Skip to content

Commit 864f4dc

Browse files
GhostTypesclaude
andauthored
fix(deps): bump tar override to 7.5.10 to patch GHSA-qffp-2rhf-9h96 (#55)
Adds tar@7.5.10 to npm overrides. Transitive dep via electron-builder > app-builder-lib > tar. Hardlink path traversal via drive-relative linkpath (high severity). Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 1e1d6de commit 864f4dc

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,8 @@
4646
},
4747
"license": "MIT",
4848
"overrides": {
49-
"js-yaml": "4.1.1"
49+
"js-yaml": "4.1.1",
50+
"tar": "7.5.10"
5051
},
5152
"dependencies": {
5253
"@cycjimmy/jsmpeg-player": "^6.1.2",

0 commit comments

Comments
 (0)