Skip to content

testcontainers depends on vulnerable versions of tar-fs #1106

@juliette-derancourt

Description

@juliette-derancourt

Dependabot brought to my attention that tar-fs introduces security vulnerabilities for versions prior to 3.0.9, 2.1.3, and 1.16.5 (CVE).

According to npm why tar-fs, testcontainers@11.5.1 transitively depends on versions 3.0.6 and 2.0.1.

Could this dependency be upgraded?

Metadata

Metadata

Assignees

No one assigned

    Labels

    triageInvestigation required

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions