Skip to content

Commit ce8ef23

Browse files
doc(npm): Add false-positive-determination for GHSA-29xp-372q-xqph (#25125)
Signed-off-by: Ankush Pathak <[email protected]>
1 parent 60acc4b commit ce8ef23

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

npm.advisories.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,11 @@ advisories:
4848
type: pending-upstream-fix
4949
data:
5050
note: Since this package relies on upstream artifacts, the vulnerability must be remediated upstream by updating tar to version 7.5.2 or later.
51+
- timestamp: 2025-11-04T09:27:38Z
52+
type: false-positive-determination
53+
data:
54+
type: vulnerable-code-not-in-execution-path
55+
note: 'npm does not utilize the affected code path. For more details, refer to the upstream discussions: https://github.com/nodejs/node/pull/60430#issuecomment-3455536702 and https://github.com/nodejs/node/pull/60012#issuecomment-3452094442'
5156

5257
- id: CGA-ff5p-6mq6-jqwc
5358
aliases:

0 commit comments

Comments
 (0)