-
Notifications
You must be signed in to change notification settings - Fork 578
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump protobuf to 3.25.5 #6343
Merged
Merged
Bump protobuf to 3.25.5 #6343
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Release note changesThe following release notes were modified. Please ensure they look correct. Release Notesfirebase-config### {{remote_config}} version 22.0.1 {: #remote-config_v22-0-1}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{remote_config}} Kotlin extensions version 22.0.1 {: #remote-config-ktx_v22-0-1}
The Kotlin extensions library transitively includes the updated
`firebase-config` library. The Kotlin extensions library has no additional
updates.
firebase-crashlytics### {{crashlytics}} version 19.2.1 {: #crashlytics_v19-2-1}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{crashlytics}} Kotlin extensions version 19.2.1 {: #crashlytics-ktx_v19-2-1}
The Kotlin extensions library transitively includes the updated
`firebase-crashlytics` library. The Kotlin extensions library has no additional
updates.
firebase-dataconnect### {{firebase_data_connect}} version 16.0.0-beta02 {: #dataconnect_v16-0-0-beta02}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
firebase-firestore### {{firestore}} version 25.1.1 {: #firestore_v25-1-1}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{firestore}} Kotlin extensions version 25.1.1 {: #firestore-ktx_v25-1-1}
The Kotlin extensions library transitively includes the updated
`firebase-firestore` library. The Kotlin extensions library has no additional
updates.
firebase-inappmessaging-display### {{inappmessaging}} Display version 21.0.1 {: #inappmessaging-display_v21-0-1}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{inappmessaging}} Display Kotlin extensions version 21.0.1 {: #inappmessaging-display-ktx_v21-0-1}
The Kotlin extensions library transitively includes the updated
`firebase-inappmessaging-display` library. The Kotlin extensions library has no additional
updates.
firebase-inappmessaging### {{inappmessaging}} version 21.0.1 {: #inappmessaging_v21-0-1}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{inappmessaging}} Kotlin extensions version 21.0.1 {: #inappmessaging-ktx_v21-0-1}
The Kotlin extensions library transitively includes the updated
`firebase-inappmessaging` library. The Kotlin extensions library has no additional
updates.
firebase-messaging### {{messaging_longer}} version 24.0.3 {: #messaging_v24-0-3}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{messaging_longer}} Kotlin extensions version 24.0.3 {: #messaging-ktx_v24-0-3}
The Kotlin extensions library transitively includes the updated
`firebase-messaging` library. The Kotlin extensions library has no additional
updates.
firebase-ml-modeldownloader### {{firebase_ml}} version 25.0.1 {: #firebaseml-modeldownloader_v25-0-1}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{firebase_ml}} Kotlin extensions version 25.0.1 {: #firebaseml-modeldownloader-ktx_v25-0-1}
The Kotlin extensions library transitively includes the updated
`firebase-ml-modeldownloader` library. The Kotlin extensions library has no additional
updates.
firebase-perf### {{perfmon}} version 21.0.2 {: #performance_v21-0-2}
* {{changed}} Updated protobuf dependency to `3.25.5` to fix
[CVE-2024-7254](https://github.com/advisories/GHSA-735f-pc8j-v9w8).
#### {{perfmon}} Kotlin extensions version 21.0.2 {: #performance-ktx_v21-0-2}
The Kotlin extensions library transitively includes the updated
`firebase-perf` library. The Kotlin extensions library has no additional
updates.
The following had changelogs that were modified, but did not have any unreleased entries for release notes to generate from. Changelogsencoders:firebase-encoders-proto |
rlazo
reviewed
Oct 4, 2024
rlazo
approved these changes
Oct 4, 2024
Lets see if this breaks smoke tests. The fact that the version number wasn't bumped might cause false positives, plus we have a bunch of exceptions on well known types anyways that could cause that too.
…rebase-android-sdk into daymon-bump-protobuf
Merged
daymxn
added a commit
that referenced
this pull request
Oct 15, 2024
Per [b/373458620](https://b.corp.google.com/issues/373458620), This PR adds changelogs that were missing from #6343; due to library groups.
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Per b/371058443,
This bumps our protobuf deps to
3.25.5
to address CVE 2024-7254.All relevant libraries should have a changelog attached, unless I missed any.
This PR also fixes the following:
Fixes #6336