Skip to content

Comments

[fix][sec] Upgrade Python protobuf version to 6.33.5 to address CVE-2026-0994#25250

Merged
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-python-protobuf
Feb 17, 2026
Merged

[fix][sec] Upgrade Python protobuf version to 6.33.5 to address CVE-2026-0994#25250
lhotari merged 1 commit intoapache:masterfrom
lhotari:lh-upgrade-python-protobuf

Conversation

@lhotari
Copy link
Member

@lhotari lhotari commented Feb 17, 2026

Motivation

  • Pulsar Functions Python support uses protobuf version 6.31.1 which includes vulnerability CVE-2026-0994

Modifications

  • Upgrade Python protobuf version to 6.33.5

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@apache apache deleted a comment from github-actions bot Feb 17, 2026
@github-actions github-actions bot added doc-not-needed Your PR changes do not impact docs and removed doc-label-missing labels Feb 17, 2026
@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.61%. Comparing base (24eba10) to head (5db360c).

Additional details and impacted files

Impacted file tree graph

@@              Coverage Diff              @@
##             master   #25250       +/-   ##
=============================================
+ Coverage     37.65%   72.61%   +34.95%     
- Complexity    13351    34025    +20674     
=============================================
  Files          1902     1959       +57     
  Lines        151237   155401     +4164     
  Branches      17238    17724      +486     
=============================================
+ Hits          56954   112840    +55886     
+ Misses        86577    33560    -53017     
- Partials       7706     9001     +1295     
Flag Coverage Δ
inttests 25.78% <ø> (-0.10%) ⬇️
systests 22.42% <ø> (-0.02%) ⬇️
unittests 73.59% <ø> (+39.24%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 1417 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@lhotari lhotari added this to the 4.2.0 milestone Feb 17, 2026
@lhotari lhotari merged commit 163b900 into apache:master Feb 17, 2026
124 of 131 checks passed
lhotari added a commit that referenced this pull request Feb 18, 2026
lhotari added a commit that referenced this pull request Feb 18, 2026
lhotari added a commit that referenced this pull request Feb 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants