Skip to content

fix: bump node-tar from 7.5.11 to 7.5.22 to resolve dependabot alerts - #381

Open
sbouchet wants to merge 1 commit into
eclipse-che:mainfrom
sbouchet:fix/bump-node-tar-7.5.22
Open

fix: bump node-tar from 7.5.11 to 7.5.22 to resolve dependabot alerts#381
sbouchet wants to merge 1 commit into
eclipse-che:mainfrom
sbouchet:fix/bump-node-tar-7.5.22

Conversation

Fixes 5 open dependabot alerts (CVEs) including a critical
decompression DoS and a high-severity infinite loop vulnerability.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant