Skip to content

fix: update protobuf version for <= 3.12 (cve fix)#1837

Merged
hallvictoria merged 6 commits intodevfrom
hallvictoria/312-protobuf-cve
Mar 16, 2026
Merged

fix: update protobuf version for <= 3.12 (cve fix)#1837
hallvictoria merged 6 commits intodevfrom
hallvictoria/312-protobuf-cve

Conversation

@hallvictoria
Copy link
Contributor

@hallvictoria hallvictoria commented Mar 16, 2026

Description

Updates protobuf, grpcio, and grpcio-tools versions for <= 3.12 to fix CVE-2026-0994.

Fixes #


Pull Request Checklist

Host-Worker Contract

  • Does this PR impact the host-worker contract (e.g., gRPC messages, shared interfaces)?
    • If yes, have the changes been applied to:
      • azure_functions_worker (Python <= 3.12)
      • proxy_worker (Python >= 3.13)
    • If no, please explain why:

Worker Execution Logic

  • Does this PR affect worker execution logic (e.g., function invocation, bindings, lifecycle)?
    If yes, please answer the following:

Python Version Coverage

  • Does this change apply to both Python <=3.12 and 3.13+?
  • If yes, have the changes been made to:
    • azure_functions_worker (Python <= 3.12)
    • runtimes/v1 / runtimes/v2 (Python >= 3.13)
  • If no, please explain why:

Programming Model Compatibility (for Python 3.13+)

  • Does this change apply to both:
    • V1 programming model (runtimes/v1)?
    • V2 programming model (runtimes/v2)?
  • Explanation (if limited to one model):

@hallvictoria hallvictoria marked this pull request as ready for review March 16, 2026 15:46
gavin-aguiar
gavin-aguiar previously approved these changes Mar 16, 2026
@hallvictoria hallvictoria merged commit 8edaef1 into dev Mar 16, 2026
42 of 46 checks passed
@hallvictoria hallvictoria deleted the hallvictoria/312-protobuf-cve branch March 16, 2026 21:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants