Skip to content

testcontainers depends on vulnerable versions of tar-fs #1106

@juliette-derancourt

Description

@juliette-derancourt

Dependabot brought to my attention that tar-fs introduces security vulnerabilities for versions prior to 3.0.9, 2.1.3, and 1.16.5 (CVE).

According to npm why tar-fs, [email protected] transitively depends on versions 3.0.6 and 2.0.1.

Could this dependency be upgraded?

Metadata

Metadata

Assignees

No one assigned

    Labels

    triageInvestigation required

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions