Repository navigation
This point release addresses a potential issue identified here: GHSA-mm34-2v69-6vg6
"github.com/jhump/protoreflect/dynamic"
Changes/fixes:
- Address potential stack overflow fatal errors in
dynamic.Message, when unmarshaling untrusted input or when marshaling a message that contains a reference cycle. A mitigation has been added for all three formats: binary, text, and json. - Fixed a bug that prevented the convert and merge methods (for converting to/from other message implementations) from working correctly with
*dynamicpb.Message(the dynamic message implementation added to the core runtime in API v2).
Additions:
- Adds new
ToDynamicPBmethod todynamic.Message, to aid with users migrating to API v2 and to work around interop issues with API v2'sprototextandprotojsonpackages.