Skip to content

Conversation

@mhassan1
Copy link
Contributor

What's the problem this PR addresses?

This PR bumps vulnerable dependency tar from v6 to v7, which resolves GHSA-8qq5-rm4j-mr97.

Changelog: https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md#70

How did you fix it?

I bumped tar in package.json.

Checklist

  • I have read the Contributing Guide.

  • I have set the packages that need to be released for my changes to be effective.

  • I will check that all automated PR checks pass before the PR gets reviewed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant