Commit 45e1223
Alexandre Machado
fix: upgrade tar to ^7.5.7 to patch path traversal vulnerability
Security fix for CVE in node-tar package that allows arbitrary file
creation outside extraction directory via hardlink path traversal.
See: https://github.com/advisories/GHSA-9r2w-394v-53g61 parent 174b73c commit 45e1223
2 files changed
+42
-94
lines changedSome generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
35 | 38 | | |
36 | 39 | | |
0 commit comments