@@ -23,13 +23,13 @@ RUN cd /usr/local/lib/node_modules/npm && \
2323 mv package node_modules/diff && \
2424 rm diff-8.0.3.tgz
2525
26- # Fix CVE-2026-23950: Manually update npm's bundled tar@7.5.3 to 7.5.4
26+ # Fix CVE-2026-23950 + CVE-2026-24842 : Manually update npm's bundled tar to 7.5.7
2727RUN cd /usr/local/lib/node_modules/npm && \
28- npm pack tar@7.5.4 && \
28+ npm pack tar@7.5.7 && \
2929 rm -rf node_modules/tar && \
30- tar -xzf tar-7.5.4 .tgz && \
30+ tar -xzf tar-7.5.7 .tgz && \
3131 mv package node_modules/tar && \
32- rm tar-7.5.4 .tgz
32+ rm tar-7.5.7 .tgz
3333
3434# Copy package files first for better layer caching
3535COPY package*.json .npmrc ./
@@ -70,13 +70,13 @@ RUN cd /usr/local/lib/node_modules/npm && \
7070 mv package node_modules/diff && \
7171 rm diff-8.0.3.tgz
7272
73- # Fix CVE-2026-23950: Manually update npm's bundled tar@7.5.3 to 7.5.4
73+ # Fix CVE-2026-23950 + CVE-2026-24842 : Manually update npm's bundled tar to 7.5.7
7474RUN cd /usr/local/lib/node_modules/npm && \
75- npm pack tar@7.5.4 && \
75+ npm pack tar@7.5.7 && \
7676 rm -rf node_modules/tar && \
77- tar -xzf tar-7.5.4 .tgz && \
77+ tar -xzf tar-7.5.7 .tgz && \
7878 mv package node_modules/tar && \
79- rm tar-7.5.4 .tgz
79+ rm tar-7.5.7 .tgz
8080
8181# Copy built artifacts and production dependencies
8282COPY --from=builder /app/dist ./dist
0 commit comments