Fixed
Status Update
Comments
cl...@google.com <cl...@google.com>
ni...@google.com <ni...@google.com> #2
Could you please provide the dependencies you're using for your project?
Compose does not use protos for any production use case, so we will need more information to determine which dependency is pulling in the protobuf dependency.
jl...@google.com <jl...@google.com> #3
libs.versions.toml does have protobuf version as "3.19.4"
And protobufs are used in production code for app inspection jars like the layout inspector jar that comes with compose:ui:ui
ni...@google.com <ni...@google.com> #4
Oh interesting,
[Deleted User] <[Deleted User]> #6
Thanks
Description
compose-ui
triggers a security alert as it imports inspector.jar which containsprotobuf-javalite:3.19.4
. Please upgrade the version ofprotobuf-javalite
to at least 3.19.6.Jetpack Compose version: 1.3.0
Jetpack Compose component(s) used: compose-ui
Steps to Reproduce or Code Sample to Reproduce:
Stack trace (if applicable):