Skip to content

Insecure protobuf rev #205

@rsheeter

Description

@rsheeter

https://github.com/googlefonts/fontc/security/dependabot/21 suggests we update our version of protobuf.

The path to it appears to be gftools > axisregistry > protobuf and indeed I see the offending version in https://github.com/googlefonts/axisregistry/blob/main/requirements.txt. Although we don't - as far as I know - process arbitrary inputs we might as well update.

Metadata

Metadata

Assignees

No one assigned

    Labels

    --review-axisRevision of a registered axis

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions