This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
ReleasePort's take
Moderate signalUpgrade the tmp dependency to version 0.2.6 to eliminate a path traversal vulnerability.
Why it matters: The security issue has severity 90; upgrading tmp resolves it and protects against arbitrary file access.
Summary
AI summaryUpdates 17.7.0, Bug Fixes, and 2026-05-29 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
upgrade tmp to 0.2.6 resolves path traversal vulnerability upgrade tmp to 0.2.6 resolves path traversal vulnerability Source: llm_adapter@2026-06-01 Confidence: high |
— |
| Feature | Low |
update librarian.yaml for Node support update librarian.yaml for Node support Source: llm_adapter@2026-06-01 Confidence: high |
— |
| Bugfix | Medium |
use artifact_id instead of distribution_name_override in librarian.yaml use artifact_id instead of distribution_name_override in librarian.yaml Source: llm_adapter@2026-06-01 Confidence: high |
— |
Security Fixes
- tmp upgraded to 0.2.6 — fixes CVE‑related path traversal vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About googleapis/release-please
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]