a2aproject / a2aproject/a2a-python
[Bug]: python-protobuf:6.33.6 vulnerability
Abierto
component: core
status: needs review
- Lenguaje dominante
- Python
- Estrellas
- 2.1k
- Forks
- 496
- Merge medio
- 4 d 17 h
- PR fusionados (30 d)
- 12
Descripción
### What happened?
Hi,
Our Blackduck scans are reporting a vulnerability in python-protobuf:6.33.6 used by a2a-sdk.
The long term fix is to upgrade to python-protobuf 7.36.1.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4322
I see there is a breaking change between versions and [this](https://github.com/a2aproject/a2a-python/pull/1019) PR caps protobuf<7.
Do you have plans to upgrade from protobuf 6 to protobuf 7?
### Relevant log output
```shell
```
### Code of Conduct
- [x] I agree to follow this project's Code of Conduct
Guía de contribución
Evaluación
Este issue todavía no se ha evaluado.