a2aproject / a2aproject/a2a-python
[Bug]: python-protobuf:6.33.6 vulnerability
Open
component: core
status: needs review
- Dominant language
- Python
- Stars
- 2.1k
- Forks
- 496
- Avg merge
- 4d 17h
- Merged PRs (30d)
- 12
Description
### What happened?
Hi,
Our Blackduck scans are reporting a vulnerability in python-protobuf:6.33.6 used by a2a-sdk.
The long term fix is to upgrade to python-protobuf 7.36.1.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4322
I see there is a breaking change between versions and [this](https://github.com/a2aproject/a2a-python/pull/1019) PR caps protobuf<7.
Do you have plans to upgrade from protobuf 6 to protobuf 7?
### Relevant log output
```shell
```
### Code of Conduct
- [x] I agree to follow this project's Code of Conduct
Contributor guide
Assessment
This issue has not been assessed yet.