Skip to content

build(deps-dev): Bump tar from 7.5.6 to 7.5.7#1288

Merged
d3xter666 merged 1 commit intomainfrom
fix-vulnerabilities
Jan 29, 2026
Merged

build(deps-dev): Bump tar from 7.5.6 to 7.5.7#1288
d3xter666 merged 1 commit intomainfrom
fix-vulnerabilities

Conversation

@d3xter666
Copy link
Copy Markdown
Member

Resolves alerts for several security advisories such as: GHSA-34x7-hfp2-rc4v

As per our assessment those vulnerabilities are not exploitable in the context of UI5 CLI. The affected versions of tar are used in dev dependencies only.

Resolves alerts for several security advisories such as:
GHSA-34x7-hfp2-rc4v

As per our assessment those vulnerabilities are not exploitable in the context of UI5 CLI.
The affected versions of tar are used in dev dependencies only.
@d3xter666 d3xter666 requested a review from a team January 29, 2026 13:21
@coveralls
Copy link
Copy Markdown

Coverage Status

coverage: 94.337% (-0.01%) from 94.35%
when pulling f043551 on fix-vulnerabilities
into 13c37ce on main.

@d3xter666 d3xter666 merged commit 845c2d2 into main Jan 29, 2026
30 checks passed
@d3xter666 d3xter666 deleted the fix-vulnerabilities branch January 29, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants