What happened?
Hi,
Our Blackduck scans are reporting a vulnerability in python-protobuf:6.33.6 used by a2a-sdk.
The long term fix is to upgrade to python-protobuf 7.36.1.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4322
I see there is a breaking change between versions and this PR caps protobuf<7.
Do you have plans to upgrade from protobuf 6 to protobuf 7?
Relevant log output
Code of Conduct
What happened?
Hi,
Our Blackduck scans are reporting a vulnerability in python-protobuf:6.33.6 used by a2a-sdk.
The long term fix is to upgrade to python-protobuf 7.36.1.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4322
I see there is a breaking change between versions and this PR caps protobuf<7.
Do you have plans to upgrade from protobuf 6 to protobuf 7?
Relevant log output
Code of Conduct