Skip to content
This repository was archived by the owner on Jan 28, 2026. It is now read-only.

Commit 898f530

Browse files
authored
Merge pull request #4 from Multiverse-io/fix/sqd-1052-cve-2026-23745-node-tar-is-vulnerable-to-arbitrary-file
fix: CVE-2026-23745 - update tar to ^7.5.3
2 parents 4a989fd + ce3bd2e commit 898f530

File tree

2 files changed

+7
-53
lines changed

2 files changed

+7
-53
lines changed

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,8 @@
102102
"webpack-dev-middleware": "7.4.5"
103103
},
104104
"resolutions": {
105-
"puppeteer-core@npm:21.11.0/ws": "8.17.1"
105+
"puppeteer-core@npm:21.11.0/ws": "8.17.1",
106+
"tar": "^7.5.3"
106107
},
107108
"volta": {
108109
"node": "25.3.0",

yarn.lock

Lines changed: 5 additions & 52 deletions
Original file line numberDiff line numberDiff line change
@@ -4680,13 +4680,6 @@ __metadata:
46804680
languageName: node
46814681
linkType: hard
46824682

4683-
"chownr@npm:^2.0.0":
4684-
version: 2.0.0
4685-
resolution: "chownr@npm:2.0.0"
4686-
checksum: 10c0/594754e1303672171cc04e50f6c398ae16128eb134a88f801bf5354fd96f205320f23536a045d9abd8b51024a149696e51231565891d4efdab8846021ecf88e6
4687-
languageName: node
4688-
linkType: hard
4689-
46904683
"chownr@npm:^3.0.0":
46914684
version: 3.0.0
46924685
resolution: "chownr@npm:3.0.0"
@@ -7320,15 +7313,6 @@ __metadata:
73207313
languageName: node
73217314
linkType: hard
73227315

7323-
"fs-minipass@npm:^2.0.0":
7324-
version: 2.1.0
7325-
resolution: "fs-minipass@npm:2.1.0"
7326-
dependencies:
7327-
minipass: "npm:^3.0.0"
7328-
checksum: 10c0/703d16522b8282d7299337539c3ed6edddd1afe82435e4f5b76e34a79cd74e488a8a0e26a636afc2440e1a23b03878e2122e3a2cfe375a5cf63c37d92b86a004
7329-
languageName: node
7330-
linkType: hard
7331-
73327316
"fs-minipass@npm:^3.0.0":
73337317
version: 3.0.3
73347318
resolution: "fs-minipass@npm:3.0.3"
@@ -10470,30 +10454,13 @@ __metadata:
1047010454
languageName: node
1047110455
linkType: hard
1047210456

10473-
"minipass@npm:^5.0.0":
10474-
version: 5.0.0
10475-
resolution: "minipass@npm:5.0.0"
10476-
checksum: 10c0/a91d8043f691796a8ac88df039da19933ef0f633e3d7f0d35dcd5373af49131cf2399bfc355f41515dc495e3990369c3858cd319e5c2722b4753c90bf3152462
10477-
languageName: node
10478-
linkType: hard
10479-
1048010457
"minipass@npm:^5.0.0 || ^6.0.2 || ^7.0.0, minipass@npm:^7.0.2, minipass@npm:^7.0.3, minipass@npm:^7.0.4, minipass@npm:^7.1.2":
1048110458
version: 7.1.2
1048210459
resolution: "minipass@npm:7.1.2"
1048310460
checksum: 10c0/b0fd20bb9fb56e5fa9a8bfac539e8915ae07430a619e4b86ff71f5fc757ef3924b23b2c4230393af1eda647ed3d75739e4e0acb250a6b1eb277cf7f8fe449557
1048410461
languageName: node
1048510462
linkType: hard
1048610463

10487-
"minizlib@npm:^2.1.1":
10488-
version: 2.1.2
10489-
resolution: "minizlib@npm:2.1.2"
10490-
dependencies:
10491-
minipass: "npm:^3.0.0"
10492-
yallist: "npm:^4.0.0"
10493-
checksum: 10c0/64fae024e1a7d0346a1102bb670085b17b7f95bf6cfdf5b128772ec8faf9ea211464ea4add406a3a6384a7d87a0cd1a96263692134323477b4fb43659a6cab78
10494-
languageName: node
10495-
linkType: hard
10496-
1049710464
"minizlib@npm:^3.0.1, minizlib@npm:^3.1.0":
1049810465
version: 3.1.0
1049910466
resolution: "minizlib@npm:3.1.0"
@@ -10521,7 +10488,7 @@ __metadata:
1052110488
languageName: node
1052210489
linkType: hard
1052310490

10524-
"mkdirp@npm:^1.0.3, mkdirp@npm:^1.0.4":
10491+
"mkdirp@npm:^1.0.4":
1052510492
version: 1.0.4
1052610493
resolution: "mkdirp@npm:1.0.4"
1052710494
bin:
@@ -14090,30 +14057,16 @@ __metadata:
1409014057
languageName: node
1409114058
linkType: hard
1409214059

14093-
"tar@npm:6.2.1":
14094-
version: 6.2.1
14095-
resolution: "tar@npm:6.2.1"
14096-
dependencies:
14097-
chownr: "npm:^2.0.0"
14098-
fs-minipass: "npm:^2.0.0"
14099-
minipass: "npm:^5.0.0"
14100-
minizlib: "npm:^2.1.1"
14101-
mkdirp: "npm:^1.0.3"
14102-
yallist: "npm:^4.0.0"
14103-
checksum: 10c0/a5eca3eb50bc11552d453488344e6507156b9193efd7635e98e867fab275d527af53d8866e2370cd09dfe74378a18111622ace35af6a608e5223a7d27fe99537
14104-
languageName: node
14105-
linkType: hard
14106-
14107-
"tar@npm:^7.4.3, tar@npm:^7.5.2":
14108-
version: 7.5.2
14109-
resolution: "tar@npm:7.5.2"
14060+
"tar@npm:^7.5.3":
14061+
version: 7.5.6
14062+
resolution: "tar@npm:7.5.6"
1411014063
dependencies:
1411114064
"@isaacs/fs-minipass": "npm:^4.0.0"
1411214065
chownr: "npm:^3.0.0"
1411314066
minipass: "npm:^7.1.2"
1411414067
minizlib: "npm:^3.1.0"
1411514068
yallist: "npm:^5.0.0"
14116-
checksum: 10c0/a7d8b801139b52f93a7e34830db0de54c5aa45487c7cb551f6f3d44a112c67f1cb8ffdae856b05fd4f17b1749911f1c26f1e3a23bbe0279e17fd96077f13f467
14069+
checksum: 10c0/08af3807035957650ad5f2a300c49ca4fe0566ac0ea5a23741a5b5103c6da42891a9eeaed39bc1fbcf21c5cac4dc846828a004727fb08b9d946322d3144d1fd2
1411714070
languageName: node
1411814071
linkType: hard
1411914072

0 commit comments

Comments
 (0)