Skip to content

Rebuild packages to remove tar vulnerability#339

Open
Matos60 wants to merge 1 commit intommomtchev:mainfrom
Matos60:fix/tar-vulnerability
Open

Rebuild packages to remove tar vulnerability#339
Matos60 wants to merge 1 commit intommomtchev:mainfrom
Matos60:fix/tar-vulnerability

Conversation

@Matos60
Copy link
Copy Markdown

@Matos60 Matos60 commented Mar 27, 2026

Fixes #325
Regenerated package-lock.json to force the update of the tar dependency within @mapbox/node-pre-gyp, resolving a high-severity vulnerability.
I understand that this vulnerability is not exploitable in production since it is only part of the build process. However, my team works with strict DevOps pipelines where automated security scanners block deployments for any high-severity flag. This update clears the alert and would significantly simplify the workflow for us.

@mmomtchev
Copy link
Copy Markdown
Owner

No. You simply posted a PR simultaneously with another person.

@Matos60
Copy link
Copy Markdown
Author

Matos60 commented Mar 27, 2026

I'm sorry, I'm not sure I follow. I don't see any other recent PRs similar to mine, aside from those by Dependabot. Could you please clarify?

@Matos60
Copy link
Copy Markdown
Author

Matos60 commented Mar 31, 2026

Hi, sorry for bothering you. Is there any update on my request?

@mmomtchev
Copy link
Copy Markdown
Owner

What kind of update do you expect?

@Matos60
Copy link
Copy Markdown
Author

Matos60 commented Mar 31, 2026

I would like to know why posting a PR at the same time as someone else (supposedly, because I do not see any other PR by a person at this time) is an issue, please.

@mmomtchev
Copy link
Copy Markdown
Owner

You were three to simultaneously post on an account with 1.2k stars - which everyone else is trying to not notice - with no other activity than the one related to the criminal affair for the last 4 years.

DNA matching has a higher probability of error than what you did. This means that In the US you can get a death penalty with this error margin.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The bundled @mapbox/node-pre-gyp includes a vulnerable version of tar

2 participants