Skip to content

[7.115.x] backport CVEs fixes from main#349

Open
sbouchet wants to merge 8 commits intoeclipse-che:7.115.xfrom
sbouchet:7.115.x
Open

[7.115.x] backport CVEs fixes from main#349
sbouchet wants to merge 8 commits intoeclipse-che:7.115.xfrom
sbouchet:7.115.x

Conversation

@sbouchet
Copy link
Copy Markdown
Contributor

No description provided.

sbouchet and others added 7 commits March 3, 2026 17:11
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
- Fixes CRW-10244, CRW-10310

Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
- This PR fixes GHSA-9ppj-qmqm-q256: Symlink Path Traversal via
  Drive-Relative Linkpath
- tar version is updated to 7.5.11
- Fixes CRW-10348

Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Bumping css-loader and style-loader to a more recent version

Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
css-loader 5.x introduces @types/json-schema as a transitive dependency,
which triggers a crash in TypeScript 3.4.5 (__spreadArrays not defined).
Upgrade typescript to 4.9.5 and ts-loader to 8.4.0 for compatibility.

Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Unplanned Tasks

Development

Successfully merging this pull request may close these issues.

1 participant