New poison for Java gencode and MSVC+Bazel combination

60 views
Skip to first unread message

David Castro

unread,
Feb 6, 2025, 9:54:36 AM2/6/25
to Protocol Buffers

Poison Java gencode


We are patching a change into the 25.x branch that will poison Java gencode that was created prior to the 3.21.7 release. We will then mark all versions of Java protobuf from 3.21.7 through 3.25.5 as vulnerable to the footmitten CVE.


Poison MSVC + Bazel


We will be dropping support for using Bazel and MSVC together in v34. As of v30, we will poison this combination with an error unless you specify the opt-out flag --define=protobuf_allow_msvc=true to silence it.


For more details on these changes, see the corresponding news article.
Reply all
Reply to author
Forward
0 new messages