Skip to content

chore(deps): bump compressing from 1.10.4 to 1.10.5#235

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/compressing-1.10.5
Open

chore(deps): bump compressing from 1.10.4 to 1.10.5#235
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/compressing-1.10.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

Bumps compressing from 1.10.4 to 1.10.5.

Release notes

Sourced from compressing's releases.

v1.10.5

1.10.5 (2026-04-13)

  • fix: prevent symlink path traversal via pre-existing symlinks during tar extraction (18def23)

This release is also available on:

Changelog

Sourced from compressing's changelog.

1.10.5 (2026-04-13)

  • fix: prevent symlink path traversal via pre-existing symlinks during tar extraction (18def23)
Commits
  • 40d5f1f Release 1.10.5
  • 18def23 fix: prevent symlink path traversal via pre-existing symlinks during tar extr...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 17, 2026
@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 17, 2026

⚠️ No Changeset found

Latest commit: e323518

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/compressing-1.10.5 branch 2 times, most recently from d3fa1c6 to ad69f73 Compare April 21, 2026 14:58
Bumps [compressing](https://github.com/node-modules/compressing) from 1.10.4 to 1.10.5.
- [Release notes](https://github.com/node-modules/compressing/releases)
- [Changelog](https://github.com/node-modules/compressing/blob/v1.10.5/CHANGELOG.md)
- [Commits](node-modules/compressing@v1.10.4...v1.10.5)

---
updated-dependencies:
- dependency-name: compressing
  dependency-version: 1.10.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/compressing-1.10.5 branch from ad69f73 to e323518 Compare May 5, 2026 20:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants