Commit 57a5f0a
chore(deps): bump tar to ^7.5.8
Updates existing tar resolution from ^7.5.7 to ^7.5.8, patching
arbitrary file read/write via hardlink target escape through symlink
chain during extraction (affected range: < 7.5.8, resolves to 7.5.9).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent cb7404a commit 57a5f0a
2 files changed
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
65 | | - | |
| 65 | + | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32800 | 32800 | | |
32801 | 32801 | | |
32802 | 32802 | | |
32803 | | - | |
32804 | | - | |
32805 | | - | |
| 32803 | + | |
| 32804 | + | |
| 32805 | + | |
32806 | 32806 | | |
32807 | 32807 | | |
32808 | 32808 | | |
32809 | 32809 | | |
32810 | 32810 | | |
32811 | 32811 | | |
32812 | | - | |
| 32812 | + | |
32813 | 32813 | | |
32814 | 32814 | | |
32815 | 32815 | | |
| |||
0 commit comments