Skip to content

deps: Bump tar from 6.2.1 to 7.5.6#200

Merged
matz3 merged 1 commit into
mainfrom
override-tar-version
Jan 23, 2026
Merged

deps: Bump tar from 6.2.1 to 7.5.6#200
matz3 merged 1 commit into
mainfrom
override-tar-version

Conversation

@matz3
Copy link
Copy Markdown
Member

@matz3 matz3 commented Jan 23, 2026

Resolves alerts for several security advisories such as: GHSA-r6q2-hw4h-h46w GHSA-8qq5-rm4j-mr97

As per our assessment those vulnerabilities are not exploitable in the context of UI5 MCP server.

The override for tar is specifically defined where necessary in order to not downgrade tar in case a new major version is being used by other dependencies.

This commit also includes a minor bump of lodash to address GHSA-xxjr-mmjv-4gpg and diff to address GHSA-73rr-hh4g-fpgx which are also not exploitable in the context of UI5 MCP server and only used as a development dependency.

Resolves alerts for several security advisories such as:
GHSA-r6q2-hw4h-h46w
GHSA-8qq5-rm4j-mr97

As per our assessment those vulnerabilities are not exploitable in the context of UI5 MCP server.

The override for tar is specifically defined where necessary in order to not downgrade tar
in case a new major version is being used by other dependencies.

This commit also includes a minor bump of lodash to address GHSA-xxjr-mmjv-4gpg
and diff to address GHSA-73rr-hh4g-fpgx which are also not exploitable in the
context of UI5 MCP server and only used as a development dependency.
@matz3 matz3 requested a review from a team January 23, 2026 13:42
@coveralls
Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 21288204920

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 82.495%

Totals Coverage Status
Change from base Build 21253294536: 0.0%
Covered Lines: 1146
Relevant Lines: 1292

💛 - Coveralls

@matz3 matz3 merged commit 87ef280 into main Jan 23, 2026
18 checks passed
@matz3 matz3 deleted the override-tar-version branch January 23, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants