Skip to content

Fix CVE-2026-59874#266

Open
TamarW0 wants to merge 5 commits into
mainfrom
APPENG-5680
Open

Fix CVE-2026-59874#266
TamarW0 wants to merge 5 commits into
mainfrom
APPENG-5680

Conversation

@TamarW0

@TamarW0 TamarW0 commented Jul 12, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@vbelouso

vbelouso commented Jul 12, 2026

Copy link
Copy Markdown
Collaborator

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@TamarW0

TamarW0 commented Jul 15, 2026

Copy link
Copy Markdown
Collaborator Author

/retest

@zvigrinberg zvigrinberg left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @TamarW0 ,

The change upgrade the node 26 version correctly, but it's overkill, and complicate the build on the downstream konflux repositories, and you need only to bump the version of node-tar to 7.5.18 , few comments in addition:

  1. The CVE is only opened for the agent repository , not for the client.
  2. Please add to the CVE description the Jira Ticket.
  3. Please change the PR Title - it's misleading, you don't "remove" the CVE, you fix/remediate it and eliminate its attach vector.
  4. Please conduct a small/quick sanity check on the client due to the sharp Node version bump.

Thank you.

@TamarW0
TamarW0 requested a review from rhartuv as a code owner July 21, 2026 00:35
@TamarW0 TamarW0 changed the title remove CVE-2026-59874 Fix CVE-2026-59874 Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants