Skip to content

Commit ea4e521

Browse files
committed
[INTERNAL] Bump tar from 6.2.1 to 7.5.6
Resolves alerts for several security advisories such as: GHSA-r6q2-hw4h-h46w GHSA-8qq5-rm4j-mr97 As per our assessment those vulnerabilities are not exploitable in the context of UI5 CLI. The override for tar is specifically defined where necessary in order to not downgrade tar in case a new major version is being used by other dependencies.
1 parent 8f6e71a commit ea4e521

2 files changed

Lines changed: 20 additions & 91 deletions

File tree

package-lock.json

Lines changed: 15 additions & 91 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,5 +63,10 @@
6363
"local-web-server": "^5.4.0",
6464
"open-cli": "^8.0.0",
6565
"traverse": "^0.6.11"
66+
},
67+
"overrides": {
68+
"pacote@19": {
69+
"tar": "^7.5.6"
70+
}
6671
}
6772
}

0 commit comments

Comments
 (0)