Improper Input Validation in GoGo Protobuf
An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.
plugin/marshalto - Implemented a reverse marshal strategy which allows for faster marshalling. This now avoids a recursive (and repeated) call to Size().
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps github.com/gogo/protobuf from 1.2.1 to 1.3.2. This update includes a security fix.
Vulnerabilities fixed
Release notes
Sourced from github.com/gogo/protobuf's releases.
... (truncated)
Commits
b03c65eskippy peanut butter550e889update to go version 1.15.6 and protoc 3.14.0 (#717)deb6fe8Update Readme.md5628607github/workflow - update protoc version to 3.9.1 (#637)09ab773Issue619safer (#627)8142193GoString plugin: generate values instead of pointers when a field is repeated...627c0c9umarshal - refactor skip from recursive calls to a loop. (#636)69adf3eGhworkflow (#632)8a5ed79Merge pull request #622 from jmarais/master33d4760merged in golang/protobuf commit 4c88cc3f1a34ffade77b79abc53335d1e511f25b - a...Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebasewill rebase this MR$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflicts