Skip to content

Bump protobufjs from 5.0.3 to 8.7.2 - #904

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/protobufjs-8.7.2
Open

Bump protobufjs from 5.0.3 to 8.7.2#904
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/protobufjs-8.7.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 20, 2026

Copy link
Copy Markdown

Bumps protobufjs from 5.0.3 to 8.7.2.

Release notes

Sourced from protobufjs's releases.

protobufjs: v8.7.2

8.7.2 (2026-08-08)

Bug Fixes

  • Also use TextDecoder for loose UTF-8 decoding (#2408) (5851a3b)
  • Parse numeric defaults according to field type (#2402) (bb2d836)
  • Parse numeric descriptor defaults by field type (#2406) (09f24ec)
  • preserve first enum alias from JSON descriptors (#2389) (8304739)
  • Preserve negative zero in codegen formatters (#2403) (92ddc9b)
  • Preserve non-finite defaults in toObject (#2393) (a38b925)

Performance Improvements

  • Optimize writer allocs and packed varint reads (#2405) (64cc8f1)

protobufjs: v8.7.1

8.7.1 (2026-07-12)

Bug Fixes

  • Accept repeated NullValue elements in ProtoJSON (#2373) (ad0b9bb)
  • Apply enum options regardless of declaration order (#2384) (b5009b0)
  • Base64-encode bytes field defaults in toObject (#2375) (e552511)
  • cli: Handle extensions during sparse generation (#2386) (1965d37)
  • cli: Match declaration imports to generated modules (#2385) (3cf7420)
  • cli: Preserve array element union precedence in pbts (#2378) (2a697a5)
  • cli: Resolve imports from cwd by default (#2381) (65f659a)
  • Merge repeated message-valued fields within map entries (#2364) (13b417b)
  • Parse aggregate objects in option arrays (#2379) (71c2532)
  • Parse Any type URLs in aggregate options (#2383) (666fa6b)
  • Parse bracketed special field names in options (#2377) (dd1870b)
  • Parse map fields inside groups (#2382) (8a2c427)
  • Preserve proto names in bundled definitions (#2390) (7ba0557)
  • Remove circular LongBits dependency (#2387) (829f5cd)

protobufjs: v8.7.0

8.7.0 (2026-07-06)

Features

  • Rework encoder architecture and add additional fast paths (#2359) (e912baf)

Bug Fixes

... (truncated)

Changelog

Sourced from protobufjs's changelog.

8.7.2 (2026-08-08)

Bug Fixes

  • Also use TextDecoder for loose UTF-8 decoding (#2408) (5851a3b)
  • Parse numeric defaults according to field type (#2402) (bb2d836)
  • Parse numeric descriptor defaults by field type (#2406) (09f24ec)
  • preserve first enum alias from JSON descriptors (#2389) (8304739)
  • Preserve negative zero in codegen formatters (#2403) (92ddc9b)
  • Preserve non-finite defaults in toObject (#2393) (a38b925)

Performance Improvements

  • Optimize writer allocs and packed varint reads (#2405) (64cc8f1)

8.7.1 (2026-07-12)

Bug Fixes

  • accept repeated NullValue elements in ProtoJSON (#2373) (ad0b9bb)
  • Apply enum options regardless of declaration order (#2384) (b5009b0)
  • Base64-encode bytes field defaults in toObject (#2375) (e552511)
  • cli: Handle extensions during sparse generation (#2386) (1965d37)
  • cli: Match declaration imports to generated modules (#2385) (3cf7420)
  • cli: Preserve array element union precedence in pbts (#2378) (2a697a5)
  • cli: Resolve imports from cwd by default (#2381) (65f659a)
  • Merge repeated message-valued fields within map entries (#2364) (13b417b)
  • Parse aggregate objects in option arrays (#2379) (71c2532)
  • Parse Any type URLs in aggregate options (#2383) (666fa6b)
  • Parse bracketed special field names in options (#2377) (dd1870b)
  • Parse map fields inside groups (#2382) (8a2c427)
  • Preserve proto names in bundled definitions (#2390) (7ba0557)
  • Remove circular LongBits dependency (#2387) (829f5cd)

8.7.0 (2026-07-06)

Features

  • Rework encoder architecture and add additional fast paths (#2359) (e912baf)

Bug Fixes

  • Preserve parsed json_name in field options (#2363) (1cdd91e)
  • Reject truncated declarations without TypeError (#2358) (5995f2a)
  • Resolve feature defaults before lazy codegen (d59d100)

... (truncated)

Commits
  • 91cdef0 chore: release master (#2391)
  • c362fe3 chore(deps-dev): Bump shell-quote from 1.8.4 to 1.10.0 (#2399)
  • 7999776 chore(deps-dev): Bump browserify-sign from 4.2.1 to 4.2.6 (#2398)
  • 549aa7a chore(deps): Bump linkify-it from 5.0.1 to 5.0.2 in /cli (#2397)
  • 5851a3b fix: Also use TextDecoder for loose UTF-8 decoding (#2408)
  • aca5b83 docs: Clarify README
  • adce445 chore(deps): update dev dependencies (#2395)
  • a38b925 fix: Preserve non-finite defaults in toObject (#2393)
  • 09f24ec fix: Parse numeric descriptor defaults by field type (#2406)
  • 64cc8f1 perf: Optimize writer allocs and packed varint reads (#2405)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for protobufjs since your current version.

Install script changes

This version modifies prepublish script that runs during installation. Review the package contents before updating.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 20, 2026
@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown

❌ STF CI report

18 failing  ·  5 test tiers (3 pass / 2 fail / 0 skip)  ·  16 Android versions (0 with a usable device in STF)

Test tiers

Tier Result
Build (npm + bower + webpack) deps cache miss
Lint (eslint + jsonlint + workflow shell) lib/, res/ and root JS + JSON, and every workflow run: block
Unit tests (mocha) lib/util + lib/wire specs
Component tests (karma + AngularJS) 104 specs, 0 failed, 0 errored (27 assert, 77 are upstream stubs)
Integration + device-less E2E (stf local + RethinkDB + Playwright) stf local failure, fake devices skipped, web UI suite skipped

Android device matrix

Android API Image Boot In STF Usable Screen Touch Shell UI E2E
5.0 21
5.1 22
6.0 23
7 24
7.1 25
8 26
8.1 27
9 28
10 29
11 30
12 31
12L 32
13 33
14 34
15 35
16 36

Image = a system image is published for that API and arch. Boot = emulator reached sys.boot_completed and answers adb. In STF = the device registered with the STF provider. Usable = STF offered it as Use and handed over control. Screen = minicap frames reached the browser canvas and kept changing. Touch = a browser tap and swipe showed up in getevent on the device, at the coordinates they were aimed at: the tap within 5% of the centre of the touch axes, the swipe descending monotonically from 0.75 to 0.25 (the emulator runs with adb root, which minitouch needs to open /dev/input). Shell = the dashboard shell widget ran a command on it. UI E2E = the rest of the Playwright web UI suite.

Failures

  • Android 5.0 (API 21): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 5.1 (API 22): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 6.0 (API 23): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 7 (API 24): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 7.1 (API 25): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 8 (API 26): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 8.1 (API 27): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 9 (API 28): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 10 (API 29): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 11 (API 30): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 12 (API 31): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 12L (API 32): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 13 (API 33): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 14 (API 34): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 15 (API 35): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Android 16 (API 36): stopped before: stf_device_present, stf_device_usable, screen_stream, touch_roundtrip, playwright_ui
  • Integration + device-less E2E (stf local + RethinkDB + Playwright): stf local failure, fake devices skipped, web UI suite skipped
  • Unit tests (mocha): lib/util + lib/wire specs

Logs, screenshots, logcat and Playwright traces are attached to the run as artifacts · full run · commit e89a2bc

Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 5.0.3 to 8.7.2.
- [Release notes](https://github.com/protobufjs/protobuf.js/releases)
- [Changelog](https://github.com/protobufjs/protobuf.js/blob/master/CHANGELOG.md)
- [Commits](protobufjs/protobuf.js@5.0.3...protobufjs-v8.7.2)

---
updated-dependencies:
- dependency-name: protobufjs
  dependency-version: 8.7.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/protobufjs-8.7.2 branch from a94f2bc to e520ff9 Compare August 27, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants