Merge pull request #112 from voc0der/fix/dependabot-tar-hardlink-path-traversal

fix(deps): bump tar to 7.5.10 to resolve advisory
pull/1163/head
voc0der 2 months ago committed by GitHub
commit 4b3d738e34
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

6
package-lock.json generated

@ -15374,9 +15374,9 @@
}
},
"node_modules/tar": {
"version": "7.5.9",
"resolved": "https://registry.npmjs.org/tar/-/tar-7.5.9.tgz",
"integrity": "sha512-BTLcK0xsDh2+PUe9F6c2TlRp4zOOBMTkoQHQIWSIzI0R7KG46uEwq4OPk2W7bZcprBMsuaeFsqwYr7pjh6CuHg==",
"version": "7.5.10",
"resolved": "https://registry.npmjs.org/tar/-/tar-7.5.10.tgz",
"integrity": "sha512-8mOPs1//5q/rlkNSPcCegA6hiHJYDmSLEI8aMH/CdSQJNWztHC9WHNam5zdQlfpTwB9Xp7IBEsHfV5LKMJGVAw==",
"dev": true,
"license": "BlueOak-1.0.0",
"dependencies": {

@ -87,6 +87,7 @@
},
"immutable": "5.1.5",
"serialize-javascript": "7.0.3",
"tar": "7.5.10",
"tmp": "0.2.5"
}
}

Loading…
Cancel
Save