Skip to content

Commit 0d62c26

Browse files
fix(docker): update tar to 7.5.7 for CVE-2026-24842 (#92)
1 parent d7a49ee commit 0d62c26

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

Dockerfile

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -23,13 +23,13 @@ RUN cd /usr/local/lib/node_modules/npm && \
2323
mv package node_modules/diff && \
2424
rm diff-8.0.3.tgz
2525

26-
# Fix CVE-2026-23950: Manually update npm's bundled tar@7.5.3 to 7.5.4
26+
# Fix CVE-2026-23950 + CVE-2026-24842: Manually update npm's bundled tar to 7.5.7
2727
RUN cd /usr/local/lib/node_modules/npm && \
28-
npm pack tar@7.5.4 && \
28+
npm pack tar@7.5.7 && \
2929
rm -rf node_modules/tar && \
30-
tar -xzf tar-7.5.4.tgz && \
30+
tar -xzf tar-7.5.7.tgz && \
3131
mv package node_modules/tar && \
32-
rm tar-7.5.4.tgz
32+
rm tar-7.5.7.tgz
3333

3434
# Copy package files first for better layer caching
3535
COPY package*.json .npmrc ./
@@ -70,13 +70,13 @@ RUN cd /usr/local/lib/node_modules/npm && \
7070
mv package node_modules/diff && \
7171
rm diff-8.0.3.tgz
7272

73-
# Fix CVE-2026-23950: Manually update npm's bundled tar@7.5.3 to 7.5.4
73+
# Fix CVE-2026-23950 + CVE-2026-24842: Manually update npm's bundled tar to 7.5.7
7474
RUN cd /usr/local/lib/node_modules/npm && \
75-
npm pack tar@7.5.4 && \
75+
npm pack tar@7.5.7 && \
7676
rm -rf node_modules/tar && \
77-
tar -xzf tar-7.5.4.tgz && \
77+
tar -xzf tar-7.5.7.tgz && \
7878
mv package node_modules/tar && \
79-
rm tar-7.5.4.tgz
79+
rm tar-7.5.7.tgz
8080

8181
# Copy built artifacts and production dependencies
8282
COPY --from=builder /app/dist ./dist

0 commit comments

Comments
 (0)