Skip to content

Conversation

@pyymenta
Copy link
Contributor

@pyymenta pyymenta commented Jul 23, 2019

Fix security update from tar, using remediation suggestion since dependabot couldn't handle the update by itself.

Error description

A vulnerability was found in node-tar before version 4.4.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

https://github.com/getninjas/tagmanager-wrap/network/alert/package-lock.json/tar/open

CHANGELOG 📝

  • Add tar as dev dependency

PRINTS 🖼️

@pyymenta pyymenta added security dependencies Pull requests that update a dependency file high severity labels Jul 23, 2019
@pyymenta pyymenta merged commit 082bf32 into master Jul 24, 2019
@pyymenta pyymenta deleted the bump-tar-2.2.2 branch July 24, 2019 18:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file high severity security

Development

Successfully merging this pull request may close these issues.

4 participants