)

Node gRPC v1.23.3

  • Fix EventEmitter import in TypeScript types file (#​1007 contributed by @​sandersn)
  • Stop importing protobufjs in TypeScript types file (#​1008)

v1.22.2: Node gRPC v1.22.2

v1.22.0: Node gRPC v1.22.0

  • Add support for the cares DNS resolver. This can be enabled by setting the environment variable GRPC_DNS_RESOLVER=ares. This will become the default in version 1.23.x, so we recommend enabling that option to verify that it works correctly with your setup (#​864)

  • Add metadata options (#​796)

  • Add support for Electron 4.2 (#​944 contributed by @​CapOM)

v1.21.0: Node gRPC v1.21.0

Compare Source

  • Remove unused ChannelCredential type definitions (#​854 contributed by @​eoogbe)

C core release notes

v1.20.3: Node gRPC v1.20.3

Compare Source

  • Add support for Electron 5 (#​848)
  • Improve error output in some cases when failing to load the native addon (#​849)

v1.20.2: Node gRPC v1.20.2

Compare Source

  • Add support for Node 12

C core changes:

  • Fix possible blue screen on Windows when using "localhost" target addresses (grpc/grpc#18834).

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from b29d55e to 4196dae Compare August 11, 2024 23:12
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from 4196dae to a655cda Compare August 28, 2024 09:18
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from a655cda to 309d389 Compare September 12, 2024 13:16
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from 309d389 to bc85b28 Compare October 9, 2024 08:20
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from bc85b28 to bc5cec6 Compare December 2, 2024 11:07
@renovate renovate bot changed the title Update dependency grpc to v1.24.4 [SECURITY] Update dependency grpc to v1.24.4 [SECURITY] - autoclosed Dec 8, 2024
@renovate renovate bot closed this Dec 8, 2024
@renovate renovate bot deleted the renovate/npm-grpc-vulnerability branch December 8, 2024 18:34
@renovate renovate bot changed the title Update dependency grpc to v1.24.4 [SECURITY] - autoclosed Update dependency grpc to v1.24.4 [SECURITY] Dec 8, 2024
@renovate renovate bot reopened this Dec 8, 2024
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from bc5cec6 to f63d253 Compare December 9, 2024 02:54
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from f63d253 to 801981f Compare December 29, 2024 12:34
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from 801981f to b884099 Compare January 23, 2025 17:50
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from b884099 to 8fdc1a6 Compare January 30, 2025 18:33
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from 8fdc1a6 to 696bb24 Compare February 9, 2025 13:03
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from 696bb24 to fff896f Compare February 19, 2025 15:32
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from fff896f to 86fa487 Compare March 3, 2025 12:41
@renovate renovate bot force-pushed the renovate/npm-grpc-vulnerability branch from 86fa487 to 427c35f Compare March 11, 2025 10:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants