npm protobufjs 6.8.6

latest releases: 7.2.6, 7.2.5, 6.11.4...
6 years ago

This is a security patch:

  • Fixes typeRefRe used in the parser (1.X-6.8.5) being vulnerable to ReDoS as reported by James Davis. Relevant where a user is allowed to provide .proto sources for parsing. Applications using trusted .proto definitions, JSON descriptors or static code exclusively are not affected.

Don't miss a new protobufjs release

NewReleases is sending notifications on new releases.