Skip to content

[stubsabot] Bump protobuf to ~=6.33.5#14887

Open
github-actions[bot] wants to merge 1 commit intomainfrom
stubsabot/protobuf
Open

[stubsabot] Bump protobuf to ~=6.33.5#14887
github-actions[bot] wants to merge 1 commit intomainfrom
stubsabot/protobuf

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Oct 16, 2025

Release: https://pypi.org/pypi/protobuf/6.33.5
Homepage: https://developers.google.com/protocol-buffers/
Repository: https://github.com/protocolbuffers/protobuf
Typeshed stubs: https://github.com/python/typeshed/tree/main/stubs/protobuf

If stubtest fails for this PR:

  • Leave this PR open (as a reminder, and to prevent stubsabot from opening another PR)
  • Fix stubtest failures in another PR, then close this PR

Note that you will need to close and re-open the PR in order to trigger CI

@github-actions github-actions bot added the bot: stubsabot 🤖 Third-party stub updates by stubsabot 🤖 label Oct 16, 2025
@srittau srittau closed this Oct 16, 2025
@srittau srittau reopened this Oct 16, 2025
@github-actions github-actions bot changed the title [stubsabot] Bump protobuf to ~=6.33.0 [stubsabot] Bump protobuf to ~=6.33.1 Nov 14, 2025
@github-actions github-actions bot changed the title [stubsabot] Bump protobuf to ~=6.33.1 [stubsabot] Bump protobuf to ~=6.33.2 Dec 7, 2025
@github-actions github-actions bot changed the title [stubsabot] Bump protobuf to ~=6.33.2 [stubsabot] Bump protobuf to ~=6.33.3 Jan 10, 2026
@github-actions github-actions bot changed the title [stubsabot] Bump protobuf to ~=6.33.3 [stubsabot] Bump protobuf to ~=6.33.4 Jan 13, 2026
Release: https://pypi.org/pypi/protobuf/6.33.5
Homepage: https://developers.google.com/protocol-buffers/
Repository: https://github.com/protocolbuffers/protobuf
Typeshed stubs: https://github.com/python/typeshed/tree/main/stubs/protobuf

If stubtest fails for this PR:
- Leave this PR open (as a reminder, and to prevent stubsabot from opening another PR)
- Fix stubtest failures in another PR, then close this PR

Note that you will need to close and re-open the PR in order to trigger CI
@github-actions github-actions bot changed the title [stubsabot] Bump protobuf to ~=6.33.4 [stubsabot] Bump protobuf to ~=6.33.5 Jan 30, 2026
@thomasaarholt
Copy link

@JelleZijlstra or @srittau, sorry for the ping, but I was wondering if we could merge this? This vulnerability requires us to update protobuf at my work, and it would be nice to have the type stubs. CVE-2026-0994.

Alternatively: Anything holding this back that I could help with?

@srittau
Copy link
Collaborator

srittau commented Feb 2, 2026

Someone needs to go through the diff (protocolbuffers/protobuf@v32.1...v33.5) and see whether there are any relevant changes for the typeshed stubs. We can't just bump the version number. That said, types-protobuf does not depend on protobuf, so it should be possible to install a newer protobuf version alongside the older stubs.

@thomasaarholt
Copy link

Ah, now I see. I was confused from the existence of the original pr. I think you are correct in that I can use the older version!

Sorry for the noise!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot: stubsabot 🤖 Third-party stub updates by stubsabot 🤖

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants