Skip to content

Commit 2eca33f

Browse files
antonisclaude
andcommitted
chore(deps): Update tar to 7.5.7 to fix security vulnerability
Fixes high severity vulnerability in tar 7.5.6: - CVE: Arbitrary File Creation/Overwrite via Hardlink Path Traversal Added resolution to force tar@^7.5.7 which includes the security patch. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
1 parent b2da380 commit 2eca33f

2 files changed

Lines changed: 8 additions & 76 deletions

File tree

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,8 @@
6161
"resolutions": {
6262
"appium-chromedriver@npm:5.6.73/@xmldom/xmldom": "0.8.10",
6363
"form-data": "4.0.4",
64-
"tar-fs": "^3.1.1"
64+
"tar-fs": "^3.1.1",
65+
"tar": "^7.5.7"
6566
},
6667
"version": "0.0.0",
6768
"name": "sentry-react-native",

yarn.lock

Lines changed: 6 additions & 75 deletions
Original file line numberDiff line numberDiff line change
@@ -15778,13 +15778,6 @@ __metadata:
1577815778
languageName: node
1577915779
linkType: hard
1578015780

15781-
"chownr@npm:^2.0.0":
15782-
version: 2.0.0
15783-
resolution: "chownr@npm:2.0.0"
15784-
checksum: c57cf9dd0791e2f18a5ee9c1a299ae6e801ff58fee96dc8bfd0dcb4738a6ce58dd252a3605b1c93c6418fe4f9d5093b28ffbf4d66648cb2a9c67eaef9679be2f
15785-
languageName: node
15786-
linkType: hard
15787-
1578815781
"chownr@npm:^3.0.0":
1578915782
version: 3.0.0
1579015783
resolution: "chownr@npm:3.0.0"
@@ -20354,15 +20347,6 @@ __metadata:
2035420347
languageName: node
2035520348
linkType: hard
2035620349

20357-
"fs-minipass@npm:^2.0.0":
20358-
version: 2.1.0
20359-
resolution: "fs-minipass@npm:2.1.0"
20360-
dependencies:
20361-
minipass: "npm:^3.0.0"
20362-
checksum: 1b8d128dae2ac6cc94230cc5ead341ba3e0efaef82dab46a33d171c044caaa6ca001364178d42069b2809c35a1c3c35079a32107c770e9ffab3901b59af8c8b1
20363-
languageName: node
20364-
linkType: hard
20365-
2036620350
"fs-minipass@npm:^3.0.0":
2036720351
version: 3.0.3
2036820352
resolution: "fs-minipass@npm:3.0.3"
@@ -26240,21 +26224,14 @@ __metadata:
2624026224
languageName: node
2624126225
linkType: hard
2624226226

26243-
"minipass@npm:^5.0.0":
26244-
version: 5.0.0
26245-
resolution: "minipass@npm:5.0.0"
26246-
checksum: 425dab288738853fded43da3314a0b5c035844d6f3097a8e3b5b29b328da8f3c1af6fc70618b32c29ff906284cf6406b6841376f21caaadd0793c1d5a6a620ea
26247-
languageName: node
26248-
linkType: hard
26249-
2625026227
"minipass@npm:^5.0.0 || ^6.0.2 || ^7.0.0, minipass@npm:^7.0.2, minipass@npm:^7.0.3, minipass@npm:^7.0.4, minipass@npm:^7.1.2":
2625126228
version: 7.1.2
2625226229
resolution: "minipass@npm:7.1.2"
2625326230
checksum: 2bfd325b95c555f2b4d2814d49325691c7bee937d753814861b0b49d5edcda55cbbf22b6b6a60bb91eddac8668771f03c5ff647dcd9d0f798e9548b9cdc46ee3
2625426231
languageName: node
2625526232
linkType: hard
2625626233

26257-
"minizlib@npm:^2.1.1, minizlib@npm:^2.1.2":
26234+
"minizlib@npm:^2.1.2":
2625826235
version: 2.1.2
2625926236
resolution: "minizlib@npm:2.1.2"
2626026237
dependencies:
@@ -26264,15 +26241,6 @@ __metadata:
2626426241
languageName: node
2626526242
linkType: hard
2626626243

26267-
"minizlib@npm:^3.0.1":
26268-
version: 3.0.2
26269-
resolution: "minizlib@npm:3.0.2"
26270-
dependencies:
26271-
minipass: ^7.1.2
26272-
checksum: 493bed14dcb6118da7f8af356a8947cf1473289c09658e5aabd69a737800a8c3b1736fb7d7931b722268a9c9bc038a6d53c049b6a6af24b34a121823bb709996
26273-
languageName: node
26274-
linkType: hard
26275-
2627626244
"minizlib@npm:^3.1.0":
2627726245
version: 3.1.0
2627826246
resolution: "minizlib@npm:3.1.0"
@@ -26300,7 +26268,7 @@ __metadata:
2630026268
languageName: node
2630126269
linkType: hard
2630226270

26303-
"mkdirp@npm:^1.0.3, mkdirp@npm:^1.0.4":
26271+
"mkdirp@npm:^1.0.4":
2630426272
version: 1.0.4
2630526273
resolution: "mkdirp@npm:1.0.4"
2630626274
bin:
@@ -26309,15 +26277,6 @@ __metadata:
2630926277
languageName: node
2631026278
linkType: hard
2631126279

26312-
"mkdirp@npm:^3.0.1":
26313-
version: 3.0.1
26314-
resolution: "mkdirp@npm:3.0.1"
26315-
bin:
26316-
mkdirp: dist/cjs/src/bin.js
26317-
checksum: 972deb188e8fb55547f1e58d66bd6b4a3623bf0c7137802582602d73e6480c1c2268dcbafbfb1be466e00cc7e56ac514d7fd9334b7cf33e3e2ab547c16f83a8d
26318-
languageName: node
26319-
linkType: hard
26320-
2632126280
"modify-values@npm:^1.0.1":
2632226281
version: 1.0.1
2632326282
resolution: "modify-values@npm:1.0.1"
@@ -32360,44 +32319,16 @@ __metadata:
3236032319
languageName: node
3236132320
linkType: hard
3236232321

32363-
"tar@npm:6.2.1, tar@npm:^6.1.11, tar@npm:^6.2.1":
32364-
version: 6.2.1
32365-
resolution: "tar@npm:6.2.1"
32366-
dependencies:
32367-
chownr: "npm:^2.0.0"
32368-
fs-minipass: "npm:^2.0.0"
32369-
minipass: "npm:^5.0.0"
32370-
minizlib: "npm:^2.1.1"
32371-
mkdirp: "npm:^1.0.3"
32372-
yallist: "npm:^4.0.0"
32373-
checksum: f1322768c9741a25356c11373bce918483f40fa9a25c69c59410c8a1247632487edef5fe76c5f12ac51a6356d2f1829e96d2bc34098668a2fc34d76050ac2b6c
32374-
languageName: node
32375-
linkType: hard
32376-
32377-
"tar@npm:^7.4.3":
32378-
version: 7.4.3
32379-
resolution: "tar@npm:7.4.3"
32380-
dependencies:
32381-
"@isaacs/fs-minipass": ^4.0.0
32382-
chownr: ^3.0.0
32383-
minipass: ^7.1.2
32384-
minizlib: ^3.0.1
32385-
mkdirp: ^3.0.1
32386-
yallist: ^5.0.0
32387-
checksum: 8485350c0688331c94493031f417df069b778aadb25598abdad51862e007c39d1dd5310702c7be4a6784731a174799d8885d2fde0484269aea205b724d7b2ffa
32388-
languageName: node
32389-
linkType: hard
32390-
32391-
"tar@npm:^7.5.2":
32392-
version: 7.5.6
32393-
resolution: "tar@npm:7.5.6"
32322+
"tar@npm:^7.5.7":
32323+
version: 7.5.7
32324+
resolution: "tar@npm:7.5.7"
3239432325
dependencies:
3239532326
"@isaacs/fs-minipass": ^4.0.0
3239632327
chownr: ^3.0.0
3239732328
minipass: ^7.1.2
3239832329
minizlib: ^3.1.0
3239932330
yallist: ^5.0.0
32400-
checksum: 3d0c4940b78908cf7a796fcc7c05a804f5019e74526cbce7a094d381983393a994ae7521830f36156c369bc8a1e2da0dba8f41e9eb8eb090fce1c2a2025bc505
32331+
checksum: 82fa04804b6cae4c0b46b84e97a08c39e1c17bb959350baa32d139bcf5e1fc7ebc3ceb72465dd3e2e311992386ecc13599a257d5672158490ceb9464146d5573
3240132332
languageName: node
3240232333
linkType: hard
3240332334

0 commit comments

Comments
 (0)