Skip to content

Minor refactor based on comments from previous PR#134

Merged
lincoln-replit merged 1 commit into
mainfrom
lwb-address-pr-comments
Jul 5, 2022
Merged

Minor refactor based on comments from previous PR#134
lincoln-replit merged 1 commit into
mainfrom
lwb-address-pr-comments

Conversation

@lincoln-replit

Copy link
Copy Markdown
Contributor

Why

Merged #132 too quickly without addressing reviewer comments

What changed

Minor refactor and spell correction for clarity

Test plan

Tests pass

@lincoln-replit lincoln-replit added the preboop boops a pr whenever tests pass label Jul 5, 2022
@replbot replbot added boop A PR is ready for review and removed preboop boops a pr whenever tests pass labels Jul 5, 2022
@replbot

replbot commented Jul 5, 2022

Copy link
Copy Markdown

Good work, this PRs short and easy to review! Promoting to bop.

@replbot replbot added the bop label Jul 5, 2022
@replbot replbot removed the boop A PR is ready for review label Jul 5, 2022
@lincoln-replit lincoln-replit merged commit 13b80d7 into main Jul 5, 2022
poorvapotnis added a commit that referenced this pull request Apr 17, 2026
Fixes Dependabot alert #134 (arbitrary code execution in protobufjs).
protobufjs is pulled in transitively via @replit/protocol and
versions <7.5.5 allow attackers who can control protobuf definitions
to execute arbitrary JS during object decoding.

The @replit/protocol package declares protobufjs "^7.2.5" so no
downstream version constraints change; only the lockfile is updated.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants