Skip to content

Commit 17c8b9f

Browse files
[TOOL-5898] Update tar to >=7.5.4 to resolve CVE-2026-23950 (#14)
Added resolutions to force tar>=7.5.4 since upstream @yarnpkg/core still requires tar@^6 with no patched v6 release available.
1 parent 416ed37 commit 17c8b9f

2 files changed

Lines changed: 8 additions & 44 deletions

File tree

package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,5 +73,8 @@
7373
"ts-jest": "^29.1.1",
7474
"typescript": "~5.1.6"
7575
},
76+
"resolutions": {
77+
"tar": "^7.5.4"
78+
},
7679
"packageManager": "yarn@4.0.0"
7780
}

yarn.lock

Lines changed: 5 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -4502,13 +4502,6 @@ __metadata:
45024502
languageName: node
45034503
linkType: hard
45044504

4505-
"chownr@npm:^2.0.0":
4506-
version: 2.0.0
4507-
resolution: "chownr@npm:2.0.0"
4508-
checksum: 594754e1303672171cc04e50f6c398ae16128eb134a88f801bf5354fd96f205320f23536a045d9abd8b51024a149696e51231565891d4efdab8846021ecf88e6
4509-
languageName: node
4510-
linkType: hard
4511-
45124505
"chownr@npm:^3.0.0":
45134506
version: 3.0.0
45144507
resolution: "chownr@npm:3.0.0"
@@ -5330,15 +5323,6 @@ __metadata:
53305323
languageName: node
53315324
linkType: hard
53325325

5333-
"fs-minipass@npm:^2.0.0":
5334-
version: 2.1.0
5335-
resolution: "fs-minipass@npm:2.1.0"
5336-
dependencies:
5337-
minipass: "npm:^3.0.0"
5338-
checksum: 703d16522b8282d7299337539c3ed6edddd1afe82435e4f5b76e34a79cd74e488a8a0e26a636afc2440e1a23b03878e2122e3a2cfe375a5cf63c37d92b86a004
5339-
languageName: node
5340-
linkType: hard
5341-
53425326
"fs-minipass@npm:^3.0.0":
53435327
version: 3.0.2
53445328
resolution: "fs-minipass@npm:3.0.2"
@@ -6913,7 +6897,7 @@ __metadata:
69136897
languageName: node
69146898
linkType: hard
69156899

6916-
"minizlib@npm:^2.1.1, minizlib@npm:^2.1.2":
6900+
"minizlib@npm:^2.1.2":
69176901
version: 2.1.2
69186902
resolution: "minizlib@npm:2.1.2"
69196903
dependencies:
@@ -6932,15 +6916,6 @@ __metadata:
69326916
languageName: node
69336917
linkType: hard
69346918

6935-
"mkdirp@npm:^1.0.3":
6936-
version: 1.0.4
6937-
resolution: "mkdirp@npm:1.0.4"
6938-
bin:
6939-
mkdirp: bin/cmd.js
6940-
checksum: 46ea0f3ffa8bc6a5bc0c7081ffc3907777f0ed6516888d40a518c5111f8366d97d2678911ad1a6882bf592fa9de6c784fea32e1687bb94e1f4944170af48a5cf
6941-
languageName: node
6942-
linkType: hard
6943-
69446919
"ms@npm:2.1.2":
69456920
version: 2.1.2
69466921
resolution: "ms@npm:2.1.2"
@@ -8045,30 +8020,16 @@ __metadata:
80458020
languageName: node
80468021
linkType: hard
80478022

8048-
"tar@npm:^6.0.5, tar@npm:^6.1.11, tar@npm:^6.1.2":
8049-
version: 6.2.1
8050-
resolution: "tar@npm:6.2.1"
8051-
dependencies:
8052-
chownr: "npm:^2.0.0"
8053-
fs-minipass: "npm:^2.0.0"
8054-
minipass: "npm:^5.0.0"
8055-
minizlib: "npm:^2.1.1"
8056-
mkdirp: "npm:^1.0.3"
8057-
yallist: "npm:^4.0.0"
8058-
checksum: a5eca3eb50bc11552d453488344e6507156b9193efd7635e98e867fab275d527af53d8866e2370cd09dfe74378a18111622ace35af6a608e5223a7d27fe99537
8059-
languageName: node
8060-
linkType: hard
8061-
8062-
"tar@npm:^7.4.3":
8063-
version: 7.5.7
8064-
resolution: "tar@npm:7.5.7"
8023+
"tar@npm:^7.5.4":
8024+
version: 7.5.9
8025+
resolution: "tar@npm:7.5.9"
80658026
dependencies:
80668027
"@isaacs/fs-minipass": "npm:^4.0.0"
80678028
chownr: "npm:^3.0.0"
80688029
minipass: "npm:^7.1.2"
80698030
minizlib: "npm:^3.1.0"
80708031
yallist: "npm:^5.0.0"
8071-
checksum: 51f261afc437e1112c3e7919478d6176ea83f7f7727864d8c2cce10f0b03a631d1911644a567348c3063c45abdae39718ba97abb073d22aa3538b9a53ae1e31c
8032+
checksum: e870beb1b2477135ca2abe86b2d18f7b35d0a4e3a37bbc523d3b8f7adca268dfab543f26528a431d569897f8c53a7cac745cdfbc4411c2f89aeeacc652b81b0a
80728033
languageName: node
80738034
linkType: hard
80748035

0 commit comments

Comments
 (0)