Repository navigation
Conversation
codyoss
force-pushed
the
release-please--branches--main--components--firestore
branch
from
May 6, 2026 18:07
7033d9c to
1b3c8a2
Compare
Contributor
There was a problem hiding this comment.
Code Review
This pull request updates the handwritten/firestore package from version 8.5.0 to 8.6.0. The update introduces new features including FieldValue.minimum(), FieldValue.maximum(), and enhanced search stage support for languageCode, offset, limit, and retrievalDepth. It also includes bug fixes for limit(0) serialization and the handling of undefined properties in subpipelines. I have no feedback to provide.
release-please
Bot
force-pushed
the
release-please--branches--main--components--firestore
branch
from
May 6, 2026 21:35
1b3c8a2 to
dd8d5f7
Compare
shivanee-p
pushed a commit
that referenced
this pull request
Aug 10, 2026
…8253) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [protobufjs-cli](https://redirect.github.com/protobufjs/protobuf.js) | [`1.2.0` → `1.2.1`](https://renovatebot.com/diffs/npm/protobufjs-cli/1.2.0/1.2.1) |  |  | --- ### protobuf.js is Vulnerable to OS Command Injection in the CLI [CVE-2026-42290](https://nvd.nist.gov/vuln/detail/CVE-2026-42290) / [GHSA-f84p-cvgm-xgjj](https://redirect.github.com/advisories/GHSA-f84p-cvgm-xgjj) <details> <summary>More information</summary> #### Details ##### Summary `pbts` invoked JSDoc by building a shell command string from input file paths and executing it through `child_process.exec`. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments. ##### Impact An attacker who can control file names or paths passed to `pbts` may be able to execute arbitrary shell commands with the privileges of the process running `pbts`. This affects the protobufjs CLI tooling path. The protobufjs runtime APIs for encoding, decoding, parsing, and loading protobuf messages are not directly affected by this issue. ##### Preconditions - The application or user must invoke `pbts` on file paths influenced by an attacker. - The attacker must be able to supply or create a path containing shell-significant characters. - The vulnerable `pbts` version must execute the generated JSDoc command through a shell. ##### Workarounds Do not run affected versions of `pbts` on attacker-controlled file names or paths. If this cannot be avoided, sanitize or rename input files before invoking `pbts`, or run the CLI in an isolated environment with minimal privileges. #### Severity - CVSS Score: 7.8 / 10 (High) - Vector String: `CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H` #### References - [https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-f84p-cvgm-xgjj](https://redirect.github.com/protobufjs/protobuf.js/security/advisories/GHSA-f84p-cvgm-xgjj) - [https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1) - [https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2) - [https://nvd.nist.gov/vuln/detail/CVE-2026-42290](https://nvd.nist.gov/vuln/detail/CVE-2026-42290) - [https://github.com/advisories/GHSA-f84p-cvgm-xgjj](https://redirect.github.com/advisories/GHSA-f84p-cvgm-xgjj) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-f84p-cvgm-xgjj) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### protobuf.js: Code injection in pbjs static output from crafted schema names [CVE-2026-44295](https://nvd.nist.gov/vuln/detail/CVE-2026-44295) / [GHSA-6r35-46g8-jcw9](https://redirect.github.com/advisories/GHSA-6r35-46g8-jcw9) <details> <summary>More information</summary> #### Details ##### Summary `pbjs` static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output without sufficient sanitization. ##### Impact An attacker who can provide or influence schemas passed to `pbjs` may be able to cause generated JavaScript output to contain attacker-controlled code. The injected code would run if the generated file is later executed or imported by the application or build process. This affects the protobufjs CLI static code generation path. Applications that only use trusted schemas, or that do not execute generated output from untrusted schemas, are not directly affected. ##### Preconditions - The application or build process must run `pbjs` static code generation on a schema or JSON descriptor influenced by an attacker. - The attacker-controlled input must contain crafted schema names that reach generated JavaScript output. - The generated JavaScript file must subsequently be executed, imported, or otherwise evaluated. ##### Workarounds Do not run affected versions of `pbjs` static code generation on untrusted schemas or descriptors. If untrusted schemas must be accepted, validate schema names before code generation and run generation in an isolated environment. #### Severity - CVSS Score: 8.7 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N` #### References - [https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-6r35-46g8-jcw9](https://redirect.github.com/protobufjs/protobuf.js/security/advisories/GHSA-6r35-46g8-jcw9) - [https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1) - [https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2) - [https://nvd.nist.gov/vuln/detail/CVE-2026-44295](https://nvd.nist.gov/vuln/detail/CVE-2026-44295) - [https://github.com/advisories/GHSA-6r35-46g8-jcw9](https://redirect.github.com/advisories/GHSA-6r35-46g8-jcw9) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-6r35-46g8-jcw9) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>protobufjs/protobuf.js (protobufjs-cli)</summary> ### [`v1.2.1`](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1): protobufjs-cli: v1.2.1 [Compare Source](https://redirect.github.com/protobufjs/protobuf.js/compare/protobufjs-cli-v1.2.0...protobufjs-cli-v1.2.1) ##### Bug Fixes - Backport input hardening and CLI fixes to 7.x ([#​2173](https://redirect.github.com/protobufjs/protobuf.js/issues/2173)) ([75392ea](https://redirect.github.com/protobufjs/protobuf.js/commit/75392ea1b78bdc4faba027b5db44ad7c50e9c454)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/googleapis/google-cloud-node). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
shivanee-p
pushed a commit
that referenced
this pull request
Oct 7, 2026
…9506) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@grpc/grpc-js](https://grpc.io/) ([source](https://redirect.github.com/grpc/grpc-node)) | [`1.14.4` → `1.14.5`](https://renovatebot.com/diffs/npm/@grpc%2fgrpc-js/1.14.4/1.14.5) |  |  | --- ### @​grpc/grpc-js can allocate memory for incoming messages well above configured limits [CVE-2024-37168](https://nvd.nist.gov/vuln/detail/CVE-2024-37168) / [GHSA-7v5v-9h63-cj86](https://redirect.github.com/advisories/GHSA-7v5v-9h63-cj86) <details> <summary>More information</summary> #### Details ##### Impact There are two separate code paths in which memory can be allocated per message in excess of the `grpc.max_receive_message_length` channel option: 1. If an incoming message has a size on the wire greater than the configured limit, the entire message is buffered before it is discarded. 2. If an incoming message has a size within the limit on the wire but decompresses to a size greater than the limit, the entire message is decompressed into memory, and on the server is not discarded. ##### Patches This has been patched in versions 1.10.9, 1.9.15, and 1.8.22 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L` #### References - [https://github.com/grpc/grpc-node/security/advisories/GHSA-7v5v-9h63-cj86](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-7v5v-9h63-cj86) - [https://github.com/grpc/grpc-node/commit/08b0422dae56467ecae1007e899efe66a8c4a650](https://redirect.github.com/grpc/grpc-node/commit/08b0422dae56467ecae1007e899efe66a8c4a650) - [https://github.com/grpc/grpc-node/commit/674f4e351a619fd4532f84ae6dff96b8ee4e1ed3](https://redirect.github.com/grpc/grpc-node/commit/674f4e351a619fd4532f84ae6dff96b8ee4e1ed3) - [https://github.com/grpc/grpc-node/commit/a8a020339c7eab1347a343a512ad17a4aea4bfdb](https://redirect.github.com/grpc/grpc-node/commit/a8a020339c7eab1347a343a512ad17a4aea4bfdb) - [https://nvd.nist.gov/vuln/detail/CVE-2024-37168](https://nvd.nist.gov/vuln/detail/CVE-2024-37168) - [https://github.com/advisories/GHSA-7v5v-9h63-cj86](https://redirect.github.com/advisories/GHSA-7v5v-9h63-cj86) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-7v5v-9h63-cj86) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @​grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash [CVE-2026-48069](https://nvd.nist.gov/vuln/detail/CVE-2026-48069) / [GHSA-99f4-grh7-6pcq](https://redirect.github.com/advisories/GHSA-99f4-grh7-6pcq) <details> <summary>More information</summary> #### Details ##### Impact An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @​grpc/grpc-js ##### Patches The following version have fixes for this vulnerability: - 1.9.16 - 1.10.12 - 1.11.4 - 1.12.7 - 1.13.5 - 1.14.4 ##### Workarounds There is no workaround. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16) - [https://github.com/advisories/GHSA-99f4-grh7-6pcq](https://redirect.github.com/advisories/GHSA-99f4-grh7-6pcq) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-99f4-grh7-6pcq) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @​grpc/grpc-js: A malformed request can cause a server crash [CVE-2026-48068](https://nvd.nist.gov/vuln/detail/CVE-2026-48068) / [GHSA-5375-pq7m-f5r2](https://redirect.github.com/advisories/GHSA-5375-pq7m-f5r2) <details> <summary>More information</summary> #### Details ##### Impact An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @​grpc/grpc-js. ##### Patches The following version have fixes for this vulnerability: - 1.9.16 - 1.10.12 - 1.11.4 - 1.12.7 - 1.13.5 - 1.14.4 ##### Workarounds There is no workaround. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4) - [https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16) - [https://github.com/advisories/GHSA-5375-pq7m-f5r2](https://redirect.github.com/advisories/GHSA-5375-pq7m-f5r2) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-5375-pq7m-f5r2) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @​grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages [CVE-2026-101915](https://nvd.nist.gov/vuln/detail/CVE-2026-101915) / [GHSA-f596-whhp-79r4](https://redirect.github.com/advisories/GHSA-f596-whhp-79r4) <details> <summary>More information</summary> #### Details ##### Impact If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using `@grpc/grpc-js` to run servers. ##### Patches This vulnerability is fixed in 1.13.6 and 1.14.5. ##### Workarounds This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information. #### Severity - CVSS Score: 3.7 / 10 (Low) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N` #### References - [https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4) - [https://nvd.nist.gov/vuln/detail/CVE-2026-101915](https://nvd.nist.gov/vuln/detail/CVE-2026-101915) - [https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea](https://redirect.github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea) - [https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f](https://redirect.github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f) - [https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d](https://redirect.github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d) - [https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6](https://redirect.github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6) - [https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5](https://redirect.github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5) - [https://github.com/advisories/GHSA-f596-whhp-79r4](https://redirect.github.com/advisories/GHSA-f596-whhp-79r4) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-f596-whhp-79r4) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @​grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized [CVE-2026-101916](https://nvd.nist.gov/vuln/detail/CVE-2026-101916) / [GHSA-m9gg-hp2v-232j](https://redirect.github.com/advisories/GHSA-m9gg-hp2v-232j) <details> <summary>More information</summary> #### Details ##### Impact When server credentials are created with the `requireClientCertificate` option set to `false`, `getAuthContext` does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for `@grpc/grpc-js` users who use the result of `getAuthContext` for authentication. In particular, `@grpc/grpc-js-xds` can both set the `requireClientCertificate` option to `false` and use the return value of `getAuthContext` for RBAC authentication in some configurations. ##### Patches This vulenrability is fixed in 1.13.6 and 1.14.5. ##### Workarounds `@grpc/grpc-js` users using `getAuthContext` this way can avoid this problem by setting `requireClientCertificate` to `true`. `@grpc/grpc-js-xds` users using RBAC can avoid this by setting the `require_client_certificate` field to `true` in the DownstreamTlsContext in the xDS configuration. #### Severity - CVSS Score: 7.4 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N` #### References - [https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j) - [https://nvd.nist.gov/vuln/detail/CVE-2026-101916](https://nvd.nist.gov/vuln/detail/CVE-2026-101916) - [https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee](https://redirect.github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee) - [https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c](https://redirect.github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c) - [https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5](https://redirect.github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5) - [https://github.com/advisories/GHSA-m9gg-hp2v-232j](https://redirect.github.com/advisories/GHSA-m9gg-hp2v-232j) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-m9gg-hp2v-232j) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>grpc/grpc-node (@​grpc/grpc-js)</summary> ### [`v1.14.5`](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc/grpc-js%401.14.5): @​grpc/grpc-js 1.14.5 [Compare Source](https://redirect.github.com/grpc/grpc-node/compare/@grpc/[email protected]...@grpc/[email protected]) - Fix a bug that caused clients to automatically transmit excessive error details to clients by default ([advisory GHSA-f596-whhp-79r4](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4)) - Fix a bug that caused `getAuthContext` to return unverified certificates as though they were verified in some configurations ([advisory GHSA-m9gg-hp2v-232j](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j)) - Fix a bug that could cause stale call data to accumulate if a channel failed to connect for a long period of time ([#​3078](https://redirect.github.com/grpc/grpc-node/issues/3078)) - Fix a bug that could cause call status to be reported with expected fields missing ([#​3079](https://redirect.github.com/grpc/grpc-node/issues/3079)) - Avoid redundant end() calls on completed HTTP/2 streams ([#​3082](https://redirect.github.com/grpc/grpc-node/issues/3082) contributed by [@​olavloite](https://redirect.github.com/olavloite)) - Unify call numbers and avoid disabled trace allocations ([#​3084](https://redirect.github.com/grpc/grpc-node/issues/3084) contributed by [@​olavloite](https://redirect.github.com/olavloite)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/googleapis/google-cloud-node). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
shivanee-p
pushed a commit
that referenced
this pull request
Oct 7, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [joi](https://redirect.github.com/hapijs/joi) | [`17.13.4` → `17.13.7`](https://renovatebot.com/diffs/npm/joi/17.13.4/17.13.7) |  |  | --- ### joi: object().rename() with a template target can set the validated object's prototype [CVE-2026-84367](https://nvd.nist.gov/vuln/detail/CVE-2026-84367) / [GHSA-gg4h-3hg2-grpc](https://redirect.github.com/advisories/GHSA-gg4h-3hg2-grpc) <details> <summary>More information</summary> #### Details ##### Impact Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern's own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x('{#​1}'), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call. Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`. ##### Patches Versions 17.13.5 and 18.2.4 have been released to address the issue. ##### Workarounds 1. Replace the template rename target with a static string target. 2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x('{#​1}'), { multiple: true })` 3. Drop { multiple: true } from the rename, which stops the rename before the assignment. #### Severity - CVSS Score: 3.7 / 10 (Low) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N` #### References - [https://github.com/hapijs/joi/security/advisories/GHSA-gg4h-3hg2-grpc](https://redirect.github.com/hapijs/joi/security/advisories/GHSA-gg4h-3hg2-grpc) - [https://nvd.nist.gov/vuln/detail/CVE-2026-84367](https://nvd.nist.gov/vuln/detail/CVE-2026-84367) - [https://github.com/hapijs/joi/pull/3134](https://redirect.github.com/hapijs/joi/pull/3134) - [https://github.com/hapijs/joi/pull/3135](https://redirect.github.com/hapijs/joi/pull/3135) - [https://github.com/hapijs/joi/commit/162f367aa178d2e1ebec8dc1164e5fe16536ddf6](https://redirect.github.com/hapijs/joi/commit/162f367aa178d2e1ebec8dc1164e5fe16536ddf6) - [https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01](https://redirect.github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01) - [https://github.com/hapijs/joi/releases/tag/v17.13.5](https://redirect.github.com/hapijs/joi/releases/tag/v17.13.5) - [https://github.com/hapijs/joi/releases/tag/v18.2.4](https://redirect.github.com/hapijs/joi/releases/tag/v18.2.4) - [https://github.com/advisories/GHSA-gg4h-3hg2-grpc](https://redirect.github.com/advisories/GHSA-gg4h-3hg2-grpc) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-gg4h-3hg2-grpc) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### joi: Prototype pollution via a `__proto__` language key in custom messages [CVE-2026-84368](https://nvd.nist.gov/vuln/detail/CVE-2026-84368) / [GHSA-6w3j-5fw6-r9vr](https://redirect.github.com/advisories/GHSA-6w3j-5fw6-r9vr) <details> <summary>More information</summary> #### Details ##### Impact An application that passes attacker-controlled data into joi's custom message configuration (`messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`) lets the attacker write properties onto `Object.prototype`, where every object in the process then inherits them. A key named `__proto__` was treated as a language name, and the code reused the object it found at that key, which resolves to the prototype rather than to a new own property; a key named `constructor` did the same to the `Object` function's statics. A consuming application that gates on the mere presence of a property (`if (user.isAdmin)`) can be made to take the wrong branch for every object it inspects. This is not reachable from data that joi validates. Custom messages are schema-construction configuration, normally written by the application developer. Exploitation therefore requires an application that feeds untrusted input straight into schema construction. ##### Patches Upgrade to version 18.2.5 or 17.13.6. ##### Workarounds Do not pass untrusted input into `messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`. Or validate that they don't contain any `__proto__` or `constructor` property. #### Severity - CVSS Score: 3.7 / 10 (Low) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N` #### References - [https://github.com/hapijs/joi/security/advisories/GHSA-6w3j-5fw6-r9vr](https://redirect.github.com/hapijs/joi/security/advisories/GHSA-6w3j-5fw6-r9vr) - [https://nvd.nist.gov/vuln/detail/CVE-2026-84368](https://nvd.nist.gov/vuln/detail/CVE-2026-84368) - [https://github.com/hapijs/joi/pull/3138](https://redirect.github.com/hapijs/joi/pull/3138) - [https://github.com/hapijs/joi/pull/3139](https://redirect.github.com/hapijs/joi/pull/3139) - [https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36](https://redirect.github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36) - [https://github.com/hapijs/joi/commit/90d07571923c90e3432a328fc041d1cda03d30fa](https://redirect.github.com/hapijs/joi/commit/90d07571923c90e3432a328fc041d1cda03d30fa) - [https://github.com/advisories/GHSA-6w3j-5fw6-r9vr](https://redirect.github.com/advisories/GHSA-6w3j-5fw6-r9vr) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-6w3j-5fw6-r9vr) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()` [GHSA-6h2x-m376-mqjq](https://redirect.github.com/advisories/GHSA-6h2x-m376-mqjq) <details> <summary>More information</summary> #### Details ##### Impact Any application that validates a user-supplied string with `Joi.string().isoDate()` can be stalled by a single request. One of the regular expressions the rule runs over the input was unanchored, so a valid ISO date followed by a long run of fractional-second digits made the regex engine restart its search from every position in the string, costing time proportional to the square of the input length. 64 KB of digits costs about 1.4 s and 256 KB about 22 s. ##### Patches Upgrade to version 17.13.7 or 18.2.6 depending on your current major version. ##### Workarounds None except capping the length of the string before it reaches joi. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq](https://redirect.github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq) - [https://github.com/hapijs/joi/pull/3143](https://redirect.github.com/hapijs/joi/pull/3143) - [https://github.com/hapijs/joi/pull/3145](https://redirect.github.com/hapijs/joi/pull/3145) - [https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec](https://redirect.github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec) - [https://github.com/hapijs/joi/commit/e70df424c367f2976db63b089504413744a21245](https://redirect.github.com/hapijs/joi/commit/e70df424c367f2976db63b089504413744a21245) - [https://github.com/advisories/GHSA-6h2x-m376-mqjq](https://redirect.github.com/advisories/GHSA-6h2x-m376-mqjq) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-6h2x-m376-mqjq) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>hapijs/joi (joi)</summary> ### [`v17.13.7`](https://redirect.github.com/hapijs/joi/compare/v17.13.6...v17.13.7) [Compare Source](https://redirect.github.com/hapijs/joi/compare/v17.13.6...v17.13.7) ### [`v17.13.6`](https://redirect.github.com/hapijs/joi/compare/v17.13.5...v17.13.6) [Compare Source](https://redirect.github.com/hapijs/joi/compare/v17.13.5...v17.13.6) ### [`v17.13.5`](https://redirect.github.com/hapijs/joi/compare/v17.13.4...v17.13.5) [Compare Source](https://redirect.github.com/hapijs/joi/compare/v17.13.4...v17.13.5) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/googleapis/google-cloud-node). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
shivanee-p
pushed a commit
that referenced
this pull request
Oct 7, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [qs](https://redirect.github.com/ljharb/qs) | [`6.15.3` → `6.16.0`](https://renovatebot.com/diffs/npm/qs/6.15.3/6.16.0) |  |  | --- ### qs: Denial of Service via Attacker Controlled isBuffer [CVE-2026-82417](https://nvd.nist.gov/vuln/detail/CVE-2026-82417) / [GHSA-4mjr-xmp4-gh2g](https://redirect.github.com/advisories/GHSA-4mjr-xmp4-gh2g) <details> <summary>More information</summary> #### Details ##### Summary `qs.stringify()` calls `utils.isBuffer()` on every value it serializes, and `utils.isBuffer()` invokes `obj.constructor.isBuffer(obj)` without checking that it is callable. A value whose own `constructor.isBuffer` is a non-function makes `qs` call a non-callable and throw `TypeError`. Such a value is produced **by `qs.parse` itself** from an untrusted query string when `plainObjects: true` or `allowPrototypes: true` is set, so a pure-`qs` `parse` → `stringify` round-trip — no `JSON.parse` — turns an unauthenticated query string into an uncaught throw. An attacker-controlled `parse` input reaches the host application's availability asset — via `qs`'s own recommended `plainObjects` mitigation — and triggers an uncaught exception during a `parse` → `stringify` round-trip. ##### Details `utils.isBuffer` runs at `lib/stringify.js:127` for every serialized value: ```js if (isNonNullishPrimitive(obj) || utils.isBuffer(obj)) { ... } ``` `utils.isBuffer` (`lib/utils.js:327-333`) invokes `obj.constructor.isBuffer` without verifying it is callable: ```js var isBuffer = function isBuffer(obj) { if (!obj || typeof obj !== 'object') { return false; } return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj)); }; ``` `constructor` and `isBuffer` are ordinary keys. `qs.parse` with `plainObjects: true` or `allowPrototypes: true` keeps them as own properties, so the parsed value carries a non-function `constructor.isBuffer`; `stringify` then calls a non-callable and throws `TypeError`. By contrast `utils.isRegExp` uses a brand check (`Object.prototype.toString`); the missing guard here is an internal inconsistency, not a platform limitation. ##### Trust Boundary Note `qs.stringify` alone treats its input as caller-constructed, so serializing a hostile object could be argued outside its contract. This report does not depend on that framing: the malicious shape is produced by **`qs.parse`, whose input is untrusted by design**. `qs.parse` normally strips a `constructor` key via its prototype guard, but with the documented options `plainObjects: true` or `allowPrototypes: true` the key survives and lands as an own property. Feeding the parsed object back into `qs.stringify` — the standard round-trip in gateways and request-forwarders — then hits the unchecked call. ##### PoC `poc02c_isBuffer_qs_only_roundtrip.js` — pure-`qs` chain, no `JSON.parse`; an untrusted query string alone reaches the throw: ```js 'use strict'; var qs = require('qs'); var untrustedQueryString = 'x%5Bconstructor%5D%5BisBuffer%5D=y'; // x[constructor][isBuffer]=y var parsed = qs.parse(untrustedQueryString, { plainObjects: true }); console.log('[parse] kept constructor key:', JSON.stringify(parsed)); try { qs.stringify(parsed); console.log('[stringify] no throw (unexpected)'); } catch (e) { console.log('[stringify] DoS reproduced ->', e.constructor.name + ':', e.message); } ``` `poc02_isBuffer.js` — the minimal defect: ```js 'use strict'; var qs = require('qs'); try { qs.stringify(JSON.parse('{"a":{"constructor":{"isBuffer":"x"}}}')); } catch (e) { console.log('[A] DoS reproduced ->', e.constructor.name + ':', e.message); } ``` `poc02b_isBuffer_async_crash.js` — worker death in an async sink: ```js 'use strict'; var qs = require('qs'); function handleRequestAsync(clientJsonBody) { try { setImmediate(function () { // async continuation, outside the try qs.stringify(JSON.parse(clientJsonBody)); // throws here, uncaught }); console.log('[handler] returned 200 synchronously; async work scheduled'); } catch (e) { console.log('[handler] caught synchronously (will NOT happen):', e.message); } } process.on('exit', function (code) { console.log('[proc] process exiting with code:', code); }); handleRequestAsync('{"filters":{"constructor":{"isBuffer":"x"}}}'); ``` ##### Execution Steps ```bash cd poc npm install [email protected] node poc02c_isBuffer_qs_only_roundtrip.js # pure qs parse->stringify -> TypeError node poc02_isBuffer.js # minimal defect -> TypeError inside stringify node poc02b_isBuffer_async_crash.js # async sink -> uncaught throw -> exit code 1 ``` ##### Reproduction Evidence `poc02c_isBuffer_qs_only_roundtrip.js` : ``` [parse] kept constructor key: {"x":{"constructor":{"isBuffer":"y"}}} [stringify] DoS reproduced -> TypeError: obj.constructor.isBuffer is not a function ``` `poc02_isBuffer.js`: ``` [A] DoS reproduced -> TypeError: obj.constructor.isBuffer is not a function ``` `poc02b_isBuffer_async_crash.js` : ``` [handler] returned 200 synchronously; async work scheduled [proc] process exiting with code: 1 TypeError: obj.constructor.isBuffer is not a function at Object.isBuffer (.../qs/lib/utils.js:332:78) at stringify (.../qs/lib/stringify.js:127:45) === EXIT CODE: 1 === ``` The pure-`qs` round-trip shows the malicious shape originates from `qs.parse` of an untrusted query string, with no `JSON.parse`. The synchronous `try/catch` in the async case does not catch the throw; the process exits with code 1, denying service to all requests on that worker. ##### Impact An unauthenticated request degrades any endpoint that re-serializes deserialized client data with `qs.stringify`. The primary impact is a per-request failure: the handler throws and the framework returns HTTP 500. Where the call sits in an unguarded async continuation, the throw escapes and the worker process exits, denying service to all requests it was handling, which means a higher impact that depends on the application's error handling, not on `qs`. ##### Recommended Fix Replace the duck-type with a brand check mirroring `utils.isRegExp`: ```js var isBuffer = function isBuffer(obj) { if (!obj || typeof obj !== 'object') { return false; } if (typeof Buffer !== 'undefined' && typeof Buffer.isBuffer === 'function') { return Buffer.isBuffer(obj); } return Object.prototype.toString.call(obj) === '[object Uint8Array]'; }; ``` If duck-typing must remain, require `typeof obj.constructor.isBuffer === 'function'` before invoking and wrap the call in `try/catch`. #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N` #### References - [https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g](https://redirect.github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g) - [https://nvd.nist.gov/vuln/detail/CVE-2026-82417](https://nvd.nist.gov/vuln/detail/CVE-2026-82417) - [https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6](https://redirect.github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6) - [https://github.com/advisories/GHSA-4mjr-xmp4-gh2g](https://redirect.github.com/advisories/GHSA-4mjr-xmp4-gh2g) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-4mjr-xmp4-gh2g) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### qs array-limit bypass via bracket-key comma parsing [CVE-2026-82562](https://nvd.nist.gov/vuln/detail/CVE-2026-82562) / [GHSA-x5fp-wj9c-mxmx](https://redirect.github.com/advisories/GHSA-x5fp-wj9c-mxmx) <details> <summary>More information</summary> #### Details ##### Summary `qs` `v6.15.3` allows bracket-key input to bypass `arrayLimit` and `throwOnLimitExceeded` when `comma: true`. The input `a[]=1,2,3,4` succeeds with `arrayLimit: 3`, while the equivalent plain-key input is rejected. Affected version tested: ```text qs v6.15.3 commit 18d085e919dae70c8f1b200ab99323058edab2c2 ``` ##### Details `parseArrayValue()` enforces the comma limit only for flat values. The `a[]` form is marked non-flat, so its comma-separated value is wrapped after parsing and the inner array is not checked. A single parameter can therefore materialize arbitrarily large arrays. ##### PoC ```js const qs = require('qs') const options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true } const result = qs.parse('a[]=1,2,3,4', options) console.log(result.a[0].length) // 4; expected RangeError const big = qs.parse('a[]=' + '1,'.repeat(1000000) + '1', { comma: true, arrayLimit: 20 }) console.log(big.a[0].length) // 1000001 ``` On `v6.15.3`, the first input parses successfully and the second creates an array with 1,000,001 elements. The equivalent `a=1,2,3,4` input throws `RangeError` as expected. ##### Impact An attacker who can supply a query string or form body can bypass configured array limits and force excessive memory allocation, causing denial of service. The limit must be applied after comma splitting and before the resulting array is wrapped. #### Severity - CVSS Score: 6.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N` #### References - [https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883](https://redirect.github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883) - [https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx](https://redirect.github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx) - [https://nvd.nist.gov/vuln/detail/CVE-2026-82562](https://nvd.nist.gov/vuln/detail/CVE-2026-82562) - [https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464](https://redirect.github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464) - [https://github.com/advisories/GHSA-x5fp-wj9c-mxmx](https://redirect.github.com/advisories/GHSA-x5fp-wj9c-mxmx) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-x5fp-wj9c-mxmx) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>ljharb/qs (qs)</summary> ### [`v6.16.0`](https://redirect.github.com/ljharb/qs/blob/HEAD/CHANGELOG.md#6160) [Compare Source](https://redirect.github.com/ljharb/qs/compare/v6.15.3...v6.16.0) - \[New] `stringify`: add a `depth` option to bound recursion depth (default `Infinity`) - \[Fix] stringify: serialize Date values when a filter is provided - \[Fix] `parse`: enforce `arrayLimit` on comma groups under `[]=` when `throwOnLimitExceeded` is set - \[Fix] `parse`: flatten a collection appended to an overflowed array ([#​571](https://redirect.github.com/ljharb/qs/issues/571)) - \[Fix] `utils`: `isBuffer`: do not invoke a non-callable `constructor.isBuffer` - \[Fix] `stringify`: do not let `allowEmptyArrays` skip cycle detection (or drop own keys) on an empty array with own properties - \[Fix] `stringify`: encode dots in a top-level key with a primitive value when encodeDotInKeys is set ([#​562](https://redirect.github.com/ljharb/qs/issues/562)) - \[Docs] threat model: clarify `stringify` deep-nesting DoS is caller-bounded - \[Docs] clarify `arrayLimit` is a representation threshold, not an element-count cap - \[Tests] `parse`: remove a test that pinned `[]=` comma groups escaping `arrayLimit` - \[Tests] `stringify`: pin current `encodeDotInKeys` separator-dot behavior - \[Dev Deps] update `@ljharb/eslint-config`, `eslint` - \[Dev Deps] update `eslint`, `evalmd` </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/googleapis/google-cloud-node). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 I have created a release beep boop
8.6.0 (2026-05-06)
Features
Bug Fixes
ignoreUndefinedPropertiesin subpipelines (#8089) (a9f6c3f)This PR was generated with Release Please. See documentation.