Skip to content

Bump protobufjs from 7.4.0 to 7.5.5 in /ios#48

Merged
rajpatta merged 1 commit intomainfrom
AAP-18854/bump-protobufjs-ios
Apr 21, 2026
Merged

Bump protobufjs from 7.4.0 to 7.5.5 in /ios#48
rajpatta merged 1 commit intomainfrom
AAP-18854/bump-protobufjs-ios

Conversation

@GayatriNairAtBrowserstack
Copy link
Copy Markdown
Collaborator

@GayatriNairAtBrowserstack GayatriNairAtBrowserstack commented Apr 21, 2026

Summary

  • Bumps protobufjs from 7.4.0 to 7.5.5 in the /ios directory to fix an arbitrary code execution vulnerability (GHSA-xq3m-2v4x-88gg)
  • The /android directory was already patched to 7.5.5 via Dependabot PR Bump protobufjs from 7.4.0 to 7.5.5 in /android #46 -- this brings iOS in line
  • Only ios/package-lock.json is changed (transitive dependency version bump, no code changes)

JIRA

AAP-18854

Test plan

  • Verified protobufjs resolves to 7.5.5 in ios/package-lock.json
  • Confirmed no breaking changes -- protobufjs 7.5.5 is a patch release compatible with ^7.2.5
  • Verified android directory already has 7.5.5 (consistency check)
  • CI passes on merge

🤖 Generated with Claude Code

Fix CVE for arbitrary code execution in protobufjs (GHSA-xq3m-2v4x-88gg).
This matches the android directory which was already patched via Dependabot PR #46.

JIRA: AAP-18854

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rajpatta rajpatta merged commit 65ae23f into main Apr 21, 2026
5 checks passed
@rajpatta rajpatta deleted the AAP-18854/bump-protobufjs-ios branch April 21, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants