a2aproject / a2aproject/a2a-python
[Bug]: python-protobuf:6.33.6 vulnerability
Offen
component: core
status: needs review
- Vorherrschende Sprache
- Python
- Sterne
- 2.1k
- Forks
- 496
- Ø Merge
- 4 T. 17 Std.
- Gemergte PRs (30 T.)
- 12
Beschreibung
### What happened?
Hi,
Our Blackduck scans are reporting a vulnerability in python-protobuf:6.33.6 used by a2a-sdk.
The long term fix is to upgrade to python-protobuf 7.36.1.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4322
I see there is a breaking change between versions and [this](https://github.com/a2aproject/a2a-python/pull/1019) PR caps protobuf<7.
Do you have plans to upgrade from protobuf 6 to protobuf 7?
### Relevant log output
```shell
```
### Code of Conduct
- [x] I agree to follow this project's Code of Conduct
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.