Commit f6fa5a1
committed
chore: upgrade tar to ^7.5.20 to address CVE-2026-59873
Refreshed the yarn.lock entry for the transitive `tar` dependency
(pulled in via node-gyp and cacache) from 7.5.16 to 7.5.20. The existing
^7.4.3 range already admitted the patched release, so no package.json
change was needed.
Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1553/sourcebot-devsourcebot-cve-2026-59873-tar-node-tar-denial-of-service#agent-session-e185a0a5)
Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>1 parent fbfea1a commit f6fa5a1
2 files changed
Lines changed: 6 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
10 | 13 | | |
11 | 14 | | |
12 | 15 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22857 | 22857 | | |
22858 | 22858 | | |
22859 | 22859 | | |
22860 | | - | |
22861 | | - | |
| 22860 | + | |
| 22861 | + | |
22862 | 22862 | | |
22863 | 22863 | | |
22864 | 22864 | | |
22865 | 22865 | | |
22866 | 22866 | | |
22867 | 22867 | | |
22868 | | - | |
| 22868 | + | |
22869 | 22869 | | |
22870 | 22870 | | |
22871 | 22871 | | |
| |||
0 commit comments