Skip to content

Conversation

@labkey-adam
Copy link
Contributor

@labkey-adam labkey-adam commented Jul 31, 2025

Rationale

Update to suppress two "new" CVE complaints related to a shaded version of protobuf bundled with GWT. As usual, detailed information is hard to come by, but I believe these are false positives because:

  • One or both pertain to the C++ version
  • The protobuf classes are internal only and not used at runtime

Nevertheless, suppressing the errors with a simple dependency update is always preferable

gwtproject/gwt#9752
https://groups.google.com/g/google-web-toolkit/c/tr2d8-RhMPc?pli=1

Note: We're relying on the automated tests to flag any issues with the legacy plate designer (our last remaining GWT component).

@labkey-adam labkey-adam requested a review from a team July 31, 2025 23:52
@labkey-adam labkey-adam self-assigned this Aug 1, 2025
@labkey-adam labkey-adam merged commit 09de5f6 into release25.7-SNAPSHOT Aug 1, 2025
10 checks passed
@labkey-adam labkey-adam deleted the 25.7_fb_gwt_update branch August 1, 2025 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants