Skip to content

Fix CVE-2026-59877 by updating protobufjs to patched version - #773

Open
sbouchet wants to merge 4 commits into
che-incubator:mainfrom
sbouchet:fix-protobufjs-cves
Open

Fix CVE-2026-59877 by updating protobufjs to patched version#773
sbouchet wants to merge 4 commits into
che-incubator:mainfrom
sbouchet:fix-protobufjs-cves

Conversation

@sbouchet

@sbouchet sbouchet commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do?

This PR fixes CVE-2026-59877
protobuf.js version is updated to 7.6.5

What issues does this PR fix?

https://redhat.atlassian.net/browse/CRW-11936

How to test this PR?

Does this PR contain changes that override default upstream Code-OSS behavior?

  • the PR contains changes in the code folder (you can skip it if your changes are placed in a che extension )
  • the corresponding items were added to the CHANGELOG.md file
  • rules for automatic git rebase were added to the .rebase folder

Summary by CodeRabbit

  • Bug Fixes

    • Improved reliability and compatibility for Copilot-related functionality.
    • Addressed potential issues affecting protocol buffer communication.
  • Chores

    • Updated release tracking information for the Copilot compatibility improvements.

@github-actions

github-actions Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Click here to review and test in web IDE: Contribute

@github-actions

Copy link
Copy Markdown
Contributor

@sbouchet
sbouchet marked this pull request as ready for review July 28, 2026 19:43
@coderabbitai

coderabbitai Bot commented Jul 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@sbouchet, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 6 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: e119f52f-3ac6-4ac6-bd90-5a5f922adb13

📥 Commits

Reviewing files that changed from the base of the PR and between fc496e9 and 5b826bd.

⛔ Files ignored due to path filters (1)
  • code/extensions/copilot/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • .rebase/CHANGELOG.md
  • code/extensions/copilot/package.json
📝 Walkthrough

Walkthrough

The Copilot package configuration now constrains protobufjs to ^7.6.5 for @grpc/proto-loader. The same override is added to the rebase package configuration. The change is recorded in .rebase/CHANGELOG.md.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

Suggested reviewers: azatsarynnyy, rgrunber, vitaliy-guliy

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Rebase Rules For Upstream Changes ❓ Inconclusive Repository clone failed, so this custom check could not run with code access. Retry the review run. If this persists, inspect pre-merge custom-check logs for infrastructure or agent runtime failures.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise, uses imperative mood, and clearly describes updating protobufjs to address the CVE.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sbouchet
sbouchet marked this pull request as draft July 30, 2026 14:02
@tolusha

tolusha commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Hi! I'm che-ai-assistant — I help with your pull requests.

I check for new comments every 10m0s, so there may be a short delay before I respond.

Available commands:

  • /che-ai-assistant generate-che-doc — Generate a documentation PR based on this PR's changes
  • /che-ai-assistant ok-pr-review — Run a comprehensive PR review (summary, code review, deep review, impact analysis)
  • /che-ai-assistant ok-pr-readiness — Ensure PR has validation steps
  • /che-ai-assistant check-pr-test-failures — Analyze failing CI checks, identify root causes, and suggest fixes
  • /che-ai-assistant update-che-e2e-tests — Update Eclipse Che e2e tests
  • /che-ai-assistant claude — Run a free-form instruction on this PR
  • /che-ai-assistant help — Show this help message

@sbouchet sbouchet closed this Aug 5, 2026
@sbouchet
sbouchet deleted the fix-protobufjs-cves branch August 5, 2026 16:58
@sbouchet
sbouchet restored the fix-protobufjs-cves branch August 6, 2026 13:42
sbouchet and others added 2 commits August 6, 2026 08:53
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
@sbouchet sbouchet reopened this Aug 6, 2026
@sbouchet sbouchet changed the title Fix multiple CVEs by updating protobufjs to patched versions Fix CVE-2026-59877 by updating protobufjs to patched version Aug 6, 2026
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
@sbouchet
sbouchet force-pushed the fix-protobufjs-cves branch from 6644af4 to fc496e9 Compare August 6, 2026 14:21
@sbouchet
sbouchet marked this pull request as ready for review August 6, 2026 14:23
@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants